Self-hosted Linux appliance

Your portal and assessment history on your infrastructure.

Install one guarded Linux server appliance, connect Okta through the guided setup, and keep your workspace data, reports, and backups on storage you control. The appliance calls the hosted Atomation Engine for assessment execution.

Private release preview — checkout activates after the release gates pass.

customer-linux-server
LOCALAtomation portalLocal login + MFA
LOCALPostgreSQLRecords and findings
LOCALBackupsYour retention policy
Outbound TLS
HOSTEDAtomation EngineLicensed assessment execution
Launch configuration

One appliance, with the first year of Engine access.

Choose the appliance and any perpetual add-ons. You first sign in to an Atomation account by email magic link; the authenticated server then opens Stripe-hosted checkout. Atomation never receives your card details.

License options
One-time total$2,500
Join the private release list

The annual Engine renewal price, taxes, supported-platform terms, and final order terms are shown before payment. Use a controlled IT/billing distribution address when possible so authorized staff can receive future magic-link access and renewal notices. Checkout remains disabled until release validation is complete.

What stays where

Customer-owned storage with a narrow hosted execution boundary.

01

On your server

Portal accounts, workspace configuration, Okta connection metadata, assessment records, findings, reports, and backup archives.

02

Through outbound TLS

Only the licensed assessment request and the minimum data required for the selected Engine rules. The final data contract is published before sale.

03

Under your operations

DNS, TLS, operating-system updates, capacity, backup destinations, recovery keys, monitoring, and access to the Linux host.

Deployment requirements

A server appliance, not a desktop utility.

The production installer targets a dedicated supported Linux server with Docker, persistent storage, outbound HTTPS, and customer-managed DNS.

Linux hostSupported x86-64 distribution and a reboot-safe Docker service. ARM64 is not part of the first release.
DNS and TLSA dedicated hostname and a supported certificate path for the setup and tenant portal.
Outbound accessOkta APIs, the Atomation Engine gateway, license/update endpoints, and certificate services.
Backup custodyAn off-host encrypted destination and recovery key controlled by your organization.
FAQ

Before you install

Is this an offline or air-gapped product?

No. The Linux appliance keeps the portal, configuration, assessment records, reports, and backups on infrastructure you control, but it requires outbound access to the hosted Atomation Engine and Okta APIs.

Does Atomation store our appliance backups?

No. You choose where appliance backups are stored and how many copies to retain. Backups consume your storage, not Atomation storage.

How is Okta connected?

The guided setup uses a temporary Okta API token (SSWS) created by a Super Administrator. The setup creates or reuses the least-privilege API Services connector and then revokes the temporary token. Routine assessments use the connector, not the temporary token.

Does the appliance require SAML SSO?

No. Local administrator accounts with MFA are supported. Enterprise directory and LDAP options are a separate future compatibility track.

What happens when Engine access expires?

New assessments stop until the annual Engine term is renewed. The installed application, local administration, stored findings and reports, exports, backups, restore, and a purchased MCP package continue working.

Does MCP stop if Engine access expires?

No. MCP is a separately purchased local capability that connects authorized appliance data to the AI client you choose. It does not require an active Atomation Engine term for previously stored local data.

What does lifetime feature updates mean?

The add-on covers compatible feature releases for the licensed appliance deployment. It does not include custom engineering, unsupported operating systems, third-party fees, or a promise that every future module will run on older hardware.

Can we connect our own AI client?

The optional MCP package is intended to expose authorized, read-only appliance data to a compatible customer-controlled AI client. It does not send your data to an Atomation AI account.