
Haystack Enterprise Platform
Enterprise platform from Berlin-based deepset for building, running and governing AI agents and RAG systems on the open-source Haystack framework, with cloud, self-hosted or air-gapped deployment and built-in access control, guardrails and audit logging.
What is Haystack Enterprise Platform?
Haystack Enterprise Platform is the commercial platform published by deepset GmbH, a Berlin company registered in 2018. Three things share the Haystack name and are worth separating: Haystack is the open-source Python framework, Haystack Enterprise Starter is a support subscription for that framework, and the Enterprise Platform is the product described here, presented as the enterprise-grade operational layer built on top of the open-source foundation.
The platform organises itself around four stages. Build offers a visual pipeline builder, a debugger, agent and pipeline templates, data indexing, custom components, MCP support and export to Python or YAML. Test adds a Playground, a Prompt Explorer, prototype sharing and feedback collection, so retrieval strategies and prompts can be compared before anything reaches users. Deploy covers one-click deployment, serverless autoscaling, a REST API and a choice between managed cloud and self-hosting. Govern brings role-based access control, a unified run history, traces, performance monitoring, usage reports and runtime guardrails.
The commercial argument is sovereignty. deepset positions the platform against tools that decide infrastructure, models and data boundaries on the customer's behalf: components are meant to be inspectable, swappable and portable, so a team can change model provider, vector store or cloud without rewriting its application. Around forty integrations are named on the product page, including OpenAI, Anthropic, Mistral, Qwen, Cohere and Ollama for models, Qdrant, Weaviate, Pinecone, Elastic, Milvus and Neo4j for storage, and AWS, Azure, NVIDIA, HPE and Hetzner for infrastructure.
The published references are unusually specific. The European Commission built its AI@EC platform on Haystack, serving 68 builders across 29 departments with 316 pipelines in staging or production. Bosch deployed an assistant to more than 600 consultants across over 120 plants. Lufthansa Industry Solutions, Airbus Defence and Space and Germany's federal BMFTR ministry are also named. A team of Forward Deployed Engineers works on customer sites, and dedicated pages address enterprise, public-sector and defence buyers.
What it does
- Design agent and RAG pipelines in a visual builder that stays aligned with code
- Index your own data and tune retrieval, metadata extraction and context
- Compare prompts, retrieval strategies and agent workflows side by side before release
- Deploy to managed cloud or your own infrastructure, including on-premise and air-gapped
- Trace every query, answer and context source in a unified run history
- Enforce role-based access control, guardrails and audit logging
- Export finished pipelines as Python or YAML for any environment
When to use Haystack Enterprise Platform / When not to
A quick filter to help you decide if Haystack Enterprise Platform is the right fit.
When to use Haystack Enterprise Platform
- Engineering teams moving an AI prototype into a governed production system without rebuilding it
- Public-sector institutions that need sovereign AI, as at the European Commission and Germany's federal BMFTR ministry
- Defence and national-security organisations deploying on-premise or in air-gapped environments
- Regulated enterprises in financial services, insurance and healthcare with strict data-boundary requirements
- Architecture teams that want to swap models, vector stores and clouds without vendor lock-in
When not to use Haystack Enterprise Platform
- Buyers who need a published price before talking to sales, since only the free tier carries a figure
- Solo users or small teams who would outgrow the free tier's single seat and single workspace
- Anyone looking for a mobile app or a browser extension, as neither exists
- Non-technical users expecting a finished assistant rather than a platform for assembling pipelines
- Teams that need certification evidence up front, as no certifying body or certificate number is published
How to use Haystack Enterprise Platform
A typical end-to-end flow, from setup to results.
