Skip to content
Secure enclave

Autonomous reliability for restricted environments.

Zof generates governed test intelligence, packages it into signed capsules, and executes through customer-controlled runners inside protected networks.

Nnnnoa nkɔ mu nkɔ ho

AI frɛ biara nfiri protected networks

Test capsules a wɔasɛn wɔn a wɔntumi nsesa wɔn

Customer-controlled execution a ɛwɔ audit trails

Ohaw no

Ɛnti adwumayɛ ahotɔ mu ho ɛhia foforo model

Netɛm a wɔakyekyɛ no amfa ho mmara a ɛhwehwɛ inbound access, model frɛ a wɔntie so, anaa automation a wɔnhwɛ so.

  • -Mfiri internet access kwan nhia wɔ nsiesie a wɔhwɛ so ho
  • -Netɛm kyekyɛ ne zero-trust boundaries
  • -Privileged access management ne sesa tumi hwɛ
  • -Data loss prevention ne adanse hwɛ amammerɛ
  • -Audit trails wɔ nhwɛso ne adwumayɛ-tua nkoa biara mu
  • -Mfiri AI frɛ a wɔntie so wɔ enclave mu firi tikrom
Adansesɛm

Zof enclave ahotɔ model

Nsusuiɛ ne tumi di dwuma wɔ baabi a policy gyaa ho kwan; dwumadi no tena customer boundary akyi wɔ transfer gateway akyi.

Intelligence Plane

Test nyansa a ɛwɔ governance ase

Di dwuma wɔ Zof Cloud, private cloud, anaa on-prem, baabi a wo policy bɛma dwumadiifo ne nhyehyɛe.

  • -Anidaso ne workflow nhwɛso
  • -System Graph nhyehyɛe ne nsiane nkɔso nhyehyɛe
  • -Test nhyehyɛe ne capsule mmɔ
  • -Remediation nhyehyɛe baabi a policy bɛma
  • -Tests a ɛfiri plane yi nko anyɛ wɔ protected apps so

Control Plane

Okwan a customer-governed

Wo policies, asɛn, ne audit trails hwɛ so dea betumi di dwuma wɔ protected environments mu.

  • -Onipa okwan ne role-based nhyehyɛe
  • -Cryptographic asɛn ne policy checks
  • -Capsule version nhyehyɛe ne promotion
  • -Nhyehyɛe ne adanse routing
  • -Audit trail titiriw wɔ dwumadie biara ho

Execution Plane

Wɔ wo boundary mu

Di dwuma fitaa wɔ customer-controlled infrastructure mu. Nsɛnkyerɛnne data tena mu sɛdeɛ wonhu wo okwan mu.

  • -Local browser, API, ne desktop nsusuwii
  • -Local screenshots, logs, ne video capture
  • -Redaction ne local adanse bundles
  • -Nsiesie a wopata ho anaa metadata-only egress a ɛho nhia da
  • -Mfiri ahohoro model frɛ bere a wodi dwuma no mu

Ahoban enclave architecture

Nimdeɛ ne tumi so hwɛ di adwuma wɔ ɛfan a wɔakyɛ no wɔ pɛ; dwumadwuma ne adanse tena mu firi capsules a wɔasina ne customer-tumi so runners.

Dwumaakyɛ baabi a wɔagyae

Intelligence Plane

Cloud, private cloud, anaasɛ on-prem

Control Plane

Hwehwɛ Capsule a Wɔasina

Customer Kwan Boundary

Customer-tumi so baabi

Execution Plane

Enclave Gateway

Edge Runner

Applications a Wɔhwehwɛ So

Beaeɛ Adanse Store

Agyagyae a Wɔasiesie Wɔ Ho Kwan

Enclave patterns

Enclave-style execution architectures

Netɛm a wɔakyekyɛ a nhyehyɛe betumi yɛ wɔ zone a wɔagyae ho kwan mu bere a dwumadi ne adanse tena customer-controlled boundary mu.

Banko a wɔahwɛ mu yie dwumadie

Dwumadie a wɔakyekyere ne signed capsule nsakrae.

Nsakraeɛ bea a wɔapatow noBan a wɔahwɛ muNyansapɔwNhyehyɛeƐkwanRunnerNsɛnkyerɛnneAdanse
Dwumadi boundary

Customer-controlled execution boundary

Wopili wɔ runners te wɔ he, deɛ wotumi ka ho, ne sɛdeɛ artifacts fi segment no mu.

