🔒 OptimusHub is SOC 2 ready - built for air-gapped and regulated environments
Solutions · Air-Gapped Operations

How do teams operate air-gapped infrastructure without cloud dependency?

Air-gapped infrastructure has no route to the public internet, which rules out any tool that depends on a SaaS backend, telemetry, or cloud-based license checks to function. Operating it well means running an operations layer entirely inside the network perimeter - with zero outbound connections required - rather than adapting a cloud-first tool after the fact. OptimusHub is built air-gap native: it installs inside your network, and a fully disconnected deployment works with zero required outbound connectivity.

Talk to us about your operating environment →
What stays inside your perimeter

Your environment stays yours.

OptimusHub is designed to work with your existing environment, not take ownership of it. Here's exactly what that means.

No cloud dependency

OptimusHub runs entirely inside your network. There is no public SaaS backend and no vendor cloud in the request path.

No required outbound connectivity

A fully air-gapped install works with zero outbound connections. Optional integrations - a Git remote, a registry, SMTP - are opt-in, never required for the platform to run.

Customer-controlled, local data storage

Operational data, configuration, credentials, and audit logs live in a database you deploy and control, inside your perimeter. Nothing is mirrored to us.

No network redesign

OptimusHub connects to the endpoints, clusters, and hosts you already run, using the credentials and network paths you configure - no VPNs or trust boundaries to rebuild.

No runtime dependency for workloads

OptimusHub is a management layer, not a request-path component. Your applications don't call it, depend on it, or route traffic through it to run.

A normal migration path

Moving off OptimusHub is an operational migration, like retiring any management tool: export configuration and audit history, repoint CI/CD and access controls, decommission the instance.

Air-gap native, not retrofitted

Air-gap native, not retrofitted

No telemetry, no phone-home, no license-check callbacks.

Local identity & access

RBAC, SSO (LDAP / OIDC / SAML), and an internal PKI enforced inside your network.

Immutable audit trail

Every action - who, what, when, from where - recorded in a database you control.

SOC 2-aligned controls

Built for teams that face real audits, not teams that just say they do.

Day to day

What changes operationally, not just architecturally

Running air-gapped is not only a security posture - it changes how deployment, access, and audit actually get done day to day. Without a shared operational layer, disconnected sites tend to be managed through whatever the last engineer on-site set up: local scripts, manual change logs, and access granted by memory rather than policy.

With one operating model applied consistently, deployment, access control, and audit logging work the same way whether the environment has internet access or none at all - so a disconnected site isn't a special case your team has to remember how to handle.

Who this is for

A practical fit when
  • Some or all of your network has no route to the public internet
  • You need identity, access, and audit enforced entirely inside your own perimeter
  • You want one operating model across both connected and disconnected sites
Probably not yet, if
  • Your environment is entirely cloud-hosted with no disconnected or restricted-network component
  • You need a managed SaaS product rather than something you deploy and operate yourself

Frequently asked questions

Does OptimusHub need internet access?
No. OptimusHub can be installed and run with zero outbound connectivity in a fully air-gapped network. Internet access is only used for optional integrations you explicitly enable, like pulling from an external Git remote - never for OptimusHub itself to function.
Does OptimusHub send data to the cloud?
No. There is no public SaaS backend. Operational data, secrets, and audit logs stay in the database you deploy inside your own environment.
Can the same OptimusHub instance manage both connected and air-gapped sites?
OptimusHub is built to apply one operating model across the environments you configure it to reach. The specific connectivity and topology for your sites should be discussed directly, since it depends on your network design.

Related pages

Talk through your specific network constraints.

Bring the details of your disconnected or restricted environment. We'll help map where this fits.

Talk to us about your operating environment →