SaaS or on-premises: choosing how to run DYCRYPT

Start quickly with DYCRYPT SaaS or bring licensing into your own environment with Enterprise.

The way your application verifies a DYCRYPT licence does not need to change with the deployment model. It still uses the product public key, expected product identifier, and the Java, Node.js, or Python SDK.

What changes is who operates the platform and where your signing keys live.

Choose SaaS for speed

DYCRYPT SaaS lets your team create an organisation, define products, issue licences, and integrate without operating a licensing deployment. It is the fastest way to evaluate the workflow and take a standard application into production.

Choose on-premises for Enterprise requirements

An on-premises deployment is available with the Enterprise plan when policy, data residency, network isolation, or existing security controls require DYCRYPT to run in your environment.

Enterprise can include custom development, custom user roles, and integration with an existing HSM or PKCS#11 device. With hardware-backed signing, the private key can remain on the device while DYCRYPT requests the signature it needs.

Key protection in either model

Your application receives only the public key or certificate needed to verify. DYCRYPT keeps private signing operations inside a protected signing boundary, separate from everyday product and licence management.

Choose the model that fits your operational requirements, then keep the same application-side contract: verify the signature, enforce the product and machine binding, handle licence status explicitly, and never place a private signing key in the application.