  • -Execution plane tena wo perimeter mu
  • -Sensitive runtime data nhia wɔ external SaaS mu
  • -Metadata-only summaries nhia ma central dashboards
  • -Evidence ne retention policies ma environment biara
  • -Runner allowlists ne identity ma audit
  • -Fa nsiesie kyekyɛ ne zero-trust models a ɛwɔ hɔ ho ka
Capsules a wɔasina

Test capsules a wɔasina

Nkɛsoɔ a wɔmfrɛ ho antwi, wɔabobɔ so, ne wɔagyae – emfa ad hoc scripts. Constrained manifests kyerɛ ɛdeɛ betumi adwuma pɛpɛɛpɛ.

Hwehwɛ capsule nkwa

Firi nhyehyɛ nhyehyɛ kosi sinia, adwuma a wɔagyae, nkyekyɛmu biara wɔ nsusuwii ne audit tumi.

SɛnsɛnNhyehyɛBɔ AnoGyaeSinaDi Adwuma
Enclave gateway

Enclave gateway

Ehwɛ signatures so, di policy so, stage capsules, to dwuma biara ho asɛm, na ɔhyɛ edge runner adwuma, a wontue inbound access mu.

PAM credential kwan

Credentials bɔ kwan wɔ dwumadwuma berɛ, mfa secrets a wɔatena akyi wɔ Zof Cloud mu.

Runner hwehwɛ session
Gateway enforced policy
PAM bɔ credential kwan
Berɛ-ahwie ase access gyae
Audit dwuma atwerɛ ase
Edge runner

Edge runner wɔ kurom

Customer-deployed execution a ɛsɔ tests wɔ kurom, kɔfa adanse, yɛ redaction, na ɛwia report wɔ netɛm a wɔhwɛ so mu.

Edge runner dwumadwuma kwan

Capsules a wɔasina kɔ firi gateway policy kosi beaeɛ dwumadwuma ne adanse di.

Enclave GatewayEdge RunnerApplications a Wɔhwehwɛ SoBeaeɛ Adanse Store
Kyekyɛ

Netɛm kyekyɛ mmoa

De gateways ne runners kɔ VLAN, DMZ, OT zone, anaa business unit biara a policies de risk akye so.

  • -Per-segment capsule promotion rules
  • -Conservative pilots wɔ zones a ɛyɛ den sen wɔ kan
  • -DMZ ne application a ɛwɔ mu pɛ nsiesie
  • -Manufacturing ne branch networks via edge runners
  • -SOC ne admin dwumadi wɔ segments a wɔakyekyɛ mu
  • -Trɛ a security architecture sign-off wie
Telemetry

Telemetry egress a wɔhwɛ so

Telemetry ne adanse fi kwan a woapae so pɛ, a wɔayɛ redaction kan.

Telemetry kwan

Runner na ɔkɔ so kwa egress a wɔahwɛ mu.

RunnerƐfam dabɔRedactionEgress a wɔapatow
Adanse tumi hwɛ

Adanse ne egress tumi hwɛ

Wopili sɛ adanse de dwuma-plane no kwan, sɛ ɛkɔ biara a.

Adanse kwan modes

Yi wo baabi a sɛsɛsɛ adanse firi execution plane.

Beaeɛ nko ara

Screenshots, logs, videos, ne ripɔt nyinaa tena wo ho dwumadi mu. Nkɔmhyɛ a ɛfiri ho mma.

Agyagyae a wɔasiesie

Fields ne ntamaho a wɔagyae kɔ firi ahintaw policies ansa na wɔfiri execution plane.

Metadata nko ara

Kyerɛ pass/fail nhwɛso ne metadata a ɛnni amammere ho ma dashboards titiriw, emfa application data titiriw.

Gyinae

Enterprise approval workflows

Onipa ho kwan de capsule promotion ne adwuma a wɔhwɛ so ansa na production kari ɔhaw.

Nsiesie patowsem nhyehyɛe

Kwan a wɔahwɛ mu fi ahunu besi asiesie a wɔayi adi.

HuTaw anoDe to soHwɛAudit
Environments a wɔhwɛ so

Environments a wɔhwɛ so ho nhwɛso

Patterns a ɛkae ma financial services, healthcare administration, ne public-sector kyekyɛ – emfa customer endorsements.

