Run on your own servers
Banks can run all of Sieve inside their own data centre: the engine, the dashboard, the database and the AI analyst. With the settings below, no customer data leaves your network.
What runs where
- Sieve API and dashboard: two containers, behind your load balancer and TLS.
- PostgreSQL: yours (a managed or existing cluster), or the bundled one.
- AI analyst: any model you host behind an OpenAI-compatible server (Ollama, vLLM, LM Studio, llama.cpp, TGI). Models with tool calling and JSON output work best, such as Qwen 2.5 or Llama 3.1. Reasoning-only models still write investigations and STR drafts.
- Sanctions lists: files your compliance team places in a folder (OFAC, UN, OpenSanctions exports, and your own internal watchlist as CSV), re-read every hour.
- Email: your SMTP relay. Code Guard: your GitHub Enterprise Server.
# Nothing leaves your network SIEVE_EGRESS=private SIEVE_EGRESS_ALLOW= # e.g. .ofac.treas.gov if you allow list downloads # Your own model, behind any OpenAI-compatible server SIEVE_AI_PROVIDER=local LOCAL_LLM_BASE_URL=http://ollama:11434/v1 # or http://vllm:8000/v1 LOCAL_LLM_MODEL=qwen2.5:14b # Your mail relay, your list files, your GitHub Enterprise SMTP_URL=smtp://relay.yourbank.local:25 WATCHLIST_DIR=/data/watchlists GITHUB_API_URL=https://github.yourbank.local/api/v3
Nothing leaves unless you allow it
With SIEVE_EGRESS=private, Sieve refuses every outbound connection that does not resolve to an address inside your network, including redirects, unless the host is on your allow-list. The cloud model is switched off automatically. Webhooks must then point at internal services. Pair this with a network policy that denies egress; the deployment bundle includes one.
Your data, from day one
Load your existing customers and transaction history, with your confirmed fraud flags, before going live. See Load your history. Keys, encryption secrets and backups stay with you: the encryption keys never leave your servers, so keep a copy of them with your database backups.
The deployment guide (Docker Compose, Kubernetes manifests, air-gapped install, sizing and hardening) is in docs/ON_PREM.md in the release bundle.