Declaw Cloud
The fastest way to start. Sign up at declaw.ai, grab an API key, and point the SDK at the production endpoint:Enterprise on-prem
For teams with data-residency, compliance, or network-isolation requirements, Declaw can be deployed inside your own cloud account or data center. The Declaw team handles the install, upgrades, and ongoing operations — you get a dedicated control plane and orchestrator nodes that never leave your perimeter. On-prem is a white-glove engagement and is not self-service. If you need it, contact sales to start the conversation.Talk to sales
Discuss on-prem deployment, compliance (SOC 2, HIPAA), and custom SLAs.
What you get either way
Regardless of whether you run on cloud or on-prem, every Declaw deployment includes:| Component | Role |
|---|---|
| Sandbox Manager | REST API for sandbox + template lifecycle |
| Orchestrator | Firecracker VM lifecycle, network isolation, per-sandbox security proxy |
| Guardrails | ML scanner service — PII, prompt injection, toxicity, code security |
| envd | In-VM daemon for filesystem, process, and PTY access |
| PostgreSQL + Redis | Sandbox state, routing, sessions |