- Request access to the free trial of the Haystack Enterprise Platform through the sign-up form
- Start from the pipeline template library rather than from a blank canvas
- Upload your own documents or use the sample datasets to explore indexing and metadata extraction
- Assemble the pipeline in the visual, code-aligned editor and add components from the library
- Add custom components, connect tools and APIs, or plug in MCP services where needed
- Tune retrieval accuracy and define what context, memory and tools each agent may reach
- Compare prompts and retrieval strategies in the Playground and Prompt Explorer
- Share the prototype with stakeholders and collect their feedback in one place
- Deploy to managed cloud or to your own infrastructure, on-premise or air-gapped
- Monitor the unified run history, inspect traces and enforce guardrails once live
Pros & Cons
Pros
- Built on a genuinely public open-source framework, so components stay inspectable and auditable
- Strong portability claim: models, vector stores and clouds can be swapped without rewriting the application
- Unusually broad deployment range, from managed cloud to on-premise and air-gapped environments
- Governance is native rather than bolted on, with access control, audit logs, traces and guardrails
- Named, checkable references in demanding sectors, including the European Commission and Bosch
- A permanent free tier with explicit quotas, alongside a free trial of the platform
- Around forty integrations named on the product page and a large ecosystem on the framework side
Cons
- No paid price is published anywhere: the only figure on the site is the free tier's zero
- The pricing page is linked from no page at all and was reachable only through the sitemap
- Five compliance claims are displayed without naming any certifying body or certificate number
- The product page contradicts itself, reading ISO 27001 certified in one place and compliant in another
- No data processing agreement is published or mentioned, and no subprocessor list is disclosed
- No hosting country or region is declared for customer data
- The free tier is tightly bounded: one user, one workspace and fourteen days of history and logs
Pricing & Plans
A permanent free plan is available. The pricing page lists two tiers: Studio at USD 0, described as suitable for individuals prototyping AI applications, and Enterprise priced as Custom, requiring contact with the sales team. Studio includes one workspace, one user, 100 pipeline hours, 50 files of up to 10 MB each, two development pipelines, cloud deployment and community support on Discord, with search history and logs kept for fourteen days. No amount is published for any paid tier, so the lowest paid price point cannot be stated. The separate Haystack Enterprise Starter support offer likewise carries no public price. Readers should note that the pricing page still refers to the former deepset AI Platform name, so its currency should be confirmed with the vendor.
- USD 0 - one workspace
- one user
- 100 pipeline hours
- 50 files (10 MB maximum each)
- two development pipelines
- cloud deployment
- community support on Discord
- fourteen days of search history and logs
- Custom pricing - unlimited workspaces
- users
- files and development pipelines
- unlimited high-availability production pipelines
- cloud or custom deployment
- dedicated infrastructure
- dedicated account team
- solution engineers and a private Slack channel
- up to four hours of remote technical consultation
- an email channel to core engineers
- priority updates
- extended version support for up to six months
- early access to selected features
- pipeline and deployment blueprints
Data, GDPR & hosting
A consolidated view of how Haystack Enterprise Platform handles your data.
GDPR overview
Implementation is concrete rather than declarative. The publisher is established in Berlin, so no Article 27 representative is required. The privacy policy, updated 26 September 2025, is written entirely around the GDPR: it names deepset GmbH as controller with its full postal address, designates an external data protection officer reachable at dsb@secjur.com, sets out the data subject rights in detail (access, rectification, erasure, restriction, portability, objection and withdrawal of consent) and states that no automated decision-making takes place. The product page claims the platform is GDPR compliant. Two gaps should be noted: no data processing agreement is published or even mentioned anywhere on the site, and no list of subprocessors is disclosed, Google Analytics being the only third party named.
Who owns the data?
The terms draw a clear line. Under section 4.1 the customer exclusively owns Customer Data, its own confidential information, the AI Applications it builds and any Bespoke Configurations; deepset exclusively owns the Services, its background and foreground intellectual property, its confidential information and System Data. Section 4.2 assigns Bespoke Configurations to the customer and grants a perpetual, irrevocable licence over Foreground IP, both effective once deepset has been paid in full. System Data is defined as anonymised or aggregated customer data plus usage data, and the terms state expressly that System Data contains no Customer Data. Ownership of what the customer uploads therefore never transfers to the vendor.
Reuse rights
Customers keep full freedom over their own material: they own Customer Data, the AI Applications they build and the Bespoke Configurations assigned to them, and can reuse all of it without asking deepset's permission. In the other direction, section 4.5 grants deepset a worldwide, non-exclusive licence over Customer Data for two purposes only, providing the services and creating System Data, the latter being anonymised or aggregated by definition. Section 4.3 lets deepset exploit customer feedback and suggestions freely. One point deserves attention: the privacy policy states that the deepset Studio product automatically captures which Haystack components are used and what kinds of pipelines are built, and that users consent to deepset using that telemetry, along with their personal contact details, to improve, market and sell further products. Model training on customer data is never addressed either way.
