Brainstack logo: a pink brain resting on a stack of booksBrainstack Self-hosted Back to Brainstack

For IT teams

Brainstack Self-hosted for IT

What you'll run, how it's locked down, and how to set it up.

Architecture

How the server is laid out.

One Linux server or VM, on-premises or in your own AWS, Azure or Google Cloud account, with Docker Engine 28.0 or later. Everything runs in containers on that server, including the local model, which runs on CPU.

Your teambrowser AI assistantsMCP Google · Microsoftprovider APIs YOUR SERVER EdgeTLS, your domainonly published routes Egress gatewayexact allow-list Brainstack appnon-owner DB roleaudited writes PostgreSQLprivate network Local modelno outbound route 3 named fields per read
The only way out to Google or Microsoft is the violet path. The gateway matches each request against an exact pattern and refuses anything else with a 404.

Scroll the diagram sideways to see all of it.

Sign-in

Your IdP, your rules

People sign in through Google Workspace, Microsoft Entra or any OIDC provider you already run. Nobody gets a separate Brainstack password.

Model

Reading stays local

Extraction and verification run on a local model (qwen2.5 7B, on CPU) inside the server, on a network with no route out. Your text is never sent to a model provider.

Keys

Encrypted where it rests

Provider access is sealed per person with keys you hold. Backups are encrypted to recipients whose secret keys never sit on the server.

Integrations

Sources, sign-in and assistants.

Connect each source once. People only ever see what they could already open in the original app, and removing someone cuts their access everywhere at the same moment.

Sources read-only sync

  • GmailLabels you pick
  • Google DriveDocs, Sheets, Slides, PDF, text and CSV, in folders you pick
  • OutlookFolders you pick
  • OneDriveWord, Excel, PowerPoint, PDF, text and CSV, in folders you pick
  • AI chatsClaude, ChatGPT and Microsoft 365 Copilot, turned on by your admin. Only the person who had a chat sees its facts. Needs Claude Enterprise (Compliance API), ChatGPT Enterprise or Edu (Compliance API), or Microsoft 365 Copilot licences (Microsoft Graph)

Sign-in your identity provider

  • Google WorkspaceInternal app in your org
  • Microsoft EntraSingle-tenant app
  • Any OIDC providerSuch as Okta, Auth0, Keycloak or Authentik

Assistants over MCP

  • ClaudeSearch and save team memory
  • ChatGPTSearch and save team memory
  • Microsoft 365 CopilotSearch and save team memory
  • Any MCP clientStandard OAuth, per-person access
  • Local modelReads your sources on the box

Assistants connect with standard OAuth and each person's own access, and look facts up by calling search_knowledge. Claude supports MCP. ChatGPT and Microsoft 365 Copilot support MCP connectors in some plans and settings, so check what your plan allows before you roll it out.

Specs

The details, in one place.

Runs on
One Linux server or VM, on-premises or in your own AWS, Azure or Google Cloud account, with Docker Engine 28.0 or later. Everything runs in containers on that server.
Local model
qwen2.5 7B, running on CPU in its own container. No GPU is needed, and there is no GPU configuration.
Sizing
By default the AI service is sized at 4 CPU cores and 12 GB of memory. The database and app need more on top of that. These are starting points to size for your load, not measured minimums.
Sources
Gmail, Google Drive, Outlook and OneDrive. Read-only sync of the labels and folders you pick. AI chats: Claude, ChatGPT and Microsoft 365 Copilot conversations, through each vendor's enterprise export API, turned on per vendor by an admin; facts from a chat are visible only to the person who had it. Requires Claude Enterprise (Compliance API), ChatGPT Enterprise or Edu (Compliance API), or Microsoft 365 Copilot licences (Microsoft Graph). Files: Google Docs, Sheets and Slides; Word, Excel and PowerPoint; PDF; and text/plain, text/markdown and text/csv files, in Drive and OneDrive.
Sign-in
Google Workspace (internal app in your org), Microsoft Entra (single-tenant app), or any OIDC provider such as Okta, Auth0, Keycloak or Authentik.
Assistants
Claude, ChatGPT, Microsoft 365 Copilot or any MCP client, with standard OAuth and per-person access. They look facts up with search_knowledge.
Network
The edge serves TLS on your domain and only published routes. Outbound calls go through an egress gateway with an exact allow-list.
Offboarding
Sessions, assistant tokens and provider access end in the same step. After restoring an old backup, one command re-applies removals before anyone can sign in.
Audit
Every assistant connection, removal and role change writes its audit record in the same transaction as the change.
Health
manage.py doctor checks the image, the database roles, the network isolation, sign-in and the backup keys, and names exactly what to fix.
Backups
Encrypted backups stream straight into GnuPG. The runbook walks you through restoring onto a fresh machine.
Upgrades
Migrations run in a one-shot step, one transaction each, before the app starts. If anything looks off, it stops and tells you how to go back.
Logs
The database logs only the name of a failed rule, never the row. Customer text stays out of the logs.
Access
People only see what they could already open in the original app. Removing someone cuts their access everywhere at the same moment.

Setup

Four things, then it's yours.

A guided setup wizard walks you through it, and we give you the exact settings for Google or Microsoft. After that, your team just signs in.

  1. A Linux server or VMOn-premises, or in your own AWS, Azure or Google Cloud account, with Docker Engine 28.0 or later. The local model runs on CPU, so no GPU is needed. Start with 4 CPU cores and 12 GB of memory for the AI service, plus room for the database and app.
  2. Your domainPoint a name like brain.yourcompany.com at it. Certificates are automatic.
  3. A sign-in appCreate an internal app in Google Workspace or Microsoft Entra, or use any OIDC provider. We give you the exact settings.
  4. Run the wizardClaim the site, invite your team, connect mail and files.

Tested like someone is attacking it

We tried to break it. Repeatedly.

Before every release, independent reviewers who didn't write the code try to leak data across teams, forge sources, stall the server and misread the docs. Each finding is fixed and re-checked before anything ships.

6adversarial audit rounds, from insider abuse to hostile providers
1,629deployment tests, 0 skipped
260product test suites on every change
49steps in the end-to-end sign-in drill
$ drill --mode local-idp   ok: claim · ok: invite-and-join · ok: stranger-refused · ok: remove-member-cli · ok: removed-member-refused · ok: issuer-pin-holds · ALL STEPS PASSED (0 skipped)

Questions about your setup?

Get in touch and we'll set up a short call. If it's a fit, we'll help you set Brainstack up.

Get in touch