> ## Documentation Index
> Fetch the complete documentation index at: https://aspect.build/llms.txt
> Use this file to discover all available pages before exploring further.

# Hosted by Aspect

> Aspect Enterprise hosted in Aspect's cloud: an isolated Aspect Workflows deployment for your organization, provisioned and operated by Aspect. What Aspect runs, what stays yours, what you provide and what you can configure.

Hosted by Aspect, Aspect Enterprise is a complete, isolated Aspect Workflows deployment (CI runners, remote cache, remote execution and the Build Results UI) in its own account in Aspect's cloud. Aspect provisions and operates it. It's for teams that need isolation without running infrastructure themselves.

The difference from [self-hosted](/docs/aspect-workflows/enterprise/deployment-options/self-hosted) is whose cloud account it sits in and who holds the credentials, not what you get.

## What Aspect operates

Everything below the endpoints:

* Provisioning the account, the network and every service in it.
* Monitoring, alerting and 24/7 on-call. Aspect holds the pager for the deployment.
* Upgrades, in scheduled windows. Patch upgrades need nothing client-side; for a minor or major, Aspect sends any client-side steps before the window.
* Capacity: runner groups and remote execution worker fleets scale to the ceilings configured for your deployment.
* Backups and restores of the build event database.
* Certificate issuance and renewal for your endpoints.

You never run `terraform apply` or hold cloud credentials.

## What stays yours

* **Your repository and your pipelines.** The pipeline definitions stay in your repo and keep calling `bazel`.
* **Your Bazel configuration.** Which actions run remotely, which platforms they target, what gets cached: all decided by your `.bazelrc` and your `BUILD` files.
* **The configuration.** You decide it and Aspect applies it, through your support channel. Routine changes, such as resizing or adding runner groups and remote execution pools, go in without downtime. Upgrades and identity or domain changes are scheduled with you.

## What you configure

| Area | What you decide |
| - | - |
| **Runner groups** | Name, instance type, scaling bounds, idle runners, warming set, disk size. See [CI runners on Aspect Enterprise](/docs/aspect-workflows/enterprise/ci-runners) |
| **Remote execution pools** | Container image, platform properties, instance type, concurrency, scaling bounds. See [Remote execution on Aspect Enterprise](/docs/aspect-workflows/enterprise/remote-execution) |
| **Retention** | How long the remote cache and the build event history keep data |
| **Endpoint domain** | Aspect's domain, or a subdomain you delegate to Aspect |
| **Sign-in** | Aspect sign-in, optionally with SSO through your identity provider; or your own identity provider in place of Aspect sign-in |
| **Network path** | Authenticated public endpoints, plus private endpoints over AWS PrivateLink or GCP Private Service Connect |

## What you provide

* **A CI provider credential**, if you use Aspect Workflows CI runners: it lets the runners register with your CI provider and scale on its queue. It doesn't give Aspect write access to your repositories. Runners clone with the credentials your CI provider issues, as your existing runners do.
* **An identity decision**: Aspect sign-in, with or without SSO, or your own identity provider.
* **A DNS decision**: endpoints on Aspect's domain, which needs nothing from you, or a subdomain you delegate.

## Reaching the endpoints

Your cache, remote execution and build event endpoints are on the public internet, authenticated, not inside your VPC. Developers and CI log in once and the Aspect CLI configures Bazel for them.

For CI runners you operate yourself, or workstations that must not egress to the internet, private endpoints (AWS PrivateLink or GCP Private Service Connect) can be added: Aspect publishes the endpoint service and you create the endpoint in your VPC. No route exchange, no CIDR coordination.

## Where the isolation stops

The infrastructure and the data are isolated **within Aspect's cloud**: the account is Aspect's, and Aspect's engineers hold the credentials to operate it. That's data isolation without data ownership; see [how to choose](/docs/aspect-workflows/platform/choosing#how-to-choose).

Choose [self-hosted](/docs/aspect-workflows/enterprise/deployment-options/self-hosted) instead if you need any of:

* The deployment in your own cloud account, with direct access to it.
* VPC peering with your own networks.
* A region or partition Aspect doesn't operate in, including GovCloud.

[Security](/security) covers what the deployment stores and who at Aspect can reach it.

## Where to go next

<Card title="Talk to us" icon="comments" href="/contact">
  Plan a deployment hosted by Aspect, or ask about a 30-day trial of Aspect Enterprise.
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.