Defense and military networks
Classified and restricted networks operate disconnected from public internet by design. Operations tools must run inside the perimeter or they are out before the procurement conversation starts.
Deployment
True air-gapped AIOps. The platform and the model both run inside your perimeter. No telemetry leaves the environment. Built for defense, government, regulated banking, and sovereign cloud.
The term "air-gapped" has been stretched to the point of being meaningless in vendor marketing. Some vendors call a single-tenant cloud deployment "air-gapped." Others call an on-premises platform "air-gapped" while the model still runs in their cloud. Both are misleading.
True air-gapped means the entire platform runs inside the customer perimeter with no network egress to vendor infrastructure. The AI model itself runs on customer hardware. Telemetry never leaves the environment. Inference happens locally. The platform can operate indefinitely without an internet connection. Model updates arrive as verified offline artifact packages that the customer's security team inspects and stages through their normal change management process.
That is the bar required by defense, government, and regulated banking customers. Anything less is single-tenant SaaS with a marketing label.
The economic and architectural reality of cloud-native AI platforms is that the model is the expensive part and the vendor owns it. Selling a model that the customer runs themselves means the vendor cannot continuously update it, cannot observe how it behaves in customer environments, and cannot benefit from cross-customer pattern learning. Most vendors have decided those tradeoffs are not worth the additional engineering investment, so their air-gapped story stops at "the platform runs on-prem but it still phones home to our model API."
That is fine for SaaS-comfortable customers. It is disqualifying for customers whose security model treats vendor cloud as an unacceptable data path.
Classified and restricted networks operate disconnected from public internet by design. Operations tools must run inside the perimeter or they are out before the procurement conversation starts.
Public sector deployments under sovereign cloud requirements (EU sovereign cloud, GCC sovereign cloud, country-specific data residency rules). Telemetry leaving the sovereign perimeter is itself a compliance violation.
Indian banks operating under RBI Tier-2 and Tier-3 controls. European banks under specific country-level residency. Banks that have classified their operational telemetry as customer-sensitive and refuse to expose it to vendor cloud.
Hospital networks and national health systems that treat operational telemetry as patient-data adjacent. Air-gapped deployment removes the data-residency review from the procurement path.
Energy, telecom, water, transport. Operators whose infrastructure is itself a national security concern. Exposing operational telemetry to a third-party cloud is treated as a meaningful attack surface, not just a compliance question.
Any enterprise whose security architecture treats outbound connectivity from production systems as an unacceptable risk. Air-gapped deployment is the only way the operational AI platform can land in those environments.
| Capability | Vendor SaaS | Single-tenant cloud | True air-gapped |
|---|---|---|---|
| Telemetry leaves customer perimeter | Yes | Yes | No |
| Model runs in customer perimeter | No | No | Yes |
| Internet connectivity required | Yes, continuously | Yes, continuously | No |
| Model update cadence | Continuous | Continuous | Batched, offline |
| Cross-customer pattern learning | Yes | Partial | No |
| Acceptable for defense / sovereign | No | No | Yes |
| Time to production | Fastest | Fast | Slowest (security review) |
Each model is correct for its target customer. The honest framing is not "air-gapped is better than SaaS." It is "the deployment model has to match the customer security architecture, and air-gapped is the only valid choice for some customers."
The air-gapped deployment of Opstral ships as a containerized package that runs entirely on customer infrastructure. Five components run inside the perimeter.
No component requires outbound connectivity to operate. The platform is installable from offline artifact packages, runs from offline artifact packages, and is updated via offline artifact packages.
Updates flow through the customer's existing secure transfer process: the offline artifact package is signed by Opstral, the customer's security team validates the signature, the package is staged in a non-prod environment, then promoted to production under the customer's change management. Update cadence is typically monthly for security and capability updates, quarterly for major releases.
Three real tradeoffs that should be visible in the procurement conversation.
None of these is a blocker for the customers who actually need air-gapped. They are the cost of the deployment model, and they are worth paying for the right risk profile.
Air-gapped is the strictest of a family of deployment models. The full menu, for reference.
| Option | What it means |
|---|---|
| SaaS (managed) | Opstral hosts and operates the platform. Fastest path to value. |
| Private cloud (customer-owned) | Customer owns the cloud account; we deploy and manage. Good middle ground for customers who want isolation without on-prem operational burden. |
| On-premises | Runs entirely in customer data center. Telemetry stays in the perimeter. Model updates fetched over internet from a controlled egress point. |
| Air-gapped | On-prem with offline model update workflow. Zero outbound connectivity required. Model inside perimeter. |
| Regional residency | SaaS deployment regions in US, EU, APAC for data sovereignty without going all the way to on-prem. Available across the above models. |
For the broader category context, see AIOps platform comparison. For a deeper read on autonomous operations in restricted environments, see Autonomous Operations in Air-Gapped Environments.