Four Isolation Tiers. One Governance Architecture.
From shared tenancy to air-gap. Each tier is a distinct deployment architecture with different network boundaries, compute isolation, and data residency guarantees — not a configuration toggle within a single shared environment.
Isolation is not a feature toggle. It is how we deploy.
Enterprise buyers evaluating AI governance platforms ask a question that no feature comparison table can answer: where does our AI traffic actually live, and what separates it from everyone else's? The answer depends on the deployment architecture — not on a checkbox in a settings panel.
Arbitex provides four isolation tiers, each representing a distinct architectural posture. The tiers are not feature flags within a shared environment. They are different deployment architectures with different network boundaries, different compute models, and different data residency guarantees.
Choose the boundary that matches your risk profile.
Shared
Multi-Tenant SaaS
Arbitex manages the full stack — data plane and control plane — in Arbitex-operated infrastructure. Tenants are logically isolated at the API and data layers. Each tenant's data is encrypted with a dedicated key. DLP pipeline execution, audit logging, and model routing are tenant-scoped.
- Compute: Logical isolation (shared instances)
- Storage: Logical isolation (shared DB, per-tenant keys)
- Network: Arbitex perimeter
- Operations: Arbitex-managed
- Time to deploy: Hours
Enhanced
Dedicated Partitions
Arbitex manages both planes with dedicated compute and storage resources allocated per tenant. No shared database tables, no shared processing queues, no shared object stores. Network-level segregation within Arbitex-managed infrastructure adds a physical boundary to logical isolation.
- Compute: Physical isolation (dedicated instances)
- Storage: Physical isolation (dedicated partitions)
- Network: Arbitex perimeter, tenant-segregated
- Operations: Arbitex-managed
- Time to deploy: Days
Outpost
Hybrid Deployment
The customer operates the Arbitex data plane inside their own VPC or on-premises infrastructure. Arbitex manages the control plane. AI traffic — prompts, responses, and DLP inspection results — is processed and stored entirely within the customer's environment. Outbound-only HTTPS to the control plane.
- Compute: Physical isolation (customer infrastructure)
- Storage: Physical isolation (customer storage)
- Network: Customer VPC perimeter
- Operations: Customer operates data plane
- Time to deploy: Weeks
Air-Gap
Isolated Outpost
Outpost supports on-premises deployment with local DLP inference and audit storage. Policy bundles sync automatically from the control plane or can be sideloaded for restricted network environments. GeoIP MMDB bundled in the container image. Software updates distributed as Ed25519-signed bundles for operator-controlled staged application.
- Compute: Physical isolation (no egress)
- Storage: Physical isolation (customer storage, offline)
- Network: Customer perimeter, no internet
- Operations: Customer operates data plane
- Time to deploy: Weeks + operator provisioning
Isolation Tier Selection Guide
The tier you choose determines the physical and logical boundaries around your AI governance data. Use this comparison to identify which tier matches your organization's security posture, compliance requirements, and operational model.
| Evaluation Criteria | Shared | Enhanced | Outpost | Air-Gap |
|---|---|---|---|---|
| Data residency | Arbitex-managed region | Arbitex-managed region | Customer VPC | Customer environment |
| Compute isolation | Logical | Physical (dedicated) | Physical (customer infra) | Physical (no egress) |
| Storage isolation | Logical (per-tenant keys) | Physical (dedicated) | Physical (customer) | Physical (offline) |
| Network boundary | Arbitex perimeter | Tenant-segregated | Customer VPC | No internet |
| Infrastructure ops | Arbitex-managed | Arbitex-managed | Customer data plane | Customer data plane |
| Control plane | Arbitex SaaS | Arbitex SaaS | Arbitex SaaS | Arbitex SaaS (periodic sync) |
| Time to deploy | Hours | Days | Weeks | Weeks + provisioning |
| Typical buyer | Dev teams, startups, SMB | Mid-market, compliance-conscious | Regulated enterprise | Defense, government |
Control plane is Arbitex-managed at all tiers. You operate the data plane at Outpost and Air-Gap. Tier selection is a deployment decision — moving between tiers involves architectural changes, not feature toggles.
No commingling at any tier.
At every isolation tier, Arbitex enforces per-tenant data boundaries. One tenant's data, configuration, and audit records are never visible to, accessible by, or co-located with another tenant's.
Per-Tenant Encryption
Each tenant's data is encrypted with a dedicated key at rest. Key material is not shared across tenants at any isolation tier.
Per-Tenant Audit Chain
tamper-proof audit logs are scoped to the individual tenant. No cross-tenant log aggregation or commingling of audit records.
Per-Tenant DLP Pipeline
DLP inspection runs in the context of the requesting tenant's policy configuration. One tenant's DLP rules never evaluate another tenant's traffic.
Per-Tenant Routing
Model routing rules, provider credentials, and fallback chains are tenant-scoped. No shared model configuration between tenants.
Per-Tenant SIEM Delivery
SIEM connector configuration is per-tenant. Audit events route to the tenant's own SIEM endpoint, not a shared collector.
Find the right isolation tier for your organization.
Our team can walk you through tier selection based on your data residency, compliance, and operational requirements.