Two ways to deploy. The same six stages in both.

Choose where analysis runs. Collection and personal-data removal always happen on your site, and raw logs never leave your network.

What you chooseModeHybrid SovereignModeSovereign Edition
Log collection and cleaningOn your siteOn your site
Analysis and Mission ControlSovereign cloud regionOn your premises
AISovereign AI in the sovereign cloudSovereign AI inside the deployment
Internet connectionOutbound only, encryptedNone needed, air-gapped
Best forFast start with data kept in your jurisdictionThe strictest data-residency rules

Hybrid Sovereign: how data moves.

Only cleaned events cross your boundary, outbound and encrypted.

Connectivity: the on-premises Sidecar collects and cleans logs, then connects outbound only over mTLS on TCP 443 to the sovereign cloud in Kuala Lumpur; raw logs stay on premises
Outbound only, mTLS on TCP 443, with no connection opened from the cloud. Raw logs stay on premises; only cleaned events reach the sovereign cloud in Kuala Lumpur.Open full size

Sovereign Edition: nothing leaves.

Every stage runs on your premises, air-gapped.

Your premises only
  1. Step 1DevicesSend logs inside your network
  2. Step 2SidecarReads logs and removes personal data
  3. Step 3AnalysisDetection and Sovereign AI on your hardware
  4. Step 4Mission ControlServed from inside your network

The same in both modes.

  • All six stages

    From on-site collection to Mission Control. No feature is held back by mode.

  • 300+ integrations

    Every source we read works the same way in both.

  • SOC and MDR

    GA-SOC Standard or Premium, with on-site support included.

Not sure which mode fits?

Answer the scoping questionnaire and a partner will recommend a mode.

Talk through your residency rules.

60-day full-platform trial. No credit card. No inbound firewall changes. Live in under an hour.