Enterprise-grade CX with deployment choice
Chatwoot runs on our managed cloud, self-hosted in your own VPC, or fully air-gapped with self-hosted models. Governance stays on: the Enterprise plan adds SSO/SAML, custom roles, and audit logs, without slowing agents down.
Why enterprises choose Chatwoot
Control data, deployments, and compliance without sacrificing agent speed or AI assist.
Governance baked in
Custom roles, per-inbox access, and audit logs on Enterprise, ready for security reviews.
Deployment flexibility
Managed cloud, your own VPC, or air-gapped. Run Captain against self-hosted models when the deployment has no outbound access.
Resilience at scale
Self-hosted deployment docs, your own backups, and webhooks for observability during peak seasons.
Enterprise partnership
Onboarding, phone support, and developer office hours aligned with procurement steps.
Built on powerful features
Explore the features that power enterprise workflows.
SSO / SAML
Okta, Azure AD connected
Access controls
Account roles, per-inbox membership
Two-Factor Auth
Available to every user
Audit Logs
Sign-ins and config changes
Audit log
Jen R. enabled SAML SSO for org
3 min ago
Mike T. added a webhook endpoint
22 min ago
Jen R. updated a custom role
1 hr ago
Command center with guardrails on
Security and CX leads work from the same settings surface, enabling SSO/SAML, custom roles, and inbox access in minutes on the Enterprise plan. Audit logs show who signed in and what configuration changed, while Captain drafts stay in every inbox for an agent to review before sending.
- Custom permission sets and per-inbox membership decide which conversations each agent can open.
- Captain drafts, improves, and translates replies; agent-facing drafts are never sent without an agent reviewing them.
- Audit logs record sign-ins and configuration changes, keeping infosec, compliance, and support aligned during reviews.
Rollout patterns we see most
Concrete blueprints to de-risk implementation and keep compliance happy.
Phased channel rollout
Move teams channel by channel with change control across cloud and self-hosted.
- Pilot with a single inbox and SSO turned on
- Add WhatsApp, email, SMS, and social DMs with rules that route by label, team, and custom attribute
- Settle roles and per-inbox access before go-live
Compliance-first setup
Satisfy audit, legal, and security before scale.
- Set up custom roles, per-inbox access, and audit logging on Enterprise
- Send conversation, message, and contact events to your own monitoring tools through webhooks and the REST API
- Use audit logs for change reviews and incident follow-ups
Hybrid deployment control
Run self-hosted for regulated teams and cloud for the rest with matching settings.
- Architect the split between self-hosted and cloud workspaces
- Match roles, SLA policies, and automation rules on both, using self-hosted Enterprise Edition where you need SSO and SLA
- Mirror webhook endpoints so both deployments report the same events
Executive reporting and handoffs
Give leadership clarity on SLAs, CSAT, and incidents without manual slides.
- SLA and CSAT reports filtered by inbox, team, and agent
- Downloadable reports and audit logs for post-incident reviews
- Private notes and mentions for regulated handoffs
Controls, integrations, and trust
Everything you need to align with security, IT, and legal without slowing operations.
Identity and access
SSO/SAML and custom permission sets on the Enterprise plan, plus two-factor authentication for every user.
Observability and data flows
Outbound webhooks and a REST API send conversation, message, and contact events to the systems you already run.
Change management
Roll out inbox by inbox, and let Enterprise audit logs record every configuration change for review.
Enterprise FAQs
Answers security, IT, and procurement teams ask most.
Do Chatwoot cloud and self-host have feature parity?
Not entirely. Self-hosted Community Edition covers channels, automations, and reports, while SSO and SLA policies require self-hosted Enterprise Edition. Captain runs against our hosted models by default, and you can point it at self-hosted models when the deployment has no outbound access.
Can we keep data residency by region?
Chatwoot cloud runs on AWS in the United States. To keep data in another region, self-host in your own VPC or data center, where you control the infrastructure.
How does Chatwoot integrate with our security stack?
Outbound webhooks and the REST API send conversation, message, and contact events to the tools you already run. The Enterprise plan adds SSO/SAML sign-in and audit logs for investigations.
What support do you provide during rollout?
Enterprise customers get onboarding, phone support, and developer office hours, which covers implementation guidance and migration help. Chatwoot does not sell a separate support SLA.
How do you handle identity and provisioning?
The Enterprise plan supports SSO/SAML sign-in and account-wide custom permission sets, and every agent's inbox membership decides which conversations they can open.
Related resources
Design your Chatwoot deployment
Bring your security checklist (SSO, residency, audit, and SLAs) and we will map a rollout plan you can keep.