Self-hosting
The kit is a Penpot file and a folder of text. There is no account to create, no service to sign in to, and nothing that calls us while you work. That changes what enterprise readiness means here, and it is worth being precise about rather than vague.
Nothing to log into
Single sign-on solves one problem: one identity across many applications. This kit is not an application. It is a file you open in your own Penpot, and a set of instruction files your own AI tool reads from disk. There is no login screen, no session and no user record, so there is nothing for an identity provider to connect to.
Identity is your Penpot
Access to the kit is access to the Penpot file, and that is governed by your Penpot rather than by us. If your organisation already runs an identity provider, connecting Penpot to it puts the kit behind the same sign-on as everything else your designers use.
What self-hosted Penpot supports today:
Nothing phones home
Every part of what you buy runs where you put it:
For a team that cannot send design work to somebody else's cloud, the whole thing can live inside the network.
Rolling it out to a team
The real question at scale is not who can log in, but how fifty people get the kit and then get the next version of it. Two moves cover it.
Publish it once as a shared library in your Penpot team. Every project connects to the same source, and updates are offered rather than forced. Membership of that team is your access control, and it is already behind whatever sign-on Penpot is configured with.
Commit them to a repository you host instead of handing out archives. Updating is a pull, the history shows who changed what, and access is governed by your Git host - which is already behind your identity provider. That gives you the audit trail provisioning would have given you, from a system you already run.
What this does not include
Said plainly, so nobody discovers it in a procurement call:
If your security review asks for a SOC 2 report or a data processing agreement covering the running product, there is no running product to cover. The questions that genuinely apply are about your Penpot instance and your Git host, and you already have answers for both.