Home/Reference Architecture/Pattern 4 · Enterprise C
The same Docker containers, deployed into your own cloud or data centre — on OpenShift, self-managed Kubernetes, or a Linux VM cluster. A ScanOps worker sits in each segmented zone and connects outbound to your own control plane. Every component, every byte of state, inside your perimeter. Available today, delivered on request through our system integrator partners.
No part of the deployment calls home. Updates arrive as signed images you promote through your own registry on your own schedule, which is what makes an air-gapped installation possible rather than merely claimed. An on-premises estate is rarely one flat network, so each segmented zone gets its own DMZ and its own collector: the core cluster cannot reach across a firewall boundary any more than we could from outside it. This is also the one pattern where sign-in can point at a directory inside your perimeter — Entra ID, Google Workspace, Okta or any SAML 2.0 provider — because a disconnected site cannot reach Microsoft or Google over the internet.
Applies to Enterprise plans. Every pattern runs the same platform — the same frameworks, the same evidence model and the same reports. What changes is who holds the infrastructure and where evidence comes to rest.
Into whichever registry you already run — Docker Hub, Amazon ECR, Azure ACR, GitLab Registry or Azure DevOps Artifacts — and promote them on your own schedule. Air-gapped installations transfer them through your existing media process.
The application and scanner worker containers, with your secrets backend — by Helm chart or Operator, or as systemd units on a VM cluster. Our system integrator partners do this work if you would rather they did.
PostgreSQL, storage for evidence — an S3-compatible object store, or a mounted filesystem on NFS or a SAN volume if you would rather not run object storage — your secrets manager and your SIEM. Sign-in goes to Microsoft Entra ID, Google Workspace, Okta or any SAML 2.0 provider you already run. AI analysis runs against Bedrock over PrivateLink, a model you host, or is switched off entirely.
One ScanOps worker per DMZ or segmented network — perimeter, virtualisation, core network, or however your estate is divided. Each reads only its own zone and connects outbound to your own control plane, so no firewall rule has to be opened between your segments.
Two plans, because they answer different questions and usually different people. Read them here, or take the PDF into your own planning.
You run everything, so this reads more like a platform deployment than a SaaS onboarding. Our system integrator partners do this work on request. Sequence matters more here than anywhere else: the supply chain and the directory have to be settled before anything useful can be deployed.
Done whenImages are in your registry and you can reproduce the pull without us.
Done whenA test user signs in against your directory and the database survives a restore drill.
Done whenThe application is reachable internally and holds no configuration that points outward.
Done whenA zone map exists with an owner and a runtime per zone.
Done whenEvery zone on the map is collecting.
Done whenThe platform is in your runbooks and your on-call rota like any other internal service.
Sequence, not schedule. Phases are ordered by dependency. Elapsed time depends on your change process and scope, so we do not guess at it — ask us and we will estimate against your specifics.
You have two audiences here, not one: the platform team who now operate a service, and the compliance team who use it. Plan for both, or the platform team will treat it as an orphan and the compliance team will not trust its uptime.
Done whenThe platform team can upgrade and restore it without calling anyone.
Done whenEvery control set in scope has a named owner who knows they own it.
Done whenOne framework has a real coverage figure the owner recognises as true.
Done whenOwners are closing their own evidence requests without being chased.
Done whenA month passes with no manual chasing and nothing falls overdue.
Done whenA customer security questionnaire is answered with a link.
Done whenThe second framework reaches useful coverage in a fraction of the first one's effort.
Sequence, not schedule. Phases are ordered by dependency. Elapsed time depends on your change process and scope, so we do not guess at it — ask us and we will estimate against your specifics.
We would rather send you to another pattern than sell you the wrong one.
Residency, tenancy, egress, air gap — tell us the rule you have to satisfy and we will show you the deployment that satisfies it.