Does CISGuard deploy on air-gapped networks?
Yes. Air-gapped deployment is a first-class supported configuration, not a workaround. Benchmark definition updates are RSA-signed by the server and verified by every agent before use; software updates ship as offline media with published SHA-256 checksums. Agent-based scanning needs no outbound connectivity; only cloud-account scanning (Azure, AWS, Microsoft 365) reaches the provider APIs. Built for classified and isolated environments where outbound connectivity is prohibited.
The longer answer.
In an air-gapped deployment the server, database, dashboard and agents all run inside the isolated network, with no telemetry and no SaaS dependency. Nothing has to leave the boundary for scanning or reporting.
Updates cross the boundary deliberately. Benchmark definitions arrive RSA-signed and are verified by every agent before use, and software updates ship as offline media with published SHA-256 checksums you can check before import. Scanning Azure, AWS or Microsoft 365 is the one capability that needs a route to those provider APIs.
More questions on Deployment?
Our compliance engineers can show you exactly how CISGuard handles Deployment in a briefing scoped to your environment.