This reference architecture describes Enterprise self-host ValGuard in a customer VPC for regulated workloads. Hosted SaaS remains the default for most teams. There is no public Docker image or free local runtime. See Trust and self-host docs.
When to use this layout
- Policy requires AI payloads to stay in infrastructure you control.
- You already run Postgres and Redis (or approved managed equivalents) in the VPC.
- You can operate nginx (or equivalent), TLS, and license heartbeats.
Trust boundaries
flowchart TB
subgraph vpc [Customer VPC]
Edge[TLS edge / WAF]
Web[ValGuard web :3000]
Proxy[ValGuard proxy :8080]
PG[(Postgres)]
RD[(Redis)]
Edge --> Web
Edge --> Proxy
Web --> PG
Web --> RD
Proxy --> PG
Proxy --> RD
Proxy --> Prov[Your LLM providers]
end
Lic[ValGuard license heartbeat]
Proxy -.->|no AI payloads| Lic
| Boundary | What crosses | What must not |
|---|---|---|
| App → ValGuard proxy | Prompts, completions, API keys you configure | Unscoped internet egress for secrets |
| Proxy → providers | Model traffic under your contracts | ValGuard subprocessors for model hosting |
| Proxy → ValGuard cloud | License heartbeat only | Customer AI content |
Secrets
INTERNAL_PROXY_SECRETand vault keys stay in your secret manager /.envon the host.- Provider keys: Provider Vault (encrypted at rest) or BYOK headers from the app.
- Rotate with your existing enterprise process; ValGuard does not ship a public secrets broker.
Failure modes
| Event | Expected behavior | Owner |
|---|---|---|
| Rule block | Fail closed; no tool side effect | Your app routing |
| Proxy down | Requests fail; no silent skip | Your SRE / fallback policy |
| Provider 5xx | Surface upstream error; optional client retry | Your app |
| License invalid | Enforce mode per license docs | Your admin + ValGuard |
See fail-closed and Trust.
Latency budget (order of magnitude)
| Segment | Typical scale | Notes |
|---|---|---|
| Engine packs | microseconds | Rule evaluation |
| Proxy path | ~0.4 ms p50 mocked | Methodology |
| Model | hundreds of ms | Dominates |
| Block / re-ask | full buffer | No early tokens |
Rollback
- Keep previous release under
apps/web/.next-releases/andcurrentpointer. make web-rebuild-prodcutover orsystemctl restart valguard-web/valguard-proxy.- Flip agents to shadow mode if a new pack misbehaves.
SaaS variant
Same logical path without VPC: hosted ValGuard + your providers. Data residency and subprocessors differ. Compare on Trust.