Skip to content
Let’s Talk(678) 203-0800 Partner ProgramDocumentationDocsBlogContact
Product  /  Deployment

Art2link runs in your Azure tenant. Not ours, and not in your server room.

Every Art2link ESB instance is deployed from the Microsoft Marketplace into the customer’s own Azure subscription. One customer, one tenant, one cloud boundary — the one you already control.

Single-tenant SaaS Your Azure subscription Microsoft Entra ID No on-premise install

In short

Art2link ESB is a single-tenant cloud platform that deploys into the customer’s own Azure subscription from the Microsoft Marketplace. Integration data, message content and logic stay inside the customer’s cloud boundary, authenticated with Microsoft Entra ID. There is no on-premise installation and no vendor-hosted multi-tenant environment.

A customer-owned Azure tenant is not self-hosting. It is a single-tenant cloud deployment in which the customer owns the subscription. There is no on-premise installation, no server to rack and no VM image to maintain — and equally, there is no vendor-hosted multi-tenant pool holding your messages.

That distinction is the whole architecture. Lose it in either direction and you get the wrong product: on one side, middleware you have to operate; on the other, a shared runtime you have to trust.

Three deployment models, side by side.

Integration platforms resolve to one of three shapes. The differences are not features — they are questions of who owns what, and they decide the answer to every security review that follows.

Comparison of vendor-hosted multi-tenant, on-premise, and customer-owned Azure tenant deployment models
Dimension Vendor-hosted multi-tenant MuleSoft, Boomi and most iPaaS On-premise BizTalk Server and classic middleware Your own Azure tenant Art2link ESB
Who owns the subscription The vendor. You hold a licence, not an environment. You own the hardware, the OS and the SQL Server licences. You. Your Azure subscription, your tenant, your billing relationship with Microsoft.
Where message data rests In the vendor’s cloud, in a pool shared with other customers. In your data centre, on storage you maintain. In your Azure region, inside your own cloud boundary.
Who holds the encryption keys Vendor-managed by default. You, together with everything else you have to key-manage. You. Azure Key Vault in your subscription; customer-managed keys supported.
Who patches the runtime The vendor, on the vendor’s schedule. Your team. Windows Server, SQL Server, cumulative updates, forever. Nobody patches servers. It is serverless on Azure App Service — there is no OS to maintain.
Region and residency Limited to the regions the vendor has chosen to operate in. Wherever the building is. Adding a second site is a project. Any Azure region you can deploy to, under your own Azure Policy and landing-zone rules.
What you actually pay for Licence plus per-message, per-connection or per-partner metering. Server licences, mandatory SQL Server licences and hardware sized for peak. One flat monthly licence per tier, plus your own Azure consumption at your own rates. No per-message or per-partner metering.
Changing an integration Vendor tooling, vendor release process. Build, redeploy, restart host instances. Configuration change in the web console. No builds, no restarts.

What “your tenant” means concretely.

Not a posture statement. Six things you can verify in the Azure portal on day one.

A Marketplace SKU, not an installer

Art2link ESB is a transactable Microsoft Marketplace offer. You deploy it the way you deploy any other Azure resource, into the subscription you choose.

Your identity provider

Authentication runs through Microsoft Entra ID. Your conditional access policies, your MFA rules and your joiner-mover-leaver process apply without an exception being written for us.

Azure-native services underneath

The runtime is a stateless workload on Azure App Service with Azure Service Bus for messaging. Familiar components, in your resource groups, visible to your monitoring.

Your Azure consumption, your rates

Infrastructure runs on your subscription, so it lands on your existing Microsoft billing at whatever discount you have already negotiated. The Art2link licence itself is one flat monthly figure per tier — no per-message or per-partner metering.

Changes go live without a build

Routing, mapping and validation are configuration. Change them in the web console and they take effect — no compile step, no redeploy, no host instances to restart.

