Three ways to run sealverity.ai. Each organisation's current model, region and data recipients are shown in Settings → Deployment.
Shared, managed platform. Fastest start; sealverity.ai runs hosting, updates and backups. Data region chosen per organisation.
Third-party detectors and AI available; sovereign mode optional.
A single-tenant installation in a private cloud network (your account or ours), with private networking to your systems.
Same features; outbound access can be limited to approved detectors.
Runs entirely in your data centre, including air-gapped networks.
Sovereign mode on: only self-hosted detectors run; no data leaves your network.
| Variable | Needed | Purpose |
|---|---|---|
| SUPABASE_URL / VITE_SUPABASE_URL | Required | Address of the database and auth service (server / browser). |
| SUPABASE_PUBLISHABLE_KEY / VITE_SUPABASE_PUBLISHABLE_KEY | Required | Public client key. |
| SUPABASE_SERVICE_ROLE_KEY | Required | Server-only key for privileged jobs (retention, SCIM, public verification). |
| REPORT_SIGNING_SEED | Required | Seed for the Ed25519 key that signs forensic reports and deletion certificates. |
| C2PA_SIGNING_CERT, C2PA_PRIVATE_KEY | Recommended | Organisation certificate and key for sealing content (test certificate used if missing). |
| CUSTOM_DETECTOR_* | Per detector | Auth values for self-hosted detectors. |
| LOVABLE_API_KEY | Cloud only | Built-in AI (review, intelligence, Ask assistant, text checks). Omit on air-gapped installs. |
| AIORNOT_API_KEY | Optional | AI or Not detector. |
| HIVE_API_KEY | Optional | Hive detector. |
| REALITY_DEFENDER_API_KEY | Optional | Reality Defender detector. |
| SIGHTENGINE_API_USER, SIGHTENGINE_API_SECRET | Optional | Sightengine detector. |
| RESEMBLE_API_KEY | Optional | Resemble AI Detect (cloud). |
| GPTZERO_API_KEY | Optional | GPTZero text detector. |
| ASSEMBLYAI_API_KEY | Optional | Transcription and audio intelligence. |
| AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_REGION | Optional | AWS Rekognition for face boxes and face match. |
Secrets are kept server-side only. Values starting with VITE_ are public and reach the browser.