On-Premise & Data Residency
Run Claro entirely on your own infrastructure, with data that never has to leave
Claro ships as a full Docker Compose stack, PostgreSQL, Redis, and MinIO included, so regulated institutions can deploy on-premise with per-tenant encryption and no required third-party data egress.
The on-premise stack runs PostgreSQL, Redis, and MinIO alongside the application containers, all inside your own network.
For banks, insurers, and government agencies, where employee data can be hosted is often as important as what a platform does with it. Claro deploys as a complete Docker Compose stack covering the application, PostgreSQL, Redis, and MinIO, so the entire platform, including any object storage for templates, evidence packages, and reports, can run inside your own network with no required third-party data egress. Every table carries row-level tenant isolation, and personally identifiable fields like email addresses are encrypted at rest with AES-256-GCM using a per-tenant data encryption key, with blind indexes so encrypted fields like email can still be searched without ever decrypting the whole column.
Data subject requests are handled two ways, matched to the scope of the request. Crypto-erasure deletes an entire tenant's encryption key, permanently rendering all of that tenant's PII unreadable without touching a single row, for whole-tenant erasure scenarios. Field-level user erasure anonymizes a single user's PII, replacing their email with an encrypted sentinel and nulling other personal fields while leaving a tombstone timestamp, for individual erasure requests. A configurable data retention policy enforces how long data is kept per tenant, run by a scheduled background job rather than a manual cleanup task, and the key provider itself is pluggable, so on-premise deployments manage their own encryption keys via environment variables rather than depending on a cloud KMS.
What you get
Full Docker Compose on-premise stack
PostgreSQL, Redis, MinIO, and the application containers deploy together, so the entire platform, including object storage, can run inside your own network.
Per-tenant AES-256-GCM encryption
Personally identifiable fields are encrypted at rest with a unique data encryption key per tenant, and the application refuses to start without the required encryption keys configured.
Blind indexes for searchable encrypted fields
Fields like email are encrypted at rest but remain searchable through a blind index, so lookups don't require decrypting the whole column.
Crypto-erasure for whole-tenant deletion
Deleting a tenant's data encryption key permanently renders all of that tenant's PII unreadable without touching individual rows, satisfying whole-tenant erasure obligations.
Field-level user erasure
Individual erasure requests anonymize a single user's PII, encrypted sentinel for email, null for other personal fields, with a tombstone timestamp marking when the erasure occurred.
Configurable retention, enforced automatically
A per-tenant retention policy is enforced by a scheduled background job, rather than a manual process someone has to remember to run.
Built for Indonesia
Data residency without giving up cloud convenience
Many Indonesian banks and government agencies are required, or strongly prefer, to keep employee and citizen data inside the country or inside their own infrastructure. Claro was designed on-premise-first: the same codebase that runs as SaaS also runs as a fully self-hosted Docker Compose deployment, with a pluggable key provider so on-prem installs manage encryption keys locally instead of depending on a cloud KMS.
- Full on-premise deployment via Docker Compose, no required third-party data egress
- Pluggable key provider: environment-based keys on-prem, cloud KMS for SaaS
- Crypto-erasure and field-level user erasure satisfy UU PDP (Indonesia's data protection law) data-subject rights
- Configurable, per-tenant data retention enforced automatically
Frequently asked questions
Yes. Claro ships as a full Docker Compose stack, including PostgreSQL, Redis, and MinIO, so it can be deployed entirely on-premise with no required third-party data egress.
Related pages
Risk Scoring & Analytics
A behavior-driven human risk score built from clicks, reports, and training activity, with department views, benchmarking, and board-ready exports.
Learn morePhishing Reporting
A one-click Outlook and Gmail report button that matches reported emails to simulations, rewards reporters, and routes real threats to your admins.
Learn moreVishing Simulation
Branching voice-call simulations with typed script nodes, DTMF-driven flows, and outcome capture that feeds directly into risk scoring and training.
Learn moreSee it running on your own domain
Book a walkthrough with our team and we'll show you this capability configured for your organization's compliance requirements and language needs.
Book a walkthrough