Plintir Bastion
Run the intelligence suite in sovereign cloud, on-premises, high-side and fully air-gapped environments, with separate key hierarchies, zero-trust controls and the accreditation evidence already assembled.
Most capability programmes lose their first year to accreditation. Bastion exists to give that year back: a hardened deployment model that behaves identically across every environment, producing the control evidence assessors ask for as a by-product of running.
Intelligence in context, with the next decision already in view.
| Environment | Domain | Hosting | Key hierarchy | Replication in | Availability |
|---|---|---|---|---|---|
| ENV-CLOUD-1 | Controlled | Sovereign cloud | KMS-A | — | |
| ENV-PREM-1 | Controlled | On-premises | HSM-B | Approved products | |
| ENV-HIGH-1 | High-side | On-premises | HSM-C | One-way, reviewed | |
| ENV-ISOLATED | Isolated | Air-gapped | HSM-D | Physical media only |
What Bastion does.
Every environment, one platform
The same platform and the same mission model deploy to commercial cloud, sovereign cloud, on-premises, high-side and disconnected air-gapped estates without redesign or a separate codebase.
Zero trust by construction
Strong identity, PKI and multi-factor authentication, service-to-service authorization and encryption in transit and at rest, with no implicit trust granted by network position.
Domain isolation done properly
Separate clusters, separate key hierarchies and separate hardware security boundaries per security domain, with only reviewed data products moving between them and no inbound management path.
Continuity and accreditation evidence
Tiered recovery objectives by mission service, exercised disaster recovery and control status collected continuously rather than assembled for a review meeting.
Evidence is collected, not assembled the week before.
| Control area | Implementation | Evidence | Checked | State |
|---|---|---|---|---|
| Identity & access | PKI, MFA, attribute-based authorisation | Automated | Hourly | SATISFIED |
| Encryption | In transit and at rest, per-domain keys | Automated | Hourly | SATISFIED |
| Audit & retention | Immutable, separate access domain | Automated | Continuous | SATISFIED |
| Supply chain | Signed artifacts, component inventory | Automated | Per release | SATISFIED |
| Vulnerability posture | Gated promotion, patch cadence | Automated | Daily | 2 ITEMS OPEN |
| Recovery | Tiered objectives, exercised | Exercise record | Quarterly | SATISFIED |
Two items are open, and that is the point. Control status is produced continuously by the platform, so a review reads the current state of the estate rather than a prepared snapshot.
Bastion produces control status continuously as the system runs, so an assessment reads the current state of the estate rather than a snapshot someone prepared the week before.
From information to Actionable Intelligence Data.
Establish
Define security domains, key hierarchies and the authority model.
Deploy
Stand the platform up identically across each approved environment.
Evidence
Collect control status and audit continuously as the system operates.
Assure
Exercise recovery, degraded modes and cross-domain paths against the plan.
Designed around intelligence outcomes.
Sovereign Deployment
Operate the suite entirely within national jurisdiction and control.
High-Side and Air-Gapped
Run isolated environments with no inbound path from lower trust.
Accreditation Support
Supply current, machine-collected control evidence to assessors.
See Bastion against your accreditation requirements.
Bring the control set you are assessed against and the environments you must operate in, and we will map what the platform evidences automatically versus what remains a programme activity.