self-hosted
Your servers. Your code. Your keys.
EnsureFix installs on infrastructure you control as a set of Docker containers. Repositories are cloned inside your boundary, credentials are encrypted on your disk, and the licence is verified on your own machine — never against ours.
Docker
Compose deployment
30
Day full-feature trial
Offline
Licence verification
Yours
Data and credentials
the path
From download to licensed deployment
Six steps, none of which require us to have access to anything of yours.
- 01
Get the bundle
A single directory holding the Docker images, the compose file, the configuration template and the documentation.
Download → - 02
Load and start
docker load, copy the .env template, fill in three secrets and your provider credentials, docker compose up -d.
- 03
30-day evaluation
Starts by itself on first use. Every feature, no key, no sign-up, no call home.
What the trial includes → - 04
Evaluate on real work
Point it at your own repositories and your own tracker. It is the product, not a sandbox.
- 05
Buy a licence
A signed key sized to the seats, repositories and edition you need.
Licensing and pricing → - 06
Activate
Paste the key into Administration → License. Verified locally, effective immediately, no restart.
the boundary
What runs where
The honest version, including the two things that do leave your network — because you configure both.
Inside your boundary
- The dashboard and API
- The worker that plans, writes and commits
- Every database — organisations, users, work, evidence
- Repository clones and working directories
- Your VCS and AI provider credentials, encrypted at rest
- Audit logs and the licence/trial state
Leaves your boundary — by your configuration
- Outbound HTTPS to the AI provider you configure, carrying the code being worked on
- Outbound HTTPS to the VCS you configure, to read repositories and open pull requests
Both are endpoints you choose and credentials you own. Nothing is sent to EnsureFix: the deployment has no telemetry requirement and no licence server to check in with.
offline and air-gapped
What works without a network, and what does not
Worth reading closely before you plan an isolated deployment.
Works fully offline
- Installation. The bundle carries its own images, so there is no registry to pull from and no login.
- Licence activation. Keys are RSA-signed and verified on your server against a public key that ships with the bundle.
- Running licensed. A vendor outage cannot disable your deployment — there is no phone-home and no kill switch.
- Upgrades. Load a newer bundle's images and recreate the containers.
Still needs a route out
The work itself does. EnsureFix reads repositories and calls a model, so it needs to reach your VCS and your AI provider — whether those are on the public internet or inside your own network.
A fully isolated network therefore needs both of those reachable internally. If that is your environment, talk to us before you plan the deployment: we will tell you plainly whether it fits rather than after you have bought it.
Talk about an isolated deploymentrunning it
Day-two operations
The questions a platform team asks after the demo is over.
Backups
Your databases and repository state live under ./data. Backing that up preserves the licence and trial state too — a restore does not reset the evaluation.
Upgrades
Back up, load the new images, docker compose up -d. Compose recreates the containers; ./data is untouched.
Health
The deployment exposes a health endpoint reporting storage and licence state, so your monitoring can see both.
Recovery
The bundle ships a backup-and-restore guide, because the time to read it is not during the incident.
questions
Self-hosting, answered
ready when you are
Install it on your own server
The bundle, the 30-day evaluation, and the documentation to go with them.