<!-- md twin of self-host (machine-readable, generated 2026-09-19) -->

Self-hosted &amp; air-gap · PG-07


# Run the ledger where the data must live

Self-hosted and air-gapped is a first-class deployment, not a hosted product with an export button: single node or bare-metal HA cluster, an offline bundle with zero egress, MCP included.

- zero egress

- single-tenant isolation profile

- verify offline

- no vendor endpoints

A self-hosted accounting ledger runs on infrastructure you control: one process on a VM, a bare-metal HA cluster, containers optional — with a single-tenant isolation profile, one tenant per deployment, and zero egress when the site is air-gapped. Ledgerbook AI ships as an offline bundle designed to install without a control-plane callback, keeps its financial MCP surface working air-gapped with your own local model, and offers chain verification offline, so immutability is checkable without trusting the vendor. No licence server, no telemetry, no vendor endpoints in the write path. Crypto-agility is built in through versioned algorithm sets, so a cryptographic migration is a cutover, not a re-architecture. The embedded deployment class and multi-region residency topologies are on the roadmap.

Verified 2026-09-19 · source: product documentation §1.8, NFR-6/8

Phase legend: ✓ PH-1 shipped now · ◇ Roadmap arrives with PH-2. Labels are always present — colour is never the only signal.


## Deployment classes, stated plainly

The deployment you test is the shape you deploy: no hosted console in the path, no licence server to phone home to.

| Class | Shape | Phase |
|---|---|---|
| Single node | One process on a VM or bare metal, local data directory, containers optional. The default for evaluation and small deployments. | PH-1 |
| HA cluster | Multiple nodes against quorum storage, for production books that cannot pause. | PH-1 |
| Air-gapped site | Offline bundle, zero egress; MCP over stdio or local network with your own local model. | PH-1 |
| Embedded class | An in-process deployment shape for platforms that embed tenants closer than a cluster boundary. | ◇ Roadmap |
| Multi-region residency | Topologies that pin ledgers to more than one jurisdiction at once. | ◇ Roadmap |


Traces: NFR-6 (deployment classes), NFR-8 (residency) · PH-1 classes above; embedded class and multi-region are Roadmap per the phase-qualifier register.


## Designed for offline install

Reference manifests cover containers, VM and bare metal. The offline bundle is designed to install without a control-plane callback, and the one-command offline install plus smoke test land with the launch build — we publish the shape before we publish the promise.

`# deployment profile — the shapes NFR-6 ships at PH-1 deployment: mode: single-node # ha-cluster: 3+ nodes, quorum storage substrate: vm | bare-metal # containers optional egress: none # air-gap: no control-plane callback isolation: single-tenant # one tenant per deployment ledger: chain_hash: on # on by default — FR-119 algorithms: v1 # versioned set; agility seam — FR-810 mcp: transport: stdio | remote # works air-gapped with your local model` [Request the offline bundle](/contact) [Developer quickstart →](/developers)


## Everything works offline — and we say what does not, yet


### What runs air-gapped

- The full ledger core: double-entry validation, the Provisional → Final lifecycle, as-of reads, typed corrections.

- Chain hashing and offline verification — an auditor can check immutability without ledger access or network access.

- MCP over stdio or the local network with your own local model — governance and provenance intact.

- The offline bundle itself: no control-plane callback, no telemetry egress.

NFR-6 · FR-121/813 · FR-343 · PH-1

**Documented gaps, not footnotes.** Two things do not ship inside an air gap yet, and we would rather you read it here: offline delegated-revocation bundles, and time attestation for chain events where a trusted clock is unavailable. Both, plus the supported local-model matrix, are ◇ Roadmap (PH-2).

NFR-6 · OI-39 · Roadmap (PH-2)


## Sovereignty, crypto and the licensing stance

Sovereignty is a deployment property, not a slogan: you choose the region, you own the data directory, and nothing in the product needs to reach us.

✓ PH-1


### Deployment sovereignty

Region pinning where you deploy; no vendor endpoints in the write path; single-tenant isolation profile — one tenant per deployment. Crypto-agile by design: algorithm sets are versioned and tagged on the payload, so a migration is a cutover, not a re-architecture.

NFR-6/8 · FR-810 (agility) · FR-813 (tamper-evidence) · PH-1

✓ PH-1


### Open-core, source-available

The licensing stance is open-core, source-available: self-host it, audit it, embed it. The exact licence text is being finalised before commercial launch — we will publish the terms, not a summary of them. Enterprise terms are quote-led.

OI-12 · see [Pricing &amp; licensing](/pricing)

◇ Roadmap


### Post-quantum migration

The crypto-agility seams are PH-1; the post-quantum hybrid suite lands on the PH-2 schedule, together with optional anchoring for chain events. Because the seams exist, that cutover is a configuration event rather than a rewrite.

FR-810 PH-1 · FR-811/812 Roadmap (PH-2)

◇ Roadmap


### Keys, PII and erasure

BYOK/HSM custody for your own keys, off-ledger PII with on-ledger commitments, and a crypto-shredding erasure path for GDPR-style deletion — each labelled Roadmap because none of them ship at PH-1.

FR-806/808/812 Roadmap (PH-2) · NFR-11


## Self-hosting FAQ

A self-hosted accounting system runs the ledger inside infrastructure you control — your VM, your bare metal, your network — instead of a vendor's cloud. Ledgerbook AI is headless, so there is no console to host: you deploy a process, point your applications and agents at its REST and MCP surfaces, and keep the data directory, keys and backups in your own boundary.

Verified 2026-09-19

It means the product has no control-plane callback: no licence server, no telemetry, no update ping. A deployment on an isolated network validates entries, runs the lifecycle, answers as-of reads and serves MCP to your local model without any outbound connection. Verification works the same way — an auditor checks the chain offline.

Verified 2026-09-19

The deployment shape is built for it: single-tenant isolation, an offline bundle, zero egress and no vendor endpoints. Two honest caveats for disconnected sites: delegated-revocation bundles and time attestation are on the roadmap, and the supported local-model matrix for air-gapped MCP ships with them. Talk to us about your constraints and we will map them.

Verified 2026-09-19


## What Ledgerbook is not

Running the ledger yourself is a deployment choice, not a commitment to run everything yourself.

- **Not an ERP (NG-2).** Self-hosting the ledger does not mean self-hosting your finance stack. Your ERP, billing and payroll stay wherever they already run; what comes in-house is the book of record they feed.

- **No models in the core (NG-4).** There is no model in the bundle and nothing that needs to reach a model vendor. In an air-gapped deployment you point the MCP surface at your own local model, and the surface behaves identically.

- **No UI (NG-1).** What installs is a service, its four surfaces and an offline verifier — not an application. That is why the offline bundle can have zero egress at all.


## Talk to us about air-gap deployments

Bring your residency, network-isolation and local-model constraints. The offline bundle ships to design partners first.
