Self-Hosting
Bedrock GRC is hosted by Foxx Cyber by default. Running it on your own infrastructure is available on request: what the self-hosting kit contains and what running it involves.
Bedrock GRC is hosted by Foxx Cyber by default: Foxx Cyber runs it, applies updates and keeps its backups, and there is nothing to install.
An organization that needs to keep the console on its own infrastructure can run it itself. Self-hosting is available on request: write to support@foxxcyber.com. Access to the release images, the deployment guide, terms and support are arranged with you then.
This page describes what running it involves, so you can judge whether it suits you.
What you run
| Part | Notes |
|---|---|
| The app | One container: a single program on a minimal image with no shell or package manager. It applies database updates and loads the framework catalog each time it starts. |
| PostgreSQL 18 | Holds everything, uploaded files included. Files and two-step sign-in secrets are encrypted by the app before they reach the database. |
| A reverse proxy you already run | Caddy, nginx, Traefik or a cloud load balancer, to provide HTTPS for your chosen address. |
One host with Docker or Podman is enough. Run exactly one app container per database: sign-in limits and a few settings are kept in the app's memory.
The kit
- A compose file that runs the released app image beside PostgreSQL 18, with health checks on both. The app listens only on the host itself, so it is reached through your proxy and nothing else.
- An example settings file listing every setting, with the commands to generate each secret.
- A deployment guide covering image tags, every setting, the reverse proxy (with Caddy and nginx examples), the first admin, backups, a restore drill and upgrades.
- Built-in commands in the app image: create the first admin's password hash, check the app's health, check that every stored file and two-step secret opens with your encryption key, and reset an admin's two-step sign-in in an emergency.
Settings and secrets
The app reads its settings from the environment and refuses to start if any is missing or malformed, listing every problem at once. The ones that matter most:
| Setting | Why it matters |
|---|---|
| Base URL | The HTTPS address people type. It goes into emails, portal links and calendar feeds. |
Session secret (SESSION_SECRET) | Signs sessions and protects client access links and calendar feeds. Changing it signs everyone out and quietly retires every link and feed already sent. |
File encryption key (FILES_KEY) | Encrypts every uploaded file, every two-step sign-in secret and every single sign-on client secret. Without it, uploads, two-step sign-in and single sign-on are off, and people whose firm requires single sign-on need an admin to unlink them before they can sign in. Losing it loses every stored file. |
| Optional: a Resend API key and a sending address. Without them, invitations and portal links are copied by hand and the board report is downloaded rather than emailed. | |
Time zone (APP_TZ) | The practice's IANA time zone. It decides what "today" is (default dates, due and overdue) and the zone every time is shown in, on pages and in emails. The audit log's CSV export gives times in UTC. |
Proxy trust (TRUST_PROXY, TRUST_PROXY_HOPS) | Tells the app to read the client's address and scheme from your proxy, and how many proxies sit in front of it, so the address recorded in the audit log is the one your own proxy saw. Turn it on only when the app is reachable from the proxy alone. |
| Limits | Upload, bulk upload and restore sizes, and the longest session an admin may allow. |
Generate every secret fresh for your deployment. Foxx Cyber never needs to see them.
First start
- Create the first admin's password hash with the app image's own command. It checks the password against the default password policy (at least 14 characters, the four kinds of character, not a commonly used password). The name, email and firm rules are checked at the first sign-in, which asks for a new password if this one falls short.
- Put the admin's email and the hash in the settings file and start everything. The first admin is created only while there are no accounts, so there is no window where the first visitor becomes admin. Remove those lines afterwards.
- Sign in, set up two-step sign-in (required for everyone by default), then review the password policy on Team, invite your team and set your practice details under Branding.
Backups
Two things must be kept, apart from each other:
- The database, dumped nightly with
pg_dump, stored encrypted and copied off the host. Files in it are encrypted, but every other record (client names, risk registers, assessment answers, the audit log) is readable to anyone with the dump. - The file encryption key and the session secret, held in escrow somewhere else: a password manager vault or secrets manager that two named people can open, or a sealed envelope in a safe. A dump without the key restores every record but no file; a dump stored beside its key protects nothing.
Once a quarter, restore the latest dump into a scratch database and run the app's file check with the escrowed key. It proves every file and two-step secret opens, and it fails loudly if anything is wrong or there is nothing to check. Write down the date, the dump used and who ran it.
Client backups from a client's Import / export page are a different thing, for handing over or moving one client; they do not replace database dumps.
Upgrades
Releases are published as image tags: an exact version that never moves, and broader tags that follow the newest release. Pin an exact version to decide when upgrades happen.
- Read the release notes.
- Take a fresh database dump.
- Pull the new image and restart. Database updates apply on start.
Database updates only move forward. To go back a version, restore the dump from step 2 and run the previous image.
Who does what
| You | Foxx Cyber |
|---|---|
| The host, its operating system and its access | Release images and release notes |
| PostgreSQL, the reverse proxy and HTTPS certificates | The deployment guide and the kit |
| Generating, storing and escrowing the secrets | Answering questions at support@foxxcyber.com, on the terms agreed |
| Database backups and the quarterly restore drill | |
| When to upgrade, and monitoring the service | |
| Who has an account, and the settings in the console |
How the application itself separates clients and protects data is the same hosted or self-hosted; see Security Model.