PremAgentic compared with the self-hosted alternatives
Five self-hosted ways to give AI assistants your company's knowledge, side by side: where each one runs, what it needs to run, how it decides who may read what, and what it does beyond that. Each cell for another product comes from that product's own documentation, repository or pricing page, as of September 28, 2026.
Updated
01Side by side
"Not documented" means the product's own pages did not describe it when we read them. It may exist, and we will correct any cell its maker shows us is wrong.
| Feature | PremAgentic | Onyx | PipesHub | Archestra | Cognee |
|---|---|---|---|---|---|
| Where it runs | Your servers, as a Windows or Linux service | Your own Kubernetes or cloud account; can run fully air-gapped | On-premises or cloud | Docker to try it; Helm on Kubernetes for production | Locally, or with Docker Compose |
| What it needs | One service and stock PostgreSQL 14 or later, no extension | Eleven services: PostgreSQL, OpenSearch, Redis, MinIO, two model servers and more | Neo4j or ArangoDB, Qdrant, MongoDB and Redis; Kafka in larger setups | PostgreSQL with pgvector (superuser); Kubernetes in production | Python 3.10 to 3.14; can run on a single PostgreSQL |
| License | GNU AGPL 3.0 | MIT core; enterprise directories under the Onyx Enterprise License | Apache 2.0 | AGPL 3.0 core, plus an enterprise license | Apache 2.0 |
| Who may read what | Rules set in PremAgentic, folder by folder; no rule means no access | Onyx's own permissions; syncing them from source systems is Enterprise | Each source system's own permissions | Source permissions synced per person; Enterprise, free under 30 users | Set up through its permissions guide, beyond a local demo |
| When the check applies | Before anything is ranked, as SQL conditions; in a standard install, access is enforced again by PostgreSQL | "At query time" | "When the query runs" | After search, fusion and reranking | Not documented |
| Superseded and stale material | Superseded held back unless asked for; stale flagged for people and held from agents | Not documented | Not documented | Not documented | Not documented |
| Machine-written content | Held from agents until a person reviews it | Not documented | Not documented | Not documented | Not documented |
| A rule for hosted models | A folder can be kept from every assistant whose model runs outside the network | Not documented | Not documented | Not documented; its traces record each call's model provider | Not documented |
| AI assistants over MCP | A token per agent; two read-only tools | An MCP server; a personal access token or API key | An MCP server; the agent connects as a specific person | An MCP gateway with OAuth 2.1 | An MCP server |
| What is kept per answer | Who asked, the question, where the model ran, the passages returned | Not documented | Not documented | Traces with prompts, tool results, model provider and user | Not documented |
| Tests for what a person must not see | A golden set names a person and the files they must not reach, and fails loudly | Not documented | Not documented | Not documented | Not documented |
| Sign-in for people | PremAgentic accounts, or a sign-in proxy you run | OIDC and SAML single sign-on on the Enterprise plan | Not checked | SSO and OIDC in the Enterprise features | Not checked |
02How to read it
- If your assistants need your company's SaaS tools (Slack, Google Drive, Jira, Salesforce) with each tool's own permissions, the products that sync source permissions fit: PipesHub, Onyx's Enterprise Edition, Archestra's Enterprise features.
- If your knowledge lives in files and folders you control, and you want old, stale and machine-written material handled as carefully as access, PremAgentic is built for that, on one box.
- If you are building agent memory, Cognee is a library-first choice.
- If your office already lives in Microsoft 365, Microsoft's own agents in SharePoint answer "based on their access permissions to the data", with nothing to install. That comparison is on Glean alternatives.
Every row in the table is a question worth asking any product in this space. The longer list is on Permission-aware RAG: before or after retrieval.
Where PremAgentic fits
PremAgentic is on-premises knowledge retrieval for agents. It indexes the Markdown, text, PDF, Word and Excel files your organization keeps and gives your people and your AI assistants cited passages out of them, with your rules enforced before anything is retrieved. It runs on your own servers, Windows or Linux, on stock PostgreSQL 14 or later, with a local embedding model: no cloud service and no third-party API key. PremAgentic is open source under the GNU Affero General Public License 3.0. The code is at github.com/premagentic/premagentic, and the latest release has the Linux and Windows archives.
Sources
Read on September 27 and 28, 2026.
- Onyx: onyx.app; pricing; MCP server; Enterprise Edition; Docker Compose file
- PipesHub: README; docs
- Archestra: deployment; knowledge base; MCP gateway; observability; pricing model
- Cognee: README
- Microsoft: agents in SharePoint