Deployment

    Spharaka Sphere™ On-Premises and Air-Gapped

    Autonomous cyber defence for environments that cannot call out. The whole loop, ingestion through response, runs inside the customer controlled data centre, and SAGE™ reasons about the evidence without any of it leaving.

    At a glance

    What the deployment gives you

    100%

    Local inference

    SAGE™ is served inside the environment. No public model API is called at any point.

    Air-gapped

    No connectivity required

    Detection, investigation and response all complete with the network disconnected.

    40+

    Specialised agents

    AuraXP™ agents covering detection, investigation, correlation, hunting and response.

    250+

    Log sources

    Endpoint, identity, firewall, proxy, email, cloud, SaaS, database, DNS, VPN, WAF and OT.

    60-120s

    Investigation cycle

    A typical autonomous cycle, against 60 to 90 minutes for the same work by hand.

    The difference

    The console is not the part that matters

    Most platforms described as on-premises run their collectors and their console locally while the reasoning happens somewhere else, behind a model API. For a bank, a defence network or a plant under restricted connectivity, that is the entire objection, and moving the user interface inside the perimeter does not answer it.

    Sphere On-Premises moves the reasoning. The practical test is simple: unplug the environment and see what stops. Here, investigations, detections and response workflows continue. What pauses is the arrival of new threat content, and that has its own controlled path.

    • Local SAGE™ serving with local inference, and no public model API dependency
    • No alert, log, prompt, evidence or embedding sent outside the environment
    • AuraXP™ querying local telemetry rather than waiting to be handed context
    • Cases, entity history and model inputs retained locally
    • Threat content delivered through approved offline packages and transfer media
    What changes

    Where each part runs

    The capability set is the platform's, not a reduced edition of it. What changes is location and how content reaches it.

    AI

    AI model

    SAGE™ is deployed and served locally. No alert, log, prompt, evidence, embedding or investigation context is sent outside the customer environment.

    INV

    Investigation engine

    AuraXP™ runs inside the on-premises platform and actively queries local data stores, connected log sources and entity context.

    DAT

    Data plane

    Ingestion, parsing, normalisation, detection, enrichment, investigation, case management and response all remain within the customer controlled network.

    UPD

    Updates

    Threat content, parsers, model updates and product upgrades arrive through controlled offline packages, approved transfer media or private update channels.

    SOA

    SOAR and response

    Actions execute through local sensors, local connectors and local approval workflows, human-in-the-loop controls included.

    How it runs

    The closed loop, entirely local

    Six stages, every one of them completing inside the customer controlled network.

    01

    Ingest and normalise

    Events from endpoint, identity, firewall, proxy, email, cloud, SaaS, database, web, OT and network sources collected through local sensors, APIs and syslog collectors.

    02

    Detect

    Rule-based, behaviour-based and correlation detections generate alerts carrying entity and event context.

    03

    Investigate

    AuraXP™ forms hypotheses, requests the evidence each one needs, queries local telemetry and iterates until it reaches a verdict.

    04

    Enrich

    Users, hosts, IPs, processes, emails, domains and assets enriched from local historical data, directory context and environment baselines.

    05

    Decide

    A verdict, an evidence trail, an attack timeline, the affected entities, the risk and the recommended response.

    06

    Respond

    Approved containment and remediation executed through local sensors and integrations.

    The distinction

    AI-driven investigation, not AI-assisted summarisation

    Industry standard, AI-assisted

    The model explains the data it was given

    A single-pass explanation or confidence score, dependent on whatever context the pipeline packaged with the alert. The analyst still decides what evidence was missing, still opens the other consoles, and still forms the hypothesis. The paperwork got faster; the bottleneck did not move.

    Spharaka AuraXP™, AI-driven

    The model decides what it needs, then goes and gets it

    Competing hypotheses, tested by actively querying local logs, timelines, profiles and connected sources. Multi-step investigation with evidence, pivots and entity context, ending in a complete report with a verdict, an attack timeline, the affected entities and the response actions.

    Core platform

    What runs inside the boundary

    Threat detection and ingestion

    Collects and normalises security events from 250+ log sources across endpoint, identity, network, cloud, SaaS and security tools.

    Autonomous investigation

    Every qualified alert investigated with evidence collection, validation, correlation and an explainable verdict.

    Entity profiling

    Context-rich profiles for users, hosts, IPs, processes, email addresses and domains, built from local historical activity.

    Attack correlation

    Validated behaviour mapped to lateral movement, persistence, privilege escalation, exfiltration and defence evasion.

