On-premise & security

Control of the deployment is control of the risk.

Where a system runs determines who can reach it, which laws apply to it, and what happens when connectivity or a supplier fails. We design for the strictest of those answers first, then relax deliberately.

Deployment topologies

Model A

Air-gapped

No egress. Signed offline update bundles, local identity, local telemetry retention.

Typical: defence, critical national infrastructure

Model B

On-premise, connected

Runs in your data centre with controlled outbound paths for updates and support.

Typical: banking, public sector

Model C

Single-tenant private cloud

Your subscription, your region, your keys — deployed and operated by us if you prefer.

Typical: healthcare, scale-ups

Model D

Hybrid

Regulated data stays inside; elastic compute and non-sensitive workloads run outside.

Typical: energy, telecommunications

Controls we implement

  • Identity federation with your directory, least-privilege roles, break-glass procedure
  • Encryption in transit and at rest, customer-held keys where the platform allows
  • Signed builds, SBOM per release, pinned and reviewed dependencies
  • Immutable audit logging with defined retention and export
  • Secrets management, credential rotation and no shared service accounts
  • Backup, restore drills and documented recovery objectives

Compliance alignment

We build to the evidence your auditors ask for and work alongside your compliance function. Certification remains yours; our job is to make it achievable. The frameworks below are ones we design evidence for — not certifications ElixTechs holds.

  • ISO 27001
  • SOC 2
  • GDPR
  • NIS2
  • HIPAA
  • PCI DSS

Performance

Security and speed are the same engineering problem.

On-premise means fixed hardware, so efficiency is not optional. Each engagement sets a small number of budgets and reports against them every release.

  • Budget type

    Read path latency, P95 and P99

  • Budget type

    Sustained ingest throughput per node

  • Budget type

    Memory and storage ceiling per tenant

  • Budget type

    Recovery time and recovery point objectives

Contact

Tell us the constraint. We will tell you what it takes.

Send a short description of the system, the environment it must run in, and the obligations attached to it. An engineer replies — usually within one working day. We reply in English or Arabic.

[email protected]