Four Deployment Models, One Trust Architecture
Managed SaaS, dedicated single-tenant, self-hosted, regional gateway, and hardware appliance deployments all run the same signed policy, trust-anchor lifecycle, and privacy-safe observability. Where you run AegisWire determines control boundaries — not the security model. The trust architecture, signed artifact pipeline, and policy enforcement operate identically regardless of deployment type. All five deployment models are available now.
Managed SaaS
AegisWire-operated control plane with managed infrastructure, signed policy workflows, and governed update paths.
Fastest adoption path. AegisWire manages infrastructure, operations, and updates. Your team retains policy publication control, trust-anchor ownership, and administrative governance.
- AegisWire-managed infrastructure and operations
- Signed policy workflows under tenant administrative control
- Governed update paths with rollback support
- Privacy-safe observability with metadata-only telemetry
- Gateway pool selection with regional publication
- Enterprise admin console with role-based access
Dedicated Single-Tenant
Isolated infrastructure per customer with dedicated trust boundaries, custom update schedules, and tenant-specific operational controls.
Stronger isolation for organizations requiring dedicated environments. Same trust architecture. Separate infrastructure boundary. Custom rollout and update timing.
- Dedicated infrastructure per customer
- Isolated trust boundaries and key material
- Custom update and rollout schedules
- Tenant-specific operational monitoring
- Same signed policy and trust-anchor lifecycle
- Tailored scaling per customer requirements
Self-Hosted / Sovereign
Customer-controlled infrastructure with full administrative ownership. Same trust architecture, deployed in your environment.
Full infrastructure control for regulated, sovereignty-sensitive, or operationally isolated environments. AegisWire's policy, trust, and evidence model operates on customer-owned infrastructure.
- Full infrastructure control and administrative ownership
- Data residency and jurisdictional alignment
- Customer-managed update governance
- Same signed policy and trust-anchor lifecycle
- Compatible with air-gapped and restricted networks
- On-premises or private cloud deployment
Regional Gateway Fabric
Regional gateway pools with policy-aware publication, controlled draining, failover, and capacity-aware scaling.
Gateway pools publish capabilities by region. Selection reflects policy and administrative intent, not only latency. Draining and failover operate as governed lifecycle operations.
- Regional pool publication with explicit capabilities
- Policy-aware gateway selection
- Controlled draining without session disruption
- Capacity-aware scaling per region
- Failover with administrative visibility
- Consistent behavior across all deployment models
Hardware Appliance
Customer-controlled edge enforcement hardware. Deploy the full AegisWire trust model on your own premises with hardware you control.
All five platform delivery models are available now, including hardware appliance. The AegisWire trust model, policy architecture, and deployment patterns operate identically across all deployment types.
- Customer-controlled edge presence
- Local enforcement and routing
- Same trust model as cloud deployment
- Branch, field, and enclave use cases
- Aligned with self-hosted operational model
- Architecture-ready, not yet shipping
Isolation & Control Boundaries
| Boundary | Managed | Dedicated | Self-Hosted |
|---|---|---|---|
| Infrastructure ownership | AegisWire | AegisWire | Customer |
| Tenant isolation | Logical | Physical | Physical |
| Policy control | Customer | Customer | Customer |
| Trust-anchor ownership | Customer | Customer | Customer |
| Update governance | Managed | Custom schedule | Customer |
| Data residency | Region-selected | Region-selected | Customer-controlled |
Find the Right Deployment Model
Talk to our team about which deployment posture matches your control, residency, and isolation requirements.
Talk to the AegisWire Team