  • -Core banking ne payment processing segments
  • -Healthcare administrative systems a PHI boundaries wom
  • -Identity ne trust platforms wɔ DMZ architectures mu
  • -Manufacturing OT-adjacent nhwɛso wɔ edge so
  • -Security operations dwumadi wɔ SOC VLANs mu
  • -Hwɛ deployment hub scenarios ma models a wɔanyae din
Deployment modes

Fa wo operating model so

Firi cloud a edi mmara kosi air-gapped on-prem, capsule model koro, planes biara wɔ farebae a ato mu.

Deployment modelBaabi AI dwumaakyɛ di adwumaBaabi dwumadwuma di adwumaInternet nhiaData agyagyae modelNhwɛso paNsɛmdie adwumaAkyi bɔ
Zof CloudZof CloudZof-tumi so anaasɛ customer runnersStandard outboundCustomer-nhyehyɛCloud-native nnipa, ahwɛ a ɛyɛ mmerɛSelf-serve kosi enterpriseTiers a wɔatwerɛ ase + enterprise
Zof Private CloudPrivate cloud a wɔakyekyɛCustomer-tumi so runnersPolicy-tumi so outboundBeaeɛ-first; agyagyae a wɔagyae wɔ ho kwanIndustries a wɔhwɛ so den, nhia a ɛwɔ ntɔkwa hoEnterprise nsɛmdieDwumadi bɔ, kasa kyerɛ nsɛmdie
Zof Hybrid EnclaveCloud anaasɛ private cloudEnclave gateway + edge runnersNhia wɔ network a wɔakyɛ muBeaeɛ-nko ara default; agyagyae a wɔasiesie wɔ ho kwanBanks, insurance, apps a ɛwɔ mu nko araAhoban deployment nkɔmmɔbɔDwumadi bɔ, kasa kyerɛ nsɛmdie
Zof On-Prem Control PlaneCustomer data centerCustomer-tumi so runnersWɔ ho kwan / air-gapped hyɛ aseBeaeɛ-nko ara boro no kɛkɛInternet mma, ntɔkwa den, mu tumi so hwɛArchitecture hwɛso hwehwɛDwumadi bɔ, kasa kyerɛ nsɛmdie
Zof Local Edge RunnerPaired control planeMfitiaseɛ, adwumakɛseɛ, edge siteNhia ma dwumadwumaBeaeɛ adanse; sɛsɛsɛ a wɔwɔ ho kwanSites a wɔakyekyɛ, networks a wɔahwie aseBotaeɛ ma enterprise deploymentDwumadi bɔ, kasa kyerɛ nsɛmdie
Customer VPC / VNetCloud anaasɛ private cloudCustomer VPC runnersOutbound-nko ara boro no kɛkɛBeaeɛ-first; policy-tumi soEnterprise SaaS wɔ wo cloud account muArchitecture hwɛsoDwumadi bɔ, kasa kyerɛ nsɛmdie
Private Kubernetes dwumadwumaCustomer-gyae control planeCustomer-tumi so cluster agentsPolicy-tumi soNamespace-ahwie ase adansePlatform nnipa a wɔwɔ K8s adwumadieArchitecture hwɛsoDwumadi bɔ, kasa kyerɛ nsɛmdie
Endpoint agentsPaired control planeDesktop / VDI / legacy UIOutbound nhyehyɛ boro no kɛkɛBeaeɛ di; agyagyae a wɔasiesie wɔ ho kwanERP, Citrix, mu desktop appsEnterprise deploymentDwumadi bɔ, kasa kyerɛ nsɛmdie

Ahoban deployment akyi bɔ da model, footprint, ne nhyehyɛ kɔkɔ so. Hwɛ enterprise deployment akyi bɔ

Ahotɔ tumi hwɛ

Wɔayɛ no ma security nhwɛso

Tumi hwɛ a wo ahotɔ ne risk teams de hwɛ, a wɔanyi certifications a yɛnna.

  • SSO/SAML/OIDC ne role-based access control
  • Runners a wɔasina ne execution allowlists
  • Audit trails ma capsules, runs, ne gyinae
  • PAM-compatible credential brokering bere a wodi dwuma
  • Redaction ne retention policies a wotumi sesa
  • Onipa gyinae ansa na wɔatua adwuma a wɔhwɛ so
  • Adanse modes: local-only, sanitized, anaa metadata-only
  • Wɔayɛ no na ɛboa bank-controlled execution models
Ahobammɔ nhwɛso

Banko Deployment Nhwɛso Listɛn

De listɛn yi di dwuma ne wo security, risk, ne infrastructure nnipa. Wɔyɛe sɛ ɛboa, ɛnyɛ sɛ ɛde wo nhwɛso a ɛwɔ mu no so.

