Air-Gap · VLAN · On-Premise

Modern development — even without internet.

Some environments simply must not be connected: KRITIS production systems, defence, sensitive industrial plants. We build development and deployment environments that run fully isolated — and still feel modern to your developers.

Air-gapped production
Multi-tier VLAN segmentation
Offline-Artifact-Feeds
Secure transfer paths

Isolation is easy. Productivity inside isolation is not.

Disconnecting a network from the internet is the easy part. The real challenge: how do NuGet packages, npm modules, container images, compiler updates and CVE databases get into the isolated network in a controlled, traceable way — without every update becoming a manual tour de force?

This is exactly where many on-premise projects fail: either the isolation gets watered down ("just this one firewall rule…"), or developers work with months-old tool versions. Both are a risk — to security or to productivity.

We have built and operated these environments several times. The result: reproducible transfer processes where every import is checked, logged and traceable.

  • 01
    KRITIS production networksEnergy, water, healthcare — systems with § 8a evidence obligations.
  • 02
    Industry & manufacturingOT-adjacent software that must never leave the plant network.
  • 03
    Government & defenceClassified environments with strict zone models.

What we build for isolated environments

Zone & VLAN architecture

Multi-tier segmentation from development through staging to air-gapped production: clear zone transitions, defined data flows, documented firewall concepts.

ZonenmodellVLAN

Offline-Artifact-Feeds

ProGet or Artifactory as internal package source: NuGet, npm, Docker and Maven — replicated via controlled transfer paths, with vulnerability scanning before import.

ProGetArtifactory

CI/CD without cloud

Azure DevOps Server with self-hosted build agents, entirely inside the isolated network: pipelines, approvals and deployments work like in the cloud — just without it.

AzDO ServerSelf-hosted Agents

Secure transfer paths

Defined, auditable import/export processes between zones: checking, approval, logging — instead of a USB stick and trust.

DatenschleusenAudit-Log

Security tooling offline

Keeping SBOM generation, CVE databases and SAST tools up to date without internet access — so compliance doesn't stop at the network boundary.

SBOM offlineCVE-Sync

Operations & maintenance concepts

Patch strategies, backup/recovery and monitoring for environments you can't "just quickly" access remotely — including runbooks for your operations team.

RunbooksMonitoring

Air-gap doesn't mean stone age. It means: controlled modernity.

Our reference architecture brings the complete modern development stack into isolated networks: Git, YAML pipelines, package feeds, code analysis, automated tests. In daily work your developers barely notice a difference from the cloud — your auditors, however, very much do: every zone transition is documented, every import checked, every change traceable. Combined with our DevSecOps & KRITIS toolkit, the result is an environment that can do both: deliver and pass.

Planning an isolated environment — or stuck operating one?

Whether it's a greenfield build or the refurbishment of a grown environment: we'll tell you honestly what's feasible and what it costs — before you commit.

info@xeam-solutions.com
Request a consultation