πŸš€

Deployment Guide

Deploy SecureInspector on your own infrastructure. Complete control, complete privacy.

🏒

100% Self-Hosted

SecureInspector runs entirely on YOUR infrastructure. We provide the software and license - you deploy it on your servers. We have zero access to your data, dashboard, or encryption keys.

Architecture Overview

SecureInspector consists of three main components that you deploy on your infrastructure:

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                     YOUR INFRASTRUCTURE                              β”‚
β”‚                                                                      β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”      β”‚
β”‚  β”‚  Mobile App  β”‚      β”‚   Backend    β”‚      β”‚  Dashboard   β”‚      β”‚
β”‚  β”‚  (with SDK)  │─────▢│   (API)      │◀─────│   (React)    β”‚      β”‚
β”‚  β”‚              β”‚      β”‚   :8080      β”‚      β”‚   :3000      β”‚      β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜      β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜      β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜      β”‚
β”‚                               β”‚                                     β”‚
β”‚                               β–Ό                                     β”‚
β”‚                        β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”                             β”‚
β”‚                        β”‚  PostgreSQL  β”‚                             β”‚
β”‚                        β”‚  Database    β”‚                             β”‚
β”‚                        β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                             β”‚
β”‚                                                                      β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                        
βš™οΈ

Backend

Kotlin/Ktor API server. Receives captures from SDKs, serves dashboard API, manages sessions.

πŸ“Š

Dashboard

React web app. View sessions, captures, crashes. Decryption happens in browser.

πŸ—„οΈ

Database

PostgreSQL for persistent storage. Stores encrypted captures, sessions, users.

Requirements

Minimum Requirements

  • 2 CPU cores
  • 4 GB RAM
  • 20 GB disk space
  • Docker 20.10+

Recommended (Production)

  • 4+ CPU cores
  • 8+ GB RAM
  • 100+ GB SSD
  • Kubernetes or Docker Swarm

Quick Start (Docker Compose)

The fastest way to get started. This will run all components on a single server.

1. Create docker-compose.yml

version: '3.8'

services:
  postgres:
    image: postgres:15-alpine
    environment:
      POSTGRES_DB: secureinspector
      POSTGRES_USER: inspector
      POSTGRES_PASSWORD: ${DB_PASSWORD}
    volumes:
      - postgres_data:/var/lib/postgresql/data
    restart: unless-stopped

  backend:
    image: secureinspector/backend:latest
    ports:
      - "8080:8080"
    environment:
      DATABASE_URL: postgres://inspector:${DB_PASSWORD}@postgres:5432/secureinspector
      LICENSE_KEY: ${LICENSE_KEY}
      JWT_SECRET: ${JWT_SECRET}
    depends_on:
      - postgres
    restart: unless-stopped

  dashboard:
    image: secureinspector/dashboard:latest
    ports:
      - "3000:80"
    environment:
      VITE_API_URL: ${API_URL}
    restart: unless-stopped

volumes:
  postgres_data:

2. Create .env file

# Database password (generate a strong one)
DB_PASSWORD=your-secure-db-password-here

# Your license key (provided by SecureInspector)
LICENSE_KEY=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...

# JWT secret for authentication (generate random 32+ chars)
JWT_SECRET=your-jwt-secret-minimum-32-characters

# Public URL where backend API is accessible
API_URL=https://api.yourcompany.com

3. Start the services

$ docker-compose up -d

# Check status
$ docker-compose ps

# View logs
$ docker-compose logs -f backend

4. Access the dashboard

Open http://your-server:3000 in your browser. Default admin credentials will be shown in the backend logs on first startup.

Backend Setup

The backend is a Kotlin/Ktor application that handles all API requests from mobile SDKs and the dashboard.

Docker Run (Standalone)

$ docker run -d \
  --name secureinspector-backend \
  -p 8080:8080 \
  -e DATABASE_URL="postgres://user:pass@db-host:5432/secureinspector" \
  -e LICENSE_KEY="your-license-key" \
  -e JWT_SECRET="your-jwt-secret-32-chars-minimum" \
  -e ADMIN_EMAIL="admin@yourcompany.com" \
  -e ADMIN_PASSWORD="initial-admin-password" \
  secureinspector/backend:latest

Health Check

$ curl http://localhost:8080/health

# Response:
{
  "status": "healthy",
  "database": "connected",
  "license": "valid",
  "version": "1.2.0"
}

API Endpoints

Backend exposes two main API groups:
β€’ /api/v1/captures/* - SDK endpoints (receive captures)
β€’ /api/v1/dashboard/* - Dashboard API (sessions, projects, users)

Dashboard Setup

The dashboard is a React application that connects to your backend API.

Docker Run (Standalone)

$ docker run -d \
  --name secureinspector-dashboard \
  -p 3000:80 \
  -e VITE_API_URL="https://api.yourcompany.com" \
  secureinspector/dashboard:latest

Static Hosting (Alternative)

The dashboard can also be deployed as static files to any web server (Nginx, Apache, Cloudflare Pages, etc.):

# Download the static build
$ wget https://releases.secureinspector.io/dashboard/latest.tar.gz
$ tar -xzf latest.tar.gz -C /var/www/dashboard

# Configure Nginx
server {
    listen 443 ssl;
    server_name dashboard.yourcompany.com;
    root /var/www/dashboard;
    index index.html;

    location / {
        try_files $uri $uri/ /index.html;
    }
}

CORS Configuration

If dashboard and backend are on different domains, configure CORS on the backend: CORS_ORIGINS=https://dashboard.yourcompany.com

Database Setup

SecureInspector uses PostgreSQL 14+ for data storage. You can use a managed service or self-host.

