1. Agent scan finds an unknown error in your environment
2. agent.ai_smart_fix(finding) called (inherited by ALL 25 agents)
3. self.claude._safe_call() routes to airlock-configured LLM
4. LLM endpoint = http://ollama-server.internal:11434 (LOCAL)
5. Local Llama 3.1 70B analyzes context + proposes remediation
6. RemediationAction created with status = PROPOSED
7. Security team reviews + approves in web UI
8. Forge executes the fix with rollback command ready
9. Full audit entry logged for HIPAA §164.312(b)
───────────────────────────────────────────
ZERO packets leave the customer network throughout.
Full internet egress. Claude API, public cloud APIs. The default for SaaS-friendly customers.
Private endpoints only. No public internet. Ideal for enterprises with ExpressRoute / DirectConnect / Cloud Interconnect.
Zero outbound. Fully contained inside customer network. Data-diode compatible.
| Component | Standard mode | AIRLOCK mode |
|---|---|---|
| AI inference | Claude API (api.anthropic.com) | Local Llama 3 / Phi-3 / Azure OpenAI private / Bedrock VPC |
| Cloud resource scanning | Public Azure / AWS / GCP APIs | Azure Stack Hub / AWS Outposts / GCP Anthos private endpoints |
| License verification | Anthropic SDK + license server check | Signed .titanlic file, offline RSA verification, no phone-home |
| Report delivery | HTTPS dashboard + email | Signed + encrypted .titanpkg bundles for data-diode / USB / SFTP-proxy |
| Software updates | HTTPS auto-update | One-way signed .titanpkg bundles imported via approved channel |
| Outbound allowlist | N/A | TITAN_AIRLOCK_ALLOWLIST env var enforces zero public egress |
| Forbidden hosts | N/A | api.anthropic.com, api.openai.com, github.com, pypi.org — all blocked |
Your SaaS competitors literally cannot sell into DMZ / air-gapped environments. TITAN AIR-GAPPED is the only option for the most regulated, highest-value security buyers on the planet.
REQUEST AIRLOCK BRIEFING FULL PRICING