Data retention & training
Hosting summary
No hosting country or region is declared anywhere on the site, so this record leaves both fields empty rather than infer them. What the site does establish is that hosting is the customer's choice. The platform runs either on deepset's managed cloud or self-hosted on the customer's own infrastructure; the defence pages add that it can operate on-premise and in air-gapped environments with no external dependencies, and the support pages mention AWS, Azure, GCP and on-premise as target environments. AWS, Azure, HPE, Hetzner, NVIDIA and Secunet appear on the product page as infrastructure partners, which is a list of options rather than a statement about where customer data actually sits. The public-sector pages speak of controlling data residency without naming any jurisdiction. Anyone with a residency obligation should therefore settle the question contractually with deepset, since the website does not answer it. The publisher itself is established in Berlin and its privacy policy is governed by German and EU data protection law.
Things to keep in mind
Risks and trade-offs to weigh before adopting Haystack Enterprise Platform.
- Three different products share the Haystack name, the free framework, the commercial platform and the support offer, so it is easy to credit the paid platform with what the open-source project does
- Compliance is claimed but not evidenced: SOC 2 Type II, ISO 27001, HIPAA and CSA STAR Level 1 appear with no certifying body and no certificate number, and CSA STAR Level 1 is a self-assessment by design
- The product page describes ISO 27001 as certified in one place and merely compliant in another, so ask which is accurate before relying on it
- deepset Studio telemetry is broad by consent: the privacy policy says the components you use, the kinds of pipelines you build and your contact details may be used to market and sell further products
- No data processing agreement, no subprocessor list and no declared hosting country, which matters if you are the one accountable for personal data
- Pricing opacity makes budgeting hard, and the pricing page is unlinked and still carries an older product name, so its figures may be stale
- A platform that makes agents easy to ship also makes it easy to trust their answers too quickly: the run history, traces and guardrails exist precisely so that humans keep checking, and they only help if someone reads them
Setup & Integrations
Technical difficulty
Moderate to high, depending on ambition. Getting started is deliberately eased: the free trial opens onto a template library and a visual, code-aligned editor, so a first pipeline needs no code. Beyond that the audience is clearly technical, involving components, indexing, retrieval strategies and export to Python or YAML. Managed cloud deployment is described as one click, but self-hosting, on-premise and air-gapped operation assume real infrastructure skills. That deepset sells both a consulting-based Starter offer and Forward Deployed Engineers suggests complex rollouts are expected to need help.
Deployment
Integrations
Behind Haystack Enterprise Platform
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What is the difference between Haystack and the Haystack Enterprise Platform?
Is there a free plan?
Is there a free trial of the platform?
How much does the paid tier cost?
Can the platform be self-hosted?
Is there an API?
Who owns the data uploaded to the platform?
Is customer data used to train models?
Which tools and models does it integrate with?
Which organisations use it publicly?
Should you pick Haystack Enterprise Platform?
Haystack Enterprise Platform is a serious, well-documented option for organisations that want production AI they can actually control. Its strongest asset is the open-source Haystack framework underneath: components stay inspectable and swappable, which turns the anti-lock-in argument into something a team can verify rather than merely trust. The deployment range is genuinely wide, from managed cloud to on-premise and air-gapped operation, and the governance layer of access control, audit logs, traces and guardrails is built in rather than added later. The published references carry real weight, naming the European Commission, Bosch, Lufthansa Industry Solutions, Airbus Defence and Space and a German federal ministry.
Three reservations deserve to be stated plainly. First, commercial transparency is poor: the only figure anywhere on the site is the free tier's zero, the paid tier is simply Custom, and the pricing page is linked from no page at all, still carrying the vendor's former product name. Second, the compliance claims are asserted rather than evidenced. SOC 2 Type II, ISO 27001, HIPAA and CSA STAR are displayed without a certifying body or a certificate number, the same page describes ISO 27001 as both certified and compliant, and the Vanta trust centre could not be read. Third, there is no published data processing agreement, no subprocessor list and no declared hosting country, which is a notable gap for a product sold on sovereignty.
For technical teams in regulated or sovereignty-conscious organisations, the platform is worth a serious look, starting with the free tier. Buyers should simply expect to obtain pricing and compliance evidence directly from deepset rather than from the website.
- Choosing a selection results in a full page refresh.
- Opens in a new window.