← Blog

Alexis · 2026-09-29

Self-hosting vs SaaS: how to decide what to run yourself

Every month you pay a SaaS bill, you are paying for someone else's infrastructure, operations team, and margin. Sometimes that is the right trade. Sometimes it is not. The question is not ideology — it is a straightforward cost-benefit analysis that most teams never actually do.

This is a practical guide to making that decision without fooling yourself in either direction.

What you are actually paying for with SaaS

When you pay for a managed service — a hosted database, a monitoring platform, a CI system, an identity provider — the bill covers more than compute:

That is real value. The question is whether you are actually consuming it.

When SaaS makes sense

You do not have the operational depth. Running a production database means understanding replication lag, vacuuming, query plans, and what to do at 3am when the disk fills up. If your team does not have someone who has done that before, the managed version buys you operational insurance. The same logic applies to email delivery, DNS, and anything where the failure mode is "our customers cannot reach us."

The data is not sensitive. If the service holds customer PII or credentials, every SaaS vendor in the supply chain is an attack surface. If it holds log aggregation for internal tools, the risk profile is different.

Time to value matters more than total cost. Spinning up a managed Postgres is 10 minutes. Building a reliable self-hosted Postgres with streaming replication, automated backups, and monitoring is two or three days of focused engineering — minimum. If you are validating something and need to ship this week, that trade is usually worth making.

The vendor's compliance coverage is what you need. If your customers require you to be on infrastructure with specific certifications, a vendor's compliance coverage might be non-negotiable regardless of cost.

When self-hosting makes sense

The total cost of ownership is lower. At scale, SaaS pricing is designed for the median customer, not your specific workload. A 50-seat Grafana Cloud subscription might cost €500/month. A self-hosted Grafana instance on a €20/month VPS costs €20/month plus a few hours of initial setup. That math compounds over years.

You need control over the data. GDPR and similar regulations impose constraints on where data can live and who can access it. Self-hosting on infrastructure you control is sometimes the only way to satisfy those constraints cleanly, without relying on a vendor's data processing agreements.

The dependency risk is unacceptable. SaaS vendors shut down, get acquired, change pricing, or become unavailable in your jurisdiction. For non-critical tooling that risk is acceptable. For the identity system that every other service depends on, it is not. Authentik on your own infrastructure is not going anywhere unless you decide it does.

Your team can actually run it. This is the honest check. Self-hosting is only cheaper if you can operate it. If every incident becomes a two-day scramble, you are not saving money — you are paying in engineering time instead of subscription fees.

The hybrid approach most teams end up using

In practice, the answer is almost never all-SaaS or all-self-hosted. The useful heuristic:

A practical decision checklist

Before committing to SaaS for a new service, answer these:

If the SaaS option wins on most of those, pay the subscription. If it loses on most, the engineering investment in self-hosting will pay off. The mistake is not making the decision at all — defaulting to SaaS because it is convenient, or defaulting to self-hosting because it feels more in control.