Skip to main content
OUTPOST

AI governance that never leaves your network.

Arbitex Outpost runs the full DLP pipeline — pattern detection, entity recognition, and compliance bundles — entirely within your infrastructure. No cloud dependency. No data egress. Same detection accuracy as SaaS.

Key Capabilities

Everything runs locally. Nothing phones home.

The Outpost data plane handles inspection, enforcement, and logging without any external dependency. DLP models, policy evaluation, and audit chain — all local.

Offline AI Inference

DLP models run locally using offline inference — no cloud calls, no external model APIs. Named entity recognition and pattern detection execute entirely within the data plane.

Certificate-Based Authentication

mTLS with full certificate chain verification — leaf, intermediate, and root CA. The data plane authenticates to the control plane using X.509 certificates, not shared secrets.

Zero-Trust Proxy

Every request is authenticated, inspected, and logged before reaching any AI model. No implicit trust. No passthrough mode. The proxy fails closed on any authentication or inspection failure.

Admin API

Full programmatic control over the Outpost data plane — policy updates, configuration changes, health checks, and certificate rotation. Automate deployment management via REST.

OpenTelemetry Metrics

Outpost emits OTLP gRPC traces and metrics covering request ingestion, DLP inspection, policy evaluation, and provider routing. Integrate with your existing Grafana, Datadog, or Splunk stack.

Fail-Closed Design

If the DLP inference engine, certificate validation, or policy store becomes unavailable, the Outpost blocks all traffic. No degradation. No bypass. Security is the default state.

Deployment Options

Run it your way.

Fastest path

Docker Compose

Single-command deployment for development, staging, and smaller production workloads. All Outpost services run as containers with Docker Compose orchestration.

  • Pre-built container images with daily CVE scanning via Trivy
  • Environment-variable configuration — no config files to manage
  • Supports volume mounts for persistent audit logs and DLP model cache
Recommended for production

Kubernetes Helm

Helm charts for production Kubernetes clusters. Horizontal pod autoscaling, liveness/readiness probes, and PodDisruptionBudget included.

  • Validated on AKS, EKS, GKE, and on-prem Kubernetes (1.26+)
  • ConfigMap and Secret references for policy and certificate management
  • Scale-to-zero capable — stateless gateway design supports cost-optimized deployments
Restricted networks

Bare Metal

For restricted network environments where container orchestration is unavailable. Direct binary deployment with systemd service management. Policy bundles sync automatically or can be sideloaded for disconnected operation.

  • Offline install package with all dependencies bundled
  • Inference model files included — no external downloads required post-install
  • Syslog-compatible audit output for integration with existing log infrastructure
Use Cases

Built for environments where data cannot leave.

Healthcare Air-Gap

Hospitals and health systems with strict network segmentation requirements. PHI never leaves the clinical network. HIPAA compliance bundle enforced locally with offline AI inference.

Learn more →

Defense & Classified Networks

Air-gapped enclaves where no data can egress to any external service. tamper-proof audit trail provides tamper-evident records for NIST 800-171 compliance.

Learn more →

Financial On-Premises

Trading floors and risk systems where latency and data sovereignty are non-negotiable. PCI-DSS and SOX compliance bundles execute locally. Sub-millisecond regex tier with zero network overhead.

Learn more →

Manufacturing & OT

Operational technology environments where IT/OT convergence requires strict network boundaries.

Learn more →
Outpost vs SaaS

Same governance. Different deployment.

Both deployment models run the identical 3-tier DLP pipeline, the same compliance bundles, and the same tamper-proof audit trail. The difference is where the data plane runs.

CapabilityOutpostSaaS
Data leaves premisesNever — all inspection localPrompts transit to SaaS for inspection
DLP inferenceOffline inference — local, no cloud callsCloud-hosted model inference
Detection accuracySame 3-tier pipeline, same accuracySame 3-tier pipeline
Audit trailLocal tamper-proof logsCloud-hosted tamper-proof logs
Policy managementControl plane sync or offline policy packsReal-time control plane
Certificate authmTLS with X.509 chain verificationAPI key + SSO
DeploymentDocker / Kubernetes / bare metalManaged — no infrastructure to operate
Network requirementsOutbound HTTPS only (or fully disconnected)Standard internet access
Read the Outpost architecture docs

Ready to deploy governance on your infrastructure?

Talk to the team about your air-gap requirements. We can walk through the Outpost architecture and what deployment looks like in your environment.