Cloud infrastructure engineered for sovereignty and scale
Five deployment models, zero-trust architecture, and cryptographic data sovereignty controls — purpose-built for the world's most demanding government and enterprise environments.
Deployment Models
Every environment, one platform
Airfree runs on your terms — public SaaS for velocity, private cloud for isolation, on-premise for compliance, air-gapped for classified workloads, and hybrid edge for field operations.
Public Cloud
Fully managed, multi-tenant SaaS delivered from Airfree-operated regional cloud regions. Elastic capacity, automatic upgrades, and a consumption-based pricing model.
Private Cloud
Dedicated single-tenant infrastructure provisioned within an Airfree data centre or your preferred co-location facility. Full workload isolation with dedicated compute, networking, and storage.
On-Premise
Software deployed entirely within the customer's own data centre. Airfree delivers a containerised, Kubernetes-native stack with remote lifecycle management and patching support.
Air-Gapped
Fully disconnected deployment with no internet egress. Packaged as an offline-installable appliance bundle with on-site licence validation and media-based update delivery.
Hybrid Edge
Control-plane in the cloud, data-plane at the edge. Field sensors, mobile units, and remote nodes synchronise with the central platform over intermittent or bandwidth-constrained links.
Architecture
Built on modern cloud-native principles
Every architectural decision is made to maximise resilience, operability, and security without sacrificing developer ergonomics or deployment flexibility.
Microservices
Every platform capability is encapsulated as an independently deployable service with a versioned API contract. Teams can release, scale, and roll back individual services without platform-wide risk.
Kubernetes-Native
All workloads run as Kubernetes-managed pods. We ship Helm charts and ArgoCD application manifests for every service, enabling GitOps-driven, reproducible deployments across any conformant cluster.
Multi-Region
Control-plane and data-plane components are deployed across geographically distributed regions. Region affinity policies ensure data stays within the designated jurisdiction while traffic is load-balanced globally.
Zero-Trust
No implicit trust between services. Every inter-service call is authenticated via mutual TLS and short-lived JWT tokens issued by Keycloak. Network policies enforce explicit allow-lists at the pod level.
Immutable Infrastructure
Infrastructure is never modified in place. Changes flow through a CI pipeline that builds new artefacts, runs compliance checks, and promotes through dev → staging → production with full audit trails.
Event-Driven
State changes propagate as durable events over Apache Kafka. Services subscribe to the streams they need, enabling loose coupling, replay-on-failure, and seamless integration with external systems.
Data Sovereignty
Your data stays where it belongs
Jurisdiction controls, end-to-end encryption, and customer-controlled key management are not optional add-ons — they are foundational to how the Airfree platform is designed.
Data Residency Controls
Every data asset is tagged with a jurisdiction code at ingestion. Storage and processing engines honour residency policies at the row, table, and object level — data never crosses a jurisdictional boundary without an explicit policy exception.
Encryption at Rest & in Transit
All persistent data is encrypted with AES-256 using envelope encryption. All network traffic — internal and external — is encrypted with TLS 1.3. Certificate rotation is automated with a 90-day maximum validity window.
Key Management — HashiCorp Vault
Encryption keys are managed exclusively by HashiCorp Vault with customer-controlled root-of-trust. Keys are stored in HSM-backed secret engines and never leave the Vault boundary. Customers can bring their own keys (BYOK) for all encryption operations.
Access Control & Audit
Role-based and attribute-based access control policies are enforced by Keycloak. Every data access event is written to an immutable audit log with cryptographic integrity seals, exportable for SIEM ingestion.
Reliability
Engineered for mission-critical uptime
National land registries, emergency management platforms, and real-time sensor networks cannot afford downtime. We architect for failure so your operations never experience it.
99.99% SLA
Our service level agreement commits to 99.99% monthly uptime across all production tiers. Compensation credits are automatically applied for any breach without requiring a customer claim.
Multi-AZ Deployment
Production workloads span a minimum of three availability zones within each region. Zone-level failures are absorbed transparently; no manual failover or customer action required.
Hot Standby
Stateful services run in active-active configuration with synchronous replication. A standby replica is promoted in under 60 seconds should the primary become unavailable.
Observability Stack
All platform components emit structured logs, distributed traces, and Prometheus metrics. A pre-built dashboard suite surfaces SLI/SLO burn rates, latency percentiles, and error budgets in real time.
Compliance
Certified for government and enterprise
Our platform meets the most demanding regulatory frameworks across Australia, the Asia-Pacific, and international markets — with independent third-party attestation.
Technology Stack
Open standards, proven components
We build on battle-hardened open-source foundations — no proprietary lock-in, no black-box dependencies. Every component is CNCF-graduated or widely adopted in production government environments.
Ready to architect your sovereign cloud?
Our cloud architects will review your requirements, map them to the right deployment model, and design a reference architecture tailored to your jurisdiction and compliance obligations.