# On-Premises Self-Deployment Evidence for Section 3.2

**Evidence date:** September 16, 2026

## Classification contract

- **Yes:** the core governance capability/control plane can be fully customer-managed on-premises or in a private data center.
- **Partial:** only a local data plane, gateway, runtime, connector, or specific edition is self-managed; a material control-plane capability remains hosted or entitlement-dependent.
- **No:** the governance control plane is vendor-hosted cloud/SaaS only.
- **Mixed:** products grouped in one report row differ.

A private endpoint, customer VPC, on-prem connector, or ability to govern on-prem assets does not by itself qualify as self-deployment.

## Verified classifications

| Offering | Result | Evidence summary | Official source |
|---|---|---|---|
| AWS Bedrock AgentCore | No | AWS-managed serverless platform; external/on-prem resource registration is not control-plane self-hosting. | https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/what-is-bedrock-agentcore.html |
| Google Gemini Enterprise Agent Platform | No | Provisioned and licensed through Google Cloud; no customer-installed control plane documented. | https://docs.cloud.google.com/gemini/enterprise/docs/before-you-begin |
| Microsoft Entra Agent ID | No | Entra is a cloud IAM service; third-party agent integration does not move its control plane on-prem. | https://learn.microsoft.com/en-us/entra/fundamentals/what-is-entra |
| Microsoft Agent Governance Toolkit | Yes | Open-source core runs locally/on-prem with no required cloud-vendor dependency. | https://github.com/microsoft/agent-governance-toolkit/blob/main/docs/deployment/README.md |
| Ping Agent Governance | No | Capability of PingOne Advanced Identity Cloud SaaS; connectors do not self-host governance. | https://docs.pingidentity.com/pingoneaic/getting-started/overview.html |
| Cisco AI Defense | Partial | Customer Kubernetes/OpenShift data plane; Cisco-hosted control plane remains in cloud. | https://securitydocs.cisco.com/docs/ai-def/user/130134.dita |
| Palo Alto Prisma AIRS | Partial | Runtime firewall can run on private infrastructure; full AIRS suite is not documented as self-hosted. | https://docs.paloaltonetworks.com/ai-runtime-security/administration/prisma-airs-overview |
| Holistic AI Guardian Agents | No | Covers on-prem environments, but public platform infrastructure is cloud-hosted. | https://www.holisticai.com/trust-center |
| Check Point/Lakera | Partial | AI Guardrails supports on-prem/air-gapped deployment; dashboard and wider agent-security plane do not fully self-host. | https://docs.lakera.ai/docs/selfhosting |
| IBM watsonx.governance | Yes | Software edition runs through customer-managed IBM Software Hub/Cloud Pak for Data; features may differ from SaaS. | https://www.ibm.com/products/watsonx-governance/pricing |
| Salesforce Trust Layer / Agentforce | No | Native Salesforce/Hyperforce hosted platform; no customer-installed control plane documented. | https://www.salesforce.com/platform/agentforce-platform/ |
| Descope Agentic Identity Hub | Partial | Dedicated private cloud is Descope-provisioned; no customer-managed on-prem control plane documented. | https://docs.descope.com/how-to-deploy-to-production/private-cloud |
| Docker MCP Enterprise Gateway | Yes | Air-gapped appliance on private Kubernetes with no outbound dependency. | https://www.docker.com/products/mcp-enterprise-gateway/ |
| Stacklok ToolHive / Enterprise | Yes | OSS core and enterprise control plane install in customer Kubernetes and support air-gapped use. | https://docs.stacklok.com/platform/enterprise-platform/ |
| Lasso MCP Security | Partial | MIT-licensed gateway self-hosts; full commercial management suite is not documented as self-hosted. | https://github.com/lasso-security/mcp-gateway |
| Cerbos | Yes | Local PDP plus documented on-prem Cerbos Hub. | https://www.cerbos.dev/features-benefits-and-use-cases/self-hosted-authorization |
| Permit.io | Partial | Local Edge PDP/data plane; Permit cloud remains the primary control plane. | https://docs.permit.io/concepts/control-plane-and-data-plane |
| Okta Cross App Access | No | Governed through a hosted Okta org; customer-hosted endpoints are not the control plane. | https://developer.okta.com/docs/guides/cross-app-access-xaa/ |
| Oasis Security | No | Contracted as a SaaS cloud-security platform; on-prem references describe managed assets. | https://www.oasis.security/legal/saas-subscription-agreement |
| Credo AI Agent Governor | Partial | Enforcement can run in the local harness; full management/telemetry self-hosting is not publicly documented. | https://www.credo.ai/agent-governor |
| Galileo Agent Control | Yes | Complete OSS server, UI, database-backed control plane, SDKs, and policies can self-host. | https://docs.agentcontrol.dev/core/quickstart |
| NVIDIA NeMo Guardrails | Yes | Library/server and local model integrations can run entirely customer-managed. | https://docs.nvidia.com/nemo/guardrails/more-deployment-options/using-docker |
| Phoenix / AgentOps / LangSmith | Mixed | Phoenix and AgentOps: Yes. LangSmith: self-hosted Enterprise add-on, classified Partial. | https://arize.com/docs/phoenix/self-hosting ; https://docs.agentops.ai/v2/self-hosting/overview ; https://docs.langchain.com/langsmith/self-hosted |

## Aggregate result

- **Yes:** 7
- **Partial:** 7
- **No:** 8
- **Mixed:** 1

The major cloud-native agent suites are mostly hosted-only. Full self-deployment is strongest among open-source middleware, gateways, policy engines, and guardrail servers. IBM watsonx.governance is the clearest full-software exception among the large platform vendors reviewed.
