Fully local
Gateway and Private LLM stay inside the perimeter. Model traffic needs no external egress.
On-premise by design / No required vendor cloud
Gateway, Control API, Control Center, policy databases and security events are installed in customer infrastructure. CyberPass does not require a connection to a vendor cloud.
Model choice does not change where policy, DLP, Guard and audit operate.
Gateway and Private LLM stay inside the perimeter. Model traffic needs no external egress.
Sensitive requests go to a Private LLM; approved requests reach a Public LLM through controlled egress.
Only a request that passed inspection and active policy is sent outside.
Public ingress remains with the customer Nginx or load balancer. Container ports listen on 127.0.0.1 by default.
The pilot package provides safe install and upgrade actions without presenting a single-node topology as enterprise HA.
Checks secrets, database credentials, disk, Docker, Compose and loopback bindings before startup.
Checksummed PostgreSQL custom dump, safety backup and explicit confirmation for destructive restore.
Clean fast-forward, optional exact SHA, backup, acceptance and rollback safety based on the Alembic revision.
The central on-premise stack ships as Linux containers. User devices connect through separate channels.
| Component | Status | Platform |
|---|---|---|
| Gateway / Control plane | Available | Linux host with Docker Engine and Compose. |
| Windows Endpoint Connector | Beta | Windows service, ZIP + PowerShell installer. |
| Chrome / Edge extension | Beta | Managed Windows browsers through Connector. |
| Kubernetes / Helm | Planned | Enterprise deliverable after HA and recovery requirements are defined. |
| Full air-gap lifecycle | Planned | Signed offline bundles and offline licensing are not yet claimed. |
First we agree the Linux host, PKI, DNS, egress and selected model endpoints.
Plan a deployment →