The same engine, either way
Midplane Cloud runs the same open-source engine and control plane that self-hosters run. Cloud layers hosting and managed credentials over it; it never reimplements enforcement. So a query that’s denied self-hosted is denied on Cloud, for the same reason, with the same audit row.Licensing
Midplane is open core. Everything in the safety story — the engine, the control plane and dashboard, table access, the guardrails, column masking, and the full audit trail — is MIT-licensed and free to self-host. The one Enterprise feature is SSO/SAML, which lives under a singleee/ directory in the control-plane source; delete that directory and you still have a complete, working Midplane. On Cloud, Free and Pro run the MIT core and the Team plan adds SSO. Contributions go to the MIT code under DCO sign-off; Enterprise licensing questions go to sales@midplane.ai.
Side by side
A few of these are worth a word:
- Deployment. Self-host now means running the Midplane control plane yourself with
MIDPLANE_SELF_HOST=1— the dashboard, projects, policy grid, and audit. One command with Docker (./bin/self-host up) brings up the whole stack; the engine runs as a local subprocess inside it, so there are no per-project containers to manage. See Quickstart and the deploy guide. - Credentials. Self-hosting, your credentials live in your environment and never leave it. On Cloud, they’re KMS-encrypted at rest — see how Cloud secures your data.
Choose Cloud if…
- You want a protected endpoint in minutes with no infrastructure to run.
- You’d rather not manage database credentials yourself — KMS-encrypted storage is handled for you.
- Data residency matters and you need to pin to the EU or US region.
- You want managed hosting and support that scales with your tier.
Choose self-host if…
- Your credentials must never leave your environment.
- You want to run inside your own VPC, behind your own ingress.
- You want the free MIT core with no hosted dependency.
- You prefer policy as version-controlled YAML in your own repo.
Get started
Quickstart
Connect a database and get a protected endpoint — Cloud or self-host.
About Midplane Cloud
Regions, projects, tokens, the dashboard, and what’s on the roadmap.