Self-Hosted · The Product

Your data stays yours.

OPSQAI is installed on the customer's Windows Server. Data, documents, embeddings, users and AI provider all live inside the customer's environment. OPSQAI Cloud is used only when the installation needs it — for license activation, update checks and support. Nothing operational ever crosses the boundary.

Data flow

Everything flows inside the boundary.

The diagram below is the entire operational path. Only license heartbeat and update checks cross the boundary — and they carry no operational content.

Windows Server

Customer-owned host, inside the customer's network.

OPSQAI Platform

Windows services managed by WinSW. The product itself.

Local PostgreSQL

Relational store. Users, chats, documents, audit — all local.

pgvector

Vector index inside PostgreSQL. Embeddings never leave.

Local storage

Documents on the customer's filesystem or object storage.

Customer's AI provider

OpenAI, Azure OpenAI, Ollama or compatible endpoint.

What crosses the boundary
  • Signed license activation
  • Update manifest checks
  • Support (opt-in, initiated by the customer)
What never leaves
  • Documents, SOPs, procedures
  • Embeddings and vector index
  • Chat messages and AI audit records
  • Users, roles and organization configuration

For People.Not Without Them.

Six pillars

Sovereign by construction.

Runs on Windows Server

Windows Server 2019/2022. Installer provisions PostgreSQL, storage, services and Caddy. WinSW manages every service. No Docker, no Kubernetes, no Linux.

Local PostgreSQL + pgvector

The database and vector store live inside the customer's Windows environment. Documents, chunks and embeddings never leave.

Customer-owned AI provider

OpenAI, Azure OpenAI, Ollama, OpenRouter or any OpenAI-compatible endpoint. The customer owns the account and the keys.

Signed everything

Signed Windows installer, signed release manifests, signed license bundles. Every artifact is cryptographically verifiable.

Single tenant by design

Every install is one customer, one workspace, one boundary. Nothing is shared across customers — not databases, not embeddings, not AI keys.

Disaster recovery built in

DR bootstrap tokens, signed backups and documented restore. The customer's ops team can rebuild the installation without OPSQAI in the loop.

System requirements

Enterprise ready.

  • Windows Server 2019 or 2022 (Standard or Datacenter)
  • 8 vCPU · 16 GB RAM · 200 GB SSD minimum
  • Outbound HTTPS to the customer's chosen AI provider (or none, with local models)
  • TLS certificate for the internal domain (Caddy can also issue via ACME)
  • Domain administrator to run the installer (elevated)
Get the signed installer

The install starts here.

Existing customers download from the Customer Portal. New customers, contact us for a licensed evaluation.