Home/Reference Architecture/Pattern 2 · Enterprise A
Your own VPC, database, evidence store and encryption key on AWS — still operated by Iron Fort, so you carry none of the run cost. The application is published, but the firewall admits only the addresses your organisation comes from.
One Iron Fort managed scanner worker runs inside that dedicated VPC, and it is the only component that reaches your systems. Everything it collects stays inside infrastructure dedicated to you, under a KMS key scoped to your tenancy alone.
Applies to Enterprise plans (SMB). Every pattern runs the same platform — the same frameworks, the same evidence model and the same reports. What changes is who holds the infrastructure and where evidence comes to rest.
Dedicated subnets, a dedicated database and evidence bucket, and an AWS KMS key scoped to you alone. Data subnets have no route to the internet.
The WAF is configured to accept requests only from your office and VPN addresses. Everything else is refused at the edge, before it reaches the application.
Through Microsoft or Google, with two-factor enforced. There is no local password path.
A single Iron Fort managed scanner worker runs inside the VPC and makes outbound read-only calls to your systems. Nothing inbound to your network is ever required.
Two plans, because they answer different questions and usually different people. Read them here, or take the PDF into your own planning.
Everything in Pattern 1, plus a dedicated environment we build for you and a firewall that only your addresses get through. The extra work is a networking conversation, and it is worth having early because it gates access for everyone.
Done whenRegion, key policy and allowlist are agreed in writing.
Done whenA request from an allowlisted address succeeds; one from anywhere else is refused at the edge.
Done whenEvery person who needs access has it, from every network they use.
Done whenEvery in-scope system returns data on a test collection.
Done whenA coverage figure exists and every required policy has an owner and a review date.
Done whenThe programme runs without anyone touching infrastructure.
Sequence, not schedule. Phases are ordered by dependency. Elapsed time depends on your change process and scope, so we do not guess at it — ask us and we will estimate against your specifics.
Same adoption path as the managed tier, with one addition: the allowlist is a live dependency. If your network changes and nobody tells us, people lose access on a Monday morning and blame the platform.
Done whenA network change has been made and access survived it.
Done whenEvery control set in scope has a named owner who knows they own it.
Done whenOne framework has a real coverage figure the owner recognises as true.
Done whenOwners are closing their own evidence requests without being chased.
Done whenA month passes with no manual chasing and nothing falls overdue.
Done whenA customer security questionnaire is answered with a link.
Done whenThe second framework reaches useful coverage in a fraction of the first one's effort.
Sequence, not schedule. Phases are ordered by dependency. Elapsed time depends on your change process and scope, so we do not guess at it — ask us and we will estimate against your specifics.
We would rather send you to another pattern than sell you the wrong one.
Residency, tenancy, egress, air gap — tell us the rule you have to satisfy and we will show you the deployment that satisfies it.