Skip to content

Deployment and security

The boundary is the product decision.

iDocHive is sold for customer-controlled, on-premise, private, or air-gapped deployment. Production data and AI processing stay inside infrastructure you approve. Public AI APIs are not required.

Illustration of an iDocHive deployment running inside an organisation's own data centre

Deployment and security

Deployment overview

Overview diagram of iDocHive deployment options: air-gapped, on-premises and sovereign cloud

Customer-controlled infrastructure boundary

No production dependency on the public internet for air-gapped systems

No uncontrolled document or telemetry path

Local or customer-approved model inference

Customer-controlled encryption keys, identity, logging, and retention

Signed and scanned offline software updates for isolated environments

Deployment and security

Three deployment profiles

Department Pilot

Docker Compose or an equivalent limited runtime. One document collection, a named user group, measurable acceptance criteria, and a controlled path to production.

Enterprise Private

K3s, Kubernetes, or customer-approved VMs. Redundant application services, highly available PostgreSQL + pgvector, internal load balancing, identity, SIEM, backup, and disaster-recovery controls.

Sovereign Air-Gapped

No internet access in production. Internal model serving, offline installation and update packages, media scanning, local observability, and runbooks.

SOVEREIGN DEPLOYMENT

Sovereign air-gapped topology

Offline update media enters a primary customer data center. An internal load balancer reaches application services and isolated AI inference nodes. PostgreSQL + pgvector and object storage stay on the inside. Replication crosses an internal WAN or dark fiber to the disaster-recovery site. There is no production internet egress.

SOVEREIGN AIR-GAPPED TOPOLOGY

01

Offline update transfer

02

Primary customer data center

03

Internal load balancer

04

Application services

05

AI inference nodes

06

PostgreSQL + pgvector

07

Object storage

08

Internal WAN / dark fiber

09

Disaster-recovery site

10

Replication

11

No internet egress

Model registry - approved only

gateway/approved-v3 · checksum verified

No public model endpoint. Offline package ready.

Air-gap update package

idochive-2026.09.signed.tar

Signature valid · rollback available

KEY CAPABILITIES

Built for security, governance and control.

Everything you need to deploy and manage document intelligence in your environment.

Identity and access

Single sign-on where available, multi-factor authentication through the identity provider, role-based access, least privilege, record- or collection-level restrictions, and privileged-administrator monitoring.

Encryption and key ownership

Encryption in transit and at rest. Customer-controlled keys where required. Approved data residency. Controlled exports.

Signed offline updates

Isolated environments receive signed application, OCR, and model packages. Checksums, provenance, media-transfer approval, and rollback are part of the update lifecycle.

Model governance

An approved-model registry tracks versions, prompt policy, retrieval evidence, and evaluation results. Customer content is not used for training without explicit authorization.

SIEM and audit integration

Access, ingestion, inference, approval, export, and administrative events can stream to the customer SIEM through syslog, API, or an approved agent.

Backup and recovery

Backup and restore are required. Two-site disaster recovery is designed for sovereign deployments. Availability and recovery objectives are contracted per topology — not published as a blanket uptime claim.

Shared responsibility

Every proposal converts this baseline into a named RACI. No commercial terms are published here.

Creation Next

Product software, configuration, solution architecture, deployment support, pipeline and workflow implementation, agreed integrations, training, support, and update packages.

Customer

Infrastructure unless contracted otherwise, identity and network access, data ownership, lawful processing, samples and subject-matter experts, role approval, security policy, and acceptance.

Local systems integrator

Local contracting where agreed, infrastructure delivery, Arabic business analysis, on-site support, and change management.

Technology providers

Licensed OCR, model, database, storage, security, or e-signature components and their offline update rights.

Certification status

ISO 9001 held
ISO 27001 certified

Designed to support customer compliance programs and deployment-specific control mapping. No software creates compliance by itself. Jurisdiction-specific conformity is validated for each deployment and tender.

AI deployment advisor

Which iDocHive deployment fits you?

Describe your documents, security boundary, connectivity, and scale. We'll recommend an approach in seconds.

Start with one document collection and one measurable outcome.

Define the use case, security boundary, document profile, and success measures before committing to enterprise rollout.

Source-grounded answers
Human approval controls
ISO 27001 certified organization

On-premise and air-gapped

No public AI API required

Permission-aware retrieval

On-premise and air-gapped
No public AI API required
Permission-aware retrieval