Skip to main content
Home > Solutions > Solutions by Deployment > Air-Gapped & Classified Zero External Connectivity

Air-Gapped & Classified
Zero External Connectivity

MyID® CMS and MyID MFA deploy fully offline, inside isolated and air-gapped environments, with no external connectivity required. Proven in air-gapped defence and government deployments.

Key Capabilities

What this deployment model delivers

Genuinely offline

Not "offline mode when connectivity is unavailable", but genuinely, architecturally offline. Certificate issuance, renewal and revocation run entirely within the isolated enclave, alongside the certificate authority CRL and OCSP services.

Proven in air-gapped environments

MyID is deployed in air-gapped defence and government environments, running entirely within the isolated enclave with no external connectivity at any point.

FIPS 140-2 Level 3 HSM support

On-enclave FIPS 140-2 Level 3 HSM support for Thales Luna and Entrust nShield, so key material never leaves the isolated environment.

You control file transfer

Intercede supplies signed software updates and CRL data as files. How you move them into the isolated environment and install them is entirely up to you, following your organisation's own approved procedures.

Architecture components

Isolated Enclave All MyID components within the isolated boundary, zero external access
On-enclave HSM FIPS 140-2 Level 3 HSM (Thales Luna or Entrust nShield); key material stays in the enclave
Local Database SQL Server on an isolated server, no external DB connections
File delivery Intercede supplies signed update files; your team installs them using your own procedures
System requirements

Detailed platform requirements

Full server, operating system, database, HSM and client requirements for every MyID deployment are maintained in the Technical Overview, alongside the architecture and API detail.

View the Technical Overview →
Context

Air-gapped deployment: complete network isolation with full credential lifecycle

An air-gapped deployment means no network connection exists between the credential management system and any external network. Certificate issuance, revocation and lifecycle management occur within the isolated enclave, alongside the certificate authority CRL and OCSP services. This model suits classified government networks, critical national infrastructure OT environments, and any system where a network breach would be unacceptable. MyID is proven in air-gapped defence and government deployments.

Air-gapped
Proven in defence and government deployments
Zero
External connectivity at any point in the lifecycle
In-enclave
Issuance and lifecycle, no external dependency
You control
File transfer and install handled by your team
Frequently Asked Questions

Common questions

Need something specific? Contact our team →

An air-gapped CMS operates with zero network connectivity to external systems: no internet, no cloud, no external certificate services. Every operation, including certificate issuance, revocation and software updates, is performed entirely within the isolated enclave. MyID CMS supports fully air-gapped operation and is deployed in air-gapped environments.

Intercede supplies MyID updates and CRL data as signed files. How you transfer them into the isolated environment and install them is up to you, following your organisation's own approved procedures. Intercede's professional services team can advise on the process.

We provide a complete security evidence package for your Authorising Official (AO) or accreditation authority including System Security Plan (SSP) excerpt, FIPS 140-2 certificates for HSM, cryptographic algorithm documentation, and network architecture diagrams at the appropriate classification level.

Deployment · Air-Gapped / Classified

Built for air-gapped networks.

MyID CMS deploys fully offline within an isolated enclave, and our team can support your security accreditation process. Book an architecture review.