Air-gapped & sovereign

Run the whole platform with nothing phoning home.

Zero outbound to any Sasquatch control plane. Signed offline package repos. Your keys, your jurisdiction, your isolated network - the severed posture defense, intelligence, and sovereign-cloud programs run on.

Zero egressSigned offline reposBYOK / SSE-KMSCMMC / ITAR ready
Runs fully disconnected in defense, intelligence, and OT/SCADA networks
Air-gap posture sealed
Your boundary
Agents + your bucket, fully inside
Control plane
unreachable
Zero egress
No outbound to our control plane
Signed offline repos
apt + yum + GHCR, GPG-signed
BYOK / SSE-KMS
Your KMS, your bucket, your keys
Break-glass custody
Offline recovery you hold, not us
Outbound connections from the boundary0
0
Outbound connections
from your boundary
100%
GPG-signed artifacts
apt / yum / GHCR
3
Offline repos
mirror, verify, promote
99.95%
Multi-region target
active-active failover
<1s
Key revocation
per environment
Where this sits

BYOC keeps your data. Sovereign cuts the cord entirely.

Same platform, three footprints. The difference that matters is not where the bytes rest - it is who can be compelled to touch them.

Air-gapped & sovereignThis page
ConnectivityNone. Nothing leaves the boundary
Where data livesYour isolated network, on infrastructure you operate
Software updatesSigned bundles you import over secure media
Who can compel accessYou alone, inside one named jurisdiction
Best forDefense, intelligence, OT/SCADA, EU sovereign
BYOC
ConnectivityOutbound-only from the data plane to our control plane
Where data livesYour VPC and your bucket, your cloud account
Software updatesPulled from signed repos when you choose
Who can compel accessYou. We never hold your data or your keys
Best forRegulated but cloud-native: fintech, healthcare
SaaS
ConnectivityInbound + outbound over the public internet
Where data livesOur cloud, our tenancy
Software updatesAutomatic, pushed by us
Who can compel accessUs, under the law our infrastructure sits in
Best forFast start, non-regulated workloads
Residency is not sovereignty

A region on a map is not control.

Legal reach

Residency is where. Sovereignty is who.

Pinning data to a region does not settle who can be ordered to hand it over. When nothing phones home to us, there is no vendor to serve. The only party who can compel access is you.

Key custody

Keys never cross the boundary.

Encryption keys and admin credentials stay inside your jurisdiction under your KMS. Our software never receives long-lived credentials; it authenticates through your cloud native identity federation.

Audit locality

Audit trails stay local.

Logs, chunks, and metadata land in your bucket and your sinks. Nothing is mirrored to a shared cloud you do not control, so the record a regulator cares about never leaves the boundary.

How the air-gap works

Every disconnected question already has an answer.

The questions a security architect asks before anything ships into an enclave. Answered by how the agent is built, not by a services engagement.

Isolation
Q

How does it run with no internet?

A

The agent compresses in-cluster and writes chunks straight to your bucket. There is no callback to a Sasquatch control plane, so an air-gapped or disconnected network is a supported posture, not a workaround.

Supply chain
Q

How do we get software in?

A

Every artifact ships from GPG-signed apt, yum, and GHCR repositories. You mirror the signed bundle into your enclave and verify the signature before anything is promoted. No unsigned binary ever enters.

Updates
Q

How do updates work offline?

A

You import a signed release bundle over your secure media path and promote it on your own schedule. Updates are a deliberate act you control, never a push we initiate.

Identity
Q

How does it authenticate with no callback?

A

Through your cloud native identity federation: IRSA on AWS, Workload Identity on GCP and Azure. The agent holds no long-lived secret, and revoking an environment key stops that deployment in under a second.

Key recovery
Q

What if we lose a key while disconnected?

A

Break-glass recovery is yours to hold. Escrowed material stays in your custody so you can decode your own archive without a call home, even in a fully severed environment.

Failure domain
Q

Does isolation cost us resilience?

A

No. Multi-region runs active-active with automatic failover inside your boundary. Isolation is a property of the network edge, not a limit on how many sites you span.

Sovereign signature
Signed offline repos, zero egress, keys and audit stay inside your boundary.
GPG-signedBYOK / SSE-KMSMulti-region
Who runs it this way

The environments that cannot phone home.

Where a single outbound connection is a finding, and data sovereignty is written into the contract before the first byte moves.

Defense & intelligence
ITAR, classified networks, CMMC Level 2+
Critical infrastructure
OT / SCADA, energy, disconnected plants
EU sovereign
NIS2, EU AI Act, Gaia-X aligned
Public sector & finance
National frameworks, data-residency mandates
Built to satisfy
CMMC Level 2+ITARNIS2EU AI ActGaia-XSOC 2HIPAA