HST-09 / ACCREDITED HOSTING

Plintir Bastion

Run the intelligence suite in sovereign cloud, on-premises, high-side and fully air-gapped environments, with separate key hierarchies, zero-trust controls and the accreditation evidence already assembled.

Core intelligence outcome
Accredited Sovereign & High-Side Hosting

Most capability programmes lose their first year to accreditation. Bastion exists to give that year back: a hardened deployment model that behaves identically across every environment, producing the control evidence assessors ask for as a by-product of running.

ENVIRONMENTSCLOUD TO AIR-GAP
DOMAINSSEPARATELY KEYED
EVIDENCECONTINUOUS
Product experience

Intelligence in context, with the next decision already in view.

PLINTIR / BASTIONLIVE
ACCREDITED SOVEREIGN & HIGH-SIDE HOSTINGSTATUS: OPERATIONALUTC
ENVIRONMENTSCLOUD TO AIR-GAPLIVE
DOMAINSSEPARATELY KEYEDVISIBLE
EVIDENCECONTINUOUSCONTROLLED
AVAILABILITY99.95%TARGET
Environment topology · 4 environments, 3 security domains
EnvironmentDomainHostingKey hierarchyReplication inAvailability
ENV-CLOUD-1ControlledSovereign cloudKMS-A—
99.97%
ENV-PREM-1ControlledOn-premisesHSM-BApproved products
99.96%
ENV-HIGH-1High-sideOn-premisesHSM-COne-way, reviewed
99.98%
ENV-ISOLATEDIsolatedAir-gappedHSM-DPhysical media only
99.95%
There is no inbound management path from lower trust. High-side and isolated environments are never administered from a less-trusted network — change arrives through the reviewed delivery path or physical media, and nothing else.
Detailed capabilities

What Bastion does.

CAP-01

Every environment, one platform

The same platform and the same mission model deploy to commercial cloud, sovereign cloud, on-premises, high-side and disconnected air-gapped estates without redesign or a separate codebase.

Sovereign cloudOn-premisesHigh-sideAir-gapped
CAP-02

Zero trust by construction

Strong identity, PKI and multi-factor authentication, service-to-service authorization and encryption in transit and at rest, with no implicit trust granted by network position.

Strong identityService authorizationEncryptionNo network trust
CAP-03

Domain isolation done properly

Separate clusters, separate key hierarchies and separate hardware security boundaries per security domain, with only reviewed data products moving between them and no inbound management path.

Per-domain keysHardware boundariesIsolated clustersReviewed replication
CAP-04

Continuity and accreditation evidence

Tiered recovery objectives by mission service, exercised disaster recovery and control status collected continuously rather than assembled for a review meeting.

Tiered RTO/RPOTested recoveryContinuous evidenceDegraded-mode drills
Interface detail

Evidence is collected, not assembled the week before.

PLINTIR / BASTION · CONTROL EVIDENCELIVE
Control areaImplementationEvidenceCheckedState
Identity & accessPKI, MFA, attribute-based authorisationAutomatedHourlySATISFIED
EncryptionIn transit and at rest, per-domain keysAutomatedHourlySATISFIED
Audit & retentionImmutable, separate access domainAutomatedContinuousSATISFIED
Supply chainSigned artifacts, component inventoryAutomatedPer releaseSATISFIED
Vulnerability postureGated promotion, patch cadenceAutomatedDaily2 ITEMS OPEN
RecoveryTiered objectives, exercisedExercise recordQuarterlySATISFIED

Two items are open, and that is the point. Control status is produced continuously by the platform, so a review reads the current state of the estate rather than a prepared snapshot.

Accreditation should be a property of the platform, not a project.

Bastion produces control status continuously as the system runs, so an assessment reads the current state of the estate rather than a snapshot someone prepared the week before.

Intelligence flow

From information to Actionable Intelligence Data.

STEP 01

Establish

Define security domains, key hierarchies and the authority model.

STEP 02

Deploy

Stand the platform up identically across each approved environment.

STEP 03

Evidence

Collect control status and audit continuously as the system operates.

STEP 04

Assure

Exercise recovery, degraded modes and cross-domain paths against the plan.

Mission use cases

Designed around intelligence outcomes.

UC-01

Sovereign Deployment

Operate the suite entirely within national jurisdiction and control.

UC-02

High-Side and Air-Gapped

Run isolated environments with no inbound path from lower trust.

UC-03

Accreditation Support

Supply current, machine-collected control evidence to assessors.

Product briefing

See Bastion against your accreditation requirements.

Bring the control set you are assessed against and the environments you must operate in, and we will map what the platform evidences automatically versus what remains a programme activity.