Home/Reference Architecture/Pattern 3 · Enterprise B
The control plane stays with Iron Fort, dedicated to you as in Pattern 2. Collection moves into your estate: a ScanOps worker — a VM, a pod or a container — running in a DMZ in every environment you have, across AWS, Azure, Google Cloud and your own data centres.
Iron Fort holds findings, control status and pointers — the artefacts themselves stay where they were collected, under your key and your retention policy. Each worker opens an outbound connection to the Iron Fort endpoint over TLS, authenticated with a key unique to it — nothing is initiated from our side, so you expose no endpoint and write no inbound rule. Every environment keeps its own DMZ and its own collector, and one control plane still shows the whole estate as a single programme.
Applies to Enterprise plans. Every pattern runs the same platform — the same frameworks, the same evidence model and the same reports. What changes is who holds the infrastructure and where evidence comes to rest.
One per cloud account and one per data centre. The ScanOps worker runs however that environment already runs things — a VM, a Kubernetes pod, or a container — in your subnet, your security group. We publish the image; you decide what it can reach and what it may not.
The worker opens the connection to the Iron Fort endpoint over TLS, with a key unique to it. Nothing is ever initiated from our side, so there is no inbound rule to write and no endpoint of yours to expose. Keys are stored encrypted, and the control plane knows nothing about the inside of your network beyond what the worker tells it.
On our call, the worker reads that environment from inside it — EC2 and IAM on AWS, VMs and Entra ID on Azure, GKE and Cloud SQL on Google Cloud, vSphere and Active Directory in the data centre — and writes artefacts to storage in that same environment.
The control plane receives control status, findings and content hashes with pointers to where each artefact lives. The artefacts themselves never transit to us.
Two plans, because they answer different questions and usually different people. Read them here, or take the PDF into your own planning.
The control plane is built as in Pattern 2. The difference is that you run a collector in every environment you have, and you provide the storage it writes to. Plan this per environment rather than as one project — each has its own network owner and its own change window.
Done whenA list of environments, each with an owner, a runtime and a storage target.
Done whenThe control plane is reachable and every worker has an identity.
Done whenOne environment collects end to end, and you can point at where the evidence sits.
Done whenEvery environment on the inventory is collecting.
Done whenOne coverage figure spans the whole estate, and each environment owner recognises their part of it.
Done whenYour security team has signed off the data-flow, in writing.
Sequence, not schedule. Phases are ordered by dependency. Elapsed time depends on your change process and scope, so we do not guess at it — ask us and we will estimate against your specifics.
This pattern has more owners than the others, because each environment brings its own network and platform team. Adoption succeeds or fails on whether those teams see the worker as theirs.
Done whenEvery environment owner has agreed to host a worker and knows what it does.
Done whenEvery control set in scope has a named owner who knows they own it.
Done whenOne framework has a real coverage figure the owner recognises as true.
Done whenOwners are closing their own evidence requests without being chased.
Done whenA month passes with no manual chasing and nothing falls overdue.
Done whenA customer security questionnaire is answered with a link.
Done whenThe second framework reaches useful coverage in a fraction of the first one's effort.
Sequence, not schedule. Phases are ordered by dependency. Elapsed time depends on your change process and scope, so we do not guess at it — ask us and we will estimate against your specifics.
We would rather send you to another pattern than sell you the wrong one.
Residency, tenancy, egress, air gap — tell us the rule you have to satisfy and we will show you the deployment that satisfies it.