Option 1: Managed PostgreSQL

Recommended for production. Use your cloud provider's managed PostgreSQL:

  • AWS RDS for PostgreSQL
  • Google Cloud SQL
  • Azure Database for PostgreSQL
  • DigitalOcean Managed Databases

Option 2: Docker PostgreSQL

$ docker run -d \
  --name secureinspector-db \
  -p 5432:5432 \
  -e POSTGRES_DB=secureinspector \
  -e POSTGRES_USER=inspector \
  -e POSTGRES_PASSWORD=secure-password \
  -v postgres_data:/var/lib/postgresql/data \
  postgres:15-alpine

Database Migrations

The backend automatically runs migrations on startup. No manual action required.

Environment Variables

Backend

Variable Required Description
DATABASE_URL Yes PostgreSQL connection string
LICENSE_KEY Yes Your SecureInspector license key
JWT_SECRET Yes Secret for JWT tokens (min 32 chars)
ADMIN_EMAIL No Initial admin email (first run only)
ADMIN_PASSWORD No Initial admin password (first run only)
CORS_ORIGINS No Allowed CORS origins (comma separated)
LOG_LEVEL No Logging level (DEBUG, INFO, WARN, ERROR)

Dashboard

Variable Required Description
VITE_API_URL Yes Backend API URL (e.g., https://api.yourcompany.com)

License Installation

When you purchase SecureInspector, you receive a license key. This key validates your installation.

1

Receive License Key

After purchase, you'll receive the license key via email.

2

Add to Environment

Set the LICENSE_KEY environment variable.

3

Restart Backend

The backend validates the license on startup.

Offline License Validation

License validation happens locally using RSA signature verification. Your backend does NOT need to contact our servers to validate the license.

SSL/HTTPS Setup

HTTPS is required for production. Mobile SDKs expect HTTPS endpoints.

Option 1: Let's Encrypt with Certbot

# Install certbot
$ apt install certbot python3-certbot-nginx

# Get certificate
$ certbot --nginx -d api.yourcompany.com -d dashboard.yourcompany.com

# Auto-renewal is configured automatically

Option 2: Cloudflare / Load Balancer

Use your cloud provider's load balancer with managed SSL certificates, or Cloudflare for SSL termination.

Reverse Proxy (Nginx)

Recommended setup with Nginx as reverse proxy for both backend and dashboard.

# /etc/nginx/sites-available/secureinspector

# Backend API
server {
    listen 443 ssl http2;
    server_name api.yourcompany.com;

    ssl_certificate /etc/letsencrypt/live/api.yourcompany.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/api.yourcompany.com/privkey.pem;

    location / {
        proxy_pass http://localhost:8080;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

# Dashboard
server {
    listen 443 ssl http2;
    server_name dashboard.yourcompany.com;

    ssl_certificate /etc/letsencrypt/live/dashboard.yourcompany.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/dashboard.yourcompany.com/privkey.pem;

    location / {
        proxy_pass http://localhost:3000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }
}

Backups

Regular backups are essential. Focus on the PostgreSQL database.

PostgreSQL Backup Script

#!/bin/bash
# backup.sh

BACKUP_DIR=/var/backups/secureinspector
TIMESTAMP=$(date +%Y%m%d_%H%M%S)

# Create backup
docker exec secureinspector-db pg_dump -U inspector secureinspector | gzip > $BACKUP_DIR/db_$TIMESTAMP.sql.gz

# Keep only last 7 days
find $BACKUP_DIR -type f -mtime +7 -delete

# Run daily via cron
# 0 2 * * * /opt/scripts/backup.sh

Updates

Updating SecureInspector is straightforward with Docker.

# Pull latest images
$ docker-compose pull

# Restart services (migrations run automatically)
$ docker-compose up -d

# Check version
$ curl http://localhost:8080/health | jq .version

Backup Before Updates

Always backup your database before updating to a new version.

Troubleshooting

Backend won't start - License invalid
  • Verify the LICENSE_KEY environment variable is set correctly
  • Check for extra whitespace or newlines in the key
  • Ensure the license hasn't expired
  • Contact support if the issue persists
Dashboard can't connect to backend
  • Check VITE_API_URL is set to the correct backend URL
  • Verify CORS_ORIGINS includes the dashboard domain
  • Ensure both use HTTPS (or both HTTP for local dev)
  • Check browser console for specific error messages
SDK not sending captures
  • Verify SDK serverUrl points to your backend
  • Check if an active session exists for the user/device
  • Ensure API key is valid
  • Check backend logs for incoming requests
  • Verify SSL certificate is valid (SDK requires HTTPS)
Database connection errors
  • Verify DATABASE_URL format: postgres://user:pass@host:port/dbname
  • Check if PostgreSQL container/service is running
  • Verify network connectivity between backend and database
  • Check PostgreSQL logs for authentication errors

Need Help?

Our team is here to help you get SecureInspector running on your infrastructure. Enterprise customers receive priority deployment support.

Contact Support