Nothing to patch

Serverless on Azure App Service means there is no Windows Server to harden, no SQL Server cumulative update to schedule and no host instance to babysit at 2am.

What Art2link is not.

Several software directories describe Art2link ESB with platform metadata that is simply wrong. For the avoidance of doubt, and in the same words those listings use:

  • No on-premise installation.There is no installer, no server build and no self-hosted edition.
  • No Windows, Mac, Linux or Chromebook build.Administration is a web console in the browser.
  • No iPhone, iPad or Android app.There has never been a mobile application.
  • No shared multi-tenant runtime.Your instance is yours. Nothing is pooled.

Residency and sovereignty.

Where the runtime sits is your decision, and it is enforced by the same controls you already use everywhere else in Azure.

Region

You choose it. It stays chosen.

Art2link deploys to the Azure region you nominate. There is no vendor control plane in a different geography deciding where your messages travel, because the control plane is inside your subscription with everything else.

If your organisation already enforces region restrictions through Azure Policy or a landing-zone blueprint, Art2link inherits them. No exception list, no shadow environment.

Governance

Compliance evidence you already own.

Because the resources are in your tenant, your existing audit tooling sees them. Activity logs, resource inventory, cost attribution and access reviews all work the way they do for the rest of your estate.

The controls themselves — encryption posture, RBAC model, audit logging, incident response — are documented on Security & Governance.

Deployment questions, answered plainly.

The nine questions that come up in every architecture review.

Does Art2link ESB run on-premise?

No. Art2link ESB is a cloud platform. It deploys into your own Microsoft Azure subscription from the Microsoft Marketplace. There is no on-premise installer, no server to rack and no VM image to maintain. Some software directories list Art2link ESB as “on-premises” or as having desktop and mobile builds — that listing metadata is incorrect.

Is Art2link multi-tenant or single-tenant?

Single-tenant. Each customer runs their own dedicated instance inside their own Azure subscription. Message content, integration logic and configuration are never pooled with another customer’s in a shared runtime.

Whose Azure subscription is it billed to?

Yours. The Art2link ESB licence is purchased through the Microsoft Marketplace, and the underlying Azure resources — App Service, Service Bus, storage, SQL — run in your subscription at your own Azure rates. You are never billed for Art2link’s cloud consumption, and Art2link is never billed for yours.

Can we choose the Azure region?

Yes. You pick the Azure region at deployment and the runtime stays there. Because the subscription is yours, residency policy and any Azure Policy or landing-zone rules you already enforce apply to Art2link exactly as they apply to everything else you run.

Does Art2link have a desktop or mobile app?

No. Art2link ESB is administered through a web console in the browser. There is no Windows, macOS, Linux or Chromebook build, and there is no iPhone, iPad or Android application.

Who holds the encryption keys?

You do. Secrets and certificates are held in Azure Key Vault inside your subscription. Data is encrypted in transit with TLS 1.3 and at rest with AES-256 using KMS-backed keys, and customer-managed keys are supported.

What does Cerebrum City have access to?

Only what you grant. The runtime and its data live in your subscription under your Microsoft Entra ID tenant, so access is governed by your own identity and RBAC policy. Cerebrum City publishes the platform and, where you engage managed run support, operates inside your tenant under the access you grant for that engagement.

How is this different from a “private cloud” option bolted onto a SaaS product?

It is not an option — it is the only deployment model. Art2link ESB has no vendor-hosted multi-tenant environment to fall back to, so there is no premium tier to buy in order to get isolation, and no migration path between a shared runtime and a dedicated one.

Do we need our own Azure OpenAI resource for the AI features?

The AI features are designed to run against customer-owned Azure OpenAI keys, so prompts and integration content stay inside your cloud boundary. Confirm the exact configuration for your edition with an architect before you plan around it.

Deploy it into your own subscription and look for yourself.

The Starter tier is free. Install it from the Microsoft Marketplace into a subscription you control, and confirm the boundary in your own Azure portal rather than taking a web page’s word for it.