AI governance
at enterprise scale.
Bonsai is built for teams that need control, visibility, and security — not just another chat window. From solo dev to Fortune 500, governance scales with you.
GPG-Signed
Cryptographic identity for publishing and authentication
TOTP 2FA
Time-based one-time password support
On-Prem VPC
Deploy behind your firewall
GDPR/CCPA
Data stays where you put it
RBAC Permissions
Scope-based access control with cascading policies. Permissions flow from Global → Workspace → Conversation Tree → Conversation → Branch.
- Cascading scope hierarchy
- Allow/Deny effect policies
- GPG key signing for identity
- API key management
Budget Governance
Never wake up to a surprise API bill. Set per-workspace, per-team, and per-agent budgets with token, USD, tool call, and concurrency limits.
- Token and USD limits
- Tool call governance
- Provider usage tracking
- Daily/Weekly/Monthly periods
Inference Locality
Control where inference happens. Enforce local-only for sensitive data, route general queries to the cloud, or mix both.
- LocalOnly, CloudOnly, Any modes
- Auto localhost detection
- Cascading policy enforcement
- Per-conversation overrides
Team Portals
Shared workspaces with roster management, invitation system, and shared building blocks. Your team's collective AI intelligence in one place.
- Team roster management
- Invitation and approval system
- Shared block publishing
- Portal-level permissions
Full Audit Trail
Every message, tool call, model request, and agent action is logged and searchable. Exportable for compliance.
- Complete event bus logging
- Per-resource audit access
- Export for external compliance
- Searchable conversation history
Block Security Validation
Every building block is scanned for malicious patterns before installation. Command injection detection, sensitive directory protection, env var scanning.
- Malicious pattern detection
- Command injection checks
- Sensitive path protection
- Audit log for validations
Deploy how you want
Bonsai runs as a single binary or Docker container. Deploy on your laptop, your team's server, or your company's VPC. Pluggable storage backends let you swap in Postgres, S3, Redis, and Elasticsearch as you scale.
Docker Container
Single container deployment. Works on any Docker host.
VPC / On-Prem
Deploy behind your firewall. No data leaves your network.
Pluggable Backends
SQLite (default), Postgres, S3, Redis — swap via config.
Health Monitoring
Built-in health endpoints. Docker healthcheck included.
Ready to bring Bonsai to your team?
We work with teams of all sizes to deploy, configure, and onboard. Enterprise support, custom SLAs, and fine-tuning pipelines available.