Sutram Enterprise
Your own dedicated instance, carrying your corporate identity through your own identity provider
The Enterprise edition
The same Sutram, under your organization's rules.
It is the same platform, with the same features and the same updates. What changes is everything around it — where the content is hosted, a common requirement under GDPR, LGPD and similar regimes; how people authenticate; and the absence of usage limits. Every contract is negotiated around what your case requires.
- 1
Dedicated instance
Your organization runs on its own installation, with a separate database, storage and configuration — not as a partition inside the shared cloud environment.
- 2
Closed identity
Sign-in exclusively through your company's identity provider. On your instance, email-and-password registration simply does not exist.
- 3
Your brand
White labelThe instance carries your organization's brand — logo, favicon, app icons and emails. You hand over the brand in high resolution; we prepare the complete kit for use on your own instance.
- 4
Everything in Max, without limits
Every project on your instance gets the Max plan's features — document classes, lifecycle roles, custom versioning — with no ceiling on projects, storage or bandwidth.
- 5
Negotiated contract
Price and terms defined case by case, paid against a contract and an invoice. No checkout, no credit card.
Single Sign-On and identity management
Your corporate identity, under your IT team's control.
On the Enterprise edition, Sutram connects directly to your company's identity provider. Your people reach the platform with the same credentials and security policies they already use every day — and your IT team keeps full control over who gets in, with which permissions, and for how long.
One login, with your company's security.
With Single Sign-On (SSO), your teams reach Sutram without one more password to remember. Authentication — including multi-factor (MFA) and conditional access policies — happens at your identity provider, exactly as your security team configured it.
Access that follows the employee lifecycle.
When someone joins, moves teams or leaves the company, their Sutram access is created, updated or deactivated automatically through SCIM 2.0. No orphaned accounts left behind by former employees: offboarding in your directory switches off access here too — immediately, ending open sessions and revoking integration keys. And because accounts are deactivated, never deleted, the audit trail stays intact.
Access governance in two layers.
Your directory decides who gets into the platform; each project's administrators decide who takes part and in which role. Projects in Sutram are cross-functional teams — assembled around the work at hand, not around the org chart — and every access event is recorded in the audit trail.
Guided setup, with no integration project required.
Our team runs the connection to your identity provider during onboarding — typically in hours, not weeks. On your side, registering the application at your provider takes a few minutes.
Works with the identity provider you already use.
Sutram Enterprise builds on the open identity federation standards — OpenID Connect (OIDC) for authentication and SCIM 2.0 for provisioning — which means compatibility with practically any corporate provider:
-
Microsoft Entra ID
formerly Azure AD
-
Okta
OIDC and SCIM 2.0
-
Google Workspace
-
Any OIDC provider
by protocol, not by integration
Using something else (Ping Identity, OneLogin, JumpCloud…)? Because we follow the industry standards, Sutram is most likely already compatible — talk to us and we'll confirm. Need SAML 2.0? SAML support comes under contractual commitment.
Isolation and data residency
Where your data lives is a contract clause.
For organizations with regulatory requirements on data location and isolation, your Enterprise instance can be provisioned under terms defined in the contract:
-
Dedicated cloud account
One account boundary per customer — isolation a third party can audit, not just logical separation inside a shared environment. If your organization prefers, the installation can be on-premises, on your own infrastructure.
-
Data residency where you need it
The full stack in the region you contract — application, database, storage and email. Any region where AWS operates, or your own datacenter. For regimes such as GDPR and LGPD, where the location of the data is a legal requirement rather than a preference.
-
Per-customer encryption key
A key dedicated to your organization, with secrets that never cross your account boundary and a policy denying resources outside the contracted region.
-
Version freeze
For regulated sectors that require revalidation — pharmaceutical, healthcare, computerized systems — your instance can have its version frozen: no production update without your sign-off.
These terms are set in the contract — talk to the Enterprise team to design the arrangement your compliance function requires.
Governance
Access control designed around the work, not the org chart.
Every Sutram governance feature applies in full on your Enterprise instance.
-
Roles per project
Owner, admin, member and viewer, assigned by each project's administrators. Roles are not inherited from directory groups — that's a product decision, not a gap.
-
Roles per document class
Beyond the project role, who can view, edit, review or approve each document, in line with the rules set for its class's lifecycle.
-
Document classes and lifecycle
Documents with mandatory metadata and lifecycle states — draft, review, approved, obsolete — with every transition recorded.
-
Audit trail
Who signed in, when and by which route; what was created, changed and transitioned. Deactivated accounts are preserved, never deleted.
-
Auditable consent
Project invitations require the participant's explicit acceptance, authenticated through your identity provider.
-
Export without restriction
Every project can be exported in an open format, under the control of its administrators.
What's included in the Enterprise edition
-
Single Sign-On (SSO) over OpenID Connect
SAML 2.0 under contractual commitment.
-
Automatic user provisioning (SCIM 2.0)
Accounts created, updated and deactivated in sync with your directory, taking effect immediately.
-
SSO enforced by construction
On your dedicated instance, password sign-in simply does not exist.
-
Roles defined per project
Each project's administrators name the participants and their permissions; cross-functional teams, independent of the org chart.
-
External collaborators under your policy
Consultants and auditors come in as guests on your own identity provider; allowing invitations from outside the directory is a configurable policy of your instance.
-
Access audit trail
Who signed in, when, and by which route; deactivated accounts are preserved, never deleted.
-
Isolation per organization
Your instance has its own infrastructure and configuration, independent of any other customer's.
-
Brand asset kit prepared by us
You hand over only the logo and the icon in high resolution; we generate every other asset the instance needs — favicon, app icons and email templates. Later changes are a matter of configuration, with no reinstallation.
Frequently asked questions
Do we need to change identity providers to use Sutram?
No. Sutram adapts to the provider you already use. Because we adopt the industry-standard protocols, the integration is a matter of configuration — it does not require you to change your identity infrastructure.
Who controls sign-in and MFA?
Your company does. Authentication happens at your identity provider, under the security and multi-factor policies your IT team defines. Sutram only trusts the identity your provider confirms.
What happens when an employee leaves?
Deactivating the account in your directory deactivates Sutram access immediately: open sessions end and integration keys are revoked. The account is deactivated, not deleted — its history in the audit trail stays intact.
Do our directory groups become permissions in Sutram?
No — and that's deliberate. Directory groups tend to mirror the organization's hierarchy; projects in Sutram are cross-functional teams, assembled for the work at hand. SSO decides who gets into the platform; each project's administrators decide who takes part and in which role.
What about collaborators from outside the company (consultants, auditors)?
There are two paths. The recommended one is to invite them as guest identities on your own provider (Entra ID B2B, Cloud Identity on Google) — they go through the same SSO and the same policies. Alternatively, your instance can be configured to allow invitations from outside the directory. Allowed or not allowed — that call belongs to your governance.
How long does setup take?
Our team runs the connection during onboarding, typically in hours. Registering the application at your identity provider takes a few minutes.
Do we need to migrate the data we already have on the cloud plan?
You don't start over. Projects can be exported from the cloud environment and imported into your Enterprise instance, preserving structure, versions and metadata.
How does billing work?
By contract. Price and terms are defined case by case, according to the size of the instance, the isolation requirements and the level of support. There is no checkout and no credit card — billing follows the contract and the invoice.
Shall we design the instance your organization needs?
Where the content is hosted, how people authenticate, your brand on the platform, no usage limits — all of it is set in the contract, case by case. Talk to our team and tell us what your operation requires.
Talk to the Enterprise team