← All postsDEPLOYMENT

Your data, your walls: cloud, VPC or air-gapped

Tariq MansourCo-founderMay 19, 20269 min read

For some organisations, “just send it to the cloud” is a non-starter. Regulated finance, public-sector programs and anyone holding sensitive records need the whole system to run inside a boundary they control. We designed for that from the start rather than bolting it on later.

One product, three deployments

iDBQuery runs multi-tenant in the cloud, single-tenant inside your own VPC, or fully air-gapped on your own hardware — and it is the same product in each. Data residency is set per customer. The federation engine, the chat, the dashboards and the autonomous Analyst behave identically; only the boundary moves.

No outbound dependency

In the air-gapped configuration the AI and the agents run locally, with no call home. Your data is queried where it lives and never crosses the perimeter. Updates arrive through a controlled, audited channel rather than an open internet connection, so the security team keeps its guarantees intact.

Because the data is queried in place rather than copied into a shared store, the surface area you have to trust is small and explicit: the systems you already own, plus a tool that reads them. There is no third copy of your most sensitive records sitting somewhere you cannot see.

Sovereignty and capability are usually pitched as a trade-off — pick safety or pick power. Designing for the hardest deployment first is how we made that choice disappear: the air-gapped customer gets the same cited answers, the same live model and the same agents as everyone else.