  • Architecture nhwɛso

    Kyerɛ beae a nyansapɔw, nhyehyɛe, ne dwumadie tenten wɔ network kyekyere ho.

  • Data kwan nhwɛso

    Map data a wɔayɛ, ahyɛ ase, ne de kɔ, a adanse ne egress kwan a ɛba bi ka ho.

  • Runner署名

    Sɛsɛ runner binary,署名 key, ne dwumadie host allowlist.

  • PAM model

    Sɛsɛ ɛkwan a wɔfa to so de PAM ahyɛde bɔ wɔ dwumadie bere.

  • DLP ne redaction

    Kyerɛ field masking, screenshot nhyehyɛe, ne ɛfam adanse ho kaa.

  • Audit akowansiɛ

    Sɛsɛ capsule promotion, dwumadie, apatow, ne admin nsɛm ho akwansiɛ.

  • RBAC ne SSO

    Bɔ Zof rɔl ne korporesen identity ne access a ɛhia nko ara.

  • Deployment model a wɔpaw

    Paw cloud, private cloud, hybrid enclave, on-prem, anaa edge a ɛda kyekyere hia so.

  • Adanse dabɔ

    Kyerɛ beae a artifact te, bere a wɔhwɛ wɔn so daa, ne hwan betumi de bi.

  • Egress nhyehyɛe

    Paw ɛfam nko, wɔasiesie, anaa metadata nko ara mode wɔ ɔman biara ho.

  • Support access model

    Kyerɛ bere a Zof nnipa betumi de system adi dwuma ne apatow nhyehyɛe bɛn mu.

  • Pilot ne rollout plan

    Kyerɛ pilot a ɛyɛ den, nkataho nsɛm, ne production ɛkwan ano.

Download listɛn no

De kyɛ security ne procurement nkurɔfo ansa wo architecture nhwɛso.

Hwɛ banko deployment listɛn
FAQ

Ahotɔ deployment asɛmhyɛ

Nnyinasom ma security, infrastructure, ne procurement reviewers.

Daabi. Zof nhwehwɛ inbound connections kɔ wo netɛm a wɔhwɛ so. Customer-deployed edge runners sɔ capsules a wɔasina wɔ kurom. Kwan, sɛ wɔwɔ biara a, yɛ outbound na policy tumi hwɛ so.
Next step

Kasa fa banko deployment ho ne Zof

Hwɛ kyekyere, capsule nhyehyɛe, ne runner beae ne nnipa a wɔboa enterprise a wɔakyekyere wɔn.

01Zof Console

Kwan baako ma tebea, adwumayɛ, ne nea ɛsɛ sɛ wɔhwɛ a edi hɔ.

Fie a wɔagye atom a mfiridwuma, QA, ne SRE akuo bue no da biara: gyinabea pa, runs a ɛrekɔ so, kataso a ɛnam module so, ne nea ɛhwehwɛ adwene a edi hɔ.

ADWUMAYƐ KPIs

  • Runs
  • Kɛsemu
  • Asiane

Ɛwɔ tebea biara a woyi nneɛma kɔ mu no nyinaa mu.

ADWUMA HO DUA

  • Specs
  • Nsɔhwɛ
  • Nhyehyɛe

Firi specification kosi nsakrae ho nhwɛsoɔ a wɔahyehyɛ.

ƆBANBƆ AKWAN

  • RBAC
  • SSO
  • nhwɛhwɛ-asɛm

Adeyɛ biara wotumi de ma onipa a wɔde din ato so.

LIVE/console
Zof AI fie ahyɛnsodua a ɛkyerɛ runs 12 wɔ 94% pass, asɛm a ɛho hia a ano da hɔ 3, kɛsemu 84%, module akwantu bars anan, specification pipeline no, nhyehyɛe a ɛreba, ne nneɛma a wɔkamfo kyerɛ a edi hɔ a runs a ɛyɛ adwuma sidebar ka ho.
Home view · Checkout Service · Staging · captured live from the product.
  • 01 · RUNS · 24H

    94% pass

    12 runs across staging

  • 02 · COVERAGE

    84%

    Across four modules

  • 03 · ACTIVE RUNS

    3 running

    Live on this branch

  • 04 · NEXT ACTIONS

    Recommended

    Triage gaps, new spec

Zof AI Secure Enclave Fawɔhodie, Customer-Tumi Testing ma Environment a Wɔhwɛ So