Platform / Intelligence / Deployment

Deploy connected, private or air-gapped, and keep the kill switch

Run the Intelligence Platform in your environment, choose what leaves it, and cut the link whenever you decide to.

Swfte Enterprise Intelligence is a customer-hosted appliance. This page describes how it is deployed, the three modes that decide what leaves your environment, and the controls that keep it under your authority: an outbound-only link, signed and typed commands, local validation that fails closed, and a kill switch.

Where it runs

The appliance is packaged as a hardened, minimal container image with an installer for a single host, and a Helm chart for Kubernetes. There is an air-gapped route for environments with no outbound access at all. Installation includes verify and uninstall scripts, and the installer is designed to leave the runtime with the least privilege it can do the job with.

Two database roles are used. One owns the schema and is used only by a one-shot migration step. The other is the runtime role: it cannot bypass row-level security, owns nothing and has only the permissions it needs. The service refuses to start if the runtime role owns any table, and database credentials arrive as files rather than as environment values.

Delivery through the cloud marketplaces is on the roadmap. <marketplace listings - founder to fill>.

Three modes, three answers to what leaves

A configuration choice you can inspect on the appliance with its status command.

  • Connected

    The appliance links outbound to the Swfte control plane. Health counts, coverage summaries, diagnostics and command results may leave. Personal and restricted data do not, and secrets are never stored. The link is mutually authenticated against a certificate authority pinned at enrolment.

  • Private

    The same behaviour, pointed at a control plane that you host, for organisations whose policy excludes a vendor-hosted control plane. The same items may leave, to your own control plane, and commands and updates remain signed and validated locally.

  • Air-gapped

    No outbound connection at all. Nothing leaves, because the link is never started and enrolment is refused. Updates arrive on signed media, verified against an update key pinned on the appliance.

How it stays under your control

Sovereignty is control, not only location. These are the specific mechanisms.

  • Outbound only

    The appliance dials out and the control plane never dials in. There is no inbound port to open for the link.

  • Signed, typed commands

    A remote operation is a typed command with an expiry and a nonce, signed by a key pinned at enrolment. The set of capabilities is a short allow-list, for example triggering a directory sync, reporting coverage, collecting diagnostics or staging an update. There is no shell or arbitrary-execution capability, by construction.

  • Validated locally, fail closed

    The appliance checks the signature, the expiry, the replay record and the capability itself. Anything it cannot verify is refused.

  • A kill switch you own

    A local command stops the link entirely, survives restarts, and each engage and release is journalled and written into the audit chain.

  • An export policy

    Personal and restricted data are local-only by default. Which classes may ever leave is a policy that you can read, and secrets and credentials are never stored at all.

  • Signed updates

    Updates are verified before they are staged, and the installer performs the swap. Upgrades are designed to be backward compatible with the previous release.

Verifiable by the people who run it

A control you cannot check is a promise. The appliance has a command that verifies the audit chain and exits non-zero if the chain breaks or diverges from the signed checkpoint. A status command prints the mode, enrolment, kill switch state, link state and coverage summary, without customer content. A plain-language data inventory describes what the appliance knows about people, written for a works council or a data protection officer.

In connected mode a signed audit checkpoint also goes out through the outbox, so an off-box anchor exists. If you prefer that no anchor leaves, use private or air-gapped mode and keep the checkpoint yourself.

Retention is configurable. Personal data of accounts deleted from the directory can be replaced with a pseudonym after a period you set, and export and erasure for a single person are available commands. Each is audited without restating the values involved.

Choosing a mode

Start from your policy and not from convenience. If you permit a vendor-hosted control plane, connected mode gives the simplest operation, because health, coverage and diagnostics reach Swfte and signed commands can reach you. If your policy requires every control plane to be under your authority, choose private. If the environment cannot make any outbound connection, choose air-gapped and accept that updates come on signed media.

The choice is not permanent. The mode is a configuration, and the kill switch gives you a local way to stop the link in any mode that has one. Whatever you choose, the data stays in your environment by default, and personal and restricted data are not sent out.

Compliance-by-design, not a compliance claim

We do not say that a deployment is compliant with any regulation. The platform provides the technical controls, governance mechanisms and evidence required to deploy AI within an organisation’s applicable regulatory, security and policy requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration.

Swfte does not hold a SOC 2 report or an ISO 27001 certificate and does not sign HIPAA business associate agreements today. A SOC 2 Type I audit is in preparation; the trust page has the current status.

Specifics such as availability and pricing are not published here. Availability is <availability - founder to fill>, and pricing is <pricing - founder to fill>.

How deployment connects to the closed loop

Deployment decides where the first stage of the loop happens. Everything after it inherits the placement, the isolation and the controls chosen here.

The same eight stages are listed in order below.
  1. 01 · Layer 02Connect dataBring directory data today, and more systems over time, into a graph that lives in your environment.(this page)
  2. 02 · Layers 02 and 03AnalyseAsk questions in plain language, explore the graph, and look for trends and anomalies.
  3. 03 · Layers 02 and 03VisualiseSee the organisation, usage, agents and outcomes as maps, timelines, dashboards and evidence views.
  4. 04 · PeopleDecideChoose the response with the owner, the approver and the evidence status in front of you.
  5. 05 · Layers 04 to 06BuildTurn the insight into an agent, a workflow or a packaged solution.
  6. 06 · Trust FabricGovernIdentity, permissions, policy, audit and human approval apply while the thing runs.(this page)
  7. 07 · Layer 06MeasureTrack the outcome and the cost against the reason you built it.
  8. 08 · Layer 02LearnFeed what happened back into the graph, so the next question starts from more evidence.

Frequently asked questions

Can we run it with no internet access?

Yes, in air-gapped mode. The link is never started and enrolment is refused. Updates arrive on signed media that the appliance verifies against a key pinned locally.

What is the difference between connected and private?

In connected mode the appliance links to the Swfte control plane. In private mode the link behaves the same way but points to a control plane that you host.

What can Swfte do to the appliance remotely?

Only what the typed command allow-list permits, such as triggering a directory sync or staging a signed update. There is no shell or arbitrary-execution capability, and the appliance validates every command locally.

How do we cut the connection?

With the local kill switch. It stops the link entirely, persists across restarts and is recorded in the audit chain.

Which install routes exist?

A virtual machine with Docker, Kubernetes with Helm, and an air-gapped route. Cloud marketplace delivery is on the roadmap.

Is the platform compliant with the EU AI Act or GDPR?

We do not claim that. It is built for compliance-by-design: it provides controls, mechanisms and evidence that help you deploy within your own requirements. The posture depends on your use case, jurisdiction, deployment and configuration.

Take deployment further with Swfte

Start with one entry point. Add intelligence, agents, workflows and infrastructure as you prove value.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.