Sovereign & air-gapped deployment

Your estate never leaves your estate

An autonomous assessment that runs entirely inside your perimeter. With no relay configured it opens no connection outside your network — not for licensing, not for telemetry, not for model inference.

This is not the cloud product with its network calls switched off. Offline is the design.

Modbus TCPDNP3IEC 60870-5-104S7commEtherNet/IPOPC UAIEC 62443IEC 61511
refinery-hist-01 — isolated segmentno route out

Real output. A historian on an isolated segment, mapping five controllers without sending them a packet.

Four properties, each one testable

A sovereignty claim you cannot check is a promise. These are mechanisms, and every one of them can be verified on your own network before you trust it with anything.

No outbound connections

With no relay configured, the agent opens no connection outside your network. Not for licensing, not for telemetry, not for model inference.

Licence verification is an Ed25519 signature check performed locally. Intel sync and token exchange are relay features that simply do not run.

Run it on a VLAN with no default route. It works.

Reasoning runs on your hardware

The model that decides what to investigate runs inside your estate, on a machine you own. No prompt, no tool output, and no finding is sent to an inference provider.

Any OpenAI-compatible runtime — Ollama, vLLM — reached over your own network. The agent never holds a provider credential.

Check the agent's egress. The only model traffic is to the host you configured.

Findings never leave the host

The assessment, its evidence and the report are written to your disk and stay there. There is no upload to acknowledge and no cloud copy to request deletion of.

Findings are stored as JSON beside a tamper-evident audit chain, with the PDF-ready report generated locally from the same document.

The whole record is a directory you can copy to removable media.

Vulnerability data arrives by hand

Intelligence updates are signed bundles you carry in. Nothing is fetched, and the agent tells you plainly how old its data is rather than implying currency it does not have.

Bundles are sealed with a key derived from your licence and verified on load. A stale store produces an explicit warning on the report cover.

Sideload a bundle from a USB device; the report states its age.

What crosses the boundary

Stated in both directions, because a security team evaluating this will ask about both and a page that only answers one has answered neither.

Never leaves

  • Assessment findings and evidence
  • Network topology, hostnames and addresses
  • Credentials or anything credential-shaped
  • Tool output, prompts or model responses
  • Telemetry, usage analytics or crash reports
  • Licence check-ins or heartbeat traffic

Comes in, by hand

  • Signed intelligence bundlesCarried in on removable media, verified on load
  • The agent binary and its updatesWhatever change process your site already uses
  • Your licence fileIssued once; verified offline thereafter

Nothing is fetched automatically. If intelligence is three months old the report says so on its cover, because a clean result against stale data reads exactly like a clean result against current data — and only one of them is good news.

How it works with nothing to call home to

Removing connectivity removes most of what a conventional scanner relies on. These are the capabilities that replace it.

Passive first, because probing is refused

On a live process network the devices that matter are the ones nobody will authorise you to scan — correctly, since documented controller families fault on a port sweep. The agent reads the host's own socket tables, neighbour cache and installed software instead, which originates no traffic at all and works beside a safety instrumented system.

The zone posture is enforced, not advised

IEC 62443 zones and asset classes are applied mechanically before every action. A passive zone refuses active tooling; a controller-class asset refuses it regardless of ceiling. The report records what was refused and why, which is the evidence that the engagement respected its boundaries.

Evidence you can prove was not edited

Every tool invocation and every finding is written to a hash-linked audit chain on your own disk. An auditor asking what ran on a critical host gets an answer the operator cannot have quietly amended afterwards.

Reports generated where the data lives

The findings document and the report are produced on the assessed host. No rendering service, no document pipeline, no third party holding a copy of your estate's weaknesses.

Where connectivity is not a choice

Different regulators, the same constraint: the estate holds systems that cannot be disturbed, and data about those systems is not permitted to leave.

Oil, gas and process industry

Offshore platforms and remote terminals often have no usable link, and the ones that do will not carry assessment data off the asset. Safety instrumented systems make an unplanned probe a safety event rather than an outage.

Passive mapping, IEC 62443 zone enforcement, SIS-aware severity.

Subsea cable and telecom

Landing stations are designated critical national infrastructure. Landing licence conditions and national security review make exporting a map of the facility's management plane untenable.

TL1, SNMP and the cleartext management planes on transport and power-feed equipment; findings stay on site.

Defence, government and classified estates

Cross-domain policy decides what may traverse a boundary, and a security tool that phones home does not get accredited. Data residency is a legal position, not a preference.

No egress, offline licensing, sideloaded intelligence.

Healthcare and medical devices

Imaging systems, infusion pumps and lab analysers run software the hospital cannot patch and the vendor will not let them touch. Patient data cannot leave the estate under HIPAA or GDPR, and a device that must not be disturbed during a procedure is closer to a controller than to a server.

Passive discovery on biomedical VLANs; DICOM and HL7 endpoints identified without probing them.

Rail, maritime and transport

Signalling, port terminals and vessel systems are safety-critical and frequently disconnected by design. Assessment data about a signalling network is itself sensitive, and in several jurisdictions exporting it is a regulatory question rather than a procurement one.

Zone-aware assessment that respects safety systems and records what it refused to touch.

Financial market infrastructure

Trading and settlement environments run inside segregated networks where egress is tightly controlled and every outbound flow is justified to an auditor. DORA obliges operational resilience testing on exactly these systems.

Runs inside the segregated zone with no new egress to approve.

Utilities and grid operators

NIS2 in the EU and NERC CIP in North America both put obligations on who may hold operational data about the network, and on demonstrating segmentation between corporate and control environments.

Segmentation findings framed against the standard you are audited on.

Choose your boundary

Three shapes, most isolated first. The agent is the same in all of them; what changes is where the boundary sits.

Air-gapped

No connectivity of any kind. Intelligence carried in, reports carried out.

The agent runs entirely on your infrastructure. Intelligence bundles and agent updates arrive through the change process you already operate for that estate.

Offshore assets, classified networks, isolated process cells.

Sovereign hosted

Relay and agents inside your perimeter, in your jurisdiction.

Console self-hosting on the roadmap

Agents and the relay they report to run on infrastructure you control, so assessment data stays within a boundary you can point to on a map. A fully self-hosted console is on the roadmap; talk to us about where your boundary needs to sit today.

Organisations under data-residency obligations who want more than air-gap but less than our cloud.

Connected on-premises

Agents on-site, console in our cloud.

Findings are uploaded to your tenant when the agent has a route. Suitable where policy permits it and the operational convenience of a hosted console is worth more than strict residency.

IT estates and less-regulated operational networks.

Test the claim before you trust it

Run the agent on an isolated segment with no route out and watch it complete an assessment. That is the whole evaluation, and it is the one we would want to do in your position.

Get Started

See what an attacker sees. Before they do.

Request a demo and we'll show you a live scan against a test environment — subnet sweep, CVE detection, and zero-day discovery in under 15 minutes.

NeuroStrike | Autonomous Attack Simulation Platform