Run it where your data is allowed to live.
Build artifacts are some of the most sensitive material an organisation owns. Mobexa runs as managed SaaS, as an isolated private instance, or fully self-hosted inside your own perimeter - the same scanning engine in every case. You choose the boundary; the platform does not make you trade capability for control.
Pick the boundary that fits your policy
The decision is about where your most sensitive artifacts are permitted to go - not about which features you get to keep.
Managed SaaS
The fastest path to value. We run the platform, keep it current and operate the infrastructure. You upload builds and get results.
Private instance
A dedicated, isolated deployment for organisations that want separation without running the infrastructure themselves.
Self-hosted
The whole platform inside your perimeter. Builds, scans, findings and evidence never leave your environment - the model for regulated and sovereign workloads.
Capability is not a deployment tier
Too many platforms reserve their best detection for the deployment that is easiest for them to run. Mobexa does not. Static, dynamic, runtime instrumentation, SBOM and framework mapping are the product - and the product is the same whether it runs in our cloud or yours. The model you choose changes who operates the infrastructure, not what gets found.
- Identical analysis engine across SaaS, private and self-hosted.
- Data residency on your terms - artifacts stay where your policy requires.
- Controlled updates so private and self-hosted instances stay current on detection.
- The same evidence and reports, wherever the compute lives.
# self-hosted: nothing leaves your network artifact your-perimeter scan your-perimeter findings your-perimeter evidence your-perimeter reports your-perimeter engine identical to SaaS updates controlled, agreed cadence
Deployment, answered plainly
What deployment models do you offer?
Three. Managed SaaS, where Mobexa runs the platform for you. A dedicated private instance, isolated to your organisation. And self-hosted, where the platform runs inside your own infrastructure and perimeter. The analysis engine and findings are identical across all three - the only thing that changes is where the data and compute live.
We cannot send build artifacts outside our network. Does that rule you out?
No - it is exactly why self-hosted exists. In that model your builds, scans, findings and evidence never leave your environment. You keep the data-residency and sovereignty guarantees your policy requires while running the same platform everyone else does.
Does a self-hosted deployment fall behind on capability?
It runs the same engine. Static, dynamic, runtime, SBOM and framework mapping are the product, not a SaaS-only tier. Where managed and self-hosted differ is operational - who runs the infrastructure and applies updates - not what the platform can find.
How do updates and new checks reach a private or self-hosted instance?
Through a controlled update process suited to the model you choose, so you stay current on detection without surrendering control of your environment. The cadence and method are agreed with you rather than imposed.
Tell us where your build artifacts are allowed to live.
We will map your data-residency requirements to the right deployment model and show you the same platform running inside it.