ZeroTrusted.ai

Product support

Clear answers for deploying and operating ZeroTrusted.ai.

Use this hub to understand the platform, choose an installation pattern, connect the right tools, and troubleshoot the difference between configured, verified, receiving data, and ready to run.

Platform guide

Read the module catalog, operator workflows, APIs, evidence chain of custody, agent lifecycle, and troubleshooting reference.

Deployment support

Plan on-premises, cloud-connected, Red Hat, Kubernetes, hybrid, or air-gapped installations with a clear readiness checklist.

Operational support

Use preflight, connector health, tool attestation, mission trace, human review, and evidence packages to diagnose real failures.

Authenticated product and support guides

These in-product references are available to authorized pilot and customer users; they are not public documentation. Please request access only after authorization through a ZeroTrusted.ai team member, approved partner, or distributor.

Technical specifications

Built for the infrastructure and assurance model you already have.

Deployment

On-premises, private cloud, hybrid, air-gapped, and restricted networks; Kubernetes, Docker Compose, RHEL/Rocky/Alma, and Red Hat OpenShift.

Cloud integration

AWS EKS, Azure AKS, Google GKE, cloud identity, posture, logging, storage, and evidence connectors.

Operations

Multi-tenant profiles, MSSP edge collectors, customer portals, role-based access, approval queues, schedules, and queue-aware missions.

Evidence

Unified Findings, SCAP/XCCDF/OVAL, OSCAL, signed evidence packages, SHA-256 hashes, timestamps, mission trace, and chain-of-custody records.

Security

AI Firewall, AI WAF, DLP, prompt-injection controls, tool allow-lists, provider trust tiers, classification banners, secrets vault, and least privilege.

Connectivity

SIEM, EDR, identity, email, cloud, network, threat intelligence, ticketing, vulnerability, custom API, STIX/TAXII, MITRE ATT&CK/ATLAS, and local tools.

Frequently asked questions

Answers for operators, security teams, and executives.

How does ZeroTrusted.ai support FedRAMP High environments?+

ZeroTrusted.ai is customer-hosted software built to FedRAMP High security requirements, with STIG-hardened Kubernetes deployment configurations. Customers can deploy on-premises or in their own private or hybrid cloud. ZeroTrusted.ai does not claim a FedRAMP authorization for the product. For a customer-operated SaaS deployment, we provide configuration and SSP information to support inventory updates, authorization-boundary documentation, security impact analysis, control responsibilities, and related assessment artifacts. Authorization remains specific to the customer's system and assessment.

Is ZeroTrusted.ai a SaaS-only product?+

No. The control plane is designed for on-premises, private cloud, hybrid, air-gapped, and restricted deployments. It connects to AWS EKS, Azure AKS, Google GKE, Red Hat OpenShift, RHEL, and other Kubernetes environments while preserving the customer boundary and data residency model.

Which models and AI providers can the platform use?+

The platform is model agnostic. The documented provider chain includes organization-managed or direct OpenAI, Anthropic Claude, Ollama local models, and NVIDIA NIM for specialized inference. Provider, model, token, data-egress, and tenant permissions remain explicit in the AI Provider Control Plane.

How do agents get approved before they run?+

Agent registration records identity, owner, tenant, skills, autonomy level, model assignment, tools, permissions, guardrails, and version history. Agent Preflight Ops checks those dependencies before a mission. Deep AI System Testing can run benchmarks, human review, mission trace, adversarial testing, certification, remediation, retest, and signed evidence export.

What happens when a connector or binary is unavailable?+

The runtime should report the actual state: connected and receiving data, configured but unverified, unreachable, unauthorized, missing binary, or not applicable. Fail-closed actions do not convert a missing dependency into a successful scan or synthetic finding. The operator receives a troubleshooting path and can queue or reschedule work.

Which compliance and assurance frameworks are supported?+

The platform provides mappings and evidence workflows for FedRAMP High-aligned deployments, NIST SP 800-53 Rev. 5, NIST SP 800-171, NIST AI RMF, CMMC 2.0, ISO 27001, ISO/IEC 42001, SOC 2 Type II, HIPAA/HITECH, PCI DSS, NERC CIP, FERC, FERPA, EU AI Act, Japan AI governance, Brazil LGPD, DoD 8140/DCWF, and DISA STIG. A framework mapping supports an assessment; it does not by itself grant an authorization or certification.

How do tenant and customer boundaries work?+

MSSP operators can manage many customers while keeping profile, customer, facility, asset, connector, evidence, finding, report, and agent scope explicit. Server-side identity and policy determine ownership. Customer users see only the data and capabilities granted to their profile, and high-impact operations require the configured approval policy.

Why do the agent and tool counts change?+

The platform distinguishes shipped definitions, active tenant registrations, clones, imported agents, development candidates, and runtime-ready handlers. Counts change as new agents and tools are added and as deployments enable or quarantine dependencies. The live tenant inventory and readiness manifest remain the source of truth for a specific installation.

Can the platform operate on a small laptop as well as a large enterprise cluster?+

Yes, within the limits of the selected model, tool workload, storage, network, and available compute. A small deployment can run local models and a focused set of agents. Enterprise deployments can add GPU capacity, workers, edge collectors, and queue-aware Autonomous SOC operations without changing the evidence and governance model.

Need help with a specific tenant, connector, or mission?

Send the deployment type, module, target, error, timestamp, and relevant preflight or mission ID. We can use that evidence to diagnose the issue without asking you to guess.