Enterprise

AI governance
at enterprise scale.

Bonsai is built for teams that need control, visibility, and security — not just another chat window. From solo dev to Fortune 500, governance scales with you.

GPG-Signed

Cryptographic identity for publishing and authentication

TOTP 2FA

Time-based one-time password support

On-Prem VPC

Deploy behind your firewall

GDPR/CCPA

Data stays where you put it

RBAC Permissions

Scope-based access control with cascading policies. Permissions flow from Global → Workspace → Conversation Tree → Conversation → Branch.

  • Cascading scope hierarchy
  • Allow/Deny effect policies
  • GPG key signing for identity
  • API key management

Budget Governance

Never wake up to a surprise API bill. Set per-workspace, per-team, and per-agent budgets with token, USD, tool call, and concurrency limits.

  • Token and USD limits
  • Tool call governance
  • Provider usage tracking
  • Daily/Weekly/Monthly periods

Inference Locality

Control where inference happens. Enforce local-only for sensitive data, route general queries to the cloud, or mix both.

  • LocalOnly, CloudOnly, Any modes
  • Auto localhost detection
  • Cascading policy enforcement
  • Per-conversation overrides

Team Portals

Shared workspaces with roster management, invitation system, and shared building blocks. Your team's collective AI intelligence in one place.

  • Team roster management
  • Invitation and approval system
  • Shared block publishing
  • Portal-level permissions

Full Audit Trail

Every message, tool call, model request, and agent action is logged and searchable. Exportable for compliance.

  • Complete event bus logging
  • Per-resource audit access
  • Export for external compliance
  • Searchable conversation history

Block Security Validation

Every building block is scanned for malicious patterns before installation. Command injection detection, sensitive directory protection, env var scanning.

  • Malicious pattern detection
  • Command injection checks
  • Sensitive path protection
  • Audit log for validations

Deploy how you want

Bonsai runs as a single binary or Docker container. Deploy on your laptop, your team's server, or your company's VPC. Pluggable storage backends let you swap in Postgres, S3, Redis, and Elasticsearch as you scale.

Docker Container

Single container deployment. Works on any Docker host.

VPC / On-Prem

Deploy behind your firewall. No data leaves your network.

Pluggable Backends

SQLite (default), Postgres, S3, Redis — swap via config.

Health Monitoring

Built-in health endpoints. Docker healthcheck included.

Deployment OptionsLocalcargo run / binarySQLite storagelocalhost:3000Notebook-first devSingle user, zero configDockerdocker compose upSQLite / VolumeTraefik reverse proxyAuto SSL (Let's Encrypt)Small team, single hostVPC / Private CloudKubernetes / NomadPostgres clusterInternal network onlyTeam portalsOrg-wide, controlledBonsai CloudManaged hostingAuto-scalingBackups + DRSLA supportEnterprise, managedStorage Backend CompatibilityStorageLocalDockerVPCCloudSQLitePostgresS3 / R2

Ready to bring Bonsai to your team?

We work with teams of all sizes to deploy, configure, and onboard. Enterprise support, custom SLAs, and fine-tuning pipelines available.

View Pricing