Skip to main content

Updated Oct 8, 2026Verified against the product Oct 7, 2026

Deploying in Your AWS Account

FunnelStory can run as a single-tenant deployment inside your own AWS account, instead of on FunnelStory's multi-tenant cloud. Choose it when your security or data-residency policies require customer data to stay in infrastructure you own: the application, its database and its storage all run in your account, behind your network controls, and your users reach it on your private network.

This page is an overview for your platform, cloud and security teams. Customer-VPC deployments are arranged with your FunnelStory account team, who provide the detailed deployment package during onboarding. For Google Cloud, see Deploying in Your Google Cloud Project.

How it works​

FunnelStory deploys and operates the application in a VPC in your account. You own the account, the network around it, and who can reach it.

Runs in your accountStays with FunnelStory
The FunnelStory application, on Amazon EKSThe deployment automation and its source code
Your data: the database (Amazon Aurora PostgreSQL), file storage (Amazon S3) and application secrets (AWS Secrets Manager)Container images, which are copied into your account for each release
Encryption keys (AWS KMS) and logs (Amazon CloudWatch)
An internal load balancer for your users

Your customer data stays in your account. The application reaches out only to the systems you connect it to, such as your CRM, data warehouse, support tool, LLM provider and messaging tools.

What you provide​

Before FunnelStory deploys, your team prepares:

  • An AWS account and region. We recommend a dedicated account for FunnelStory.
  • A VPC with private subnets in at least two Availability Zones.
  • A hostname and certificate for the address your users will use, such as funnelstory.example.com.
  • Private access for your users, from your corporate network or VPN to the internal load balancer.
  • Outbound access from the VPC to the services you connect FunnelStory to.
  • Single sign-on with your identity provider. See Single Sign-On (SSO).

If your organization uses Service Control Policies or other guardrails, share them with FunnelStory before the first deploy. Some steps, such as creating security groups or IAM roles, can be done by your team instead when a policy requires it.

How FunnelStory's access is controlled​

FunnelStory's access to your account follows two principles:

  • Changes go through automation, not people. Infrastructure changes and releases run from FunnelStory's deployment pipeline using short-lived, federated credentials. Only reviewed changes can reach your account, and no long-lived AWS keys exist.
  • People have no standing access. If an incident needs hands-on work, FunnelStory engineers use a break-glass role that is disabled by default. Your team enables it for that incident and disables it afterward. FunnelStory can't grant itself access.

You create the roles FunnelStory uses, and you can revoke them at any time. FunnelStory doesn't need organization, billing or account-management access.

Shared responsibility​

AreaYouFunnelStory
Account and networkThe AWS account, VPC, routing, security groups and network monitoringThe application's network requirements
Identity and accessAWS administrators, your identity provider, and approving break-glass accessApplication roles and permissions inside FunnelStory
ApplicationApproving changes to infrastructure you controlDeploying, upgrading and operating the application
DataData classification and retention policiesEncryption in transit and at rest, and backups
Security monitoringAccount-level logging, threat detection and scanningApplication audit logging, and fixing vulnerabilities in FunnelStory's components
IncidentsAccount and network issuesApplication issues, with joint triage through a shared channel

AWS is responsible for the security of the cloud itself: its data centers, the EKS control plane and the managed database engine. Response times, maintenance windows and other commitments are set in your agreement with FunnelStory.

Getting started​

  1. Talk to your FunnelStory account team about scope: the region, the data sources to connect, and your LLM provider.
  2. Review the deployment package. FunnelStory provides the access, network and sizing requirements for your platform and security teams.
  3. Prepare your account and create the access roles, following the package.
  4. FunnelStory deploys the application and gives you the address to point your hostname at.
  5. Connect single sign-on and your data sources, and agree the shared support and incident process.