H33 Air-Gapped Deployment

We don’t need access to your classified environment.

H33 authority infrastructure can operate entirely inside classified, disconnected and air-gapped environments — with no runtime dependency on H33.

H33 goes to the enclave; the enclave does not come to H33. In this configuration the authority stack runs inside your boundary: no H33.ai connection, no SaaS dependency, no outbound API, no callback. You own the hardware, the network, the keys, ingress and egress, deployment and policy.

The objection, answered

deployment posture · not a feature flag

The usual objection is “we don’t permit external APIs into this environment.”

Our answer is not that our API is unusually secure. Our answer is: neither do we.

H33-API-G does not mean an Internet-accessible H33 endpoint. It is an authority protocol that operates locally, inside the enclave, between your own components. Nothing crosses the boundary because nothing needs to.

What runs inside the boundary

self-contained authority stack
Mission Application
  ↓
Local H33-API-G  —  governed execution boundary
  ↓
Agent-008  —  governance
  ↓
H33-Key  ·  H33-Root  —  custody & admission
  ↓
H33-BIND  —  cryptographic identity
  ↓
AIR  ·  Lookup  ·  HATS
  ↓
H33-74  —  portable evidence
  ↓
Local evidence store

Your own hardware, HSM or KMS retains key custody. H33 supplies the local authority, governance, proof generation, verification, provenance and evidence machinery — not the secrets, and not a dependency on us.

Three deployment modes

Connected → Enclave-Installed → Fully Air-Gapped
EnvironmentH33 deploymentExternal H33 dependency
Commercial / normal federalConnectedAllowed
Classified private networkEnclave-InstalledNone required
True air gap / tactical edgeFully Air-Gapped — autonomous nodeZero

This matches how disconnected, intermittent and low-bandwidth environments actually operate, and it matches Zero Trust: authority comes from attributes and least privilege, never from being inside a network.

Updates cross the boundary as evidence, not as trust

H33-BIND + H33-Root admission

H33 does not phone home to update. We publish a signed release package on the outside: code identity, artifact hash, composition identity, policy version, dependency graph, post-quantum signatures and a BIND record.

You control movement through your own approved transfer mechanism. Once it is inside, H33-BIND verifies the exact identity and H33-Root determines whether that artifact is authorized. Installation happens only if admission succeeds.

The enclave never has to trust the transfer medium to establish software authority. That is a materially different proposition from “download our latest update.”

Evidence can leave without the sensitive material leaving

H33-74 · portable attestation

A sensitive system performs classified computation on classified data and reaches a classified decision. None of that should leave. But you may still need to show that:

  • approved software executed
  • approved authority authorized it
  • required policy was followed
  • required security checks occurred
  • the computation was valid and the system had not drifted
  • a particular outcome occurred

The inputs stay inside. The enclave produces cryptographic evidence and, ultimately, a compact H33-74 attestation representing the governed event — instead of exporting logs, telemetry and internal state.

Important: cryptography does not make an artifact unclassified. Your organization determines classification and releasability, including whether hashes, metadata, timing, identities or derived proofs may cross the boundary at all. H33 provides the mechanism; the release decision remains yours.

What an air-gapped deployment does not require

the boundary, stated as refusals

Internet access

H33 does not require outbound connectivity, DNS, or reachability to h33.ai.

Your secrets

H33 does not receive, escrow, or hold your key material. Custody stays in your HSM, KMS or enclave.

Runtime trust in us

Your system does not call us to make a decision. Authority is resolved locally.

A licence callback

H33 does not phone home to validate entitlement or to keep operating.

Trust in the transfer medium

Admission does not depend on how an update arrived. It depends on whether BIND and Root admit its identity.

What it does

H33 does supply the mechanism proving only authorized computation, software, identities and actions can produce accepted outcomes — inside your boundary.

Authority infrastructure that runs inside the mission boundary

The government owns the hardware. The government owns the network. The government controls the keys, ingress and egress, deployment and policy.

H33 is not another security SaaS product to be admitted into a classified environment. It is the authority mechanism that operates entirely inside the mission boundary.

Discuss an air-gapped deployment →
Related

What runs inside the boundary

H33-API-GAgent-008H33-KeyH33-RootH33-BINDH33-74Government