    Case summarisation

    SOC-ready investigation reports with summary, malicious behaviour, evidence, timeline, impact and recommended remediation.

    EdgeProtect™ visibility

    Local agent capabilities providing process, network and operating system telemetry alongside prevention and response controls.

    Governed response

    Autonomous does not mean ungoverned

    Response is based on investigation evidence rather than static playbooks, and every recommendation is tied to the evidence and affected entities that produced it. AirWatch™ validates each action against verified evidence and customer policy before it executes.

    Endpoint containment

    Isolate hosts, terminate malicious processes, block files or run controlled remediation.

    Identity response

    Disable accounts, force password reset, revoke sessions or flag risky users for review.

    Network response

    Block malicious IPs, domains or URLs through firewall, proxy, DNS or gateway integrations.

    Email and SaaS

    Quarantine messages, remove malicious mail and flag suspicious senders.

    Why it holds up

    The four properties a regulated buyer tests

    Data sovereignty by design

    Telemetry, cases, entity history, model inputs and investigation outputs remain inside the customer environment.

    No external model dependency

    Local inference removes reliance on public model providers and external API calls entirely.

    Operational continuity

    Investigations, detections and response workflows continue while the environment is disconnected from the internet.

    Audit-ready control

    Every investigation step, evidence query and response action is traceable for governance, compliance and SOC review.

    Output

    What the SOC receives

    Not a summary and a score. A complete investigation, with the reasoning chain that produced it, in a typical cycle of 60 to 120 seconds.

    Investigation verdict

    Threat, suspicious or benign, based on validated evidence.

    Evidence trail

    The specific events, queries, pivots and observations used during the investigation.

    Attack timeline

    A chronological reconstruction across users, hosts, IPs, processes and services.

    Response recommendation

    Prioritised containment and remediation, with approval or autonomous execution options.

    Questions

    Frequently asked questions

    Can Spharaka Sphere run fully air-gapped?

    Yes. Sphere On-Premises is designed for on-premises, private cloud, secure enclave and fully air-gapped deployment. Ingestion, detection, investigation, decision and response all complete inside the customer controlled network, and SAGE™ inference runs locally, so investigations continue while the environment is disconnected from the internet.

    Does any data leave the environment when the AI investigates?

    No. SAGE™ is deployed and served locally. No alert, log, prompt, evidence, embedding or investigation context is sent outside the customer environment, and there is no public model API dependency to call.

    How does an air-gapped deployment receive threat content and updates?

    Through controlled offline packages, customer approved transfer media or private update channels. Threat content, parsers, model updates and product upgrades all follow that path, so the environment stays disconnected and new content arrives on terms the customer sets.

    Is the on-premises version a reduced edition of the platform?

    No. The capability set is the same: autonomous investigation through AuraXP™, local SAGE™ reasoning, 250+ log sources, entity profiling, attack correlation, case summarisation, EdgeProtect™ endpoint visibility, and governed SOAR response. What changes is where each part runs and how content is delivered, not what the platform can do.

    How is this different from an AI-assisted SIEM running on our hardware?

    An AI-assisted tool summarises the alert and whatever context it was handed, in a single pass. AuraXP™ forms competing hypotheses and then actively queries local logs, timelines, profiles and connected sources for the evidence needed to validate or disprove each one, iterating until it reaches a verdict. The output is a full investigation report with evidence, timeline and affected entities rather than a summary and a score.

    What stops the platform taking an unsafe autonomous action?

    AirWatch™, the governance layer, validates AI reasoning against verified evidence, enforces customer policy and prevents unsafe actions while preserving auditability. Low-risk and pre-approved actions run automatically; high-impact actions can require analyst, manager or customer approval. Escalation, deferral and override are tunable controls rather than exceptions.

    Does it support multi-tenancy for an MSSP running air-gapped?

    Yes. The architecture is natively multi-tenant, with tenant-level data separation and reporting, which is what lets a service provider run autonomous investigations for several customers without their data mixing.

    Where is investigation data stored, and for how long?

    In customer controlled hot, warm and archive storage, sized to the organisation's own retention, search and compliance requirements. Cases, entity history, model inputs and investigation outputs stay inside the customer environment.

    Which compliance regimes does an on-premises deployment support?

    It is built for regulated environments that require data sovereignty, restricted connectivity and auditable cyber operations. Every investigation step, evidence query and response action is traceable, which is what internal audit, regulatory review and customer governance ask for.

    Experience the Future

    See it run with the network unplugged

    A walkthrough on your own estate, in the deployment model your environment actually permits, rather than a canned demo on someone else's infrastructure.

    Talk to an Expert