Skip to main content

Free 30-min security demo Book Now

Application security on your terms.

Choose a deployment around your data, network and operational requirements. Offensive360 offers cloud, on-premise and air-gapped options; the right configuration depends on the products and workflows you need.

Discuss your deployment

Compare deployment options

Questions to resolve for each deployment model
OptionGood starting point whenConfirm before rollout
CloudYour organization permits hosted processing and wants to minimize infrastructure management.Hosting location, data handling, access controls, retention and product availability.
On-premiseYou need to operate the service in infrastructure you control.OVA or Azure VHD delivery, resource sizing, backup, upgrades and permitted network connections.
Air-gappedThe environment cannot depend on public internet access for the agreed workflows.Offline licenses, rule and intelligence updates, integration limits and a disconnected acceptance test.

Separate data residency from network isolation

Keeping a service in your own cloud tenant does not automatically make it air-gapped. Document which systems can communicate with it, what data leaves the environment, and which optional features require external services. Use those requirements to scope the configuration and acceptance tests.

Define an offline acceptance test

  1. List the required products, languages and workflows. Include the integrations that matter to your developers and security team.
  2. Agree how the environment receives licenses, rules, vulnerability intelligence and application updates.
  3. Run the agreed workflows with external connectivity disabled and record the results. Distinguish unsupported or unavailable checks from checks that ran successfully.
  4. Test report export, backup and recovery. Identify who owns maintenance and how support works in a disconnected environment.

Bring these requirements to the demo

Share the deployment model, products of interest, expected workload, identity requirements and any data-residency constraints. You do not need to upload production source code to request a walkthrough. Agree the scope of any later evaluation with the team.

Start with source code security, web application and API testing, or risk and compliance. Use the application security evaluation guide to define what success should look like.

Deployment questions

Does Offensive360 support on-premise deployment?

Offensive360 offers virtual appliance deployment, including OVA and Azure VHD options. The products, capacity and integrations included in a deployment should be agreed during evaluation.

What should an air-gapped security evaluation test?

Test the required workflows with external network access disabled. Confirm how rules and vulnerability data are updated, which integrations need connectivity, how offline licenses are maintained, and how results are exported.

Are all capabilities identical across deployment options?

Do not assume feature parity. External intelligence, integrations and managed services can have different requirements. Ask for a product-specific capability matrix and verify the required workflows in the proposed environment.