PostgreSQL, inside
The database ships in the image, tuned at startup to the memory you gave the container. Point DATABASE_URL at your own server when you outgrow it.
One Docker image tonight, the same core as a Helm chart when the estate grows. The details and requirements are below.
docker run -d --name classifyre \ -p 3000:3000 \ --shm-size=1g \ -v classifyre-pgdata:/var/lib/postgresql/data \ -v classifyre-data:/var/lib/classifyre \ -v classifyre-uv-cache:/cache/uv \ classifyre/all-in-one:0.6.11Then open localhost:3000. Needs Docker and 4 GB of memory. Those volumes are what keep your work across an upgrade: the Docker guide covers the environment variables, external databases and object storage.
helm install classifyre \
oci://registry-1.docker.io/classifyre/classifyre-core \
--version 0.6.11One image, the same on macOS, Windows and Linux. The database and the scan workers are already inside, so there is nothing to provision and nothing to connect.
The database ships in the image, tuned at startup to the memory you gave the container. Point DATABASE_URL at your own server when you outgrow it.
Extraction and detection run as separate processes that exit with the scan, the same code the cluster runs as Kubernetes Jobs.
Bind-mount a directory read-only and point a source at it. Nothing is copied out; the files are read where they sit.
Sources, credentials, findings, and cases live in volumes on your disk. Nothing is uploaded to us.
Nothing here needs a config file. Every step is in the app, and each one has a page on the docs site when you want the detail.
One command, then open localhost:3000. The first boot initialises the database and creates a workspace; give it a few minutes on a laptop.
Point it at something you already run: a database, an S3 bucket, a Confluence space, or just a local folder. Credentials are encrypted at rest.
Configuring sources →Enable the built-in packs you care about: PII, secrets, security, moderation, quality. They work on the first scan with no model setup.
Pre-built detectors →Findings land ranked by importance. Group them into inquiries and cases, or add an AI provider and let the autopilot work them between scans.
AI providers →The same open-source core as a Helm chart: web, API, worker, and ephemeral scan Jobs that fan out under load and scale to zero between runs.
helm show chart oci://registry-1.docker.io/classifyre/classifyre-corelinux/amd64 + linux/arm64
Values files for k3s, an external database, and CloudNativePG; ingress, TLS, scaling, and storage.
Read the docs →Schema layout, migrations on upgrade, and connecting managed PostgreSQL.
Read the docs →Optional buckets for scan logs and uploaded artifacts.
Read the docs →How image tags track the chart appVersion, and what a version bump implies.
Read the docs →Both runtimes carry the same features, and a namespace export moves your work from one to the other, so this is not a decision you are locked into.
Wondering what the enterprise layer adds on top of either runtime? It is SSO, roles, and per-workspace authorization, not features held back from the open-source core.
Open source vs EnterpriseThe fastest honest test is a system you already run. Install it, connect one source, and see what the investigator turns up.
docker run -d --name classifyre \ -p 3000:3000 \ --shm-size=1g \ -v classifyre-pgdata:/var/lib/postgresql/data \ -v classifyre-data:/var/lib/classifyre \ -v classifyre-uv-cache:/cache/uv \ classifyre/all-in-one:0.6.11