PuReAIpureAi
Free scan

Deployment

Run it in our cloud, or entirely in yours

Most platforms in this category are vendor-hosted only. PuReAI can be deployed as EU SaaS, inside your own cloud tenancy, or fully on-premise with an air-gapped option, with the same modules and the same published scoring in every model.

Three deployment models

SaaS, hosted by Reputeo in the EU

The fastest way to start. Reputeo runs the platform, the collectors and the threat graph in EU infrastructure and you use it through the web application.

Where data resides
Scan results, findings and the threat graph are stored in EU infrastructure operated by Reputeo.
Who administers it
Reputeo administers the platform, applies updates and operates the collectors. You administer users, domains and roles inside the tenant.
What leaves the environment
You submit domains and vendor names. PuReAI collects only publicly reachable data about them. No agents are installed and no access to your internal systems is required.

Regulatory concerns addressed

  • EU data residency for organisations that need processing to stay inside the Union.
  • Suitable where the tool itself is not classified as a critical ICT service under DORA.

Private cloud, in your own tenancy

The same platform deployed into a cloud subscription you own, in the region you choose, under your own identity provider and network controls.

Where data resides
All collected data, findings and the graph database live in your cloud account, in your region.
Who administers it
You own the subscription, the keys and the backups. Reputeo supplies the build, upgrades and support under an agreed access model, which can be break-glass only.
What leaves the environment
Outbound traffic goes to public OSINT sources and vulnerability feeds. Nothing about your findings is sent to Reputeo unless you choose to share it for support.

Regulatory concerns addressed

  • DORA ICT third-party dependency: the register entry changes shape when the processing runs in your own environment.
  • NIS2 supply chain measures where an essential entity must keep security telemetry under its own control.
  • Group policies that forbid a supplier holding a consolidated view of the estate.

On-premise, inside your infrastructure

A fully self-contained installation in your own data centre, including an air-gapped option where feeds are imported on a controlled schedule.

Where data resides
Everything stays on hardware you control. Nothing is stored outside your perimeter.
Who administers it
Your team administers the whole stack. Reputeo provides installation packages, signed updates and documented runbooks.
What leaves the environment
In a connected install, only collector traffic to public sources leaves the network. In the air-gapped variant nothing leaves at all, and vulnerability and threat feeds are imported through a controlled transfer.

Regulatory concerns addressed

  • National sovereignty requirements where security data may not leave the country.
  • Public sector and defence procurement rules that exclude vendor-hosted processing.
  • Sectoral supervision that requires the supervised entity to hold and retain the raw evidence itself.

Side by side

The functional differences between the models are operational, not analytical. The modules, the evidence and the score are identical.

DimensionHostedSelf-hosted
Where the data residesSaaS: EU infrastructure operated by Reputeo.Private cloud and on-premise: your tenancy or your data centre, in your region.
Who administers itSaaS: Reputeo operates, you administer the tenant.Private cloud and on-premise: you operate; Reputeo supports under an agreed access model.
What leaves the environmentSaaS: collector traffic to public sources.On-premise air-gapped: nothing; feeds are imported on a controlled schedule.
IdentitySaaS: platform accounts with role-based access.Private cloud and on-premise: your identity provider and your access policy.
UpdatesSaaS: continuous, managed by Reputeo.Private cloud and on-premise: signed release packages applied on your change calendar.
Time to first reportSaaS: same day.Private cloud and on-premise: a scoped installation project.

Why this matters for DORA and NIS2

Deployment is a regulatory question, not only an IT preference.

Under DORA, every ICT third-party arrangement supporting a critical or important function has to be registered, assessed and exit-planned. A platform that holds a consolidated external view of your estate is itself an ICT dependency. Deploying it inside your own environment changes that calculation, and it removes the concentration argument that supervisors raise when several critical functions rely on one hosted vendor.

NIS2 asks essential and important entities to take supply chain security measures proportionate to their risk. Where the entity is expected to retain its own security telemetry, a self-hosted deployment lets the evidence stay under its control while still producing the same dated findings.

See the DORA and NIS2 mapping for the requirement-level detail, and the methodology for how findings become a score.

Questions we get asked

Can PuReAI run without any connection to the vendor?

Yes. The on-premise model includes an air-gapped variant where the platform never contacts Reputeo. Vulnerability and threat feeds are imported through a controlled transfer on a schedule you set.

Does the scoring change between deployment models?

No. The Company Risk Score uses the same published weights in every model: Compromises 0.4, Issues 0.3, Supply Chain 0.2, Exposure 0.1.

Do we need to install agents on our systems?

No. PuReAI is an outside-in platform. It collects publicly reachable data about domains you nominate, so there is nothing to install on the assets themselves.

Which model do regulated entities usually choose?

It depends on how the tool is classified internally. Entities that treat exposure data as supervised evidence tend to choose private cloud or on-premise; the rest start on EU SaaS.

Tell us where it has to run

Bring your residency, procurement and supervision constraints to the call and we will map them to a model.