Fix nine definitions
For the intended deployment, identify where each layer runs and who operates it:
- app builder and control plane;
- end-user application runtime;
- platform metadata store;
- business data and uploaded files;
- identity and access configuration;
- secrets and integration credentials;
- logs, metrics, and audit evidence;
- update, backup, and restore systems; and
- licensing or entitlement service.
“Data stays in our VPC” does not establish that the builder, telemetry, authentication, license checks, or support access also stay there.
Distinguish documented fact from judgment
Budibase's hosting documentation offers cloud and self-hosted methods and explicitly warns that self-hosters must understand servers, security, maintenance, and troubleshooting. ToolJet's system requirements state supported architecture and baseline compute and storage for its self-hosted deployment.
Those are documented facts about vendor-described requirements. They do not measure upgrade safety, recovery time, vulnerability response, or the staffing needed in a particular environment.
Publish a responsibility matrix
| Layer | Runs where? | Customer operates | Vendor operates | Evidence | Unresolved |
|---|---|---|---|---|---|
| Control plane | |||||
| Runtime | |||||
| Platform state | |||||
| Business data/files | |||||
| Identity/secrets | |||||
| Observability | |||||
| Updates/recovery | |||||
| Licensing |
Apply the same evidence threshold to every candidate. A product page is evidence of a claim. A tested installation, upgrade, and restore provide stronger evidence of behavior.
Run the independent-recovery test
Before relying on self-hosting as an exit property, verify whether the buyer can:
- reinstall an approved version from retained artifacts;
- restore platform state and representative app data;
- recover required files and identity configuration;
- operate through a temporary loss of vendor service;
- obtain security and compatibility updates;
- understand the license behavior after expiration; and
- move to another operator using available documentation.
The answer may reasonably include vendor assistance. Label that dependency rather than inferring independence.
Interpret the tradeoff
Self-hosting can improve data-location control, private-network access, customization, and account ownership. It can also transfer patching, backups, capacity, monitoring, certificates, identity integration, incident response, and upgrade compatibility to the buyer.
The recommendation depends on the intended operator. A team with a supported platform practice may prefer control. A small team without recovery capacity may be safer with a managed service even when self-hosting is technically available.
The decision output should say “customer operates these seven components with this recovery evidence,” not merely “self-hosted: yes.”