Pick whose subscription it runs in
The product is the same build on every path. What changes is who owns the infrastructure, who operates it, and how much of our time comes with it.
Two topologies, one product
Self-hosted, the managed application creates the whole stack in a resource group you own and hands you the keys. Hosted, we run that stack and give your workspace a dedicated database and its own secrets on shared compute.
How each one works
Stingray-hosted — free month, then $150/month
Take it with your Microsoft account and the workspace is provisioned in minutes; the first month costs nothing. We operate the infrastructure and the upgrades. Shared compute, so throughput is lower than a dedicated deployment, and support is standard rather than implementation hours.
Self-hosted managed application
Deploys into your own subscription as an Azure managed application. The application tier, database, storage and Key Vault are provisioned into your resource group and owned by you, under your network policy and your governance.
GCC High
For US government and regulated workloads, Nexus deploys into Azure Government through the service catalog, against government identity endpoints. Same product, same controls, scoped per engagement.
What actually differs
| Stingray-hosted | Self-hosted / GCC High | |
|---|---|---|
| Price | Free for 1 month, then $150 / month, billed by Microsoft | Private offer, scoped with you |
| Runs in | Stingray's Azure subscription | Your Azure subscription and region |
| Infrastructure | Shared compute, dedicated database and secrets | Dedicated throughout, owned by you |
| Data custody | Your data is processed on infrastructure we operate | Data never leaves your tenant |
| Secrets | Key Vault we operate, isolated per tenant | Your Key Vault, no vendor access |
| Throughput | Lower — the substrate is shared | Sized by you |
| Support | Standard support | Implementation and support scoped with you |
| Time to first query | Minutes, self-serve | A deployment session with us |
What you get on every path
Whichever way you run it, the platform is the same: the same adapters, the same query engine, the same pipelines, Sites, MCP server and desktop app — and the same controls around them. Authentication is Microsoft Entra ID, access is governed by per-resource RBAC, secrets are resolved from Key Vault and never returned by the API, and every action lands in an append-only audit log alongside a git-backed history of everything anyone authored.
- Microsoft Entra ID authentication and granular RBAC
- Key Vault-backed secrets, never logged or returned
- Append-only audit log and version history
- Signed image updates
Not sure which path fits?
Tell us what you need to connect and where the data is allowed to live. We will tell you which one to buy.