Reference architecture: ValGuard in a regulated VPC

Enterprise self-host layout: trust boundaries, secrets, failure modes, and latency budget for regulated workloads.

This reference architecture describes Enterprise self-host ValGuard in a customer VPC for regulated workloads. Hosted SaaS remains the default for most teams. There is no public Docker image or free local runtime. See Trust and self-host docs.

When to use this layout

  • Policy requires AI payloads to stay in infrastructure you control.
  • You already run Postgres and Redis (or approved managed equivalents) in the VPC.
  • You can operate nginx (or equivalent), TLS, and license heartbeats.

Trust boundaries

flowchart TB
  subgraph vpc [Customer VPC]
    Edge[TLS edge / WAF]
    Web[ValGuard web :3000]
    Proxy[ValGuard proxy :8080]
    PG[(Postgres)]
    RD[(Redis)]
    Edge --> Web
    Edge --> Proxy
    Web --> PG
    Web --> RD
    Proxy --> PG
    Proxy --> RD
    Proxy --> Prov[Your LLM providers]
  end
  Lic[ValGuard license heartbeat]
  Proxy -.->|no AI payloads| Lic
BoundaryWhat crossesWhat must not
App → ValGuard proxyPrompts, completions, API keys you configureUnscoped internet egress for secrets
Proxy → providersModel traffic under your contractsValGuard subprocessors for model hosting
Proxy → ValGuard cloudLicense heartbeat onlyCustomer AI content

Secrets

  • INTERNAL_PROXY_SECRET and vault keys stay in your secret manager / .env on the host.
  • Provider keys: Provider Vault (encrypted at rest) or BYOK headers from the app.
  • Rotate with your existing enterprise process; ValGuard does not ship a public secrets broker.

Failure modes

EventExpected behaviorOwner
Rule blockFail closed; no tool side effectYour app routing
Proxy downRequests fail; no silent skipYour SRE / fallback policy
Provider 5xxSurface upstream error; optional client retryYour app
License invalidEnforce mode per license docsYour admin + ValGuard

See fail-closed and Trust.

Latency budget (order of magnitude)

SegmentTypical scaleNotes
Engine packsmicrosecondsRule evaluation
Proxy path~0.4 ms p50 mockedMethodology
Modelhundreds of msDominates
Block / re-askfull bufferNo early tokens

Rollback

  1. Keep previous release under apps/web/.next-releases/ and current pointer.
  2. make web-rebuild-prod cutover or systemctl restart valguard-web / valguard-proxy.
  3. Flip agents to shadow mode if a new pack misbehaves.

SaaS variant

Same logical path without VPC: hosted ValGuard + your providers. Data residency and subprocessors differ. Compare on Trust.

Next step

Read self-host, then contact for Enterprise licensing.