# AutoST Hosted vs On-Premises: Where the Dashboard Runs and Where the Data Stays

> AutoST has two deployment options. Hosted means Zyberum runs the backend and dashboard in the EU and you install only the Carbyne test agent on your bench. On-premises means the same backend runs as a container on your own servers, operated by your IT. In both cases the agent on the bench is the only component that touches the ECU, and the test results belong to you. The choice is about where scan results, ODX/CDD files and reports are stored, who operates the server and how fast you want to start.

AutoST runs hosted by Zyberum in the EU or as a container on your own servers. The test agent is always on your bench. What differs: data location, operations, start.

Source: https://auto-st.com/compare/hosted-vs-on-premises · Updated: 2026-10-07

## What is the difference?

This is not a comparison between two products but between two ways of running the same one. AutoST has three parts: a web dashboard, a backend that orchestrates jobs and stores findings, and Carbyne, the test agent that sits next to the ECU on your bench and does the actual bus and IP communication. The agent is always yours and always on your bench. The choice is where the other two parts live.

Hosted: Zyberum runs the backend and dashboard as a managed instance in the EU. You install the agent on a Windows or Linux machine on the bench, pair it with a token and start testing the same day. Zyberum handles updates, backups and availability; your data is stored in the EU and belongs to you.

On-premises: the backend runs as a single container on your own infrastructure, behind your own identity and network controls, operated by your IT. ODX and CDD files, scan results, fuzzing payloads and reports never leave your network. You handle updates and backups, and you can run it in a segment with no internet access at all.

## Side by side

| | Hosted by Zyberum (EU) | On-premises |
|---|---|---|
| What it finds | Identical: the same engines, the same test content, the same reports | Identical |
| What it misses | Nothing the on-premises version finds; the test runs on the same agent | Nothing the hosted version finds |
| Who does it | Your test engineers run tests; Zyberum operates the server | Your test engineers run tests; your IT operates the container |
| Bench time | Same per run; outbound HTTPS from the bench is needed | Same per run; works in a network segment without internet |
| Cost | Licence per tested component, hosting included, price on request | Licence per tested component, price on request; your server and IT time |
| Fits a release cycle | Yes; API tokens and the Bamboo plugin reach the EU instance over HTTPS | Yes; the pipeline and the backend sit on the same network |
| Required by | Nothing in the standards; fine where internal policy allows EU-hosted engineering data | Customer or OEM contracts that forbid supplier data leaving the premises; air-gapped benches; corporate policy on pre-series firmware and diagnostic descriptions |
| Output | PDF, SARIF, CSV and JSON, downloaded from the instance | The same, stored on your servers |

## Choose hosted when

- You want to start this month. A hosted instance needs an agent install and a token, not a server request, a firewall ticket and a change window.
- The team is small and nobody wants to operate another container. Updates, backups and availability are Zyberum's job.
- The data is engineering data you are allowed to store with an EU processor: scan results of your own ECUs, your own diagnostic descriptions. Many Tier-1 and OEM teams are, and a pilot is the typical case.
- You test from several sites or with an external partner and want one dashboard everybody reaches without a VPN.

## Choose on-premises when

- A customer contract or OEM requirement says supplier data stays on the premises. Pre-series firmware, ODX and CDD files and seed/key related findings often fall under this, and the on-premises container is the answer.
- The bench network has no internet access and is meant to stay that way. The agent then needs a backend it can reach on the same segment.
- You already run containers and want AutoST behind your own identity provider, logging and backup regime.
- Your security policy treats test results as evidence that must be under your retention control for the UN R155 CSMS and ISO/SAE 21434 verification files. That is possible with hosted data too, but on-premises makes the question disappear.

## Both together

Most organisations end up with one of the two, but the two are not exclusive. A common path is a hosted pilot on one ECU to see whether the product fits, then an on-premises instance when the programme grows and the contracts get stricter. Some groups run a hosted instance for an external lab or an engineering service provider and an on-premises instance for their own series ECUs. Components, scan history and the Fix Plan move between them, because it is the same software with the same licence.

Whichever you choose, the part that matters for the ECU does not change: a Carbyne agent on your bench, your CAN or Ethernet interface, your ECU. AutoST does not become a service that tests your hardware remotely; nobody at Zyberum touches your ECU unless you book a penetration test. If your only requirement is a few scans on one ECU and you have a spare machine, on-premises is a one-container install and we will not talk you into hosting.

## FAQ

**Does the hosted version send ECU traffic to Zyberum?**

No. The Carbyne agent on your bench talks to the ECU over CAN, CAN FD or Ethernet and runs the tests locally. What it sends to the backend over HTTPS are job requests, progress and results: findings, response classifications, fuzzing payloads that triggered a finding, and the files you attach to a component such as ODX or CDD. Bus traffic itself stays on the bench.

**Does the bench need an inbound connection?**

No, in either deployment. The agent polls the backend over HTTPS and pulls its jobs, so no inbound ports are opened on the bench network. For on-premises the backend is on your network; for hosted the agent needs outbound HTTPS to the EU instance.

**Can we start hosted and move on-premises later?**

Yes. It is the same software, and the licence is per tested component, not per deployment type. Teams often pilot hosted to avoid waiting for a server and move the instance in-house when the pilot becomes a programme. Scan history and components move with it.

## Sources

- [ISO/SAE 21434:2021 Road vehicles, Cybersecurity engineering, Clause 7 (distributed cybersecurity activities) and Clause 10.4.2 (verification evidence)](https://www.iso.org/standard/70918.html)
- [UN Regulation No. 155, paragraph 7.2 (CSMS requirements, including management of supplier and service provider related risks)](https://unece.org/transport/documents/2021/03/standards/un-regulation-no-155-cyber-security-and-cyber-security)
- [Regulation (EU) 2016/679 (GDPR), Chapter V (transfers of personal data to third countries)](https://eur-lex.europa.eu/eli/reg/2016/679/oj)

## Related

- [On your servers, or ours.](https://auto-st.com/deployment)
- [A dashboard in the browser, an agent on the bench.](https://auto-st.com/how-it-works)
- [Priced around your ECUs, not per seat.](https://auto-st.com/pricing)
- [AutoST for OEM Security Teams: Supplier ECUs, Gateways and Vehicle Networks](https://auto-st.com/for/oem-security-teams)
- [In-House ECU Security Testing vs an External Test Lab](https://auto-st.com/compare/in-house-ecu-testing-vs-test-lab)
- [ECU (Electronic Control Unit)](https://auto-st.com/glossary/ecu)

---
AutoST by Zyberum. Canonical page: https://auto-st.com/compare/hosted-vs-on-premises
