Choose the boundary you need
Run Kordon in your own infrastructure when you need tighter control over data location, access paths, network exposure, or internal hosting policy.
Kordon can run inside your own infrastructure when policy, data boundary, or deployment requirements rule out vendor-hosted SaaS. If you're evaluating an on-premise GRC platform, you still get the same connected system for risks, controls, tasks, evidence, assets, vendors, and business processes.
On-premises GRC is judged on whether the system still makes security and compliance work operational once it is inside your environment, not on where the software lives.
Run Kordon in your own infrastructure when you need tighter control over data location, access paths, network exposure, or internal hosting policy.
Document the assets, vendors, business processes, risks, and framework requirements that matter to your organisation instead of forcing everything into a generic template.
Link each control to the risks it mitigates and the requirements it satisfies, then operationalise it through recurring tasks owned by the people responsible for the work.
As tasks are completed, evidence accumulates, auditors get clear traceability, and the platform reflects whether your program is working as designed or drifting out of shape. How audit management works in Kordon →
On-prem deployment changes where the platform runs. Kordon keeps the same operating model whether you host it in your own environment or use our cloud deployment.
Deploy Kordon inside the environment you control when internal hosting policy, network segmentation, or customer requirements make vendor-hosted SaaS a bad fit.
Risks, controls, requirements, tasks, evidence, assets, vendors, and business processes stay connected in one place instead of being scattered across spreadsheets and folders.
Kordon turns policies and controls into recurring tasks, ownership, reminders, and evidence so the program keeps running inside your environment instead of turning into static documentation.
Use custom fields, labels, permissions, and structure that reflect how your organisation works instead of reshaping your program around a vendor's default schema. Still comparing categories? See how GRC tools, software, and platforms differ →
Give control owners, risk owners, auditors, and operational stakeholders clear visibility and responsibility without turning the security team into a documentation bottleneck.
API access and automation matter on-premises. Connect Kordon to the rest of your toolchain and keep evidence collection, workflows, and reporting tied into your environment. How GRC engineering works in Kordon →
Data residency is usually what brings people to this page, and both Kordon deployments answer it: the hosted platform runs in Finland or Germany, or you run the whole thing yourself. A self-hosted edition is often a cut-down one, a release behind the hosted version or carrying integrations that quietly route back through the vendor's cloud. Kordon changes the deployment target and nothing else.
| Kordon Cloud | Your own infrastructure | |
|---|---|---|
| Where the data physically sits | Kordon CloudIn the EU, in the country you pick. Choose Finland or Germany when the account is set up, and your data stays in that region. | Your own infrastructureWherever you put it. Data residency stops being a question you have to take a vendor's word on. |
| Object model, interface, permissions | Kordon CloudFull platform | Your own infrastructureThe same platform, at the same version |
| REST API and n8n node | Kordon CloudComplete API, official n8n node | Your own infrastructureSame API, same node. No capability is reserved for the hosted tier. |
| What you run it on | Kordon CloudWe operate it | Your own infrastructureA Docker container on standard Linux infrastructure, configured through environment variables |
| HTTPS | Kordon CloudManaged | Your own infrastructureBuilt into the container, so there is no separate reverse proxy to stand up |
| Single sign-on | Kordon CloudGoogle Workspace, Microsoft Entra, Okta, Keycloak | Your own infrastructureThe same four, built into the container rather than needing an identity proxy alongside it |
| Automated user provisioning | Kordon CloudSCIM 2.0 with Entra, Okta, OneLogin and Google Workspace | Your own infrastructureSame |
| Where evidence files are stored | Kordon CloudManaged by us | Your own infrastructureLocal filesystem, Google Cloud Storage or AWS S3, in a bucket you own |
| Framework content | Kordon CloudISO 27001, SOC 2, NIS2, DORA, E-ITS, ISO 9001, ISO 14001 and hundreds more preloaded, plus your own internal frameworks as custom requirements | Your own infrastructureThe same library, preloaded. One control can satisfy requirements across several frameworks at once. See how framework management works → |
| AI and agents | Kordon CloudBring your own agent. No model is embedded in the platform. Agents connect through the REST API, the official n8n node and purpose-built Kordon skills, using whichever framework you already work in. How agentic GRC works → | Your own infrastructureIdentical, and it is what keeps the boundary intact: because the model is never inside the platform, your agent and its inference can live wherever you need them to, including on hardware inside your own network |
| Upgrades, backups, uptime, capacity | Kordon CloudOur responsibility | Your own infrastructureYours, on your change schedule rather than ours |