Zero-egress diagnosis
Keep raw logs, signatures, incident records and monitoring inside the controlled network boundary.
For regulated and isolated environments
Air-gapped reliability work cannot depend on uploading a proprietary training log or calling a hosted model. The diagnostic path, pattern corpus, incident record and monitoring output must operate inside the environment and remain useful when no external service is reachable.
Denpex local mode runs its deterministic diagnosis engine on the host, stores incident JSON locally and exposes Prometheus metrics. Hosted research and AI fallback are unavailable offline, so the evaluation must test whether deterministic coverage is sufficient for the environment's real failure mix.
These incidents look adjacent in the final alert, but they require different owners and different proof before recovery.
Keep raw logs, signatures, incident records and monitoring inside the controlled network boundary.
Verify agent, engine and pattern artifacts with the published checksum manifest before import.
Expose local Prometheus metrics for the environment's approved collection and dashboard stack.
Measure deterministic coverage explicitly because hosted fallback and live research are not available offline.
Transfer the agent, local engine and pattern database through the approved software supply process.
Run dry mode and network controls to verify what the selected deployment can and cannot transmit.
Wrap jobs or inspect saved logs while incident files remain in the configured local directory.
Route Prometheus output and reports through the organization's existing security boundary.
Use your incidents and timestamps. These are measurement definitions, not Denpex customer-outcome claims.
| Metric | Measurement |
|---|---|
| Zero-egress verification | Observed outbound connections and payload inspection under the organization's own network controls. |
| Offline coverage | Resolved historical incidents correctly routed by the deterministic path without hosted assistance. |
| Update effort | Operator time to verify, import, deploy and roll back a signed pattern or agent release. |
| Local resolution time | Time from incident capture to verified action while disconnected from external services. |
Review the documented in-VPC and zero-egress paths, prerequisites and metrics.
Inspect current controls, subprocessors, responsibilities and document requests.
Request the deeper data-flow, deployment and evaluation material.
See the current evaluation status and limitations before procurement.
The documented DENPEX_LOCAL path performs deterministic diagnosis on the host, writes local incident records and serves local Prometheus metrics. It does not require an API key and does not send logs, signatures or heartbeats to the hosted service.
Hosted AI fallback and live external research are unavailable. The bundled deterministic matcher, causal pipeline, local incident records and metrics remain available. A pilot should quantify which historical incidents require evidence beyond that offline path.
The organization controls transfer and approval. Denpex publishes the agent bundle and checksum manifest; the operator verifies artifacts before import and should test both update and rollback in the target deployment process.
No. The Trust Center documents current controls and status, while organization-specific accreditation, hosting, contractual and support requirements require procurement and security review. Denpex should not be represented as approved for a regime solely from a marketing page.
Freeze the expected owner and outcome, replay the evidence, then compare operator time and decision quality with your current process.
Build the evaluation plan