Skip to main content
DATA ISOLATION

Four Isolation Tiers. One Governance Architecture.

From shared tenancy to air-gap. Each tier is a distinct deployment architecture with different network boundaries, compute isolation, and data residency guarantees — not a configuration toggle within a single shared environment.

Shared: Multi-Tenant SaaS
Enhanced: Dedicated Partitions
Outpost: Data Plane in Your VPC
Air-Gap: No Internet Egress

Isolation is not a feature toggle. It is how we deploy.

Enterprise buyers evaluating AI governance platforms ask a question that no feature comparison table can answer: where does our AI traffic actually live, and what separates it from everyone else's? The answer depends on the deployment architecture — not on a checkbox in a settings panel.

Arbitex provides four isolation tiers, each representing a distinct architectural posture. The tiers are not feature flags within a shared environment. They are different deployment architectures with different network boundaries, different compute models, and different data residency guarantees.

Deployment Tiers

Choose the boundary that matches your risk profile.

Tier 1

Shared

Multi-Tenant SaaS

Arbitex manages the full stack — data plane and control plane — in Arbitex-operated infrastructure. Tenants are logically isolated at the API and data layers. Each tenant's data is encrypted with a dedicated key. DLP pipeline execution, audit logging, and model routing are tenant-scoped.

  • Compute: Logical isolation (shared instances)
  • Storage: Logical isolation (shared DB, per-tenant keys)
  • Network: Arbitex perimeter
  • Operations: Arbitex-managed
  • Time to deploy: Hours
Tier 2

Enhanced

Dedicated Partitions

Arbitex manages both planes with dedicated compute and storage resources allocated per tenant. No shared database tables, no shared processing queues, no shared object stores. Network-level segregation within Arbitex-managed infrastructure adds a physical boundary to logical isolation.

  • Compute: Physical isolation (dedicated instances)
  • Storage: Physical isolation (dedicated partitions)
  • Network: Arbitex perimeter, tenant-segregated
  • Operations: Arbitex-managed
  • Time to deploy: Days
Tier 3

Outpost

Hybrid Deployment

The customer operates the Arbitex data plane inside their own VPC or on-premises infrastructure. Arbitex manages the control plane. AI traffic — prompts, responses, and DLP inspection results — is processed and stored entirely within the customer's environment. Outbound-only HTTPS to the control plane.

  • Compute: Physical isolation (customer infrastructure)
  • Storage: Physical isolation (customer storage)
  • Network: Customer VPC perimeter
  • Operations: Customer operates data plane
  • Time to deploy: Weeks
Tier 4

Air-Gap

Isolated Outpost

Outpost supports on-premises deployment with local DLP inference and audit storage. Policy bundles sync automatically from the control plane or can be sideloaded for restricted network environments. GeoIP MMDB bundled in the container image. Software updates distributed as Ed25519-signed bundles for operator-controlled staged application.

  • Compute: Physical isolation (no egress)
  • Storage: Physical isolation (customer storage, offline)
  • Network: Customer perimeter, no internet
  • Operations: Customer operates data plane
  • Time to deploy: Weeks + operator provisioning

Isolation Tier Selection Guide

The tier you choose determines the physical and logical boundaries around your AI governance data. Use this comparison to identify which tier matches your organization's security posture, compliance requirements, and operational model.

Evaluation CriteriaSharedEnhancedOutpostAir-Gap
Data residencyArbitex-managed regionArbitex-managed regionCustomer VPCCustomer environment
Compute isolationLogicalPhysical (dedicated)Physical (customer infra)Physical (no egress)
Storage isolationLogical (per-tenant keys)Physical (dedicated)Physical (customer)Physical (offline)
Network boundaryArbitex perimeterTenant-segregatedCustomer VPCNo internet
Infrastructure opsArbitex-managedArbitex-managedCustomer data planeCustomer data plane
Control planeArbitex SaaSArbitex SaaSArbitex SaaSArbitex SaaS (periodic sync)
Time to deployHoursDaysWeeksWeeks + provisioning
Typical buyerDev teams, startups, SMBMid-market, compliance-consciousRegulated enterpriseDefense, government

Control plane is Arbitex-managed at all tiers. You operate the data plane at Outpost and Air-Gap. Tier selection is a deployment decision — moving between tiers involves architectural changes, not feature toggles.

Per-Tenant Isolation

No commingling at any tier.

At every isolation tier, Arbitex enforces per-tenant data boundaries. One tenant's data, configuration, and audit records are never visible to, accessible by, or co-located with another tenant's.

Per-Tenant Encryption

Each tenant's data is encrypted with a dedicated key at rest. Key material is not shared across tenants at any isolation tier.

Per-Tenant Audit Chain

tamper-proof audit logs are scoped to the individual tenant. No cross-tenant log aggregation or commingling of audit records.

Per-Tenant DLP Pipeline

DLP inspection runs in the context of the requesting tenant's policy configuration. One tenant's DLP rules never evaluate another tenant's traffic.

Per-Tenant Routing

Model routing rules, provider credentials, and fallback chains are tenant-scoped. No shared model configuration between tenants.

Per-Tenant SIEM Delivery

SIEM connector configuration is per-tenant. Audit events route to the tenant's own SIEM endpoint, not a shared collector.

Read the data isolation guide

Find the right isolation tier for your organization.

Our team can walk you through tier selection based on your data residency, compliance, and operational requirements.