Features Platform Pricing Security API Sign in Start Free
Self-hosted HR software on Cloudflare

Run a dedicated HRlume instance inside your own Cloudflare account.

Own the Worker, database and file-storage resources while keeping the complete HRlume application experience.

Dedicated infrastructure

Infrastructure isolation without operating a traditional server stack.

HRlume's dedicated deployment is a self-hosted option for organisations that want the application's Cloudflare resources in their own account.

It is not an on-premise virtual machine: the stack remains serverless and Cloudflare-managed, while the account ownership and resource boundary belong to the customer.

What gets provisioned

A complete, isolated application stack.

Cloudflare Worker

The HRlume application runtime, authenticated API and static product interface.

D1 database

A dedicated structured database for employees, settings, workflows and application records.

R2 bucket

Private object storage for uploaded documents and files used by the instance.

Scheduled trigger

A recurring licence revalidation job aligned with the standard HRlume deployment.

Unique secrets

A fresh session-signing secret and the bindings the application requires to operate.

Bound licence

A signed HRlume licence connected to the resulting application URL and selected products.

Provisioning process

From scoped access to a working HR workspace.

The deployment flow creates the resources and returns control to the customer.

  1. 01

    Verify access

    A customer provides a scoped Cloudflare API token and account ID for the provisioning request.

  2. 02

    Create resources

    The flow creates the Worker, D1 database, R2 bucket and scheduled trigger.

  3. 03

    Deploy HRlume

    The current application source and static assets are deployed with unique instance configuration.

  4. 04

    Activate the workspace

    The customer registers the first administrator and activates the issued licence in the new instance.

Token custody

The provisioning token is used for the request and not stored by HRlume.

The token remains in the request's in-memory execution context while the resources are created. It is not written to the HRlume licence database or audit log. A future redeployment requires the customer to provide fresh access again.

Own your deployment boundary

Tell us what isolation your organisation needs.

We can review account ownership, provisioning access and rollout requirements with your team.

Talk to us