# AI-Infra-Guard Deployment Profiles: On-Premises, SaaS, and Open-Source Explained

> Explore AI-Infra-Guard deployment profiles: on-premises, SaaS, and open-source. Discover the best fit for your environment with a shared core Go binary and scan engine.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: architecture
- Published: 2026-08-22

---

**TLDR:** AI-Infra-Guard supports three deployment profiles — **on-premises**, **SaaS**, and **open-source** — each designed for different runtime environments while sharing the same core Go binary and scan engine.

AI-Infra-Guard from Tencent is a security scanner purpose-built for AI infrastructure. According to the project's architecture documentation, the repository's deployment model was deliberately designed to be flexible, supporting everything from isolated private data centers to fully managed cloud services. This guide breaks down the three AI-Infra-Guard deployment profiles, explains when to use each, and provides runnable setup commands based on the actual repository code.

## What Are the AI-Infra-Guard Deployment Profiles?

The project defines **three distinct deployment profiles** in its [`docs/architecture_evolution.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docs/architecture_evolution.md) file. Each profile targets a different operator persona, but all share the same underlying codebase, binary structure, and scan engine.

| Profile | Typical Use-Case | Key Characteristics |
|---------|------------------|----------------------|
| **On-Premises** | Enterprises running the scanner inside a private data center or isolated network. | Self-hosted services, no external internet required post-sync, uses Docker-Compose. |
| **SaaS** | Customers wanting a managed, cloud-hosted service. | Same binaries exposed via public API, reverse proxy and TLS termination, cloud config addresses. |
| **Open-Source** | Developers and researchers running locally for testing, CI/CD, or hobby projects. | Minimal setup, single binary, no container dependency required. |

The selection of a profile affects how build scripts, Docker assets, and command-line interfaces are organized throughout the AI-Infra-Guard repository.

## On-Premises Deployment Profile

The **on-premises profile** targets enterprises that must keep all scanning infrastructure behind a firewall. All services — the Go vault server, the agent, and the optional Python vulnerability scan modules — are self-hosted and orchestrated with Docker-Compose.

This profile does not require external internet connectivity after the initial data synchronization. The `data sync configuration` is a one-time step that pulls the latest vulnerability fingerprints and rule updates; operations thereafter run entirely on the private network.

### On-Premises Quick Start

```bash

# Pull the pre-built images (or build locally)

docker-compose -f docker-compose.images.yml up -d   # one-click start

# Verify the service is listening on the internal address

curl http://127.0.0.1:8088/api/v1/health

```

**Key files for on-premises:** the [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml), [`docker-compose.images.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.images.yml), `Dockerfile`, and `Dockerfile_Agent` in the repository root orchestrate the full stack of webserver, agent, and Python scanners.

## SaaS Deployment Profile

The **SaaS profile** delivers the exact same scan engine as a managed cloud service, either on a public or private cloud. Companies that want centralized security scanning without self-hosting overhead choose this profile.

From a drop-in configuration perspective, SaaS differs from on-premises in three ways:

- The service is published through a public API endpoint rather than a private URL.
- A reverse-proxy (typically Nginx) terminates TLS and routes incoming requests to the Go web server.
- Environment variables such as `AIG_SERVER` point to the cloud address.

The same binary is used for both the SaaS and CLI modes, so the workload doesn't change — only the network exposure.

### SaaS Deployment Quick Start

```bash

# Build the binary for the target OS/arch

GOOS=linux GOARCH=amd64 go build -o ai-infra-guard ./cmd/cli/main.go

# Run behind a reverse proxy (example using Nginx)

# /etc/nginx/conf.d/aig.conf

#   location / {

#       proxy_pass http://localhost:8088;

#       proxy_set_header Host $host;

#   }

```

**Key files for SaaS:** [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) acts as the entry vector for both CLI and server modes; [`frontend/README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/frontend/README.md) details proxy aliasing for the UI, and [`docs/api_data_update.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docs/api_data_update.md) shows how to point the API base URL to the cloud host.

## Open-Source Deployment Profile

For developers, researchers, and CI/CD pipelines, the **open-source profile** is the most direct path to scanning. It requires just a single binary with no mandatory container or multi-service orchestration. You can run it on a workstation with minimal overhead and plug in your custom rules or fingerprint files easily.

This profile is the entry point described in the contact README quick-start section, and it's optimized for speed-of-first-scan.

### Open-Source Standalone Quick Start

```bash

# Build the CLI

go build -o ai-infra-guard ./cmd/cli/main.go

# Run the web server directly

./ai-infra-guard webserver --server 127.0.0.1:8088

# Run a quick scan against a local target

./ai-infra-guard scan -t http://127.0.0.1:8088

```

**Key files for open-source:** [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) is the single entry point; [`README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/README.md) contains the official quick-start guide; [`frontend/README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/frontend/README.md) notes how to use the Vite alias for private deployments and development.

## Key Files Across All Deployment Profiles

| File | Purpose |
|------|---------|
| [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml) | Orchestrates the full on-premises stack (web server, agent, Python scanners). |
| `Dockerfile` | Base container image for the Go service; used for both on-premises and SaaS. |
| [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) | CLI entry point; identical binary used for SaaS and open-source modes. |
| [`frontend/README.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/frontend/README.md) | Explains how to alias the UI for private deployments and run development mode. |
| [`docs/architecture_evolution.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docs/architecture_evolution.md) | Defines the three deployment profiles in detail. |
| [`docs/api_data_update.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docs/api_data_update.md) | Shows how to adjust API base URL for different deployment scenarios. |

## Summary

- AI-Infra-Guard uses three production profiles: **on-premises**, **SaaS**, and **open-source**.
- All three profiles share the same core Go binary; deployment differences are handled by configuration rather than separate builds.
- **On-premises** relies on Docker-Compose and runs entirely behind your network.
- **SaaS** exposes the same scanner behind a TLS-terminating reverse proxy, with `AIG_SERVER` pointing to the cloud endpoint.
- **Open-source** is the lightest runtime (single binary, no container required), ideal for CI/CD and local testing. Those same CLI authors maintain the server code, so the feature set in each mode is identical.

## Frequently Asked Questions

### Does AI-Infra-Guard require Docker for all deployment types?

No. The open-source and SaaS command-line profile can run with a single, at-most `-i` binary (`./ai-infra-guard`). Docker is only mandatory for the on-premises profile, where the [`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml) orchestrates the multi-service stack of web server, agent, and Python scanners.

### Where are the deployment profiles defined in the source code?

The profiles are defined in [`docs/architecture_evolution.md`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docs/architecture_evolution.md) in the repository root. The actual configuration and startup assets ([`docker-compose.yml`](https://github.com/Tencent/AI-Infra-Guard/blob/main/docker-compose.yml), `Dockerfile`, [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go)) implement those definitions in concrete build and run scripts.

### Can the same binary serve both SaaS and open-source modes?

Yes, one binary built from [`cmd/cli/main.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/cmd/cli/main.go) works in both scenarios. The distinction is determined by environment configuration ([`AIG_SERVER`] or CLI flags), not by a separate binary compilation. Purely optionally, the agent and Python scanner containers are only required for the on-premises stack.