Skip to content

Self-hosted, SSO-governed, audited to the line.

Falcon FDE Enterprise

Run the FDE assistant entirely on your own infrastructure with unlimited seats, SAML/OIDC single sign-on, granular data boundaries, an immutable audit log and a 99.95% SLA.

  • Self-hosted, including air-gapped
  • Unlimited seats
  • SSO with directory-driven access control
  • 99.95% SLA with service credits
Choose a plan

Licence keys are issued the moment payment clears. Prices exclude VAT, which is calculated at checkout from your billing country.

Overview

Some source code cannot be indexed by a third party, whatever the contract says. Falcon FDE Enterprise is the same assistant, deployed inside your own network, so repositories, indexes and generated artefacts never leave infrastructure you control.

Seats are unlimited and governed by your identity provider. Group membership in your directory maps to what an engineer can see, which means access to a sensitive repository is revoked when someone changes team, not when someone remembers to update a list. Every query, citation, generated diff and document is recorded in an append-only audit log with the identity that requested it, exportable to your SIEM for retention alongside your other controls.

The commercial shape matches the technical one: a 99.95% availability SLA with service credits, a signed DPA, support for your security questionnaire and penetration test, and a named delivery contact. Air-gapped installations are supported, with offline model and index updates delivered as signed bundles.

  • Self-hosted in your VPC, your data centre, or fully air-gapped
  • Unlimited seats governed by SAML/OIDC and directory groups
  • Append-only audit log of every query and every artefact
  • 99.95% SLA, signed DPA, named delivery contact

Capabilities

  • Entirely self-hosted

    Deploys to your Kubernetes cluster on AWS, Azure, GCP or bare metal. Repositories, indexes and outputs never leave your network.

  • Unlimited seats

    Licence the platform, not the headcount. Every engineer who needs it gets access without a procurement conversation.

  • Directory-driven access

    SAML 2.0 and OIDC single sign-on with SCIM provisioning. Repository visibility follows directory group membership, so access changes when the group does.

  • Audited to the line

    Every query, citation, diff and document is written to an append-only log with the requesting identity, and exported to your SIEM.

  • Granular data boundaries

    Define which repositories, paths and knowledge bases may ever appear together in a single answer, and enforce it at retrieval time.

  • Air-gap support

    Model and index updates are delivered as signed offline bundles, so a fully disconnected installation stays current without egress.

  • Contractual SLA

    99.95% monthly availability with service credits, a signed DPA, and support for your security questionnaire and penetration testing.

  • Named delivery contact

    A named engineer who knows your deployment and your constraints, on an agreed escalation path with 24/7 P1 cover.

Where it earns its keep

  • Regulated engineering organisations

    Banking, defence, healthcare and critical infrastructure teams where source code cannot be sent to a third-party service under any terms.

  • Large platform teams

    Give hundreds of engineers consistent, cited answers about a monorepo that no individual understands end to end.

  • Audit and compliance evidence

    Demonstrate exactly which engineer asked what, what the assistant returned, and which artefacts were generated from which commit.

Questions

Can this run with no internet access at all?
Yes. Air-gapped installations receive model and index updates as cryptographically signed offline bundles that you transfer and verify yourself. No outbound connectivity is required for normal operation.
How is access to sensitive repositories controlled?
Through your directory. You map directory groups to repositories and paths, and the mapping is enforced at retrieval time, so a user outside the group cannot receive a citation from that code even indirectly.
What does the audit log actually capture?
The requesting identity, timestamp, the query, every citation returned with its commit hash, every generated diff or document, and the boundary decisions applied. It is append-only and cannot be edited from the application.
Do you need access to our cluster to support us?
No. Support is delivered through diagnostic bundles that you generate, review and send. We never require inbound access to your environment.
How is Enterprise priced beyond the listed figure?
The listed price is the entry point for a standard single-cluster deployment on an annual contract. Air-gapped, multi-cluster and multi-year arrangements are quoted individually against your requirements.