Managed / Private Deployments
Managed cloud + per-client private deployment + ongoing maintenance. For clients needing sovereign by self-host (high data sensitivity, regulated vertical, or IP transfer mandate).

Engagement for clients whose scope requires the stack running on their infrastructure (on-prem) or client cloud (BYOC — Bring Your Own Cloud) with operational governance handled by Capital Commerce.
For whom?
- Regulated vertical clients (banking, fintech, healthcare, BUMN) needing data residency + audit posture per regulator (UU PDP, OJK, sectoral)
- Tier 1A burned-builder who've experienced cloud-managed pattern failure and want sovereign default
- Organizations with internal IT policy mandating self-host for sensitive data
- Clients with existing infrastructure (own data center, own cloud account) needing operational management layer
What's in scope
- Self-host architecture design — Postgres, n8n, Strapi, LiteLLM, Plausible, etc. all self-hosted on client infra
- Provisioning — Linux server setup, Docker compose, systemd unit, nginx vhost, TLS, firewall, monitoring
- Governance + access control — RBAC, audit log, secrets management (Bitwarden / HashiCorp Vault)
- Backup + DR — nightly backup, offsite replication, quarterly restore drill
- Compliance posture — Indonesia data residency, audit log retention per regulator mandate
- Monitoring + alerting — Plausible self-host for web analytics, custom Prometheus / Grafana for infra metrics
- Maintenance retainer — we operate the stack for you within scope explicit in SOW
- IP transfer Day 1 — code, configs, runbook all client-owned from deploy
- Quarterly security review — patch cadence, vulnerability assessment
What's NOT included
- 24/7 on-call enterprise-grade SLA — Phase 1 retainer is Indonesian business hours (07:00-22:00 WIB), escalation via WhatsApp
- Compliance certification (ISO 27001, SOC 2) — we align to standards but don't issue certification
- Hardware procurement — we advise, client procures
- Multi-tenant SaaS hosting for your clients — separate scope
Sovereign posture per Sovereign Decision Matrix
Tier 1 self-host mandatory for:
- Operational database with client data
- Workflow execution engine processing sensitive context
- LLM context proxy (LiteLLM)
- CMS + content custodian
Tier 2 with client account (if client has cloud budget + operational capacity):
- LLM API endpoint (Anthropic direct or via OpenRouter — multi-model exit path)
- Email + Workspace (Google / Microsoft)
- Asset CDN (Cloudflare R2 / S3-compatible)
Per-engagement decision depends on client posture: full Tier 1 (heavy regulated) or hybrid Tier 1 + Tier 2 (sovereign mid-market).
Engagement model
- Implementation phase (8-16 weeks): provision + setup + UAT + handover. Project-fee.
- Managed retainer (ongoing): operational maintenance + monitoring + monthly report + quarterly review. Monthly retainer fee.
- Clients preferring in-house ops post-handover: implementation phase only, no retainer. Client team runs post-handover.
Pricing model
Implementation = project-fee per scope. Retainer = monthly bucket. Quotation per requirement post initial consultation.
Ready to discuss your needs?
Initial consultation 30-60 minutes, free. We map pain, scope, and alternatives before discussing pricing.
