Air-Gapped & Classified
Zero External Connectivity
MyID® CMS and MyID MFA deploy fully offline, inside isolated and air-gapped environments, with no external connectivity required. Proven in air-gapped defence and government deployments.
What this deployment model delivers
Genuinely offline
Not "offline mode when connectivity is unavailable", but genuinely, architecturally offline. Certificate issuance, renewal and revocation run entirely within the isolated enclave, alongside the certificate authority CRL and OCSP services.
Proven in air-gapped environments
MyID is deployed in air-gapped defence and government environments, running entirely within the isolated enclave with no external connectivity at any point.
FIPS 140-2 Level 3 HSM support
On-enclave FIPS 140-2 Level 3 HSM support for Thales Luna and Entrust nShield, so key material never leaves the isolated environment.
You control file transfer
Intercede supplies signed software updates and CRL data as files. How you move them into the isolated environment and install them is entirely up to you, following your organisation's own approved procedures.
Architecture components
| Isolated Enclave | All MyID components within the isolated boundary, zero external access |
| On-enclave HSM | FIPS 140-2 Level 3 HSM (Thales Luna or Entrust nShield); key material stays in the enclave |
| Local Database | SQL Server on an isolated server, no external DB connections |
| File delivery | Intercede supplies signed update files; your team installs them using your own procedures |
Detailed platform requirements
Full server, operating system, database, HSM and client requirements for every MyID deployment are maintained in the Technical Overview, alongside the architecture and API detail.
Air-gapped deployment: complete network isolation with full credential lifecycle
An air-gapped deployment means no network connection exists between the credential management system and any external network. Certificate issuance, revocation and lifecycle management occur within the isolated enclave, alongside the certificate authority CRL and OCSP services. This model suits classified government networks, critical national infrastructure OT environments, and any system where a network breach would be unacceptable. MyID is proven in air-gapped defence and government deployments.
Common questions
Need something specific? Contact our team →
An air-gapped CMS operates with zero network connectivity to external systems: no internet, no cloud, no external certificate services. Every operation, including certificate issuance, revocation and software updates, is performed entirely within the isolated enclave. MyID CMS supports fully air-gapped operation and is deployed in air-gapped environments.
Intercede supplies MyID updates and CRL data as signed files. How you transfer them into the isolated environment and install them is up to you, following your organisation's own approved procedures. Intercede's professional services team can advise on the process.
We provide a complete security evidence package for your Authorising Official (AO) or accreditation authority including System Security Plan (SSP) excerpt, FIPS 140-2 certificates for HSM, cryptographic algorithm documentation, and network architecture diagrams at the appropriate classification level.