Get started
Exposing your network with a VPN or distributing long-lived credentials to reach private servers and databases carries risk. Boundary removes both by brokering secure, identity-based access to private endpoints. Choose HCP (HashiCorp Cloud Platform) Boundary for a managed deployment, or Boundary Enterprise to self-host with full control.
| Deployment model | Hosting | Worker management | Best for | |
|---|---|---|---|---|
| HCP Boundary | Managed | HashiCorp-hosted control plane | You run your own worker proxies | Teams that want full feature parity with Enterprise without operating the control plane |
| Boundary Enterprise | Self-managed | Customer-hosted | You run the full deployment | Organizations that can't use SaaS products for compliance or regulatory reasons |
Review the Get started with HCP Boundary section to deploy the managed offering, or the Deploy Boundary section to build a self-managed production environment using Boundary Enterprise.
We recommend you use the Boundary model that best meets your intended use case. If you’re not sure what’s best for you, we recommend reviewing the Getting started with HCP Boundary section.
Key concepts
Before getting started with Boundary, it's important to understand a few key concepts. Please consult any of the following Boundary concepts pages to familiarize yourself with Boundary's architecture and terminology: