On-premises Agentic SecOps

Agentic security for on-prem and air-gapped environments

Strike48's on-prem SOC appliance provides the first turnkey deployment of agentic security operations capabilities for air-gapped environments. Choose your models and your telemetry never leaves.

Autonomous security operations on-premises

Align Top Left Square Streamline Icon: https://streamlinehq.com

Air-Gapped Autonomy

Run the full agentic platform on a server with no external connection. Classified, sovereign, and isolated environments get the same autonomous capabilities as cloud deployments.

Database Streamline Icon: https://streamlinehq.com

Data Stays Where It Belongs

Security telemetry stays on-site or in-country. Organizations under residency mandates or cloud prohibitions can adopt agentic operations without moving a single log.

Encrypted Lock Streamline Icon: https://streamlinehq.com

Sealed Model Usage

Models are loaded onto the appliance and run inside encrypted memory. Prompts, telemetry, and context stay protected, so there is no path for cross-pollination into an externally hosted model.

Scanner 3 Streamline Icon: https://streamlinehq.com

Cost You Can Forecast

Local inference removes per-token billing from the equation. The appliance scales at a fraction of the cost of a SaaS deployment, which makes expansion a budget decision you can actually model.

Four Ways to Deploy

One platform, flexible deployment

Strike48 can run in the cloud, managed or in a private cloud you control, or on-premises on an appliance, with the option to be fully air-gapped with no external connection.

The platform, the agents, and the operator experience stay identical across all four. You choose the modality that matches your regulatory posture and change it as that posture changes.

Managed cloud (SaaS)On-premises appliance
Where it runs
Strike48's AWS account
Your hardware, with no dependency on Strike48's cloud
Edge
Cloudflare fronts all traffic and absorbs DDoS and WAF duties
N/A
Identity
Keycloak as OIDC identity provider at the edge
Identity service runs on the appliance
In transit
TLS 1.3 browser to edge and edge to origin,
AES-256-GCM inside the boundary on the AWS Nitro System
TLS at the single entry point, encrypted memory space between services
At rest
Amazon RDS encrypted with AWS KMS
You control the encryption or trusted hardware level
Orchestration
Private Kubernetes cluster with horizontally scaling worker nodes
You control the encryption or trusted hardware level
Inference
Hosted model access
Optional on-appliance inference layer with local GPU
Deployment modalities
Cloud
Private Cloud
On-Premises
On-Prem / Air-Gapped
[modern tech interface]
Models on the Box

Local inference without a single-vendor dependency

For on-premises and air-gapped deployments, an inference layer is added to the appliance and AI models are loaded directly onto it. A GPU attaches through PCI passthrough with CUDA, so model execution happens entirely on your hardware and the platform makes no external API calls. Model flexibility was built into Strike48 from the start, so we package models that are approved for your controlled environment rather than binding you to one model developer. When a better model arrives, you swap it. The agents keep running.

On-appliance model loading
Local inference
Model-flexible architecture
No external API calls
GPU via PCI passthrough (CUDA)
Built to Run Enclosed

No connection required for agents

Most agentic tools degrade when you cut them off from frontier model updates. Strike48 splits work between deterministic agents that execute defined procedures and cognitive agents that reason over context. That architecture supports a fully enclosed system that holds its quality without relying on broader LLM learning loops. Detection engineering, alert triage, phishing investigation, and threat hunting all run inside the perimeter.

Deterministic workflows
Cognitive agents
Hybrid architecture
Configurable human oversight
Real-time data federation
[modern tech interface]
[modern tech interface]
Hardware-Level Isolation

Every service runs in its own protected memory

The appliance runs on trusted compute, which means CPU memory encryption protects workload memory from the host it runs on. Every workload runs as a pod inside its own lightweight virtual machine with a dedicated guest kernel, separated by network policy. A compromise in one service cannot reach another through a shared kernel, and communication between virtual machines stays inside encrypted memory space. Isolation is enforced by the hardware rather than by configuration you have to maintain.

Confidential computing
Per-service VM isolation
Dedicated guest kernels
Network-policy separation
Encrypted VM-to-VM memory
Hardware or Software

Delivered on our hardware or deployed on yours

The Strike48 Appliance ships as dedicated hardware or as a soft-appliance on infrastructure that meets our specifications. Kubernetes orchestrates the platform at the system level in both cases, so the deployment model changes who owns the metal and nothing else. Existing investments stay in place. Strike48 works across your environment without requiring you to centralize data or replace the tooling you already run.

Dedicated hardware
Soft-appliance
Kubernetes-orchestrated
Runs on your existing cluster
[modern tech interface]

Requirements

What the hardware supplies,
and what the install brings

What the hardware provides

Shield 3 Streamline Icon: https://streamlinehq.com

Trusted compute.

CPU memory encryption, so workload memory is protected from the host.

Database Shield Streamline Icon: https://streamlinehq.com

Disk encryption.

Full-disk encryption supplied to the operating system.

What the install provides

Padlock Key Streamline Icon: https://streamlinehq.com

Single SSL termination.

One TLS endpoint for all external traffic.

Hub Integration Connection Streamline Icon: https://streamlinehq.com

Orchestration.

You control the encryption or trusted hardware level.

Network Node Connection Integration Streamline Icon: https://streamlinehq.com

Hardware-level isolation per service.

Pods in dedicated virtual machines with network-policy separation.

Optional local inference.

An LLM inferencing layer with a GPU attached via PCI passthrough.

For Service Providers

Bring agentic operations to more  customers

A share of every MSSP pipeline sits blocked on cloud AI adoption. Regulatory limits, data residency rules, and internal security policy keep those accounts on legacy service models. The Appliance turns that segment into addressable revenue, delivered inside the customer environment and managed as part of your service.

Customer-hosted delivery
Sovereign and regulated accounts
Multi-tenant service models
Predictable unit economics

Everything you run in the cloud, on-site

Warning Diamond Streamline Icon: https://streamlinehq.com

Alert Triage

Autonomous enrichment and disposition

Phishing Investigation

End-to-end analysis and verdict

Checklist Rule Streamline Icon: https://streamlinehq.com

Detection Engineering

Rule creation and tuning

Search Visual Streamline Icon: https://streamlinehq.com

Threat Hunting

Hypothesis-driven investigation

Task List Streamline Icon: https://streamlinehq.com

Remediation

Governed action with approval gates

Data Federation

Query across sources without centralizing

See agentic security operations run inside your perimeter

Get a walkthrough of the Strike48 Appliance and see how on-premises and air-gapped deployments change what your team can automate.