Cloud, On-Prem & Hybrid Device Identity Solutions | Smallstep

From cloud to on-prem — we've got you covered

Run in the cloud, deploy on-prem, or operate fully air-gapped. Every deployment secures services, AI workloads, inference systems, and MCP servers using the same cryptographic identity controls. Contact our team to discuss options and pricing.

Flexible deployment options

Smallstep has three common deployment styles: SaaS, Hybrid, and Run Anywhere. Your style will depend on your organization’s resources, compliance requirements, threat model, and need for customization. And no matter how you deploy Smallstep, we can offer standard or Enterprise-grade customer support.

SaaS Hybrid (Step CA Pro) Run Anywhere
Cost $ $$ $$$+
Installation No installation required You install the CA on your hardware or cloud (single binary) You install the full platform on your bespoke infrastructure (Kubernetes or VM)
Customer-managed infrastructure None CA only Full device identity platform
Updates Automatic, rolling updates by Smallstep Periodic updates of the single binary, requiring manual intervention Periodic updates of Kubernetes pods or VM appliance, requiring manual intervention
Scalability Our infrastructure scales with you Additional scaling costs and effort Additional scaling costs and effort
Data residency Data is stored with Smallstep Your CA can be standalone or linked to Smallstep’s cloud Complete ownership and control of all sensitive data simplifies compliance story
Key protection FIPS 140-2 HSM with hardware protection Customer KMS Customer KMS
Key residency Smallstep-managed (optional: customer-owned keys with HSM attestation verification) Customer-managed Customer-managed
Integrations API, webhooks, certificate templates, and other configuration options API, webhooks, certificate templates, and other configuration options Tailored configuration and design to integrate deeply with existing infrastructure, or to meet specific organizational needs
Operational overhead Fully managed by Smallstep Requires dedicated IT resources for setup, maintenance, and day-to-day management Requires dedicated IT resources for setup, maintenance, and day-to-day management
High availability Highly available (99.9%) from day one Can be deployed in a HA setup Can be deployed in a HA setup
Compliance SOC2 SOC2 Optional FedRamp

Leading the industry in Zero Trust for devices

Empower your teams to work at the pace and scale of modern engineering.

FAQs deployment options

What deployment models does Smallstep support, and how do they differ?

How does the Smallstep Cloud architecture guarantee isolation and security?

What is Smallstep Run Anywhere, and when is it recommended?

How does Run Anywhere differ from deploying step-ca yourself?

How does Smallstep handle high availability (HA) and disaster recovery?

What data stores and services does Run Anywhere require?

Can Smallstep integrate with sovereign or compliance-mandated cloud environments?

How are CA private keys protected in each deployment model?

Which deployment option is best for large-scale device fleets (10k–200k+ endpoints)?

Can deployment options be mixed (hybrid)?

How do upgrades and maintenance differ across deployment models?

Does Smallstep support migration from Open Source → Run Anywhere → SaaS?