On-premise by design / No required vendor cloud

Control stays inside your perimeter

Gateway, Control API, Control Center, policy databases and security events are installed in customer infrastructure. CyberPass does not require a connection to a vendor cloud.

Compose pilot availableKubernetes later
Server OSLinux + Docker Compose
IngressCustomer TLS / PKI
PortsLoopback by default
Cloud dependencyNone required
01 / DEPLOYMENT MODES

Three modes.
One control layer.

Model choice does not change where policy, DLP, Guard and audit operate.

01 / PRIVATE ONLY

Fully local

Gateway and Private LLM stay inside the perimeter. Model traffic needs no external egress.

02 / HYBRID

Policy-based routing

Sensitive requests go to a Private LLM; approved requests reach a Public LLM through controlled egress.

03 / CONTROLLED PUBLIC

Public model

Only a request that passed inspection and active policy is sent outside.

02 / PILOT TOPOLOGY

Six containers.
Explicit network boundaries.

Public ingress remains with the customer Nginx or load balancer. Container ports listen on 127.0.0.1 by default.

CUSTOMER INFRASTRUCTURE
01Customer ingressTLS 1.2/1.3 · customer PKI
02AGateway + Control APIdata and control planes
02BSite + Consoleunprivileged Nginx
03APostgreSQLconfiguration · events
03BRedislimits · circuits · SIEM queue
DEFAULT BINDINGS127.0.0.1 only
EGRESSExplicit hostname allowlist
03 / OPERATIONS

Deployment is more than
just compose up.

The pilot package provides safe install and upgrade actions without presenting a single-node topology as enterprise HA.

Available

Preflight & install

Checks secrets, database credentials, disk, Docker, Compose and loopback bindings before startup.

Available

Backup & restore

Checksummed PostgreSQL custom dump, safety backup and explicit confirmation for destructive restore.

Available

Guarded upgrade

Clean fast-forward, optional exact SHA, backup, acceptance and rollback safety based on the Alembic revision.

04 / PLATFORM SUPPORT

The server is Linux.
Clients are not only Linux.

The central on-premise stack ships as Linux containers. User devices connect through separate channels.

ComponentStatusPlatform
Gateway / Control planeAvailableLinux host with Docker Engine and Compose.
Windows Endpoint ConnectorBetaWindows service, ZIP + PowerShell installer.
Chrome / Edge extensionBetaManaged Windows browsers through Connector.
Kubernetes / HelmPlannedEnterprise deliverable after HA and recovery requirements are defined.
Full air-gap lifecyclePlannedSigned offline bundles and offline licensing are not yet claimed.

Install CyberPass in a test environment.

First we agree the Linux host, PKI, DNS, egress and selected model endpoints.

Plan a deployment →