Some companies cannot put their engineering knowledge on somebody else's infrastructure. Banks, mostly. Anyone whose security team's default answer is no. The appliance is Hive as a licensed virtual appliance: the same code we run, on your hardware, on your network, with your backups and your keys.
One container image with the server and its database, a compose file and a runbook. Nothing is compiled on your side, nothing is assembled by your team and nothing phones out to answer a request.
The master key is generated on your machine and mounted. It is never baked into the image and never held by us. Every organisation's data key is wrapped with it, so we cannot read your memories because we do not have it. That is a statement about custody and it is the strongest one anybody can honestly make.
The licence is an Ed25519-signed claim, verified against a key compiled into the binary. A firewall change on your side can never stop your brain answering, because nothing asks us for permission at request time. The appliance contacts us for renewal and updates and for nothing else.
It names your organisation and will not start against another, it refuses to run against a clock wound back behind the latest time it has already seen and over the seat count it refuses the next person rather than cutting off the ones already working. What that does and does not protect →
Your developers install the ordinary client and point it at your hostname. Session hooks, auto-recall, the CLI, MCP and the web view all work exactly as they do everywhere else. Nothing about the deployment leaks into how anyone works.
An appliance is three separate obligations wearing one invoice and vendors usually blend them into a single number so you cannot tell which part you are paying for. Split out, each one answers a different question: what does it cost to get running, who carries the CVE treadmill and what does the software itself cost.
Registration, the signed licence file, the image and a working installation on your hardware with us in the room. It is scoped as half a day and it ends on a checklist rather than on a handover document:
What it is not: an integration project. Nothing is compiled on your side and nothing is written to fit your environment, so there is no discovery phase and no statement of work. If your security review needs more from us than a call and a questionnaire, that shows up here rather than as a surprise later.
The image ships an operating system and a database as well as our server. Every CVE inside any of those three is our advisory to write and your upgrade to schedule and that treadmill runs whether or not anything about the product changes in a given year. This line is what pays for it and it buys three things:
It is a separate line rather than folded into the subscription because folding it in hides it. A vendor who bundles maintenance into a per-person price has an incentive to stop shipping patches for a small customer and you have no way to see it happening.
The software and the shared brain, the same thing hosted customers pay for, priced the same way: per company, never per seat. Running it yourself does not cost more per person than letting us run it, because you are not paying for our operations in either case. What you save by hosting it yourself is our hosting cost, which was never the expensive part; what you take on is the hosting itself.
Two hundred people is the hosted ceiling, so the appliance subscription starts from the shape of the largest hosted tier and scales with headcount above it. The perimeter is the real reason to be on this page though, not the headcount: a forty-person bank whose security team will not put engineering knowledge on somebody else's infrastructure belongs here and a hundred-person startup that does not care belongs on hosted.
| Line | If it lapses |
|---|---|
| Setup | Nothing. It is paid once and it is done. |
| Maintenance | The appliance keeps running. You stop receiving patched images and advisories, which is a decision you can make deliberately and reverse later. |
| Subscription | The licence stops renewing and the sequence below runs: notice, countdown, then the brain stops serving and offers a download of the entire database. |
Figures come from a conversation rather than a pricing table, because two of the three depend on your headcount and on what your security review needs from us. That is also why the first step is a call in which we may tell you not to buy this.
Written here rather than in a contract nobody reads, because it is the question every security team asks and most vendors answer vaguely.
| day 0 | Payment fails. We email and the appliance shows a notice to your admins only. |
| day 7 | The notice is shown to everyone who uses the brain, with a countdown. |
| day 14 | The brain stops serving and offers one thing: a link where an admin downloads the entire database. |
It stops answering. Export keeps working, at every point in that sequence and after it and ns-brain hive leave --apply puts every memory back into local brains your developers own outright. We would rather lose the renewal than be the company that locked a team out of what it knew.
You will have root on that box and the binary in your hands. Somebody determined could patch the verification out and no amount of cryptography changes that: closing it needs remote attestation, which needs the call home this appliance exists to avoid. We would rather have the property you actually want than a licence check nobody can audit.
So the signing is there to make non-compliance deliberate and provable rather than impossible and everything around it is built on the same footing. The one thing that genuinely stops at the end of a term is on our side of the wire: patched images and advisories.
Said here because a security reviewer will ask and because a vendor claiming their offline licence cannot be bypassed is telling you something about the rest of their claims.
Ranking, decay, supersession, provenance, the guards, encryption and export are identical in all three editions. A price multiple should buy a different thing, not the same thing with permissions.
It is not a way to buy features early either. If something is not built, the honest answer is that it is not built and the current examples are the same ones on the Hive page: the hosted UI is read-only, there is no MCP endpoint on the server and single sign-on through your identity provider is real work we would quote for rather than promise into a contract.
Team size, what your security review needs and whether hosted would do. If it would, we will tell you.