Private deployment
Dokus. Inside your boundary.
A commissioned deployment on approved infrastructure, maintained with your authorisation.
Every Dokus deployment reads and classifies your documents locally. Private deployment places the complete system — including how the optional assistant is configured — under your control.
Who needs it
A practice holding the records of hundreds of clients is the clearest case: the sensitivity is not yours, it is your clients'. Beyond that, the requirement is usually already written down — in a client contract that forbids external processing, in a security questionnaire from a larger client, in what your professional body expects of you, or in your own policy on what may be sent to an AI service.
Typically 25 to 200 people: enough infrastructure to run it, enough sensitivity to need it. If you don't need to own the boundary, hosted Dokus is the better answer.
What stays, and what crosses.
Open a connection to see what crosses it and why. Each one is part of the deployment’s design, agreed before rollout.
Inside your environment
- Documents
- Financial database
- Document processing
- Local extraction
- Embeddings and retrieval
- Activity history
- Backups
Crosses a controlled boundary
PeppolCertified access point
E-invoices go out and come in through a certified access point. Transmission cannot run inside any network — that is how Peppol works, in every deployment.
Bank connectionWhen enabled
Account movements arrive over a PSD2 connection you choose to switch on. Statements can be uploaded instead, and then nothing crosses here.
Optional assistantAs configured
Documents are read and classified inside your environment. How the optional assistant is configured in a private deployment is settled with you before rollout.
Software updatesThe same releases as hosted
The same build as hosted Dokus, on the same cycle. You choose when to apply a release.
Support accessCustomer authorised
Maintenance happens on your authorisation, inside your network policy. Maintained does not mean a standing door into your network.
TelemetryDefined by deployment policy
What, if anything, is reported back is set in the deployment policy you agree. Nothing is assumed.
Peppol transmission requires a certified access point. It cannot run locally, in any deployment, and nothing here will claim otherwise. The left column is the part that can.
Who operates it
The usual price of on-premise is becoming the operator. Here the engagement carries it end to end — and all of it is the same team.
- Releases
- The same build as hosted, on the same cycle — you choose when to apply. No private fork to fall behind on.
- Models
- The extraction profile is ours to keep current. A quality regression is our problem to fix, not a setting you inherit.
- Support
- Support email is answered within the hour, 08:00–20:00 CET, except Belgian public holidays and announced absences, never later than the same day — by the people who build Dokus, not a ticket queue.
- Access
- On your authorisation, inside your network policy. Maintained does not mean a standing door into your network.
Deployment options
The same Dokus. A private deployment runs the same build as the hosted product, on the same release cycle. Updates and support are part of the engagement, not a separate contract.
Your infrastructure
Deployed on hardware you approve.
Dokus installs and maintains the stack on your servers, in your private virtualisation environment, or in the datacentre your IT partner already runs for you.
Managed deployment
A dedicated environment, operated for you.
A standardised deployment supplied, configured and maintained by Dokus, inside your network boundary.
Indicative sizing
The models run beside the records, so the memory that holds them is the specification. Everything else follows your document volume, and we size it with you before anything is ordered.
- Apple
- Mac Studio, M4 Max (16-core CPU, 40-core GPU), 128 GB unified memory
- Windows or Linux
- A workstation GPU with 96 GB VRAM (NVIDIA RTX PRO 6000 Blackwell), or two 48 GB cards
- Storage and CPU
- Sized to your document volume
Indicative, not a bill of materials. If your existing hardware already clears it, we deploy on that.
Commissioning and annual operation
A private deployment is commissioned, not subscribed to. We design the boundary, deploy the system, maintain the models and releases, and stand behind its operation.
One time
Commissioning
Architecture, installation, the security boundary, backup strategy, and production validation.
Annual
Operation
Releases on the hosted cycle, upkeep of the models, security responsibility, and support from the people who build Dokus. Not a licence to run the software yourself.
No per-seat pricing. No metered AI.
Scope decides the price, so we quote after the first conversation.
If Dokus stops, your system does not.
Your records leave whenever you want them, in the formats your accountant already reads. A private deployment keeps running on your own infrastructure — what stops is new releases, not the system. Source-code escrow is available where a contract requires it.
The ones that decide it.
Is a private deployment air-gapped?
Can we run our own models?
Do we need a GPU?
Why not just use a European cloud?
What happens when Dokus updates?
Our staff already paste client data into public AI tools. Does this help?
Start a conversation
Tell us what your environment requires.
We answer within one working day. If private deployment is the wrong answer for you, we will say so.
Your financial reality stays yours.
Storage, processing and retrieval inside your boundary. Every connection that crosses it is explicit, and configured with you.