Private delivery · TaiGong 1.3.4

Keep phishing simulation inside your security boundary.

01 / Operating boundary
Infrastructure · Data · Credentials

Customer-controlled by design.

Self-hosting changes who operates the environment; it does not imply that every licensed module is included.

Application and storageCUSTOMER ENVIRONMENT

Run the management service, simulation engine, and database locally.

TaiGong can run as a packaged server or through the documented Docker path. SQLite is the default local database.

Operational evidenceCUSTOMER CONTROL

Set your own retention and backup policy.

Campaign records, result evidence, configuration, logs, and backups remain governed by the customer deployment.

Delivery configurationCUSTOMER RESPONSIBILITY

Connect your own domains and providers.

The customer configures DNS, TLS, phishing domains, SMTP, and any separately licensed messaging provider.

Production operationsSHARED PROCESS

Separate software delivery from infrastructure responsibility.

Yofune_Labs supplies releases, licensing, and contracted support. The customer owns network exposure, credentials, monitoring, backups, delivery reputation, and production hardening.

02 / What the license changes
Core · Licensed · Integration-only

A deployment method is not a feature bundle.

The Community baseline can be self-hosted. Commercial entitlements add the corresponding 1.3.4 modules to a machine-bound deployment.

Self-hosted capabilityStatusCurrent boundary
Packaged server and documented Docker pathCoreCustomer-operated application deployment.
SQLite local databaseCoreDefault local storage path; backup and retention are customer responsibilities.
Email campaigns, templates, pages, groups, SMTP, results, and IMAP monitoringCoreCommunity email-simulation baseline.
API tokens and tenant-aware resourcesCoreAvailable for platform integration and resource scoping.
SMS, DingTalk, Feishu, WeCom, stages, automation, advanced analytics, awareness, RBAC, and audit consoleLicensedEnabled only by the corresponding commercial entitlement and provider configuration.
Slack event-notification webhookIntegration-onlySelected outbound TaiGong events can be posted to Slack. Slack is not an exercise-delivery provider.
Slack or Microsoft Teams simulation deliveryUnsupportedNot shipped as delivery channels in 1.3.4.
Autonomous AI Agent / v1.3.5 featuresUnsupportedNot part of the current self-hosted release statement.
03 / Governance
Access · Audit · Release integrity

Fit TaiGong into an existing operating model.

Use core tenant-aware resources and API tokens, then add licensed RBAC and the audit-log console where the commercial deployment requires them.

Customer controls

Own the environment.

Control network segmentation, administrator access, DNS, certificates, credentials, storage, log handling, backups, and disaster recovery.

  • Do not expose the management plane unnecessarily
  • Separate exercise domains from production domains
  • Keep SMTP and provider secrets server-side
  • Back up the database, configuration, and license files
Review security controls
Release and license controls

Deploy versioned artifacts.

Release packages can include build hashes and integrity signatures. Commercial self-hosted licenses are machine-bound and must be reissued through the approved process when the deployment machine changes.

  • Current public product version: 1.3.4
  • Schema compatibility checks fail closed
  • Optional modules follow the signed entitlement
  • Commercial resale requires separate authorization
Discuss the deployment
04 / Alternative
Managed SaaS

Need the workflow without maintaining the application?

Managed SaaS keeps TaiGong’s product model while Yofune_Labs operates the application environment. Select the path according to data boundary and operational responsibility—not feature-count assumptions.

Private evaluation

Review the boundary before the feature list.

Discuss infrastructure, scale, provider dependencies, license scope, and operating responsibility for one representative deployment.