What is Air-Gapped Deployment?
A system deployed on a network with no physical or logical connection to the public internet — the strictest form of sovereign deployment.
Also known as
Air-Gapped Deployment — explained.
An air-gapped deployment runs on a network that has no physical or logical connection to the public internet — the strictest form of sovereign deployment. Updates and patches are delivered via offline media (USB, removable drives) following defined procedures; outbound telemetry, license-key phone-home, and software-update mechanisms must all be designed to either work offline or be explicitly disabled. Air-gap deployments are common in defence, intelligence, classified research, critical-infrastructure SCADA, certain banking back-office systems, and any environment where the threat model treats outbound network connectivity itself as the unacceptable risk. The vendor implications are significant: every dependency must be air-gap-installable (no calls to package registries at runtime), every license-validation mechanism must work offline (RSA-signed offline licence files, allowlist of approved kiosk MAC addresses), and the update lifecycle must produce installable bundles rather than depending on network deploy. Smart Parking's offline license model is the Zeour reference pattern.
Zeour solutions that operate on this layer.
Verticals where air-gapped deployment is operationally critical.
Blog posts that go deeper on air-gapped deployment.
Adjacent definitions to read next.
Sovereign Deployment
Sovereign DeploymentSoftware that runs entirely inside the operator's perimeter — their hardware, their network, their backups, their keys — with no third-party dependency for continued operation.
On-Premises AI
AI & ModelsOpen-weight large language models running on the operator's own hardware — no prompt, completion, or embedding ever leaves the perimeter.
Source Code Escrow
Sovereign DeploymentA contractual arrangement where the vendor deposits source code with a neutral third party — the operator can claim it under defined trigger conditions (vendor bankruptcy, abandonment, etc.).
BYOK (Bring Your Own Key)
Sovereign DeploymentA deployment model where the operator supplies and controls the encryption keys protecting their data — the vendor cannot decrypt without operator co-operation.
Data Residency
Sovereign DeploymentA requirement that personal or regulated data is stored, processed, and backed up within a defined jurisdiction — usually a country or a treaty bloc.
National Card Scheme
Sovereign DeploymentThe country-operated card-payment scheme that processes domestic transactions on sovereign rails — mada in KSA, KNET in Kuwait, OmanNet in Oman, the UAE national scheme in the Emirates.
National Identity Gateway
Sovereign DeploymentThe country-operated identity-federation surface citizens use to prove who they are to public + private services — typically over OIDC against a sovereign-hosted gateway.
RSA-Signed License Gate
Sovereign DeploymentA sovereign anti-fraud + anti-piracy pattern where each edge device boots only if a cryptographically-signed licence file (RSA-SHA256) validates against an embedded public key + MAC-address allowlist — no daily phone-home required.
Talk to a Zeour engineer.
A 30-minute scoping call to walk your operational profile against where air-gapped deployment actually sits in your stack, then a fixed-fee Discovery price by the end of the call.