For organizations running critical security infrastructure in the cloud is not an option.
Data residency requirements, regulatory constraints, network isolation, or fully disconnected environments mean that authorization systems must run entirely inside controlled infrastructure. At the same time, these organizations still need centralized, consistent authorization with clear auditability across distributed systems.
To meet these needs, we are happy to announce the release of on-premise Cerbos Hub.
You can now run Cerbos Hub inside your own environment while continuing to manage authorization centrally across apps, services, workloads, and non-human identities. Cerbos Hub now supports all deployment options:

In regulated environments, authorization is one of the few controls that should operate continuously at runtime. Every request, every service interaction, every automated action depends on it. That is what Zero Trust authorization requires.
Authorization failures are particularly hard to detect and harder to explain. Access is granted inside trusted systems, often based on dynamic context, usually without a clear audit trail that ties decisions back to policy intent. For security and IAM teams,it is a real accountability gap.

When access rules live in application code, proving least-privilege enforcement becomes nearly impossible. Investigating incidents takes too long. Responding when policies need to change means coordinating across multiple teams and deployments. By the time a problem surfaces, it is already in production.
Cerbos Hub addresses this by making authorization a governed, observable capability at runtime. On-premise support ensures this governance model can be applied in environments with strict requirements.
Running Cerbos Hub on-premise brings the full authorization management platform inside your environment. Access decisions are governed, audited, and enforced under your operational control, without relying on external services or cloud-hosted control planes.
We know that when you run infrastructure on-premise, you expect the full product, not a limited version. That is why all Cerbos Hub capabilities are available on-premise:
All authorization use cases are supported on-premise. Whether you are securing enterprise applications, multi-tenant SaaS products, services, workloads, or AI agents, you use the same authorization management platform, regardless of how Cerbos Hub is deployed.

On-premise Cerbos Hub extends centralized authorization to every environment where it is needed. Learn more about on-premise Cerbos Hub or talk to our team to see how it fits your needs.
Book a free Policy Workshop to discuss your requirements and get your first policy written by the Cerbos team




Join thousands of developers | Features and updates | 1x per month | No spam, just goodies.
What is Cerbos?
Cerbos is an end-to-end enterprise authorization software for Zero Trust environments and AI-powered systems. It enforces fine-grained, contextual, and continuous authorization across apps, APIs, AI agents, MCP servers, services, and workloads.
Cerbos consists of an open-source Policy Decision Point, Enforcement Point integrations, and a centrally managed Policy Administration Plane (Cerbos Hub) that coordinates unified policy-based authorization across your architecture. Enforce least privilege & maintain full visibility into access decisions with Cerbos authorization.