Every environment, one platform
The same platform and the same mission model deploy to commercial cloud, sovereign cloud, on-premises, high-side and disconnected air-gapped estates without redesign.
Accredited Sovereign & High-Side Hosting
Accreditation as a starting point, not a project
Most capability programmes lose their first year to accreditation. BASTION exists to give that year back — a hardened deployment model that runs identically in commercial cloud, sovereign cloud, on-premises, high-side and fully air-gapped environments, with the evidence pack that accreditors ask for.
99.95%
Core service availability target
30 / 5 min
Recovery objectives, critical state
Per-domain
Key hierarchies and isolation
Air-gap
Full disconnected deployment
Capabilities
The same platform and the same mission model deploy to commercial cloud, sovereign cloud, on-premises, high-side and disconnected air-gapped estates without redesign.
Strong identity, PKI and multi-factor authentication, service-to-service authorisation, encryption in transit and at rest, and no implicit trust from network position.
| Environment | Domain | Hosting | Key hierarchy | Replication in | Availability |
|---|---|---|---|---|---|
| ENV-CLOUD-1 | Controlled | Sovereign cloud | KMS-A | — | |
| ENV-PREM-1 | Controlled | On-premises | HSM-B | Approved products | |
| ENV-HIGH-1 | High-side | On-premises | HSM-C | One-way, reviewed | |
| ENV-AIRGAP-1 | Isolated | Air-gapped | HSM-D | Physical media only |
Separate
Key hierarchy per security domain
One-way
Reviewed replication into high-side
None
Inbound management from lower trust
Tested
Disaster recovery per environment
No inbound path from lower trust. High-side and isolated environments are never managed from a lower-trust network — updates arrive through the reviewed delivery path or physical media, and nothing else.
Separate clusters, separate key hierarchies and separate hardware security boundaries per security domain, with only approved data products replicated between them.
Tiered recovery objectives by mission service, failure-domain separation, tested disaster recovery and exercised degraded-mode operation.
| Control area | Implementation | Evidence | Continuous check | State |
|---|---|---|---|---|
| Identity & access | PKI, MFA, attribute-based authorisation | Automated | Hourly | SATISFIED |
| Encryption | In transit and at rest, per-domain keys | Automated | Hourly | SATISFIED |
| Audit & retention | Immutable, separate access domain | Automated | Continuous | SATISFIED |
| Supply chain | Signed artifacts, bill of materials | Automated | Per release | SATISFIED |
| Vulnerability posture | Gated promotion, patch cadence | Automated | Daily | 2 ITEMS OPEN |
| Recovery | Tiered objectives, exercised | Exercise record | Quarterly | SATISFIED |
Evidence is collected, not assembled. Control status is produced continuously by the platform, so an accreditation review reads current state rather than a snapshot someone prepared for the meeting.
Deploys where you work
BASTION runs identically in commercial cloud, sovereign cloud, on-premises, high-side and fully air-gapped estates, and degrades predictably at the tactical edge.
Works with
PLINTIR CONDUIT
Continuous Delivery & Fleet Assurance
Delivers signed, policy-gated software updates across cloud, classified and disconnected estates, with staged rollout, verified provenance and one-step rollback.
Explore
PLINTIR ENCLAVE
Coalition & Cross-Domain Collaboration
Publishes a releasable subset of the mission picture to partners and other agencies under per-object handling rules, with complete dissemination audit and controlled cross-domain transfer.
Explore
PLINTIR VANGUARD
Expeditionary Ground Station & Deployable Node
Ruggedised, rapidly emplaced hardware and software that gives a deployed headquarters direct sensor access and full local analytic capability within hours of arrival.
Explore
Next step
We run briefings on a real mission problem you bring, not a scripted demonstration. Bring the question your analysts cannot currently answer.