AI governance that never leaves your network.
Arbitex Outpost runs the full DLP pipeline — pattern detection, entity recognition, and compliance bundles — entirely within your infrastructure. No cloud dependency. No data egress. Same detection accuracy as SaaS.
Everything runs locally. Nothing phones home.
The Outpost data plane handles inspection, enforcement, and logging without any external dependency. DLP models, policy evaluation, and audit chain — all local.
Offline AI Inference
DLP models run locally using offline inference — no cloud calls, no external model APIs. Named entity recognition and pattern detection execute entirely within the data plane.
Certificate-Based Authentication
mTLS with full certificate chain verification — leaf, intermediate, and root CA. The data plane authenticates to the control plane using X.509 certificates, not shared secrets.
Zero-Trust Proxy
Every request is authenticated, inspected, and logged before reaching any AI model. No implicit trust. No passthrough mode. The proxy fails closed on any authentication or inspection failure.
Admin API
Full programmatic control over the Outpost data plane — policy updates, configuration changes, health checks, and certificate rotation. Automate deployment management via REST.
OpenTelemetry Metrics
Outpost emits OTLP gRPC traces and metrics covering request ingestion, DLP inspection, policy evaluation, and provider routing. Integrate with your existing Grafana, Datadog, or Splunk stack.
Fail-Closed Design
If the DLP inference engine, certificate validation, or policy store becomes unavailable, the Outpost blocks all traffic. No degradation. No bypass. Security is the default state.
Run it your way.
Docker Compose
Single-command deployment for development, staging, and smaller production workloads. All Outpost services run as containers with Docker Compose orchestration.
- Pre-built container images with daily CVE scanning via Trivy
- Environment-variable configuration — no config files to manage
- Supports volume mounts for persistent audit logs and DLP model cache
Kubernetes Helm
Helm charts for production Kubernetes clusters. Horizontal pod autoscaling, liveness/readiness probes, and PodDisruptionBudget included.
- Validated on AKS, EKS, GKE, and on-prem Kubernetes (1.26+)
- ConfigMap and Secret references for policy and certificate management
- Scale-to-zero capable — stateless gateway design supports cost-optimized deployments
Bare Metal
For restricted network environments where container orchestration is unavailable. Direct binary deployment with systemd service management. Policy bundles sync automatically or can be sideloaded for disconnected operation.
- Offline install package with all dependencies bundled
- Inference model files included — no external downloads required post-install
- Syslog-compatible audit output for integration with existing log infrastructure
Built for environments where data cannot leave.
Healthcare Air-Gap
Hospitals and health systems with strict network segmentation requirements. PHI never leaves the clinical network. HIPAA compliance bundle enforced locally with offline AI inference.
Learn more →Defense & Classified Networks
Air-gapped enclaves where no data can egress to any external service. tamper-proof audit trail provides tamper-evident records for NIST 800-171 compliance.
Learn more →Financial On-Premises
Trading floors and risk systems where latency and data sovereignty are non-negotiable. PCI-DSS and SOX compliance bundles execute locally. Sub-millisecond regex tier with zero network overhead.
Learn more →Manufacturing & OT
Operational technology environments where IT/OT convergence requires strict network boundaries.
Learn more →Same governance. Different deployment.
Both deployment models run the identical 3-tier DLP pipeline, the same compliance bundles, and the same tamper-proof audit trail. The difference is where the data plane runs.
| Capability | Outpost | SaaS |
|---|---|---|
| Data leaves premises | Never — all inspection local | Prompts transit to SaaS for inspection |
| DLP inference | Offline inference — local, no cloud calls | Cloud-hosted model inference |
| Detection accuracy | Same 3-tier pipeline, same accuracy | Same 3-tier pipeline |
| Audit trail | Local tamper-proof logs | Cloud-hosted tamper-proof logs |
| Policy management | Control plane sync or offline policy packs | Real-time control plane |
| Certificate auth | mTLS with X.509 chain verification | API key + SSO |
| Deployment | Docker / Kubernetes / bare metal | Managed — no infrastructure to operate |
| Network requirements | Outbound HTTPS only (or fully disconnected) | Standard internet access |
Ready to deploy governance on your infrastructure?
Talk to the team about your air-gap requirements. We can walk through the Outpost architecture and what deployment looks like in your environment.