Friction 04 · The closed boundary

Your boundary won’t
let agents phone home.

Self-hosted, inside your enclave.

Controlled unclassified information. Export-controlled designs. Patient data. Source code you are contractually forbidden to transmit anywhere. Most agent platforms answer all of that with a trust-us SaaS tenancy, which ends the conversation in a lot of buildings.

Docker Compose, your infrastructure, your database, your models. Air-gapped operation is a supported configuration, not a workaround.

What it costs you

The tooling assumed a public cloud. Your program doesn’t have one.

This friction rarely shows up as a technical objection. It shows up as a procurement dead end six weeks into an evaluation.

01 · The reality

Every hosted agent is an egress question.

Prompt content, repository context, and generated artifacts crossing a vendor boundary is a data-handling event — whatever the marketing page says about retention.

02 · The cost

Two-speed engineering.

The commercial side of the house gets agents and ships faster. The regulated side gets a memo and falls behind, inside the same company, on the same deadlines.

03 · The workaround

Ban them, or don’t look too hard.

Policies that forbid agents outright get quietly ignored by engineers who need the speed. Now you have unsanctioned agents and no record at all — the worst of both.

How ASE removes it

Built self-hosted first, because that was the hard requirement.

ASE was designed for teams whose boundary is non-negotiable, and it stays useful when nothing is allowed to leave it.

Self-hosted

Your infrastructure, start to finish.

ASE deploys with Docker Compose into your environment, with a SQL operational store and graph evidence you own. There is no vendor tenancy holding your run data.

Bring your own models

API models, or fully local.

Harness catalogs cover Codex, Claude Code, and OpenCode, plus a multi-provider adapter for OpenAI, Anthropic, and xAI — or Ollama and LM Studio when nothing may leave the enclave at all.

Offline licensing

Activation that survives an air gap.

Licenses activate online or through a signed offline exchange, so a disconnected enclave doesn’t become an unlicensed one.

Control-mapped evidence

Artifacts an assessor recognizes.

Compliance control matrices, exception workflows, and chain-hashed audit exports line up with the regimes you already report against. Working under CMMC? See ASE for GovCon & the DIB.

In practice

What deployment actually involves.

Four steps, all of them inside your perimeter.

Step 1

Stand it up in your environment

Docker Compose brings up ASE, the worker, the operational store, and the graph evidence layer on infrastructure you control.

Step 2

Point it at your identity provider

Keycloak handles OIDC, MFA, passkeys, and role mapping against your existing directory and access policy.

Step 3

Choose your models

Wire API providers if your program permits egress, or local models through Ollama or LM Studio if it doesn’t. The governance layer is identical either way.

Step 4

Run governed work, export the evidence

Constellations execute inside the boundary and produce audit and compliance artifacts that never had to leave it.

What you can hand someone

Evidence that stays where the work stayed.

Nothing in this list requires an outbound connection to produce.

  • Chain-hashed audit trail — tamper-evident run records stored in your own graph evidence layer.
  • Compliance reports — control-mapped exports in JSON, CSV, HTML, or PDF for assessors and program offices.
  • Exception workflow — documented deviations with justification and approver, inside the boundary.
  • Document generation — governed PPP, SCG, SSP, and POA&M drafting, with the same evidence discipline as code.
  • Offline activation — signed license exchange for enclaves with no route to the internet.
See it on your stack

Run it inside your boundary.

We’ll walk the deployment shape for your enclave — models, identity, evidence, and what an assessor sees at the end.

Elevate Your Vibe with ASE Precision.

Cookie Compliance

We use cookies to ensure you get the best experience on our website. By continuing to use our site, you accept our use of cookies, privacy policy and terms of service.