# On-Premises

This page covers running CKEditor AI on-premises, including which features need it, what it requires from you, and where to find the installation documentation.

Run CKEditor AI on-premises when your documents cannot leave your network, or when you want to pick the models behind the features. The service ships as a Docker image and runs the same endpoints and features as SaaS.

To run CKEditor AI on our cloud instead, see [SaaS](saas.md). For how the two variants differ across CKEditor Cloud Services, in updates, support, and regions, see [SaaS vs. On-Premises](../saas-vs-on-premises.md).

<a id="features-that-need-an-on-premises-deployment">

## Features that need an on-premises deployment

* **Your own models:** prompts and document content go only to the provider you contract with, and every feature runs on the models you choose. See [Model providers](extensions/model-providers.md) for the supported providers.
* **Full data control:** conversations, documents, and uploaded files stay in your database and file storage, encrypted inside your infrastructure. See [Security & compliance](security-and-compliance.md) for the retention rules and the encryption details.
* **Operational control:** you decide whether moderation runs, which endpoint performs the check, and what each guardrail checkpoint rejects. Traces go to a collector you choose, and you read the service logs directly.
* **More extensibility:** [Hooks](extensions/hooks.md) let a service you host take part in answering each chat message. [MCP tools](extensions/mcp-tools.md) from servers defined in the deployment configuration are available in chat and in Document Processing.

<a id="what-it-requires">

## What it requires

An on-premises deployment requires a container platform, an SQL database, Redis, and file storage. Any Open Container runtime works, such as Docker, Kubernetes, Amazon ECS, or Azure Container Instances. The service needs outbound access to the LLM provider endpoints you configure and to the destinations of the features you turn on: moderation, web search, web scraping, MCP servers, and observability. With an online license key, it also calls our license server.

You also provide a token endpoint in your application. It signs the tokens your users send with each request. You handle upgrades, scaling, and monitoring. See [Requirements](../../onpremises/ckeditor-ai-onpremises/requirements.md) for the supported versions, the hardware recommendations, and the full list of outbound destinations.

You need a license key to install, and a download token to pull the image. You create the token in the [Customer Portal](https://portal.ckeditor.com/) under **Subscription → License keys → CKEditor AI Server**. If that entry is missing, or you want a trial license or access to the development build, [contact us](https://ckeditor.com/contact/). See [Deployment](../../onpremises/ckeditor-ai-onpremises/deployment.md) for the registry login and the `docker run` command.

<a id="next-steps">

## Next steps

The [on-premises documentation](../../onpremises/ckeditor-ai-onpremises/overview.md) covers installation, configuration, and operation, in the order you will need them.

---

Full index of the Cloud Services documentation: [llms.txt](../../../llms.txt)
