Dedicated deployment
Your own asset and worker API infrastructure
The dedicated tier moves the whole PIM Sync plane — the asset pipeline, the worker API and the provenance ledger — into your own Cloudflare account, alongside your own data plane and your own signing authority. Two ways to get there, delivering the same result; they differ only in who runs the deployment and how you are billed. What PIM Sync does →
Two paths
We deploy it, or you do
Path A — delegated. $30,000 once, then $7,500/month. We provision the worker API and asset pipeline into your Cloudflare account, run the signing-key ceremony with you, and hand over a running deployment with its runbook. Invoiced against a contract or RFP response.
Path B — self-deployed. $9,500/month, no upfront. Your team stands the deployment up from the licensed source; we take custody from there and maintain it. Billed through Shopify as a private plan on the PIM Sync app you already have — no capital request, and no new supplier for procurement to onboard.
Cumulative cost
The two paths cross at fifteen months
The figure that matters is the running total, not the monthly.
| Elapsed | Path A — we deploy | Path B — you deploy | Difference |
|---|---|---|---|
| Day one | $30,000 | $0 | B lower by $30,000 |
| 6 months | $75,000 | $57,000 | B lower by $18,000 |
| 12 months | $120,000 | $114,000 | B lower by $6,000 |
| 15 months | $142,500 | $142,500 | the crossover — identical |
| 24 months | $210,000 | $228,000 | A lower by $18,000 |
| 36 months | $300,000 | $342,000 | A lower by $42,000 |
Path B costs more past fifteen months, and we would rather explain that than have you find it. In Path A the deployment is paid for separately, so the retainer is pure maintenance. In Path B there is no deployment fee, so the monthly covers maintaining a system we did not build and do not control — verifying a configuration we did not choose, supporting drift we did not introduce, running ceremonies against an environment we inherited. The difference is $2,000 a month, and what it buys is the absence of a capital request and the absence of a procurement cycle. If both of those are easy for you, take Path A.
Identical on both
All three trust roots become yours
Your Xano instance holding the product, asset and market records. Your Cloudflare account running the worker API and R2 asset storage, with your own master key wrapping every stored credential. Your Ed25519 signing keys and your own published JWKS — so your provenance certificates verify against you, not against us. On the shared tier we sign the proof of what happened; here you do, and your evidence chain no longer depends on us continuing to exist.
The custody obligations are the same on both paths: scheduled key ceremonies, credential rotation across all three expiry clocks, SBOM regeneration as the dependency surface moves, CRA evidence upkeep, and the runbook kept true against the versions you are actually running. There is no one-time price because there is no one-time security — deployment is the part that ends, custody is the part that does not.
One thing changes contractually on either path: we stop attesting on your behalf. The assurance an auditor evaluates becomes yours. That is a transfer of responsibility, not only of infrastructure, and it is better understood before purchase than during a review.
Data plane
Your records live in a backend you own
Both paths require your own Xano instance, and we set it up with you — a guided session provisions it, creates the tables, mints a scoped key and hands you the credentials. You leave owning it, and Xano bills you directly. A breach of our systems cannot expose your data because we hold no copy of it; revoke the key you issued and access ends the same second, with nothing to delete on our side.