Airfree
Cloud Infrastructure

Cloud infrastructure engineered for sovereignty and scale

Five deployment models, zero-trust architecture, and cryptographic data sovereignty controls — purpose-built for the world's most demanding government and enterprise environments.

Deployment Models

Every environment, one platform

Airfree runs on your terms — public SaaS for velocity, private cloud for isolation, on-premise for compliance, air-gapped for classified workloads, and hybrid edge for field operations.

Public Cloud

Fully managed, multi-tenant SaaS delivered from Airfree-operated regional cloud regions. Elastic capacity, automatic upgrades, and a consumption-based pricing model.

Ideal for: Commercial enterprises, SMEs, and innovation teams requiring fast time-to-value with minimal operational overhead.

Private Cloud

Dedicated single-tenant infrastructure provisioned within an Airfree data centre or your preferred co-location facility. Full workload isolation with dedicated compute, networking, and storage.

Ideal for: National mapping agencies, defence contractors, and financial institutions with strict data isolation requirements.

On-Premise

Software deployed entirely within the customer's own data centre. Airfree delivers a containerised, Kubernetes-native stack with remote lifecycle management and patching support.

Ideal for: Sovereign governments and classified environments where data must never leave the organisation's physical perimeter.

Air-Gapped

Fully disconnected deployment with no internet egress. Packaged as an offline-installable appliance bundle with on-site licence validation and media-based update delivery.

Ideal for: Military, intelligence, and critical national infrastructure operators with zero-external-connectivity mandates.

Hybrid Edge

Control-plane in the cloud, data-plane at the edge. Field sensors, mobile units, and remote nodes synchronise with the central platform over intermittent or bandwidth-constrained links.

Ideal for: Cadastral field survey teams, disaster response units, and satellite-connected remote sensing deployments.

Architecture

Built on modern cloud-native principles

Every architectural decision is made to maximise resilience, operability, and security without sacrificing developer ergonomics or deployment flexibility.

Microservices

Every platform capability is encapsulated as an independently deployable service with a versioned API contract. Teams can release, scale, and roll back individual services without platform-wide risk.

Kubernetes-Native

All workloads run as Kubernetes-managed pods. We ship Helm charts and ArgoCD application manifests for every service, enabling GitOps-driven, reproducible deployments across any conformant cluster.

Multi-Region

Control-plane and data-plane components are deployed across geographically distributed regions. Region affinity policies ensure data stays within the designated jurisdiction while traffic is load-balanced globally.

Zero-Trust

No implicit trust between services. Every inter-service call is authenticated via mutual TLS and short-lived JWT tokens issued by Keycloak. Network policies enforce explicit allow-lists at the pod level.

Immutable Infrastructure

Infrastructure is never modified in place. Changes flow through a CI pipeline that builds new artefacts, runs compliance checks, and promotes through dev → staging → production with full audit trails.

Event-Driven

State changes propagate as durable events over Apache Kafka. Services subscribe to the streams they need, enabling loose coupling, replay-on-failure, and seamless integration with external systems.

Data Sovereignty

Your data stays where it belongs

Jurisdiction controls, end-to-end encryption, and customer-controlled key management are not optional add-ons — they are foundational to how the Airfree platform is designed.

Data Residency Controls

Every data asset is tagged with a jurisdiction code at ingestion. Storage and processing engines honour residency policies at the row, table, and object level — data never crosses a jurisdictional boundary without an explicit policy exception.

Encryption at Rest & in Transit

All persistent data is encrypted with AES-256 using envelope encryption. All network traffic — internal and external — is encrypted with TLS 1.3. Certificate rotation is automated with a 90-day maximum validity window.

Key Management — HashiCorp Vault

Encryption keys are managed exclusively by HashiCorp Vault with customer-controlled root-of-trust. Keys are stored in HSM-backed secret engines and never leave the Vault boundary. Customers can bring their own keys (BYOK) for all encryption operations.

Access Control & Audit

Role-based and attribute-based access control policies are enforced by Keycloak. Every data access event is written to an immutable audit log with cryptographic integrity seals, exportable for SIEM ingestion.

Reliability

Engineered for mission-critical uptime

National land registries, emergency management platforms, and real-time sensor networks cannot afford downtime. We architect for failure so your operations never experience it.

99.99%
Uptime SLA
Annual availability guarantee
< 15 min
RTO
Recovery time objective
< 5 min
RPO
Recovery point objective
Multi-AZ
Hot Standby
Active-active across zones

99.99% SLA

Our service level agreement commits to 99.99% monthly uptime across all production tiers. Compensation credits are automatically applied for any breach without requiring a customer claim.

Multi-AZ Deployment

Production workloads span a minimum of three availability zones within each region. Zone-level failures are absorbed transparently; no manual failover or customer action required.

Hot Standby

Stateful services run in active-active configuration with synchronous replication. A standby replica is promoted in under 60 seconds should the primary become unavailable.

Observability Stack

All platform components emit structured logs, distributed traces, and Prometheus metrics. A pre-built dashboard suite surfaces SLI/SLO burn rates, latency percentiles, and error budgets in real time.

Compliance

Certified for government and enterprise

Our platform meets the most demanding regulatory frameworks across Australia, the Asia-Pacific, and international markets — with independent third-party attestation.

ISO 27001
Information security management — certified
SOC 2 Type II
Trust services criteria — attested annually
IRAP Assessed
Australian Government cloud security framework
FedRAMP-Aligned
US federal risk and authorisation controls mapped
ISO 9001:2015
Quality management systems — certified
GDPR & Privacy Act
Data processing agreements available for all regions

Technology Stack

Open standards, proven components

We build on battle-hardened open-source foundations — no proprietary lock-in, no black-box dependencies. Every component is CNCF-graduated or widely adopted in production government environments.

Kubernetes
Container orchestration
Apache Kafka
Event streaming
PostgreSQL / PostGIS
Relational + spatial database
Redis
In-memory cache & pub/sub
MinIO
S3-compatible object storage
HashiCorp Vault
Secrets & key management
Keycloak
Identity & access management
ArgoCD
GitOps continuous delivery
Prometheus + Grafana
Metrics & observability
Istio
Service mesh & mTLS
NGINX
Ingress & reverse proxy
Terraform
Infrastructure as code

Ready to architect your sovereign cloud?

Our cloud architects will review your requirements, map them to the right deployment model, and design a reference architecture tailored to your jurisdiction and compliance obligations.