Plintir // Actionable intelligence // Interface visuals use synthetic data

Plintir / Products / BASTION

Plintir BASTION

Accredited Sovereign & High-Side Hosting

Accreditation as a starting point, not a project

Most capability programmes lose their first year to accreditation. BASTION exists to give that year back — a hardened deployment model that runs identically in commercial cloud, sovereign cloud, on-premises, high-side and fully air-gapped environments, with the evidence pack that accreditors ask for.

CLOUDHIGH-SIDEAIR-GAPPED

99.95%

Core service availability target

30 / 5 min

Recovery objectives, critical state

Per-domain

Key hierarchies and isolation

Air-gap

Full disconnected deployment

Capabilities

What BASTION does.

Every environment, one platform

The same platform and the same mission model deploy to commercial cloud, sovereign cloud, on-premises, high-side and disconnected air-gapped estates without redesign.

Sovereign cloudOn-premisesHigh-sideAir-gapped

Zero trust by construction

Strong identity, PKI and multi-factor authentication, service-to-service authorisation, encryption in transit and at rest, and no implicit trust from network position.

Strong identityService authorisationEncryption everywhereNo network trust
Plintir · BASTION · Environment topology4 environments · 3 security domains Synthetic data
EnvironmentDomainHostingKey hierarchyReplication inAvailability
ENV-CLOUD-1ControlledSovereign cloudKMS-A
99.97%
ENV-PREM-1ControlledOn-premisesHSM-BApproved products
99.96%
ENV-HIGH-1High-sideOn-premisesHSM-COne-way, reviewed
99.98%
ENV-AIRGAP-1IsolatedAir-gappedHSM-DPhysical media only
99.95%

Separate

Key hierarchy per security domain

One-way

Reviewed replication into high-side

None

Inbound management from lower trust

Tested

Disaster recovery per environment

No inbound path from lower trust. High-side and isolated environments are never managed from a lower-trust network — updates arrive through the reviewed delivery path or physical media, and nothing else.

Domain isolation done properly

Separate clusters, separate key hierarchies and separate hardware security boundaries per security domain, with only approved data products replicated between them.

Per-domain keysHSM boundariesIsolated clustersApproved replication only

Continuity and recovery

Tiered recovery objectives by mission service, failure-domain separation, tested disaster recovery and exercised degraded-mode operation.

Tiered RTO/RPOFailure isolationTested DRDegraded-mode drills
Plintir · BASTION · Control statusAccreditation evidence · continuously collected Synthetic data
Control areaImplementationEvidenceContinuous checkState
Identity & accessPKI, MFA, attribute-based authorisationAutomatedHourlySATISFIED
EncryptionIn transit and at rest, per-domain keysAutomatedHourlySATISFIED
Audit & retentionImmutable, separate access domainAutomatedContinuousSATISFIED
Supply chainSigned artifacts, bill of materialsAutomatedPer releaseSATISFIED
Vulnerability postureGated promotion, patch cadenceAutomatedDaily2 ITEMS OPEN
RecoveryTiered objectives, exercisedExercise recordQuarterlySATISFIED

Evidence is collected, not assembled. Control status is produced continuously by the platform, so an accreditation review reads current state rather than a snapshot someone prepared for the meeting.

Deploys where you work

One platform, every environment.

BASTION runs identically in commercial cloud, sovereign cloud, on-premises, high-side and fully air-gapped estates, and degrades predictably at the tactical edge.

Sovereign cloudOn-premisesHigh-side Air-gappedTactical edgeCoalition workspace Zero trustAttribute-based accessImmutable audit

Next step

See BASTION against your own mission thread.

We run briefings on a real mission problem you bring, not a scripted demonstration. Bring the question your analysts cannot currently answer.