BARRYBARRY

Governance

Self-hosted, and outward-only by design.

BARRY runs entirely in infrastructure you control, and the client only ever connects outward.

Security here is the shape of the architecture rather than a list of features added afterwards. BARRY is self-hosted: the server runs in your cloud or your own data centre, the metadata lives in a PostgreSQL database you operate, and no data is routed through infrastructure belonging to us. The on-prem client only ever opens connections outward, so there is nothing inbound to your network at any point and no service of yours becomes reachable from outside. Sign-in uses your own identity provider through OIDC – Keycloak, Microsoft Entra ID or another – so accounts, groups and offboarding stay where they already are. Credentials can be stored as references into your own vault.

  • No inbound connection to your network, ever
  • Runs in your own cloud or on-premises
  • OIDC login via Keycloak, Microsoft Entra ID or any provider
  • Secret references to Azure Key Vault or HashiCorp Vault
  • Metadata in a PostgreSQL database you own
Outward only
The client dials out; nothing dials in.
Vault-backed
Secrets referenced, never stored in the clear.
Your estate
Your cloud, your database, your identity provider.

Ready to unlock your data?

See how BARRY brings your on-premises data to the cloud — safely, and on your terms.