Run the entire MessageBlue stack in your cloud, your VPC, or on-prem — so customer data never leaves your security boundary. Full isolation, your compliance controls, backed by our team.
module "messageblue" {
source = "messageblue/stack/aws"
region = "us-east-1" // your region
vpc_id = var.private_vpc // your network
kms_key = var.byo_kms_key // your keys
data_residency = "in-region" // never leaves
}
// Runs entirely in your account. You own the data. TRUSTED BY REGULATED & SECURITY-FIRST TEAMS
From a fully managed private instance to a stack that lives entirely in your own datacenter.
Deploy into your own AWS, GCP or Azure account. We ship the stack as infrastructure-as-code; you own the compute, the network and the data plane.
Run entirely within your datacenter or private network — including air-gapped environments — for the strictest data-sovereignty requirements.
Prefer we operate it? Get a single-tenant, fully isolated instance managed by our team, with a 99.99% uptime SLA and dedicated support.
When MessageBlue runs in your infrastructure, messages, numbers and logs stay inside your compliance boundary. You hold the encryption keys, set the network policy, and control retention and access — end to end.
┌─ Your Cloud Account ─────────────┐
│ │
│ MessageBlue stack │
│ ├── API + webhooks │
│ ├── message store (your DB) │
│ └── numbers (your KMS) │
│ │
│ ⇅ Apple iMessage / SMS · RCS │
└──────────────────────────────────┘
data + keys stay inside the box The controls your security, legal and compliance reviewers expect — out of the box.
Independently audited controls for security, availability and confidentiality.
Deploy in a HIPAA-aligned configuration and sign a Business Associate Agreement.
Keep data in a specific region or country to meet sovereignty requirements.
Encrypt everything with keys in your own KMS — we never hold them.
Connect your identity provider and automate user provisioning and de-provisioning.
Full audit trails and retention windows you configure to match your policy.
Where data can't leave the building — but the blue bubble still has to work.
Client comms and alerts with the isolation and audit trails regulators require.
Patient messaging in a HIPAA-aligned deployment, with a signed BAA and PHI kept in your boundary.
On-prem and air-gapped options for data-sovereignty and residency mandates.
Yes. MessageBlue can be deployed entirely inside your own cloud account (AWS, GCP or Azure), your VPC, or on-premises for air-gapped environments. We ship the stack as infrastructure-as-code; you own the infrastructure and the data plane.
No. In a self-hosted deployment, messages, numbers and logs stay inside your compliance boundary. You control encryption keys, network policy, data residency and retention.
Yes. We offer SOC 2 Type II controls and HIPAA-ready deployments, and we sign a Business Associate Agreement for covered entities.
Our team helps you stand up the stack and ships versioned updates you roll out on your schedule. Enterprise plans include a dedicated account manager, priority support and a 99.99% uptime SLA on managed instances.
Yes. Connect the iMessage numbers your team already texts from and control them through the API — send, receive and automate from the same trusted lines, with inbound routed to your agents or logic.
Tell us about your environment and compliance needs, and we'll scope a deployment that fits — in your cloud, your VPC, or on-prem.