Inspector Hub
Documentation

Hosted or self-hosted?

Documentation

The inspection engine is open source. You can let us run it, or run it yourself. Both are the same software; what differs is who operates it and what exists around it.

The two ways

Hosted — we run it. You sign up, you get a workspace, and the platform handles deployment, upgrades, backups, sending infrastructure and the carrier registration your text messages need.

Self-hosted — you deploy it on your own Cloudflare account, on your own domain. Nobody can see your data but you, there is no platform bill, and every operational responsibility is yours.

What actually differs

Almost nothing about the inspection work itself. The differences cluster in three places:

Hosted Self-hosted
Billing, seats, usage caps Yes — there is a plan None. You are the platform
Sending email and texts Platform infrastructure by default; bring your own if you prefer Yours, always: connect a provider and register your own numbers
Managed text-message compliance Available Not possible — nobody can file a carrier registration on your behalf
AI assistance Platform credentials, metered; or your own Your own model and key
Content marketplace Installable, and entries can be published to you Installable — the catalogue your own build ships. Nothing is published to you
Workspace switching Several workspaces on one login One deployment, one company
First-run setup wizard Not needed Yes — /setup, gated on a secret only you hold
Branding Per workspace, in settings Settings, with environment defaults behind them

The capability-by-capability list is maintained with the engine, in its own docs/reference/deployment-modes.md, and is generated rather than written by hand.

What self-hosting actually costs

Not money — the hosting itself is inexpensive. It costs attention, in four specific places:

  1. Upgrades. New versions do not apply themselves.
  2. Deliverability. Your domain's mail records are yours to get right, and nothing in the product can tell you they are wrong.
  3. Text-message registration. Carriers require it, it takes weeks, and it is per-brand. This is the single most common reason a self-hosted deployment ends up sending only email.
  4. Backups and keys. Including the e-signature key, whose retired versions must be kept for as long as the signatures they sealed matter.

If none of those sentences worries you, self-hosting is genuinely fine. If several do, the hosted service is doing exactly that work.

When each is the right answer

Choose self-hosted when a policy requires data to stay in infrastructure you control, when you already run things on Cloudflare, or when running your own systems is something you want rather than tolerate.

Choose hosted when your time is better spent inspecting, when you need text messaging working this month rather than after a carrier review, or when nobody in the company wants to be the person who gets paged.

There is no feature ransom here: the inspection engine is the same, and this documentation covers both — a page that applies to only one says so at the top.

Moving between them

Self-hosted → hosted: export your data, register, import. The paths are the same ones any migration uses — see Switching from Spectora for the shape of a move.

Hosted → self-hosted: export from your workspace, deploy, import.

In both directions, what does not travel is the same list: signed agreements stay verifiable where they were signed, and published report versions keep the signatures they were sealed with. Moving them would mean re-signing them under a different key, which is precisely the thing the signature exists to prevent.

Plan the move so the old deployment stays readable until your retention obligations for those records are satisfied.


Next: Getting started with Inspector Hub, or the engine's own quickstart if you are deploying it yourself.