Research

PremAgentic compared with the self-hosted alternatives

Five self-hosted ways to give AI assistants your company's knowledge, side by side: where each one runs, what it needs to run, how it decides who may read what, and what it does beyond that. Each cell for another product comes from that product's own documentation, repository or pricing page, as of September 28, 2026.

01Side by side

"Not documented" means the product's own pages did not describe it when we read them. It may exist, and we will correct any cell its maker shows us is wrong.

FeaturePremAgenticOnyxPipesHubArchestraCognee
Where it runsYour servers, as a Windows or Linux serviceYour own Kubernetes or cloud account; can run fully air-gappedOn-premises or cloudDocker to try it; Helm on Kubernetes for productionLocally, or with Docker Compose
What it needsOne service and stock PostgreSQL 14 or later, no extensionEleven services: PostgreSQL, OpenSearch, Redis, MinIO, two model servers and moreNeo4j or ArangoDB, Qdrant, MongoDB and Redis; Kafka in larger setupsPostgreSQL with pgvector (superuser); Kubernetes in productionPython 3.10 to 3.14; can run on a single PostgreSQL
LicenseGNU AGPL 3.0MIT core; enterprise directories under the Onyx Enterprise LicenseApache 2.0AGPL 3.0 core, plus an enterprise licenseApache 2.0
Who may read whatRules set in PremAgentic, folder by folder; no rule means no accessOnyx's own permissions; syncing them from source systems is EnterpriseEach source system's own permissionsSource permissions synced per person; Enterprise, free under 30 usersSet up through its permissions guide, beyond a local demo
When the check appliesBefore anything is ranked, as SQL conditions; in a standard install, access is enforced again by PostgreSQL"At query time""When the query runs"After search, fusion and rerankingNot documented
Superseded and stale materialSuperseded held back unless asked for; stale flagged for people and held from agentsNot documentedNot documentedNot documentedNot documented
Machine-written contentHeld from agents until a person reviews itNot documentedNot documentedNot documentedNot documented
A rule for hosted modelsA folder can be kept from every assistant whose model runs outside the networkNot documentedNot documentedNot documented; its traces record each call's model providerNot documented
AI assistants over MCPA token per agent; two read-only toolsAn MCP server; a personal access token or API keyAn MCP server; the agent connects as a specific personAn MCP gateway with OAuth 2.1An MCP server
What is kept per answerWho asked, the question, where the model ran, the passages returnedNot documentedNot documentedTraces with prompts, tool results, model provider and userNot documented
Tests for what a person must not seeA golden set names a person and the files they must not reach, and fails loudlyNot documentedNot documentedNot documentedNot documented
Sign-in for peoplePremAgentic accounts, or a sign-in proxy you runOIDC and SAML single sign-on on the Enterprise planNot checkedSSO and OIDC in the Enterprise featuresNot checked

02How to read it

  • If your assistants need your company's SaaS tools (Slack, Google Drive, Jira, Salesforce) with each tool's own permissions, the products that sync source permissions fit: PipesHub, Onyx's Enterprise Edition, Archestra's Enterprise features.
  • If your knowledge lives in files and folders you control, and you want old, stale and machine-written material handled as carefully as access, PremAgentic is built for that, on one box.
  • If you are building agent memory, Cognee is a library-first choice.
  • If your office already lives in Microsoft 365, Microsoft's own agents in SharePoint answer "based on their access permissions to the data", with nothing to install. That comparison is on Glean alternatives.

Every row in the table is a question worth asking any product in this space. The longer list is on Permission-aware RAG: before or after retrieval.

Where PremAgentic fits

PremAgentic is on-premises knowledge retrieval for agents. It indexes the Markdown, text, PDF, Word and Excel files your organization keeps and gives your people and your AI assistants cited passages out of them, with your rules enforced before anything is retrieved. It runs on your own servers, Windows or Linux, on stock PostgreSQL 14 or later, with a local embedding model: no cloud service and no third-party API key. PremAgentic is open source under the GNU Affero General Public License 3.0. The code is at github.com/premagentic/premagentic, and the latest release has the Linux and Windows archives.

Sources

Read on September 27 and 28, 2026.

  1. Onyx: onyx.app; pricing; MCP server; Enterprise Edition; Docker Compose file
  2. PipesHub: README; docs
  3. Archestra: deployment; knowledge base; MCP gateway; observability; pricing model
  4. Cognee: README
  5. Microsoft: agents in SharePoint