AfterPack Enterprise

A custom contract: priority on custom development, a private engine installation in your own cloud, a joint security review, and two deployment shapes for source that cannot leave your infrastructure.

Enterprise is a working relationship rather than a bigger plan, for organizations that cannot let a third party touch their source on that party's infrastructure. Two deployment shapes cover most cases: a Confidential Computing enclave in your own cloud, and an on-prem double-blind install. Both run the full pipeline, with the same transforms and presets as the public cloud; only where it runs changes. Enterprise sits above Studio.

Delivered per engagement

Everything on this page is scoped, built, and installed under a custom contract. There is no self-serve path and no price list: scope, timeline, and attestation policy are written into the agreement. To keep source on your own machines today with no contract, use Mode 1, the free local engine.

What an engagement delivers

  • Priority on custom development. Your deployment requirements, and the transforms or preservation rules your stack needs, are worked ahead of the public queue.
  • A private engine installation. The engine runs in your own GCP, AWS, or Azure account, or on hardware inside your perimeter. The two shapes below are the options.
  • A joint security and certification process. We work through your security constraints with your team: questionnaires, architecture review, data-handling terms, and the evidence your auditor asks for.

Confidential Computing

Confidential Computing is Enterprise-only, scoped during onboarding, with attestation policies set per contract.

The AfterPack engine runs inside a Confidential Computing enclave in your cloud account (AWS Nitro Enclaves, GCP Confidential Space, Azure Confidential VMs). Your build uploads source to the enclave and receives obfuscated output back, using the same wire contract as the public cloud. The enclave is attested before any source enters it, so once attestation passes, AfterPack the company cannot see your source, and you can verify that independently on every build.

Your VPCYour build(CI runner)AfterPack-CC enclaveattested, sealed binaryno source egresssource →← obfuscatedattestation → your audit logSource never leaves your VPC.

The enclave proves what is running through hardware-rooted attestation on every build, and a changed binary fails attestation and fails your build. It runs as a sealed binary with no debug interface, no remote management and no telemetry channel, its network policy permits attestation endpoints only, and each build emits a signed report (input hash, output hash, attestation hash) for your own evidence locker.

Your developers change nothing: the framework plugin and npx afterpack@latest work as they do on the public cloud, and @afterpack directives are honored the same way.

On-prem / double-blind install

For Enterprise. The AfterPack engine ships as a sealed binary installed inside your environment: air-gapped data centers, government-adjacent clouds, or anything that cannot reach the public internet at build time.

Two properties make it double-blind:

  • AfterPack never sees your source. The runtime lives inside your perimeter. There is no callback to AfterPack infrastructure.
  • Your team never reads AfterPack's source. The binary is signed, integrity-verified, and ships without symbols. Reverse-engineering it is contractually prohibited.

This deployment targets the strictest government and regulated-industry regimes. It is built and installed for your environment under a custom contract, and the installation and update procedure is agreed with your team before the first build runs.

SLA and operations

Enterprise is the only tier with a contractual, financially-backed uptime SLA: 99.9% annual, compared with the 99.5% monthly SLO the standard cloud API runs for Indie, Team, and Studio. Incident response, support channels, patch commitments, and data-residency terms are all part of the same contract. See SLA for what those targets cover. An on-prem deployment's uptime depends on your own infrastructure.

Compliance. A SOC2 Type II report is not available. A GDPR DPA, security-posture documentation, and customer-specific addenda are available on request, and an engagement includes working through your own certification process with your team.

Custom transforms

Enterprise engagements can request additions to the transform catalog, for example:

  • A pattern recognizer for a custom DSL or templating language your team uses.
  • A preservation rule for a proprietary runtime-reflection mechanism, beyond what identifiers.reserved covers.
  • An additional destructive transform tuned to a specific threat, for example trace-replay-hostile binding for anti-cheat. Anti-cheat still needs server-authoritative validation. Read What AfterPack does not replace first.

Custom transforms ship as part of your private build of the engine. They are scoped per contract and never added to the public engine.

When the cloud SaaS isn't enough

Three signals tell you you've outgrown the public cloud plans:

  1. Compliance won't approve the cloud touching source and your auditor wants the runtime in your own environment. → The free local engine.
  2. You need transforms that don't exist in the public engine. → Studio or Enterprise.
  3. You need a custom contract: SLAs, indemnification, or data-handling commitments beyond the standard DPA. → Enterprise.

If none of these apply, use Team or Studio on the public cloud.

Contact

For Enterprise scoping, deployment questions, or custom-transform requests:

support@afterpack.dev. Typical response time is one business day. Include the scale of code you are protecting (lines or megabytes), your cloud or on-prem requirements, and the compliance regime driving the conversation.


Next