Deploy around the network and data boundary you have.
zer0cipher supports four deployment models that change where Brain and Pinky run, how HQ connects, who operates the environment, and how updates and licensing are handled.
Interactive architecture
See where Brain, Darko, and Pinky run in each model.
Pick a model to trace how the control plane, evidence store, and internal execution agents sit across the network boundary — and where the data stays.
Managed deployment
Managed Brain. Client-side reach.
HQ, the client-specific Brain deployment, and External Pinky run in zer0cipher-managed AWS. Internal Pinkys execute from approved client VLANs.
zer0cipher-managed AWS
Control planezer0cipher HQFleet + operations
State + evidenceBrain + DarkoClient-specific deployment
ExternalPinkyInternet-facing execution
Client network boundary
Corporate VLAN
Pinky / 01PinkyInternal execution
Restricted VLAN
Pinky / 02PinkyInternal execution
Secure VLAN
Pinky / 03PinkyInternal execution
Internal Pinkys do not bridge VLANs. Each agent reports the networks reachable from its placement and polls for matching engagement work.
Managed HQ + BrainExternal Pinky in AWSOne Pinky per reachable segment
At a glance
Compare the four operating models.
01SaaS
Operations
Managed by the zer0cipher team.
Connectivity
HQ heartbeat, licensing, management, and approved telemetry paths.
Data boundary
A client-specific Brain runs in zer0cipher-managed AWS.
Best fit
Teams that want a fully managed operating model.
02Client-hosted
Operations
Shared between the client and zer0cipher.
Connectivity
A documented outbound management path to HQ, not a blanket “no data leaves” claim.
Data boundary
Brain and evidence run on client-controlled infrastructure.
Best fit
Teams that require direct infrastructure ownership.
03MSSP / partner
Operations
Partner-operated from a single MSSP HQ.
Connectivity
Partner HQ coordinates isolated per-client Brains and their Pinkys.