Deployment Guide
Deploy SecureInspector on your own infrastructure. Complete control, complete privacy.
100% Self-Hosted
SecureInspector runs entirely on YOUR infrastructure. We provide the software and license - you deploy it on your servers. We have zero access to your data, dashboard, or encryption keys.
Architecture Overview
SecureInspector consists of three main components that you deploy on your infrastructure:
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β YOUR INFRASTRUCTURE β
β β
β ββββββββββββββββ ββββββββββββββββ ββββββββββββββββ β
β β Mobile App β β Backend β β Dashboard β β
β β (with SDK) βββββββΆβ (API) ββββββββ (React) β β
β β β β :8080 β β :3000 β β
β ββββββββββββββββ ββββββββ¬ββββββββ ββββββββββββββββ β
β β β
β βΌ β
β ββββββββββββββββ β
β β PostgreSQL β β
β β Database β β
β ββββββββββββββββ β
β β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Backend
Kotlin/Ktor API server. Receives captures from SDKs, serves dashboard API, manages sessions.
Dashboard
React web app. View sessions, captures, crashes. Decryption happens in browser.
Database
PostgreSQL for persistent storage. Stores encrypted captures, sessions, users.
Requirements
Minimum Requirements
- 2 CPU cores
- 4 GB RAM
- 20 GB disk space
- Docker 20.10+
Recommended (Production)
- 4+ CPU cores
- 8+ GB RAM
- 100+ GB SSD
- Kubernetes or Docker Swarm
Quick Start (Docker Compose)
The fastest way to get started. This will run all components on a single server.
1. Create docker-compose.yml
version: '3.8'
services:
postgres:
image: postgres:15-alpine
environment:
POSTGRES_DB: secureinspector
POSTGRES_USER: inspector
POSTGRES_PASSWORD: ${DB_PASSWORD}
volumes:
- postgres_data:/var/lib/postgresql/data
restart: unless-stopped
backend:
image: secureinspector/backend:latest
ports:
- "8080:8080"
environment:
DATABASE_URL: postgres://inspector:${DB_PASSWORD}@postgres:5432/secureinspector
LICENSE_KEY: ${LICENSE_KEY}
JWT_SECRET: ${JWT_SECRET}
depends_on:
- postgres
restart: unless-stopped
dashboard:
image: secureinspector/dashboard:latest
ports:
- "3000:80"
environment:
VITE_API_URL: ${API_URL}
restart: unless-stopped
volumes:
postgres_data:
2. Create .env file
# Database password (generate a strong one)
DB_PASSWORD=your-secure-db-password-here
# Your license key (provided by SecureInspector)
LICENSE_KEY=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...
# JWT secret for authentication (generate random 32+ chars)
JWT_SECRET=your-jwt-secret-minimum-32-characters
# Public URL where backend API is accessible
API_URL=https://api.yourcompany.com
3. Start the services
$ docker-compose up -d
# Check status
$ docker-compose ps
# View logs
$ docker-compose logs -f backend
4. Access the dashboard
Open http://your-server:3000 in your browser.
Default admin credentials will be shown in the backend logs on first startup.
Backend Setup
The backend is a Kotlin/Ktor application that handles all API requests from mobile SDKs and the dashboard.
Docker Run (Standalone)
$ docker run -d \
--name secureinspector-backend \
-p 8080:8080 \
-e DATABASE_URL="postgres://user:pass@db-host:5432/secureinspector" \
-e LICENSE_KEY="your-license-key" \
-e JWT_SECRET="your-jwt-secret-32-chars-minimum" \
-e ADMIN_EMAIL="admin@yourcompany.com" \
-e ADMIN_PASSWORD="initial-admin-password" \
secureinspector/backend:latest
Health Check
$ curl http://localhost:8080/health
# Response:
{
"status": "healthy",
"database": "connected",
"license": "valid",
"version": "1.2.0"
}
API Endpoints
Backend exposes two main API groups:
β’ /api/v1/captures/* - SDK endpoints (receive captures)
β’ /api/v1/dashboard/* - Dashboard API (sessions, projects, users)
Dashboard Setup
The dashboard is a React application that connects to your backend API.
Docker Run (Standalone)
$ docker run -d \
--name secureinspector-dashboard \
-p 3000:80 \
-e VITE_API_URL="https://api.yourcompany.com" \
secureinspector/dashboard:latest
Static Hosting (Alternative)
The dashboard can also be deployed as static files to any web server (Nginx, Apache, Cloudflare Pages, etc.):
# Download the static build
$ wget https://releases.secureinspector.io/dashboard/latest.tar.gz
$ tar -xzf latest.tar.gz -C /var/www/dashboard
# Configure Nginx
server {
listen 443 ssl;
server_name dashboard.yourcompany.com;
root /var/www/dashboard;
index index.html;
location / {
try_files $uri $uri/ /index.html;
}
}
CORS Configuration
If dashboard and backend are on different domains, configure CORS on the backend:
CORS_ORIGINS=https://dashboard.yourcompany.com
Database Setup
SecureInspector uses PostgreSQL 14+ for data storage. You can use a managed service or self-host.
