Air-Gap · VLAN · On-Premise
Modern development — even without internet.
Some environments simply must not be connected: KRITIS production systems, defence, sensitive industrial plants. We build development and deployment environments that run fully isolated — and still feel modern to your developers.
The problem
Isolation is easy. Productivity inside isolation is not.
Disconnecting a network from the internet is the easy part. The real challenge: how do NuGet packages, npm modules, container images, compiler updates and CVE databases get into the isolated network in a controlled, traceable way — without every update becoming a manual tour de force?
This is exactly where many on-premise projects fail: either the isolation gets watered down ("just this one firewall rule…"), or developers work with months-old tool versions. Both are a risk — to security or to productivity.
We have built and operated these environments several times. The result: reproducible transfer processes where every import is checked, logged and traceable.
Typical use cases
- 01KRITIS production networksEnergy, water, healthcare — systems with § 8a evidence obligations.
- 02Industry & manufacturingOT-adjacent software that must never leave the plant network.
- 03Government & defenceClassified environments with strict zone models.
Scope of services
What we build for isolated environments
Zone & VLAN architecture
Multi-tier segmentation from development through staging to air-gapped production: clear zone transitions, defined data flows, documented firewall concepts.
Offline-Artifact-Feeds
ProGet or Artifactory as internal package source: NuGet, npm, Docker and Maven — replicated via controlled transfer paths, with vulnerability scanning before import.
CI/CD without cloud
Azure DevOps Server with self-hosted build agents, entirely inside the isolated network: pipelines, approvals and deployments work like in the cloud — just without it.
Secure transfer paths
Defined, auditable import/export processes between zones: checking, approval, logging — instead of a USB stick and trust.
Security tooling offline
Keeping SBOM generation, CVE databases and SAST tools up to date without internet access — so compliance doesn't stop at the network boundary.
Operations & maintenance concepts
Patch strategies, backup/recovery and monitoring for environments you can't "just quickly" access remotely — including runbooks for your operations team.
Air-gap doesn't mean stone age. It means: controlled modernity.
Our reference architecture brings the complete modern development stack into isolated networks: Git, YAML pipelines, package feeds, code analysis, automated tests. In daily work your developers barely notice a difference from the cloud — your auditors, however, very much do: every zone transition is documented, every import checked, every change traceable. Combined with our DevSecOps & KRITIS toolkit, the result is an environment that can do both: deliver and pass.
Next step
Planning an isolated environment — or stuck operating one?
Whether it's a greenfield build or the refurbishment of a grown environment: we'll tell you honestly what's feasible and what it costs — before you commit.
info@xeam-solutions.com