Deployment Models: Brand and Hosting
Paprel is one product with one API contract. Deploying it involves two independent choices, and the common mistake — ours as much as anyone's, in earlier versions of this page — is to present them as a single menu of three "models". They are not alternatives to each other. You pick one option on each axis.
| Axis | Default | Alternative |
|---|---|---|
| Whose brand fronts it | Paprel-visible — you integrate over the API; Paprel-hosted workspace surfaces carry our name | White-label — your brand end to end, partner_id on every tenant |
| Where it runs | Shared — Paprel-operated multi-tenant infrastructure | Dedicated or BYOC — your cloud, or isolated infrastructure scoped per engagement |
White-label is a branding and attribution choice, not a hosting one: a white-label platform runs on the same shared infrastructure as everyone else unless it also picks the alternative on the second axis. Conversely, a dedicated deployment does not have to be white-label. All four combinations exist.
Hosting and branding do not determine the billing unit. Standard shared-infrastructure subscriptions cover one accounting entity: one separate set of books. Starter is US$149/month per entity, including 5,000 Ops/month for that entity; Growth is US$499/month per entity, including 30,000 Ops/month for that entity. Each additional entity requires a separate subscription and Ops allowance. B2B platforms and embedded accounting partners require a commercial agreement even when using shared infrastructure and Paprel branding. Dedicated, isolated and private/BYOC deployments also use custom commercial terms. Contact Sales for custom pricing; shared plans and Op definitions explain the standard per-entity offer.
Vendors are routinely vague about deployment boundaries; we'd rather you cite this page in your evaluation.
Shared hosting — the default
Paprel operates shared multi-tenant infrastructure: API, ledger, hosted workspace surfaces. You integrate over REST (or MCP for agents) and never think about infrastructure.
Two properties matter architecturally:
- Processing locations. Confirm hosting, backups, logs, support access and onward processing locations in the deployment schedule. A tenant region does not itself guarantee that every processing activity stays in that region.
- Sandbox → production is the trial path. Sandbox is self-serve — no billing, no sales call. Run the 20-minute build there, then move to production on Starter (US$149/month per accounting entity, including 5,000 Ops/month for that entity) with a 14-day trial. Sandbox and production are separate, isolated environments, so evaluation never touches live data.
Choose shared hosting when its infrastructure and data-residency boundaries meet your needs. An entity can use a standard Starter or Growth subscription for its own books. B2B platforms and embedded accounting partners can also use shared hosting, under custom commercial terms; shared hosting does not make a platform’s merchant entities included in one standard subscription.
White-label — your brand end to end
The brand axis, not the hosting axis. Same infrastructure you were already on, different ownership of the customer relationship. Every tenant you provision carries your partner_id, attributing it to your platform rather than floating as an independent signup — the field that makes this white-label rather than just multi-tenant. The full setup (provisioning, per-tenant roles, tenant-scoped OAuth) is walked in the white-label setup guide.
Two delivery surfaces today:
- Headless API under your brand. Your UI, your domain, your design system. Paprel is the engine behind your endpoints.
- Hosted surfaces. Paprel-hosted workspace views you hand your customers, for the accounting screens you don't want to rebuild.
Published @paprel/embed-* npm packages provide production Web Components and typed resources for accounts, journals, banking, transactions, reconciliation, and financial reports inside your application shell. Invoices, bills, expenses, and credit notes remain API-first surfaces.
Commercially, white-label is scoped as a partner agreement: white-label SaaS distribution, committed usage bands, and rollout support, priced per engagement rather than metered off Starter.
Choose white-label when you sell accounting to your own customers — vertical SaaS, neobanks, accounting firms, fintech platforms — and our name should never appear on their books.
Dedicated deployment / BYOC — your cloud
The hosting axis. For teams whose compliance posture or network boundary rules out shared infrastructure: dedicated infrastructure or bring-your-own-cloud, with private networking where the engagement calls for it.
This is not a checkbox; it's a scoped engagement. Usage, support, infrastructure, security review, and rollout support are scoped together under the same partner agreement — deployment shape, region, and operational responsibilities get decided with your security reviewers in the room, not discovered after signature. Bring them: we'll walk architecture, controls, and documentation in detail.
Choose private/BYOC when a regulator, a procurement gate, or your own security policy requires the ledger to run inside infrastructure you control — and accept that the path starts with a conversation, not a sandbox key. (You can and should still evaluate the product in sandbox first; it's the same API surface.)
What stays the same whichever you pick
Neither axis changes the product — only who hosts and whose name your customers see:
- Same OpenAPI surface. One API contract across every combination of the two axes. Code you write against sandbox is the code you ship, whichever model you land on.
- Same ledger guarantees. Double-entry, balance-validated postings — unbalanced entries are rejected, not corrected silently. Journal history is append-only; writes are idempotent via client-supplied keys.
- Supported exports. Confirm formats, coverage, permissions and exit access for the agreed service.
- Same ownership terms. Your data is yours — processed to provide the service, not sold or used for advertising. A DPA and sub-processor list are available on request during evaluation.
Confirm provider, processing-location, recovery and assurance details for your deployment. Provider assurance does not certify Paprel. No certification delivery date is promised; uptime targets differ from commitments in an agreed SLA.
Where to go next
- White-label accounting — commercial page for branded distribution, and why it is independent of where the ledger runs
- Build embedded accounting in 20 minutes — the sandbox path every model starts from
- White-label platform setup — tenants, roles, and scoped tokens under your brand
- Security & trust — controls, data ownership, and compliance posture in full
- Pricing — per-entity Starter/Growth subscriptions on shared infrastructure; custom commercial terms for platform partnerships and dedicated/private/BYOC deployments