Skip to main content
DEPLOYMENT ARCHITECTURE

Your infrastructure. Your data. Your control.

Arbitex deploys as a Hybrid Outpost — the data plane runs inside your environment, the control plane is SaaS-hosted. Prompts and responses never leave your network.

Hybrid Outpost Model

Two planes. One architecture. No data egress.

Arbitex splits the gateway into two distinct components — a data plane that runs in your VPC and a control plane hosted by Arbitex. The separation is not a configuration option; it is the architecture.

Regulated enterprises cannot route AI traffic through a third-party SaaS gateway and call it governed. The Arbitex data plane — responsible for inspection, enforcement, and logging — runs entirely within your infrastructure. Prompts and responses are inspected in your environment, enforced against your policies, and logged to your storage. Nothing crosses the boundary.

The control plane handles policy management, dashboards, team administration, and reporting. It is SaaS-hosted and communicates with the data plane via outbound-only HTTPS. No inbound ports are required in your network.

Choose Your Model

Two deployment paths for every infrastructure posture.

Fastest path

Multi-Tenant SaaS

Arbitex manages the full stack — data plane and control plane — in isolated, single-tenant partitions within our managed regions.

Regions
Deployed in your region
Isolation
Tenant isolation enforced at the API and data layers
Availability
Multi-AZ deployment, no single point of failure in the gateway data path

Best for: Organizations without strict data residency requirements who want immediate deployment.

Recommended for regulated enterprises

Hybrid Outpost

The data plane runs in your VPC or on-premises infrastructure. Your AI traffic — prompts, responses, and inspection results — never leaves your environment.

Data plane
Runs in customer VPC or on-premises. Handles inspection, enforcement, and logging.
Control plane
SaaS-hosted by Arbitex. Handles policy management, dashboards, and reporting.
Connectivity
Outbound-only HTTPS from data plane to control plane. No inbound ports required.
High availability
Multi-AZ deployment, no single point of failure in the gateway data path.

Best for: Regulated enterprises with data residency, compliance, or contractual requirements.

Network Architecture

Outbound-only. No inbound exposure.

The Arbitex gateway is designed for environments where inbound network access is unacceptable. The data plane initiates all communication — there are no listening ports that require inbound firewall rules or public ingress.

Connectivity Model

  • Outbound-only HTTPS — The data plane connects to the Arbitex control plane over outbound HTTPS (port 443). No inbound ports are opened in the customer network.
  • Private network connectivity — Hybrid Outpost runs inside your VPC. All control-plane communication stays within your private network perimeter.
  • No data egress — AI traffic (prompts, responses, inspection results) remains within the customer environment. Only policy state and operational telemetry flow to the control plane.

Perimeter Controls

  • WAF — Web Application Firewall on all public-facing endpoints. OWASP Top 10 rule sets active.
  • DDoS protection — Layer 3/4 and Layer 7 DDoS protection. Automatic traffic scrubbing.

Traffic Flow

Your Application
Arbitex Data Plane (Customer VPC)
Inspect · Enforce · Log
Arbitex Control Plane (SaaS)
Policy sync · Dashboard · Reporting
Read the deployment guide

Ready to deploy governance in your environment?

Talk to the team about your infrastructure requirements. We can walk you through the Hybrid Outpost architecture and what deployment looks like in your environment.