product / edge api

The API That Runs
Where Your Data Lives

Deploy a lightweight API in your own cloud. Your private key stays in your VPC — we route requests, never read data.

See how it works ↓
Zero data exposureDocker / K8s readyBYOD — Bring Your Own Data
how it works

Deploy once. Own everything.

Four steps to a fully sovereign analytics pipeline — no vendor data access at any point.

01

Deploy

Docker image, K8s-ready

Pull the Edge API Docker image and deploy it inside your own cloud or on-premise environment. One command, and it's running in your VPC.

  • Docker image
  • Kubernetes-ready
  • Self-hosted
02

Configure

Private key + ClickHouse connection

Set your private decryption key and your ClickHouse connection string in the Edge API config. The key never leaves your environment — not even on startup.

  • Private key stays in your VPC
  • Bring your own ClickHouse
  • Zero key exposure
03

Route

Enspect handles metadata and routing

Encrypted event payloads flow through Enspect's cloud — but Enspect only sees ciphertext. We handle auth, rate limiting, and routing. Plaintext stays in your infra.

  • Ciphertext-only routing
  • Auth & rate limiting
  • Zero-knowledge cloud layer
04

Query

Direct ClickHouse queries from dashboards

Dashboard queries run through the Edge API directly against your ClickHouse. Results are returned to the Enspect UI — never cached or stored in the cloud.

  • Direct ClickHouse queries
  • Results never leave your infra
  • No data warehouse needed
capabilities

Your infra. Your rules.

VPC-native deployment

Runs inside your network perimeter.

The Edge API container runs entirely within your cloud environment. No traffic to external endpoints except Enspect's routing layer — and that only sees ciphertext.

Private key ownership

You hold the decryption key. Always.

Your AES-256-GCM private key is set in your Edge API config and never transmitted. Enspect has no copy, no escrow, no access — by architecture.

Bring your own ClickHouse

Connect to any ClickHouse instance.

Point the Edge API at any ClickHouse cluster — cloud-hosted, self-managed, or on-premise. Your data schema stays yours; we never define or migrate it.

No data warehouse required

Query in place. No staging copies.

Analytics queries hit your ClickHouse directly — no ETL, no staging area, no mirrored warehouse. Your data stays exactly where it is.

Compliance-scoped

Audits cover only your infrastructure.

Because no plaintext ever reaches Enspect's cloud, your compliance scope — SOC 2, GDPR, HIPAA — covers only your own environment. Not a third-party vendor.

Lightweight footprint

One container, minimal resources.

The Edge API is a single stateless container. No complex orchestration, no databases to manage, no persistent state. Easy to scale, easy to update.

topology

How data moves. And where it stops.

Your infrastructure · VPC
Edge API container
Decrypts payloads · Routes queries
Private key store
AES-256-GCM · Never transmitted
ClickHouse cluster
All your plaintext data lives here
Enspect Cloud · Control Plane
Routing layer
Auth · Rate limiting · Queue
Metadata store
Chart schemas · Query templates · Config
Dashboard UI
Visualizes results returned by Edge API
ciphertext only
Zero-knowledge guarantee
Private key never transmitted
Query results never touch Enspect
Enspect holds metadata only

Your private key. Your ClickHouse. Your infra. We just route the requests.

get started

Ready to own your pipeline?

Deploy the Edge API in your cloud and run analytics without ever handing your data to a vendor.

← Back to features