New Sakshi sandboxes are live. Try agent governance on synthetic data, in your browser. Get a sandboxarrow_forward
witnessDeployment

Runs where your data lives.

A governance product you can't trust is a contradiction. So Sakshi is single-tenant and installs inside your environment. Three ways to deploy, one guarantee: your evidence never leaves your control, and we could not hand it over if compelled.

Deployment options

Three ways to deploy, the same isolation

Every model is single-tenant. Pick the one that fits your platform team and your regulator, not the other way around.

cloud

Your VPC or cloud

Deploy into your own AWS, Azure, or GCP account with a Helm chart or docker-compose. One-command install, upgrades on your schedule, nightly evidence backups. You hold the keys and the data.

  • Helm / docker-compose
  • Your cloud account, your network
  • You control upgrades
dns

On-premise or air-gapped

For restricted and air-gapped environments. Nothing calls home; the platform, the models, and the evidence stay entirely within your network boundary. Bring your own container registry.

  • No outbound calls required
  • Private registry supported
  • Full network isolation
public

Rota-managed, in India

For teams without a platform crew. A single-tenant instance in an India region, operated by us with the same isolation and residency guarantees. You still own the evidence; we still cannot see it.

  • Managed operations
  • India region
  • Same single-tenant isolation

Data residency

India by default, yours by design

Evidence is written where you deploy, and it stays there. India residency is the default, PII is tokenized before anything is stored, and the vendor never has a path to your data. The deployment model is the privacy model.

We never see your evidence, and could not hand it over if compelled. That is a property of where the software runs, not a promise on a slide.

Residency posture
IN YOUR ENVIRONMENT
Data locationIndia (default)
TenancySingle-tenant
PII at restTokenized
Vendor accessNone
BackupsNightly, local

Install & operate

Simple to stand up, simple to run

rocket_launch

One-command install

Helm or docker-compose brings up the full stack: registry, decision chain, policy engine, and console. A generated bootstrap key writes the first evidence record before you finish your coffee.

backup

Backups & upgrades

Nightly evidence backups by default, kept local. Upgrades run on your schedule, and the chain makes any gap or tamper self-evident, so you can prove continuity.

monitoring

Observability

A liveness endpoint and Prometheus metrics ship with every install. Point your own monitoring at them; nothing is phoned home to us.

verified

Self-verifying

The evidence chain recomputes every hash on demand, so an auditor can confirm integrity without trusting Rotavision at all. See the architecture.

One host is one install: container and volume names are pinned, single-tenant by design. Egress-blocked environments are supported; the only online extras (like hosted API-docs assets) degrade gracefully.

Deploy it where your regulator expects

Talk to us about your environment, or try a synthetic-data sandbox first.