sealverity.ai
Docs

Deployment guide

Three ways to run sealverity.ai. Each organisation's current model, region and data recipients are shown in Settings → Deployment.

Deployment models

Cloud SaaS

Shared, managed platform. Fastest start; sealverity.ai runs hosting, updates and backups. Data region chosen per organisation.

Third-party detectors and AI available; sovereign mode optional.

Dedicated VPC

A single-tenant installation in a private cloud network (your account or ours), with private networking to your systems.

Same features; outbound access can be limited to approved detectors.

On-premises

Runs entirely in your data centre, including air-gapped networks.

Sovereign mode on: only self-hosted detectors run; no data leaves your network.

On-premises requirements

Environment variables

VariableNeededPurpose
SUPABASE_URL / VITE_SUPABASE_URLRequiredAddress of the database and auth service (server / browser).
SUPABASE_PUBLISHABLE_KEY / VITE_SUPABASE_PUBLISHABLE_KEYRequiredPublic client key.
SUPABASE_SERVICE_ROLE_KEYRequiredServer-only key for privileged jobs (retention, SCIM, public verification).
REPORT_SIGNING_SEEDRequiredSeed for the Ed25519 key that signs forensic reports and deletion certificates.
C2PA_SIGNING_CERT, C2PA_PRIVATE_KEYRecommendedOrganisation certificate and key for sealing content (test certificate used if missing).
CUSTOM_DETECTOR_*Per detectorAuth values for self-hosted detectors.
LOVABLE_API_KEYCloud onlyBuilt-in AI (review, intelligence, Ask assistant, text checks). Omit on air-gapped installs.
AIORNOT_API_KEYOptionalAI or Not detector.
HIVE_API_KEYOptionalHive detector.
REALITY_DEFENDER_API_KEYOptionalReality Defender detector.
SIGHTENGINE_API_USER, SIGHTENGINE_API_SECRETOptionalSightengine detector.
RESEMBLE_API_KEYOptionalResemble AI Detect (cloud).
GPTZERO_API_KEYOptionalGPTZero text detector.
ASSEMBLYAI_API_KEYOptionalTranscription and audio intelligence.
AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_REGIONOptionalAWS Rekognition for face boxes and face match.

Secrets are kept server-side only. Values starting with VITE_ are public and reach the browser.