Sovereign Deployment
Self-hosted. Air-gap capable. Sovereign by construction.
Stella Ops is developed in Europe; our own infrastructure is hosted in Switzerland. The product runs entirely on your infrastructure — connected or fully disconnected — and the evidence never leaves your boundary.
Self-hosted is the only deployment model — there is no SaaS edition.
- European vendor, Swiss-hosted The operating company is registered in Bulgaria, in the European Union. Our own services are hosted in Switzerland, which holds an EU adequacy decision; no US-headquartered vendor sits in your supply chain.
- Self-hosted The entire suite — scanner, policy engine, evidence store, console — deploys on infrastructure you control: on-premises, private cloud, or an isolated enclave. There is no vendor-side control plane.
- Air-gap capable Advisories,
VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your contextstatements, and policy packs arrive as signed offline bundles. Scans, verdicts, and decisions run with no outbound connection.
Where does our data go?
Teams evaluating a release control plane ask this early. The answer is short: nowhere. There is no vendor backend in the data path.
Runs in your boundary
Every component runs where you deploy it. The Stella Ops operator runs no service that sees your images, SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software documents, or findings.
Telemetry is opt-in, off by default
Nothing is reported home unless you turn telemetry on. In connected mode, outbound traffic is the feed synchronisation you configure; in air-gapped mode, there is none.
Decisions use local knowledge
Verdicts are computed against the local advisory snapshot. The snapshot's age is tracked and shown — staleness is visible, never hidden.
Evidence is packaged as Decision CapsuleA signed, exportable evidence bundle that seals every input and output of a release decision for offline audit and deterministic replay bundles that live in your evidence store and leave only when you export them. Verification tooling is open source (Apache-2.0), so an auditor can check a decision without asking us. Evidence & Audit →
Connected or disconnected — the same control model
Connected mode
Standard deployment with optional feed updates from public sources.
- → Live vulnerability feed sync (
NVDNational Vulnerability Database - the U.S. government repository of standards-based vulnerability data,OSVOpen Source Vulnerabilities - a distributed vulnerability database for open source projects, vendor advisories) - → Opt-in telemetry for fleet analytics (disabled by default)
- → Automated signature verification
Air-gapped mode
Fully isolated deployment for regulated or sensitive environments with no outbound traffic unless telemetry is manually enabled.
- → Signed feed bundles imported via sneakernet or DMZ relay
- → Zero external network dependencies
- → Customer-controlled update cadence
Deterministic replay does not depend on the network. Re-running a verdict from its capsule and frozen feed snapshot produces the same result on any machine that has the inputs. An input the machine does not have is reported, not substituted.
Bring knowledge in — and verify it without a network
The minimal loop for a disconnected estate: bring knowledge in as a signed kit, know how old that knowledge is, and verify evidence against local trust roots.
$ stella offline status
Kit signatures are verified against a trust root you own, and the kit's snapshot digest is recorded so the same knowledge state can be replayed later.
Commands as shown in the product console (v1.0-RC1).
- Download and verify Fetch the latest kit and signature on a connected mirror. Verify with your
CosignContainer signing tool from Sigstore project for signing and verifying container images and artifactspublic key before transfer. - Transfer to air-gapped site Use your approved channel: USB, courier, or controlled rsync drop box. Unsigned bundles never cross the boundary.
- Import Automation scripts, manifest audits, and troubleshooting live in the Offline Kit guide.
- Global feeds plus regional sources (CNNVD,
JVNJapan Vulnerability Notes - Japan's vulnerability database managed by JPCERT/CC and IPA, ENISA, BDU) preserved as individual signed snapshots so policy can trust or ignore each one independently. - Each air-gapped site imports independently according to its own maintenance schedule.
Regional cryptography
Signing and verification run through pluggable crypto profiles, so evidence carries the algorithms your jurisdiction expects.
FIPS-aligned profile · eIDAS-compatible signing · SM2 / SM3 / SM4 · HSM via PKCS#11 · Multi-profile signing
Stella Ops consumes operator-supplied qualified trust material and records the evidence trail. Stella Ops is not a trust service provider or qualified trust service provider under eIDAS. Stella Ops does not itself provide qualified electronic signatures, qualified electronic seals or qualified electronic time stamps, and does not claim the legal presumptions reserved for qualified trust services.
Doctor verifies algorithm availability before you depend on it. The HSM and its drivers remain customer-provided.
Profile availability describes what the software can do. Certification, validation, and legal effect depend on your modules, your keys, and your assessors.
Crypto profiles in detail → · Availability and sanctions notice →
Who this is for
- Defence & government Classified networks requiring national crypto profiles and zero external dependencies.
- Critical infrastructure Energy, transport, and telecom operators who must prove every deployment decision to regulators.
- Financial institutions Banks and insurers needing
FIPSFederal Information Processing Standards - U.S. government cryptographic standards for secure systems-aligned crypto (validation depends on your key provider) with auditable, deterministic release gates. - Healthcare & pharma Organisations handling sensitive data that require offline-first operation and signed evidence chains.
