Run the whole platform with nothing phoning home.
Zero outbound to any Sasquatch control plane. Signed offline package repos. Your keys, your jurisdiction, your isolated network - the severed posture defense, intelligence, and sovereign-cloud programs run on.
unreachable
BYOC keeps your data. Sovereign cuts the cord entirely.
Same platform, three footprints. The difference that matters is not where the bytes rest - it is who can be compelled to touch them.
A region on a map is not control.
Residency is where. Sovereignty is who.
Pinning data to a region does not settle who can be ordered to hand it over. When nothing phones home to us, there is no vendor to serve. The only party who can compel access is you.
Keys never cross the boundary.
Encryption keys and admin credentials stay inside your jurisdiction under your KMS. Our software never receives long-lived credentials; it authenticates through your cloud native identity federation.
Audit trails stay local.
Logs, chunks, and metadata land in your bucket and your sinks. Nothing is mirrored to a shared cloud you do not control, so the record a regulator cares about never leaves the boundary.
Every disconnected question already has an answer.
The questions a security architect asks before anything ships into an enclave. Answered by how the agent is built, not by a services engagement.
How does it run with no internet?
The agent compresses in-cluster and writes chunks straight to your bucket. There is no callback to a Sasquatch control plane, so an air-gapped or disconnected network is a supported posture, not a workaround.
How do we get software in?
Every artifact ships from GPG-signed apt, yum, and GHCR repositories. You mirror the signed bundle into your enclave and verify the signature before anything is promoted. No unsigned binary ever enters.
How do updates work offline?
You import a signed release bundle over your secure media path and promote it on your own schedule. Updates are a deliberate act you control, never a push we initiate.
How does it authenticate with no callback?
Through your cloud native identity federation: IRSA on AWS, Workload Identity on GCP and Azure. The agent holds no long-lived secret, and revoking an environment key stops that deployment in under a second.
What if we lose a key while disconnected?
Break-glass recovery is yours to hold. Escrowed material stays in your custody so you can decode your own archive without a call home, even in a fully severed environment.
Does isolation cost us resilience?
No. Multi-region runs active-active with automatic failover inside your boundary. Isolation is a property of the network edge, not a limit on how many sites you span.
your boundary.The environments that cannot phone home.
Where a single outbound connection is a finding, and data sovereignty is written into the contract before the first byte moves.
