ZeroTrusted.ai

Customer-hosted deployment and authorization

ZeroTrusted.ai is customer-hosted software built to FedRAMP High security requirements, with STIG-hardened Kubernetes deployment configurations. Customers can deploy on-premises or in their own private or hybrid cloud. ZeroTrusted.ai does not claim a FedRAMP authorization for the product. For a customer-operated SaaS deployment, we provide configuration and SSP information to support inventory updates, authorization-boundary documentation, security impact analysis, control responsibilities, and related assessment artifacts. Authorization remains specific to the customer's system and assessment.

Deployment guide

Deploy AI security inside your boundary, then connect the platforms you already operate.

ZeroTrusted.ai is on-premises first. Use private infrastructure, Red Hat, Kubernetes, AWS, Azure, Google Cloud, hybrid, or air-gapped patterns while keeping tenant, data, model, agent, and evidence controls explicit.

Deployment topologies

Choose the infrastructure that matches the mission.

The governance model stays consistent across environments. The install profile determines where data, models, connectors, evidence, and execution workers run.

On-premises and Red Hat

Run the control plane and tool runners on RHEL, Rocky, Alma, or Red Hat OpenShift. Keep sensitive data, evidence, models, and credentials inside the boundary.

Kubernetes and private cloud

Deploy to RKE2, K3s, Talos, or a hardened Kubernetes distribution with separate workers for scanners, agents, evidence, and connectors.

AWS, Azure, and Google Cloud

Connect EKS, AKS, and GKE estates for posture, identity, logs, assets, vulnerability, and remediation evidence while the AI SOAR control plane remains in the chosen boundary.

Hybrid and air-gapped

Use edge collectors, local models, offline tool registries, signed evidence packages, and controlled synchronization for disconnected or restricted operations.

Installation prerequisites

Make readiness visible before the first mission.

Boundary and identity

Select the owner, customer, profile, facilities, locations, system boundary, data classification, identity provider, and approval policy before enabling missions.

Compute and storage

Size CPU, memory, persistent storage, optional GPU, worker concurrency, queue capacity, and evidence retention for the selected workloads.

Network and secrets

Define egress, proxy, DNS, TLS, firewall, private endpoints, service accounts, certificates, and the Security Authority Vault or approved secret store.

Tool runtimes

Install or attach the approved binaries and handlers, then run version probes, smoke tests, target verification, and connector live tests. Missing tools remain unavailable.

Models and providers

Assign an approved local or external model per agent and tenant. Record provider, model version, token limits, cost controls, data egress, and fallback behavior.

Evidence and reporting

Set retention, classification, hash/signing, report templates, customer access, export formats, and the workflow for human review and residual risk.

Recommended onboarding flow

A repeatable path for every customer and instance.

01

Create the installation profile

Register the instance, owner, customer or MSSP scope, location, classification, license, and data boundary.

02

Install the control plane

Deploy the web/API services, database, queue, identity integration, vault, audit ledger, and health endpoints.

03

Connect infrastructure

Add AWS, Azure, GCP, Red Hat, Kubernetes, SIEM, EDR, identity, email, ticketing, cloud, threat, and custom connectors.

04

Initialize the fleet

Register agents, models, tools, skills, permissions, autonomy envelopes, schedules, and customer-specific defaults.

05

Run preflight and test

Verify binaries, connectors, target reachability, authorization, model access, queue capacity, and evidence output before a mission starts.

06

Operate and improve

Schedule assessments, monitor signals, triage findings, approve response, preserve evidence, remediate, retest, and update the release manifest.

Security and assurance

The install is part of the evidence.

Documented deployment decisions become part of the system boundary and audit record. AI SOAR can retain configuration snapshots, version probes, connector tests, target verification, tool attestation, agent preflight, model routing, and remediation evidence for review.

Database and evidence

Profile-scoped records, hashes, timestamps, export packages, retention, and backup planning.

Fail-closed readiness

Unavailable tools, connectors, permissions, or models remain visible and actionable.