Enterprise & Self-Hosted

Deploy the iMessage API inside your own infrastructure.

Run the entire MessageBlue stack in your cloud, your VPC, or on-prem — so customer data never leaves your security boundary. Full isolation, your compliance controls, backed by our team.

SOC 2 Type II · HIPAA-ready · Data residency
deploy.tf
module "messageblue" {
  source   = "messageblue/stack/aws"

  region   = "us-east-1"        // your region
  vpc_id   = var.private_vpc    // your network
  kms_key  = var.byo_kms_key    // your keys

  data_residency = "in-region"  // never leaves
}

// Runs entirely in your account. You own the data.
Your VPC · Your keys 🔐

TRUSTED BY REGULATED & SECURITY-FIRST TEAMS

Choose how you run it.

From a fully managed private instance to a stack that lives entirely in your own datacenter.

☁️

Your cloud (BYOC)

Deploy into your own AWS, GCP or Azure account. We ship the stack as infrastructure-as-code; you own the compute, the network and the data plane.

🏢

On-prem / self-hosted

Run entirely within your datacenter or private network — including air-gapped environments — for the strictest data-sovereignty requirements.

🔒

Private managed cloud

Prefer we operate it? Get a single-tenant, fully isolated instance managed by our team, with a 99.99% uptime SLA and dedicated support.

100%
In your environment
SOC 2
Type II & HIPAA-ready
99.99%
Uptime SLA
BYO
Keys, network & numbers
Your boundary, your data

Customer data never leaves your environment.

When MessageBlue runs in your infrastructure, messages, numbers and logs stay inside your compliance boundary. You hold the encryption keys, set the network policy, and control retention and access — end to end.

  • Data residency in the region you choose
  • Bring your own KMS / encryption keys
  • Private networking & VPC peering — no public egress
  • SSO / SAML & SCIM provisioning
  • Full audit logs & configurable retention
  • Connect & automate your team's own existing iMessage numbers
architecture
┌─ Your Cloud Account ─────────────┐
│                                  │
│   MessageBlue stack              │
│   ├── API + webhooks             │
│   ├── message store  (your DB)   │
│   └── numbers        (your KMS)  │
│                                  │
│   ⇅ Apple iMessage / SMS · RCS   │
└──────────────────────────────────┘
  data + keys stay inside the box

Built for regulated teams.

The controls your security, legal and compliance reviewers expect — out of the box.

📋

SOC 2 Type II

Independently audited controls for security, availability and confidentiality.

🏥

HIPAA-ready · BAA

Deploy in a HIPAA-aligned configuration and sign a Business Associate Agreement.

🌍

Data residency

Keep data in a specific region or country to meet sovereignty requirements.

🔑

Bring your own keys

Encrypt everything with keys in your own KMS — we never hold them.

👥

SSO, SAML & SCIM

Connect your identity provider and automate user provisioning and de-provisioning.

🧾

Audit & retention

Full audit trails and retention windows you configure to match your policy.

Made for finance, healthcare & government.

Where data can't leave the building — but the blue bubble still has to work.

Finance

📈 Banks & fintech

Client comms and alerts with the isolation and audit trails regulators require.

Healthcare

🏥 Providers & payers

Patient messaging in a HIPAA-aligned deployment, with a signed BAA and PHI kept in your boundary.

Public sector

🏛️ Government

On-prem and air-gapped options for data-sovereignty and residency mandates.

Self-hosted & enterprise, explained.

Can we run MessageBlue in our own cloud or on-prem?

Yes. MessageBlue can be deployed entirely inside your own cloud account (AWS, GCP or Azure), your VPC, or on-premises for air-gapped environments. We ship the stack as infrastructure-as-code; you own the infrastructure and the data plane.

Does customer data leave our environment?

No. In a self-hosted deployment, messages, numbers and logs stay inside your compliance boundary. You control encryption keys, network policy, data residency and retention.

Do you support HIPAA and sign a BAA?

Yes. We offer SOC 2 Type II controls and HIPAA-ready deployments, and we sign a Business Associate Agreement for covered entities.

How is a self-hosted deployment supported and updated?

Our team helps you stand up the stack and ships versioned updates you roll out on your schedule. Enterprise plans include a dedicated account manager, priority support and a 99.99% uptime SLA on managed instances.

Can we use our existing business numbers?

Yes. Connect the iMessage numbers your team already texts from and control them through the API — send, receive and automate from the same trusted lines, with inbound routed to your agents or logic.

Talk to us about a private deployment.

Tell us about your environment and compliance needs, and we'll scope a deployment that fits — in your cloud, your VPC, or on-prem.