Certyo/v1
Back to blog
Buyer GuideMay 19, 2026 · 8 min read

Self-hosted or managed: how to choose your integrity deployment model

The verification math is identical either way. The decision is about data residency, key custody, operational burden, and audit scope. Here is a neutral framework for choosing — before you ever talk to sales.

Once a team accepts that they need independently verifiable record integrity, the next question is operational, not cryptographic: do we run it ourselves or have it run for us? Both models produce the same proof — a Merkle root anchored to a public chain that anyone can verify. What differs is who holds the keys, where the data sits, and who carries the pager. This guide lays out the trade-offs so you arrive at a procurement conversation already knowing which model fits.

01

The two models in one paragraph each

Self-hosted means the integrity platform runs inside your own infrastructure — your Kubernetes cluster, your cloud account or data centre, your key management service. You operate it; the vendor licenses the software and supports you. Managed means the vendor runs the platform as a dedicated, single-tenant instance on their infrastructure, and you integrate against an API. In both cases the anchoring target is the same public chain, and the proofs are verifiable by third parties either way.

The instinct that self-hosted is 'more secure' and managed is 'easier' is too coarse to decide on. The real decision turns on four concrete axes, and for most organisations one or two of them dominate.

02

The four axes that actually decide it

Score your situation on each. If any one is a hard constraint, it usually settles the question on its own:

  • Data residency — if regulation or contract requires that record data never leaves your environment or a specific jurisdiction, self-hosted removes the question entirely. Managed can often meet residency with regional dedicated instances, but it becomes a clause to negotiate rather than an architectural fact.
  • Key custody — who holds the signing key is the real security boundary. Self-hosted keeps it in your KMS under your IAM. Managed holds it in an isolated, single-tenant KMS on your behalf. If 'we must be the only party that can ever hold the key' is non-negotiable, that points to self-hosted.
  • Operational capacity — self-hosted means you run a signer with high availability, manage key rotation, and pin proof packages. If you do not have a platform team with spare capacity, managed turns those obligations into someone else's SLA.
03

What the price difference reflects

The two models are priced differently because the cost structure is different, not because one is a discount on the other. Managed includes the infrastructure, uptime, and operational labour. Self-hosted is a license against software you run on hardware you already pay for.

$24K+
Managed, starting / yr
$90K+
Self-hosted, starting / yr
Same
Proof, either model

Self-hosted carries a higher list price precisely because it does not include the operations you take on yourself — and because the buyers who require it are typically the ones with the strictest residency and custody mandates. If your driver is purely cost, managed is almost always the lower total cost of ownership once you price your own operational labour honestly.

04

How the decision flows in practice

For most teams the path is short. Walk the axes in order and stop at the first hard constraint:

Residency mandate?
Key-custody mandate?
Platform team capacity?
Cost sensitivity?
Model is decided

A regulated bank with a 'data stays in our tenant' policy lands on self-hosted before cost ever enters the conversation. A healthcare scale-up that wants the integrity guarantee without standing up another HA service lands on managed and negotiates a BAA. Most organisations are one of these two; the in-between cases are where a real conversation helps.

05

Which profile fits which model

As a rough map — not a rule — the regulated profiles tend to cluster:

  • Self-hosted fitslarge banks, government, and any entity with absolute data-residency or sole-key-custody mandates and a capable platform team.
  • Managed fitsfintech and healthcare scale-ups, audit and compliance teams, and anyone who wants the guarantee without operating another stateful service.
  • Either works formid-market firms with moderate requirements — here the decision is genuinely a cost-and-preference call, and a pilot resolves it fastest.
06

Bring the answer, not the question

Because both models are quote-only, the fastest conversation is the one where you already know your residency and key-custody constraints and your operational capacity. With those three answers in hand, the deployment model is usually obvious within a sentence, and the remaining discussion is about volume and timeline rather than architecture. If you are genuinely between the two, a scoped pilot on the managed instance is the cheapest way to learn what you actually need before committing to running it yourself.

Both models produce the same proof. The decision is not about cryptography — it is about who holds the key, where the data lives, and who carries the pager.

May 19, 2026 · 8 min read

Ready to see this in action?

Request a demo and verify your first record in minutes.

Request demo → See how it works