Option 1: Managed PostgreSQL
Recommended for production. Use your cloud provider's managed PostgreSQL:
- AWS RDS for PostgreSQL
- Google Cloud SQL
- Azure Database for PostgreSQL
- DigitalOcean Managed Databases
Option 2: Docker PostgreSQL
$ docker run -d \
--name secureinspector-db \
-p 5432:5432 \
-e POSTGRES_DB=secureinspector \
-e POSTGRES_USER=inspector \
-e POSTGRES_PASSWORD=secure-password \
-v postgres_data:/var/lib/postgresql/data \
postgres:15-alpine
Database Migrations
The backend automatically runs migrations on startup. No manual action required.
Environment Variables
Backend
| Variable | Required | Description |
|---|---|---|
DATABASE_URL |
Yes | PostgreSQL connection string |
LICENSE_KEY |
Yes | Your SecureInspector license key |
JWT_SECRET |
Yes | Secret for JWT tokens (min 32 chars) |
ADMIN_EMAIL |
No | Initial admin email (first run only) |
ADMIN_PASSWORD |
No | Initial admin password (first run only) |
CORS_ORIGINS |
No | Allowed CORS origins (comma separated) |
LOG_LEVEL |
No | Logging level (DEBUG, INFO, WARN, ERROR) |
Dashboard
| Variable | Required | Description |
|---|---|---|
VITE_API_URL |
Yes | Backend API URL (e.g., https://api.yourcompany.com) |
License Installation
When you purchase SecureInspector, you receive a license key. This key validates your installation.
Receive License Key
After purchase, you'll receive the license key via email.
Add to Environment
Set the LICENSE_KEY environment variable.
Restart Backend
The backend validates the license on startup.
Offline License Validation
License validation happens locally using RSA signature verification. Your backend does NOT need to contact our servers to validate the license.
SSL/HTTPS Setup
HTTPS is required for production. Mobile SDKs expect HTTPS endpoints.
Option 1: Let's Encrypt with Certbot
# Install certbot
$ apt install certbot python3-certbot-nginx
# Get certificate
$ certbot --nginx -d api.yourcompany.com -d dashboard.yourcompany.com
# Auto-renewal is configured automatically
Option 2: Cloudflare / Load Balancer
Use your cloud provider's load balancer with managed SSL certificates, or Cloudflare for SSL termination.
Reverse Proxy (Nginx)
Recommended setup with Nginx as reverse proxy for both backend and dashboard.
# /etc/nginx/sites-available/secureinspector
# Backend API
server {
listen 443 ssl http2;
server_name api.yourcompany.com;
ssl_certificate /etc/letsencrypt/live/api.yourcompany.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/api.yourcompany.com/privkey.pem;
location / {
proxy_pass http://localhost:8080;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
# Dashboard
server {
listen 443 ssl http2;
server_name dashboard.yourcompany.com;
ssl_certificate /etc/letsencrypt/live/dashboard.yourcompany.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/dashboard.yourcompany.com/privkey.pem;
location / {
proxy_pass http://localhost:3000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
}
}
Backups
Regular backups are essential. Focus on the PostgreSQL database.
PostgreSQL Backup Script
#!/bin/bash
# backup.sh
BACKUP_DIR=/var/backups/secureinspector
TIMESTAMP=$(date +%Y%m%d_%H%M%S)
# Create backup
docker exec secureinspector-db pg_dump -U inspector secureinspector | gzip > $BACKUP_DIR/db_$TIMESTAMP.sql.gz
# Keep only last 7 days
find $BACKUP_DIR -type f -mtime +7 -delete
# Run daily via cron
# 0 2 * * * /opt/scripts/backup.sh
Updates
Updating SecureInspector is straightforward with Docker.
# Pull latest images
$ docker-compose pull
# Restart services (migrations run automatically)
$ docker-compose up -d
# Check version
$ curl http://localhost:8080/health | jq .version
Backup Before Updates
Always backup your database before updating to a new version.
Troubleshooting
Backend won't start - License invalid
- Verify the LICENSE_KEY environment variable is set correctly
- Check for extra whitespace or newlines in the key
- Ensure the license hasn't expired
- Contact support if the issue persists
Dashboard can't connect to backend
- Check VITE_API_URL is set to the correct backend URL
- Verify CORS_ORIGINS includes the dashboard domain
- Ensure both use HTTPS (or both HTTP for local dev)
- Check browser console for specific error messages
SDK not sending captures
- Verify SDK serverUrl points to your backend
- Check if an active session exists for the user/device
- Ensure API key is valid
- Check backend logs for incoming requests
- Verify SSL certificate is valid (SDK requires HTTPS)
Database connection errors
- Verify DATABASE_URL format: postgres://user:pass@host:port/dbname
- Check if PostgreSQL container/service is running
- Verify network connectivity between backend and database
- Check PostgreSQL logs for authentication errors
Need Help?
Our team is here to help you get SecureInspector running on your infrastructure. Enterprise customers receive priority deployment support.
Contact Support