Refix self-hosted

Your AI growth agent. On your infrastructure.

Refix investigates growth opportunities across your business and follows the work through. Run the full agent on your infrastructure, with your choice of models and access controls.

Good morning, Claire.

One experiment ready for review. Two more bets in motion.

Your next conversion experiment is ready. Invite a teammate after the first useful report. Keep signup unchanged. Review the experiment →

Accounts with a teammate convert more often

Paid conversion by day of trial

TRIAL · 14D
INVITEteammate in theaccount+4.7 pts by day 14Solo 8.4Team 13.1Paid, %

Onboarding is improving. Checking the next cohort.

Acquisition quality: waiting for trials to finish.

Try asking
What's driving growth this week?Where do users drop off?
Ask anything

Used by teams at

Your deployment, your controls

Bring Refix to your data. Keep control of the environment.

Your platform team decides where Refix runs and which services it can reach. We help you configure the deployment around your network and access requirements.

Network access you define

  • Network policies included in the chart
  • Destination controls through your firewall
  • Optional connection to the Refix control plane

Engineers to help you deploy

  • Deployment support for your platform team
  • Answers for your security review
  • Release scan reports for review

Visibility on your terms

  • Optional tracing inside your cluster
  • Controls for reporting back to Refix
  • Application updates you approve

Getting started

A clear path to your first investigation.

We work with your platform team on the setup, so your team can start using Refix in your environment.

Deployment options

Fits the infrastructure your team already runs.

Start with a single container or deploy to a production cluster. Choose the setup that fits your team and manage Refix with tools you already know.

Minimum
4 CPU cores
8 GB of memory
Intel or Arm nodes
  • Kubernetes with Helm

    The production setup. One Helm chart with network policies included, plus a reference deployment for Amazon EKS.

  • Docker Compose

    Run Refix on a single machine with one command. Connect your own Postgres and Redis when you're ready.

  • Docker All-in-One

    Try Refix in a single container. Built for evaluation and testing, with everything you need to get started.

  • Docker Swarm

    Run Refix on the Swarm cluster your team already manages, with rolling updates and failover across nodes.

Your models

Refix runs inside your walls. You pick the model.

Refix runs in your cloud and reaches only the places you allow. It calls the model you pick, with your own key or through your gateway. Every step is traced inside your cluster, where your team can review it.

Bring your own model

Pick the provider in your dashboard, and use your own key.

Traces stay in your cluster

Every plan, query, and answer is traced on your side, for your own review.

  • Prompts, answers, and actions logged locally
  • Bedrock or any OpenAI-compatible gateway
  • Switch providers without a redeploy

The full product

The same agent. Working on your growth.

Your team works with Refix in Home and Slack, with business context that carries forward. Ongoing investigations continue between conversations, inside your deployment.

Growth goals followed through

Give Refix an outcome to pursue over days and weeks. Each finding shapes what it investigates next.

Answers your team can act on

Work through a business question in Home or Slack, with the evidence behind the recommendation available to review.

Knows your business

Builds on earlier decisions, so each recommendation starts with more of your team's context.

Learns what your data means

Examines the values behind the field names to guide the investigation toward the right data.

Approvals you control

Require your team's approval before Refix takes action in connected tools.

Operate Refix on your terms.

Disable the updater to stop calls to the Refix control plane and manage releases yourself. Use your registry for images and your firewall to allow the external services your deployment needs.

  • Refix control plane connection can be disabled
  • Images mirrored to your own registry
  • Models through your own gateway
  • Updates on your schedule
  • External analytics and error reporting disabled
  • Destination allowlist enforced by your firewall

Out of the box

Self-hosted ships with the whole stack.

  • Infrastructure included

    The supporting services come bundled with Refix, ready to run privately in your environment.

  • Credentials handled for you

    Refix generates its internal credentials during setup and keeps them through upgrades.

  • Encrypted at rest

    Sensitive values are encrypted with an app key, on disks your storage class encrypts.

  • Non-root, scanned images

    Every image runs as a non-root user and is scanned with Trivy and Checkov before release.

  • Works with your secret store

    Layer SealedSecrets or External Secrets on top, with no changes to the chart.

  • No static cloud keys

    On AWS, Refix reads Athena with its pod's own IAM role, so there is no key to leak.

Before you deploy.

What your platform and security teams need to know.

Talk to a human

What do I need to self-host Refix?

For production, use Kubernetes 1.27 or newer with at least 4 CPU cores and 8 GB of memory available. You'll need Helm 3.12 or newer, an ingress controller, and a domain you control. Create a Slack app and connect a model provider or your own gateway.

Which deployment option should we choose?

Use Kubernetes with Helm for production, or Docker Compose for a single machine. Docker All-in-One is for evaluation and testing. If your team already runs Docker Swarm, deploy there with rolling updates and failover.

Does self-hosted Refix need internet access?

Your deployment needs access to the services it uses, including Slack, your model connection, and any external data sources. Image pulls and enabled services such as SSO or the updater need access too. The Helm chart limits network traffic; your firewall controls the allowed destinations.

Does any data leave our network?

Data goes to the model services and connected tools needed for the work. The optional updater also sends Refix deployment status, business context, and workspace instructions. Reporting is on by default and adds usage, user activity, investigation state, and discovered data structure. You can disable reporting separately, or disable the updater to stop calls to the Refix control plane.

What reporting can we turn off?

External analytics and error reporting are disabled in self-hosted deployments. The updater has separate reporting controls. Disable its reporting to keep usage and activity reports local. Disable the updater itself to stop its calls to Refix, including deployment status and business context.

How do updates work?

With the updater enabled, approve a new application version from your Refix dashboard. Broader chart upgrades require a separate opt-in. You can also disable the updater and run Helm upgrades yourself.

How do we back up and restore Refix?

Your platform team manages backups. Keep copies of the Postgres databases and the deployment's secrets, including the encryption key. Both are needed to restore the instance.

Which models can Refix use?

Anthropic is recommended. You can also use OpenAI, Google Gemini, Groq, DeepSeek, or OpenRouter. To manage model access centrally, route calls through your own OpenAI-compatible gateway, including one connected to AWS Bedrock.

Can we switch model providers later?

Yes. Change the provider in your Refix dashboard settings. You don't need to redeploy.

How do people sign in to the dashboard?

Use Slack sign-in or your own identity provider through OIDC, including Okta or Microsoft Entra ID. Your deployment controls which sign-in options are configured.

How much does self-hosting cost?

Self-hosting is included in Enterprise. Talk to us about pricing for your team and the help you need with deployment.

Your next growth hire. On your infrastructure.