Platform

How it works The analyst team Trust & audit Integrations Deployment Evidence

Solutions

Defense & suppliers Government Healthcare Financial services MSSPs

Company

About Partners Resources Contact Responsible disclosure
Home/Deployment

Deployment

Runs where the data has to live

Three tiers of the same platform, so the deployment model is a choice rather than a constraint. Run it managed by us, inside your own cloud account, or entirely on your own hardware with no route to the internet. The analysts, the pipeline and the audit trail are identical in all three.

We run the platform for you in a dedicated, isolated tenant. Alerts cross the boundary under your agreement and land in an environment reserved for you alone, not a shared pool. Fastest path to a working investigation queue.

Egress : to a dedicated tenant
  Intruex-hosted Your cloud On-premises / air-gapped
Where it runs Our infrastructure, dedicated isolated tenant Inside your own AWS account Your hardware, your data center
Model inference Managed Managed inference within your account Open-weight models, local
Outbound network calls Yes Yes None
External threat intelligence Full Full Optional: the pipeline is built to run on internal signal alone
Who operates it We do Shared You do, with full control of the stack
Time to first verdict Fastest Moderate Longest
Tenant isolation Row-level, per-tenant encrypted credentials Row-level, plus your account boundary Physical

Tier by tier

What is true, scoped to where it is true

Tier 1

Intruex-hosted

Managed SaaS in a dedicated, isolated tenant. The fastest way to find out whether the verdicts are any good, which is the only question that matters in week one.

  • SOC 2 Type II certified
  • PostgreSQL row-level security on alerts, incidents and narratives
  • Per-tenant credentials encrypted at rest, never cached to the session store
  • Per-tenant cost observability at alert, agent and tenant level
  • Session authentication, scoped API keys, and per-organization SSO
Tier 2

Your cloud

The same platform, deployed as infrastructure as code into your own AWS account. Your VPC, your key management, your retention policy, your logging. We do not hold the data.

  • Containerized services on ECS, provisioned from version-controlled templates
  • PostgreSQL, a cache tier and a search tier, all inside your account
  • Deployable on AWS GovCloud, which is FedRAMP High authorized infrastructure
  • Model inference stays within your account boundary

Precise wording for a proposal: Intruex is deployable on AWS GovCloud, which is FedRAMP High authorized infrastructure. That is the sentence we will put our name to in writing, and it is worded that way so it holds up under exactly the scrutiny it invites.

Tier 3

On-premises & air-gapped

Open-weight models running on your hardware. This is the only tier where no data leaves your network is true without a footnote, so it is the only tier where we say it.

  • Zero outbound network calls
  • Local inference: no external model provider is contacted
  • Triage, deep investigation and your knowledge base all function offline
  • Alert ingestion, correlation and the full decision record are unaffected

Built for internal signal. A public reputation lookup needs egress by definition, so an offline deployment reasons from what your environment knows: entity memory, prior sightings, correlation across your own alerts, and your runbooks. Each verdict states which signals it used, so the record is complete either way.

Why this is not three products

One codebase, one inference abstraction

The model backend is chosen by configuration behind a single interface. A managed endpoint and a locally hosted open-weight model are two implementations of the same contract, so the analysts, the pipeline, the correlation engine and the audit trail are identical in all three tiers.

Practically, that means an air-gapped deployment is not a stripped-down build with a separate release cadence and its own bugs. It is the product, with a different inference target.

inference backend: selected by config
tier 1managed endpointhosted
tier 2managed, in your accountyour cloud
tier 3local open-weight servingair-gapped

Everything above this line changes.
Everything below it does not: routing, specialists, enrichment, correlation, dispositions, approval gates, audit trail.

The property that matters to a security reviewer is contractual: in the on-premises tier, inference is local and nothing leaves your network. The model behind it is an implementation choice we keep free to improve.

Before you put this in an RFP

The questions an evaluator asks, answered

Answered here so the language you write into a requirement is the language we can stand behind in the response.

What exactly does "air-gapped" mean in your architecture?
Model inference runs on open-weight models hosted on your own hardware, so no request leaves your network to reach a third-party provider. Alert ingestion, normalization, specialist analysis, deep investigation, correlation, your knowledge base and the full decision record all operate inside the boundary. We can supply a component-by-component data-flow document showing which processes make outbound calls in each tier, usually the artifact that actually settles this question.
How should we word the FedRAMP position?
Use this: "Deployable on AWS GovCloud, which is FedRAMP High authorized infrastructure." That describes the hosting environment accurately and is the sentence we will confirm in writing. For a requirement that cannot be met in any cloud, the on-premises tier removes the question entirely.
Is it the same product in all three tiers?
Yes. The model backend sits behind a single interface chosen by configuration, so a sovereign deployment is not a stripped-down build on its own release cadence. The analysts, the pipeline, the correlation engine and the audit trail are the same code. Choosing on-premises costs you nothing in capability.
What does self-hosting require from our team?
A container platform, PostgreSQL, a cache tier, a search tier and an inference host. It is provisioned as infrastructure as code, and we support the deployment. If you would rather not carry the stack, the hosted and your-cloud tiers are the same product with the operations handled for you.
How is one tenant kept separate from another?
Organization scoping is enforced throughout the data layer, with PostgreSQL row-level security behind it on the alert, incident and narrative tables. Credentials are encrypted per tenant and are never written to the session cache. Isolation is a property of the schema rather than a filter in a query, and we will walk your engineers through it.
Which models do you run?
The property that belongs in a requirement is where inference happens, not whose model it is: in the on-premises tier, inference is local and nothing leaves your network. Keeping the model itself an implementation choice is what lets us move you onto a better one without a contract amendment.

Bring us an alert you already know the answer to

Hand it something from last week and read the reasoning. If the verdict is wrong, you will see exactly where it went wrong, which is the whole point.