DEPLOYMENT
Three ways to run it
The same rule engine and the same gate in every model. What changes is where the data rests and who holds the keys.
Managed cloud
FASTEST TO A FIRST RULE
- Multi-tenant with per-region data residency
- Gateways ship pre-enrolled
- Rolling firmware and rule updates
- Best for wellness, remote monitoring pilots, research cohorts
Hybrid on-premises
DATA STAYS INSIDE
- Orchestrator inside your estate, identity from your directory
- Signal and ledger never leave the perimeter
- Vendor access is broker-mediated and logged
- Best for hospital networks and large employers
Sovereign air-gapped
NO OUTBOUND PATH AT ALL
- Full stack on isolated infrastructure
- Offline rule signing and media-based updates
- Operates through extended communications blackouts
- Best for defence, critical infrastructure, government
WHAT YOU OPERATE
| Concern | Managed cloud | Hybrid | Air-gapped |
|---|---|---|---|
| Signal storage | Regional tenant | Your datacentre | Isolated enclave |
| Key custody | Managed HSM | Your HSM | Your HSM, offline root |
| Rule publishing | Console | Console | Signed media transfer |
| Upgrade cadence | Continuous | Scheduled | On your terms |
| Identity source | BioFlow or SSO | Your directory | Your directory, offline |
| Typical time to pilot | 4 weeks | 10 weeks | 16 weeks |
Start with one ward, one shift, or one squad
A pilot runs four to sixteen weeks depending on deployment model. You bring the population and the responders. We bring devices, gateways and the first set of rules, and we measure override rate and time-to-answer from day one.