For IT teams
Brainstack Self-hosted for IT
What you'll run, how it's locked down, and how to set it up.
Architecture
How the server is laid out.
One Linux server or VM, on-premises or in your own AWS, Azure or Google Cloud account, with Docker Engine 28.0 or later. Everything runs in containers on that server. There is no AI model to run: Brainstack stores the notes people save and searches them with its own built-in search.
Scroll the diagram sideways to see all of it.
Your IdP, your rules
People sign in through Google Workspace, Microsoft Entra or any OIDC provider you already run. Nobody needs a separate Brainstack login.
Nothing to run but the app
Brainstack runs no AI model. People save notes from their assistant, and Brainstack stores them and searches them with its own built-in search. When someone asks, their assistant gets only the notes they may see.
Encrypted where it rests
Notes live in PostgreSQL on your server. Backups are encrypted to recipients whose secret keys never sit on the server.
Integrations
Sign-in and assistants.
People sign in with the work account they already have and connect their own assistant. A note is visible only to the person who saved it until they share it, and removing someone cuts their access everywhere at the same moment.
Sign-in your identity provider
- Google WorkspaceInternal app in your org
- Microsoft EntraSingle-tenant app
- Any OIDC providerSuch as Okta, Auth0, Keycloak or Authentik
Assistants over MCP
- ClaudeSave, share and search notes
- ChatGPTSave, share and search notes
Microsoft 365 CopilotSave, share and search notes- Any MCP clientStandard OAuth, per-person access
Roll-out one person or everyone
- For everyoneAn admin adds the Brainstack connector once in your assistant's admin settings, and people just sign in.
- For one personAnyone can add it with your Brainstack address and sign in with their work account.
Assistants connect over MCP with standard OAuth and each person's own access, so an assistant only ever gets the notes that person may see. Claude, ChatGPT and Copilot can all connect. Some plans need your admin to turn on custom connectors.
Specs
The details, in one place.
- Runs on
- One Linux server or VM, on-premises or in your own AWS, Azure or Google Cloud account, with Docker Engine 28.0 or later. Everything runs in containers on that server.
- Search
- Brainstack's own built-in search over saved notes. No AI model runs on the server.
- Sizing
- 2 CPU cores and 4 GB of memory for a team of about 25; no GPU.
- Sign-in
- Google Workspace (internal app in your org), Microsoft Entra (single-tenant app), or any OIDC provider such as Okta, Auth0, Keycloak or Authentik.
- Assistants
- Claude, ChatGPT, Microsoft 365 Copilot or any MCP client, with standard OAuth and per-person access. Some plans need your admin to turn on custom connectors.
- Network
- Inbound 443; outbound only to your sign-in provider. The edge serves TLS on your domain and only published routes.
- Offboarding
- Sessions and assistant tokens end in the same step. After restoring an old backup, one command re-applies removals before anyone can sign in.
- Audit
- Every assistant connection, removal and role change writes its audit record in the same transaction as the change.
- Health
manage.py doctorchecks the image, the database roles, the network isolation, sign-in and the backup keys, and names exactly what to fix.- Backups
- Encrypted backups stream straight into GnuPG. The runbook walks you through restoring onto a fresh machine.
- Upgrades
- Migrations run in a one-shot step, one transaction each, before the app starts. If anything looks off, it stops and tells you how to go back.
- Logs
- The database logs only the name of a failed rule, never the row. Customer text stays out of the logs.
- Access
- A note is visible only to the person who saved it until they share it with a person, a personal group or a company team. Removing someone cuts their access everywhere at the same moment.
Setup
Set up in an afternoon.
Three things, then run the wizard: claim the site, invite your team, add Brainstack to your assistants. We give you the exact settings for Google or Microsoft, and after that your team just signs in.
- A Linux server or VMOn-premises, or in your own AWS, Azure or Google Cloud account, with Docker Engine 28.0 or later. 2 CPU cores and 4 GB of memory for a team of about 25; no GPU, and no AI model to run.
- Your domainPoint a name like brain.yourcompany.com at it. Certificates are automatic.
- A sign-in appCreate an internal app in Google Workspace or Microsoft Entra, or use any OIDC provider. We give you the exact settings.
- Run the wizardClaim the site, invite your team, add Brainstack to your assistants.
Tested like someone is attacking it
We tried to break it. Repeatedly.
Before every release, independent reviewers who didn't write the code try to leak notes across people and teams, get past sign-in, stall the server and misread the runbook. Each finding is fixed and re-checked before anything ships.
Questions about your setup?
Get in touch and we'll set up a short call. If it's a fit, we'll help you set Brainstack up.