Who owns and operates it
Network, data and inference
Cost, time and clouds
The cloud you deploy on and the provider that serves the models are separate decisions. The
self-hosted package ships configured for Azure OpenAI out of the box, on any cloud, and
any model provider can be connected to Galtea through the LiteLLM gateway configuration.
See Cloud-specific details.
Which one is for you
- Shared SaaS: the default. Nothing to install, always on the latest version. Choose it unless a written policy prevents it.
- Enterprise organization: same SaaS, but your evaluation and generation jobs run on worker pools reserved for you. Choose it when you need predictable capacity for heavy or time-sensitive workloads, or when you need to sign in through your own corporate identity provider.
- Private tenant: a complete, single-customer copy of the platform in a dedicated cloud account, with its own network, database, storage and identity provider, and the option of no public exposure at all. Choose it for strict compliance, data-residency or network-control requirements, without taking on the operational work.
- Managed in your cluster: the infrastructure is yours, the platform operation is Galtea’s. You provide the cloud account, network and Kubernetes cluster; Galtea deploys, upgrades and keeps the platform healthy on it, optionally with your team approving each change before it reaches production. Choose it when the data must stay in your account but you do not want your platform team operating a product they did not build. This is where most enterprises land.
- Self-hosted: the platform runs inside your own cloud subscription or data center, on your Kubernetes cluster, operated by your team. Choose it when no third party may hold any operational role at all.
What does not change across models
- The product surface: dashboard, REST API, Python SDK and CLI.
- The release line: the same versioned images and Helm charts.
- Encryption in transit and at rest.
- Role-based access control inside an organization.
- The option to sign in through your own identity provider (SAML or OIDC) from model 2 onward.
The platform in one picture
What Galtea is, who uses it, and what it connects to. Identical in all five deployment models; every diagram on the following pages zooms into part of it. The deployment boundary is the only thing that changes: everything in this picture runs the same way whether the platform is a shared multi-tenant service or an installation inside your own data center. What moves between the five models is the line between what Galtea operates and what you operate.What to read next
- Deciding between models: Choosing a deployment model
- What the platform is made of: Reference architecture
- Security and network questions: Security assurance, with the setup side in Connectivity implementation
- Who does what: Responsibility matrix