Air-gapped AI security — cloud-scale, or sealed behind the wire

Monarch deploys where your security posture requires. The capability doesn't change with the environment; only the boundary does.

Cloud

  • Multi-node elastic scale
  • Managed connectors and updates
  • Multi-provider models with local fallback

For teams that want scale without standing up infrastructure.

Air-gapped

  • 100% on-premise — zero data export, ever
  • Sovereign local models: the compact local model or Ollama, no internet
  • CentOS Stream 9, systemd — a single VM (16 vCPU / 64 GB)
  • SQLite mode, Redis optional with graceful degradation
  • Offline threat-intel mirror

No data leaves the network. Ever.

Deployment architecture

Monarch supports three deployment modes. The platform capability is identical across all three — only the network boundary and operational responsibility change.

Managed cloud

Multi-node, elastic infrastructure fully operated by UD Works. Agents scale horizontally across availability zones with automatic failover. Updates, model upgrades and connector maintenance are handled as part of the subscription — no customer hardware, no ops overhead.

Best for teams that want continuous security operations at scale without standing up or staffing their own infrastructure. Multi-provider model access (300+) with sovereign local model fallback for sensitive workloads.

Private cloud

Monarch deployed inside the customer's own cloud tenancy — AWS, Azure, GCP or sovereign cloud providers. UD Works supplies managed connectors for ingestion and update channels, while the customer retains full custody of data and network perimeter.

Designed for organisations with data-residency requirements or existing cloud commitments. All telemetry and findings remain inside the customer's tenancy. Model weights are deployed locally; no inference calls leave the environment.

Air-gapped on-premise

A single VM, zero egress. The entire platform — the sovereign local model, orchestration engine, memory store, governance runtime and identity layer — runs on one machine with no outbound network connection of any kind. No licensing callout, no DNS, no telemetry.

Built for defence, intelligence and critical-infrastructure buyers who cannot tolerate any data export. Updates arrive via controlled one-way transfer with cryptographic chain-of-custody. The compact sovereign model solves 25/33 Cybench on this single machine — air-gapped is not the weaker edition.

Compliance by deployment mode

Each deployment mode inherits different compliance properties. The table below maps regulatory frameworks to the guarantees each mode provides out of the box.

FrameworkManaged cloudPrivate cloudAir-gapped on-prem
PDPA (Singapore)Data processed in SG regionFull custody in customer tenancyZero export — fully compliant
GDPR (EU)EU region available, DPA includedCustomer controls data residencyNo cross-border transfer possible
NIS2 (EU)Incident reporting supportFull audit trail in-tenancyComplete evidence chain, local
EU AI ActGovernance gateway, audit logsGovernance gateway, local logsFull governance, zero external dependency

All deployment modes share the same governance runtime — policy enforcement under 2ms, PII redaction, prompt-injection blocking, non-repudiable audit trail.

Hardware requirements

Air-gapped on-premise

  • OS: CentOS Stream 9
  • Compute: 16 vCPU / 64 GB RAM
  • Init: systemd
  • Storage: SQLite (Redis optional, graceful degradation)
  • Network: None — zero egress by design

A single VM runs the entire stack: sovereign model, orchestration, memory, governance and identity. No GPU required for inference — the compact sovereign model is optimised for CPU execution. The simplicity is deliberate: fewer moving parts mean fewer attack surfaces and easier certification.

Managed & private cloud

  • Managed cloud: No customer hardware — fully operated by UD Works
  • Private cloud: Standard VM in customer tenancy (AWS, Azure, GCP)
  • Scaling: Horizontal agent scaling across availability zones

Cloud deployments scale elastically. The customer never provisions hardware for the managed tier; private cloud uses the customer's existing compute with UD Works managing the platform layer.

Customer scenarios

Defence ministry — air-gapped, zero egress

A defence ministry needs continuous red teaming across classified IT and OT networks that may never connect to an external system. Monarch deploys on a single VM inside the ministry's secure enclave. The sovereign local model, threat intelligence mirror and governance runtime all operate without any outbound path. Updates arrive via write-once media with cryptographic verification. The ministry owns the entire chain — model weights, engagement memory, audit logs — with zero vendor access.

Regional bank — private cloud with data residency

A Southeast Asian bank must keep all customer data and security telemetry within its domestic jurisdiction. Monarch deploys inside the bank's own cloud tenancy, with managed connectors pulling from the bank's existing Splunk and Wazuh infrastructure. The sovereign model runs locally in-tenancy; no inference calls cross the border. PDPA and data-residency requirements are met by architecture, not by contractual promise. The bank retains full custody while UD Works manages platform updates through a controlled channel.

MSSP — managed cloud for multiple clients

A managed security services provider runs continuous validation and detection for dozens of SME clients. Monarch's managed cloud deployment gives the MSSP elastic scale — spinning up agents per client, per engagement, without provisioning hardware. Each client's data is tenant-isolated. The flat per-agent pricing makes 24/7 continuous operations commercially viable at a fraction of the cost of staffing equivalent human analysts for every client.

Cloud vs air-gapped vs hybrid — at a glance

The three deployment modes differ in boundary and operational responsibility, not in platform capability. The table below summarises the trade-offs.

Managed cloudPrivate cloudAir-gapped on-prem
Data exportTo Monarch cloud onlyStays in your infraZero — nothing leaves
Compliance fitStandard enterpriseData residency reqsDefence / critical infra
HardwareNone (managed)Customer-providedSingle VM (16 vCPU / 64 GB)
UpdatesAutomaticManaged pushOffline transfer path
Setup timeHoursDaysDays (one-time)
ModelMulti-provider + localMulti-provider + localSovereign local only

This page describes how Monarch deploys across three modes. For a vendor-neutral evaluation checklist for any air-gapped AI platform, see our air-gapped deployment requirements guide.

Why this matters

Most security-AI platforms are cloud-only because their intelligence lives in someone else's model. Every query is a data export. Monarch runs its own model on your hardware. The compact local model solves 25/33 Cybench on a single machine, ahead of cloud frontier agents.

Full capability, full custody.

Sovereignty and compliance

Built in Europe, tuned in Singapore. PDPA · GDPR · NIS2 · EU AI Act. Zero export means the hardest questions in a security review are already answered.

One platform. Your infrastructure. Your custody.