Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Knowledge hub / On-premises

Knowledge hub

On-premises

Software running on hardware you own or control, not a vendor's.

What it means

On-premises means the software runs on machines you own or control, inside your own network, rather than on the vendor's servers. Your data stays beside the rest of your data, and the vendor holds no copy of it.

NIST's definition of cloud computing sorts deployments by who operates the infrastructure and who it serves, which is where the line gets drawn. The middle ground most vendors now offer is a self-hosted agent. A small component in your environment does the sensitive work, and the account and the interface stay with the vendor.

Why it matters

For most software this is a preference. Where source code or regulated data is involved it becomes a requirement, and it decides whether the deal happens at all. Security review boards, banks, health customers and anyone under a data residency rule ask the same thing early. Does anything leave our network?

It also shortens the questionnaire. When nothing leaves, whole sections about vendor storage, retention and sub-processors stop applying. The trade is that you run it, including the machine and the person who notices when it stops.

How it shows up

Ask precise questions. What runs inside our network? What does it send out, how often, and can we watch it? Does it need inbound ports opened, which is the answer that usually ends the conversation? What happens to the data when a job finishes, and how does the component get updated?

The Cyberlop agent runs inside your own network with four outbound calls and no inbound ports, and we publish the full list of what it sends.

Questions people ask

On-premises, answered

Is it on-premise or on-premises?

On-premises is the correct form. A premise is a proposition in an argument; premises are buildings and land.

Nobody will correct you in a meeting, and the singular has become common in marketing, but the plural is what you want in a contract.

Is on-premises the same as self-hosted?

Near enough in everyday use. Self-hosted usually means you run the vendor's software yourself, whether that is on your own hardware or in your own cloud account.

Plenty of vendors publish both options side by side, and the security question is the same in each case: what leaves your boundary?

Is on-premises more secure than cloud?

Not automatically. You take on patching, backups, monitoring and the hardware, and a neglected machine in your own rack is not safer than a well-run managed service.

What it does change is exposure. If the sensitive material never leaves, a breach at the vendor cannot include it.

Is it cheaper than a cloud subscription?

Sometimes, and the comparison is rarely as simple as the licence line. You are adding your own operating costs, and those depend on scale and on how much automation you already have.

Treat any blanket claim in either direction with suspicion, including from us.

What should we ask a vendor offering an on-premises agent?

Get the list of outbound destinations in writing, and ask whether the agent needs any inbound port. Then ask what it holds on disk while a job runs, and what it deletes afterwards.

Then ask how it updates, because an agent nobody patches is a new problem you just installed on your network.

Nothing should leave your network

The Cyberlop agent runs inside your own network with four outbound calls and no inbound ports, and the list of what it sends is published. Ask us for it before you book anything.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.