Sovereign deployment
Your data, your infrastructure,your jurisdiction.
CISGuard is built for environments where data sovereignty is non-negotiable. Deploy on-premises or fully air-gapped, with no SaaS dependency, no data egress and no cross-border transfer.
- Deployment models
- On-premises, air-gapped, private cloud, hybrid
- Internet connectivity
- None required for air-gapped mode
- Data egress
- Zero. All scan data stays within the customer perimeter
- SaaS dependency
- None
- Per-jurisdiction isolation
- Supported. UAE data stays in the UAE, Saudi data in Saudi Arabia, per-country residency enforced
- Sovereign clouds
- Azure UAE North, Azure Saudi Arabia Central, AWS GovCloud, AWS Middle East, Oracle Sovereign Cloud
Operating principles
Four principles. No exceptions.
No data egress
No scan results, configuration data or asset metadata ever leaves your infrastructure.
No SaaS dependency
CISGuard runs on your hardware or in your cloud tenant. We have no operational visibility into your environment.
No telemetry
No analytics phone-home, no anonymised usage data collection, no vendor backchannel.
Per-jurisdiction isolation
Multi-site deployments support per-country data residency. Saudi data stays in Saudi infrastructure. UAE data stays in UAE infrastructure.
Deployment models
Four ways to deploy. All sovereign.
Choose the topology that matches your regulatory boundaries and operational reality.
On-premises
A single installer on your server. Agents on Windows, Linux and container hosts. All scan data is processed and stored inside your data centre.
- CISGuard server
- Windows agents
- Linux agents
- Cloud API scanner
- Your database
Air-gapped
Fully offline operation for classified networks. No internet connectivity at install, scan or report time. Agent updates arrive on secure media.
- Isolated server
- Classified endpoints
- Offline agent updates
- Local reports
- No external egress
Private cloud
Run inside your own Azure, AWS or GCP tenant. Scan results stay in your cloud account. Compatible with sovereign regions such as Azure UAE and AWS GovCloud.
- Tenant-hosted server
- Cloud-native agents
- VPC-isolated storage
- Sovereign region
- No cross-tenant egress
Hybrid
A central server on-premises with agents across multiple sites, cloud accounts and Kubernetes clusters. One dashboard, jurisdictional data isolation.
- Central HQ server
- Site relay agents
- Cross-cloud API scanners
- Per-site data isolation
- Unified dashboard
Regulatory coverage
Where sovereign deployment is not optional.
The regulations that demand data residency, operational isolation or air-gapped environments, and how CISGuard satisfies each.
UAE
- UAE PDPL (Federal Decree-Law 45 of 2021)Personal data stays within UAE jurisdiction. On-premises deployment satisfies the storage requirement.
- UAE IAS (Information Assurance Standards)Controls for classified federal networks. Air-gapped deployment with NIST 800-53 mapping.
- ADHICS (Abu Dhabi healthcare)Sector-specific data handling for Abu Dhabi healthcare. Per-facility isolation supported.
Saudi Arabia
- NCA ECC (Essential Cybersecurity Controls)Saudi National Cybersecurity Authority. On-premises deployment with NIST 800-53 and ISO 27001 mapping for the ECC-2:2024 technical controls.
- SAMA Cybersecurity FrameworkSaudi Central Bank requirements for financial entities. On-premises deployment for tier-1 data.
United States
- FedRAMP High, IL4 and IL5Air-gapped deployment satisfies network isolation for federal high-impact systems.
- CMMC Level 2 and Level 3Defence contractor handling of CUI. NIST 800-53 mapping with an on-premises CUI boundary.
- CJIS (criminal justice)Law enforcement data handling. Full on-premises deployment with a role-based audit trail.
European Union
- GDPR Article 32Technical and organisational measures. EU-region deployment with no cross-border transfer.
- NIS2 DirectiveEssential and important entities. Continuous monitoring supports Article 21.
- DORA (financial sector)EU financial entity ICT risk management. Sovereign deployment for tier-1 financial infrastructure.
Frequently asked
Sovereign deployment questions, answered directly.
Can CISGuard run fully air-gapped with no internet access?
Yes. CISGuard installs from a single offline installer delivered on secure media. No internet connectivity is required at install, configuration, scan or report-generation time. Agent updates are delivered through encrypted media for classified networks.
Does CISGuard send any telemetry, usage data or scan results outside the customer perimeter?
No. CISGuard has no telemetry, no usage analytics phone-home and no vendor backchannel. All scan data, configuration data and asset metadata stay within the customer infrastructure. Per-jurisdiction data residency is supported for multi-site deployments.
Which sovereign-cloud and air-gapped regulations does CISGuard satisfy?
UAE PDPL, UAE IAS, ADHICS, Saudi NCA ECC, the SAMA Cybersecurity Framework, FedRAMP High, IL4 and IL5, CMMC Level 2 and 3, CJIS, the NIS2 Directive, DORA and GDPR Article 32. CISGuard maps each regulation to specific control families.
Does CISGuard work in Azure UAE, AWS GovCloud or other sovereign cloud regions?
Yes. CISGuard deploys inside any customer-controlled tenant, including Azure UAE North, Azure Saudi Arabia Central, AWS GovCloud (US), AWS Middle East regions and Oracle Sovereign Cloud. Scan results remain in the customer cloud account.
How long does an air-gapped deployment take?
Air-gapped deployment is seamless: our compliance engineers handle the full rollout, including the offline media transfer, and classified environments with hardened approval workflows follow your own change process.
Sovereign by design. Briefing on request.
Walk through the deployment architecture for your jurisdictional and regulatory boundaries with our compliance engineering team.