Product support
Clear answers for deploying and operating ZeroTrusted.ai.
Use this hub to understand the platform, choose an installation pattern, connect the right tools, and troubleshoot the difference between configured, verified, receiving data, and ready to run.
Platform guide
Read the module catalog, operator workflows, APIs, evidence chain of custody, agent lifecycle, and troubleshooting reference.
Deployment support
Plan on-premises, cloud-connected, Red Hat, Kubernetes, hybrid, or air-gapped installations with a clear readiness checklist.
Operational support
Use preflight, connector health, tool attestation, mission trace, human review, and evidence packages to diagnose real failures.
Authenticated product and support guides
These in-product references are available to authorized pilot and customer users; they are not public documentation. Please request access only after authorization through a ZeroTrusted.ai team member, approved partner, or distributor.
Technical specifications
Built for the infrastructure and assurance model you already have.
Deployment
On-premises, private cloud, hybrid, air-gapped, and restricted networks; Kubernetes, Docker Compose, RHEL/Rocky/Alma, and Red Hat OpenShift.
Cloud integration
AWS EKS, Azure AKS, Google GKE, cloud identity, posture, logging, storage, and evidence connectors.
Operations
Multi-tenant profiles, MSSP edge collectors, customer portals, role-based access, approval queues, schedules, and queue-aware missions.
Evidence
Unified Findings, SCAP/XCCDF/OVAL, OSCAL, signed evidence packages, SHA-256 hashes, timestamps, mission trace, and chain-of-custody records.
Security
AI Firewall, AI WAF, DLP, prompt-injection controls, tool allow-lists, provider trust tiers, classification banners, secrets vault, and least privilege.
Connectivity
SIEM, EDR, identity, email, cloud, network, threat intelligence, ticketing, vulnerability, custom API, STIX/TAXII, MITRE ATT&CK/ATLAS, and local tools.
Standards reference
Ground the implementation in the source standards.
Framework mappings are implementation aids. The customer, authorizing official, assessor, or regulator still determines the applicable scope and final assurance decision.
NIST AI RMF
Risk management across Govern, Map, Measure, and Manage.
Read the official source ↗NIST SP 800-53 Rev. 5
Security and privacy control catalog with OSCAL materials.
Read the official source ↗FedRAMP baselines
High-impact cloud control baselines and authorization guidance.
Read the official source ↗CMMC resources
DoD resources for protecting FCI and CUI in the defense industrial base.
Read the official source ↗ISO/IEC 42001
AI management-system requirements for responsible, controlled AI use.
Read the official source ↗Frequently asked questions
Answers for operators, security teams, and executives.
How does ZeroTrusted.ai support FedRAMP High environments?+
ZeroTrusted.ai is customer-hosted software built to FedRAMP High security requirements, with STIG-hardened Kubernetes deployment configurations. Customers can deploy on-premises or in their own private or hybrid cloud. ZeroTrusted.ai does not claim a FedRAMP authorization for the product. For a customer-operated SaaS deployment, we provide configuration and SSP information to support inventory updates, authorization-boundary documentation, security impact analysis, control responsibilities, and related assessment artifacts. Authorization remains specific to the customer's system and assessment.
Is ZeroTrusted.ai a SaaS-only product?+
No. The control plane is designed for on-premises, private cloud, hybrid, air-gapped, and restricted deployments. It connects to AWS EKS, Azure AKS, Google GKE, Red Hat OpenShift, RHEL, and other Kubernetes environments while preserving the customer boundary and data residency model.
Which models and AI providers can the platform use?+
The platform is model agnostic. The documented provider chain includes organization-managed or direct OpenAI, Anthropic Claude, Ollama local models, and NVIDIA NIM for specialized inference. Provider, model, token, data-egress, and tenant permissions remain explicit in the AI Provider Control Plane.
How do agents get approved before they run?+
Agent registration records identity, owner, tenant, skills, autonomy level, model assignment, tools, permissions, guardrails, and version history. Agent Preflight Ops checks those dependencies before a mission. Deep AI System Testing can run benchmarks, human review, mission trace, adversarial testing, certification, remediation, retest, and signed evidence export.
What happens when a connector or binary is unavailable?+
The runtime should report the actual state: connected and receiving data, configured but unverified, unreachable, unauthorized, missing binary, or not applicable. Fail-closed actions do not convert a missing dependency into a successful scan or synthetic finding. The operator receives a troubleshooting path and can queue or reschedule work.
Which compliance and assurance frameworks are supported?+
The platform provides mappings and evidence workflows for FedRAMP High-aligned deployments, NIST SP 800-53 Rev. 5, NIST SP 800-171, NIST AI RMF, CMMC 2.0, ISO 27001, ISO/IEC 42001, SOC 2 Type II, HIPAA/HITECH, PCI DSS, NERC CIP, FERC, FERPA, EU AI Act, Japan AI governance, Brazil LGPD, DoD 8140/DCWF, and DISA STIG. A framework mapping supports an assessment; it does not by itself grant an authorization or certification.
How do tenant and customer boundaries work?+
MSSP operators can manage many customers while keeping profile, customer, facility, asset, connector, evidence, finding, report, and agent scope explicit. Server-side identity and policy determine ownership. Customer users see only the data and capabilities granted to their profile, and high-impact operations require the configured approval policy.
Why do the agent and tool counts change?+
The platform distinguishes shipped definitions, active tenant registrations, clones, imported agents, development candidates, and runtime-ready handlers. Counts change as new agents and tools are added and as deployments enable or quarantine dependencies. The live tenant inventory and readiness manifest remain the source of truth for a specific installation.
Can the platform operate on a small laptop as well as a large enterprise cluster?+
Yes, within the limits of the selected model, tool workload, storage, network, and available compute. A small deployment can run local models and a focused set of agents. Enterprise deployments can add GPU capacity, workers, edge collectors, and queue-aware Autonomous SOC operations without changing the evidence and governance model.
Need help with a specific tenant, connector, or mission?
Send the deployment type, module, target, error, timestamp, and relevant preflight or mission ID. We can use that evidence to diagnose the issue without asking you to guess.