Deployment Options
CloudPeek is designed to run wherever your security and compliance posture requires. The same product supports four deployment models, and in every one your data stays under your control.
Cloud (managed SaaS)
Fully managed software-as-a-service for teams with standard internet connectivity. You sign in and use CloudPeek; the hosting, scaling and updates are handled for you. This is the fastest way to get started and a good fit for organisations without strict data-residency or disconnection requirements.
- Best for: teams that want minimal operational overhead.
- Connectivity: standard internet access.
- You manage: your tools, users and configuration.
On-premises
Deploy CloudPeek inside your own data centre, behind your own perimeter. You run the software on your infrastructure, so data never leaves your network, while still benefiting from the full feature set.
- Best for: organisations with data-residency rules or that prefer to keep everything inside their boundary.
- Connectivity: within your network; outbound access optional.
- You manage: the deployment, infrastructure and updates.
Air-gapped (disconnected)
Full autonomous capability with zero external connectivity. CloudPeek is purpose-built for classified, defence and critical-national-infrastructure (CNI) networks where cloud-dependent tools simply cannot operate. The AI engine runs against models hosted inside your environment, so triage and investigations work with no internet at all.
- Best for: classified, defence and CNI environments.
- Connectivity: none required.
- You manage: a self-contained deployment, including in-environment AI models.
Air-gapped operation is the capability that most distinguishes CloudPeek from typical AI security tools, which assume a constant connection to a cloud service. See What is CloudPeek? for why this matters.
Hybrid
Split workloads across cloud and on-prem as your posture requires, for example keeping sensitive data and AI inference on-premises while using cloud components for less sensitive functions. You decide where each part runs.
- Best for: organisations with mixed sensitivity levels.
- Connectivity: partial, by design.
- You manage: the split between environments.
Sovereign data control in every model
Whichever model you choose, the principles are the same:
- Your data stays where you put it: under your governance and within the boundary you define.
- Tenant isolation keeps every organisation's data separate at the database level (see Platform Architecture).
- Full audit trail of every action, by people and AI agents alike, is available in Audit Logs.
- The AI can run entirely in-environment, so no alert content or investigation data has to leave your network to use CloudPeek's intelligence.
Choosing a model
| If you need… | Choose |
|---|---|
| The quickest start, minimal ops | Cloud |
| Data to stay inside your network | On-premises |
| Operation with no internet at all | Air-gapped |
| A mix of sensitivity levels | Hybrid |
For on-premises and air-gapped deployments you install CloudPeek on your own host, from a signed installer bundle. Start with Prerequisites, then Installing CloudPeek.
Talk to your CloudPeek contact about the specifics of provisioning for your chosen model. Infrastructure sizing and in-environment model hosting both depend on it.