Henry for Enterprise
The AI teammate your security team will approve
Henry works inside Slack and Microsoft Teams and across your tools, with the controls enterprises require: SSO, audit logs, per-workspace encryption, and deployment options down to fully air-gapped.
Security & control
Built to pass your security review
These aren't roadmap promises. The approval gate, tenant isolation, and prompt-injection defenses are already how Henry works today.
SSO & SAML
Sign in through Okta, Entra, or any SAML identity provider. Just-in-time provisioning, domain enforcement, and clean deprovisioning when someone leaves.
Unified audit log
Every action Henry takes, every tool call and every approval, is recorded. Admins can review the log and export it whenever they need answers.
Per-workspace encryption
Your workspace's secrets are encrypted under its own key. A compromise anywhere else never touches your credentials.
Database-level isolation
Workspace isolation enforced with row-level security in Postgres itself, not just discipline in application code.
Human approval gate
Reads run instantly. Anything that matters waits for a cryptographically verified human confirmation. A model can't talk its way around it.
Export & provable deletion
Take a complete machine-readable export of your data anytime. When you leave, deletion is provable, including upstream providers.
Models
Your models, your terms
Henry is model-agnostic. Pick from the latest Anthropic and OpenAI models per workspace, or bring your own API key and bill usage through your own account. Self-hosted deployments can point at any OpenAI-compatible endpoint, including models you run yourself.
- Choose any Anthropic or OpenAI model, per workspace
- Bring your own model API key, and usage bills to your account
- Explicit model selection, never silent failover
- Self-hosted inference on your own hardware
Deployment
Our cloud, or yours
Henry Cloud Enterprise
All the controls, none of the ops. Enterprise features flip on per workspace on our managed cloud, the same product your team already knows, hardened for your requirements.
- SAML SSO with just-in-time provisioning
- Admin-facing audit log with export
- Per-workspace encryption keys
- Bring your own Anthropic or OpenAI key
Self-hosted
Run Henry entirely inside your infrastructure: your database, your vector store, your models. Docker and Helm packaging for teams with real DevOps capacity, connected or fully air-gapped.
- Your own Postgres, vector store, and storage
- Any OpenAI-compatible model endpoint: vLLM, Ollama, or your enterprise gateway
- Self-hosted SAML SSO
- Air-gapped operation with versioned, offline updates
Talk to us about Enterprise
We'll walk your security team through the architecture, share our subprocessor list, and scope the deployment that fits.