Skip to content
Enterprise resource

Secure Deployment Checklist

Checklist for secure enclave, on-prem, and private cloud deployment patterns.

Checklist

  • No inbound access to protected networks required
  • Signed test capsules with versioning
  • Enclave gateway verifies signatures and policy
  • Local edge runner deployment documented
  • Runtime execution without external model calls
  • Local-only evidence mode available
  • Sanitized egress optional and approved
  • PAM-compatible credential brokering
  • Audit trail for capsule promotion and runs
  • Human approval on remediation paths
  • Air-gapped import procedure documented
  • Private cloud region and isolation confirmed
  • On-prem control plane option evaluated
  • Redaction policies for screenshots and fields
  • Runner allowlists and binary signing
  • SSO/RBAC for control plane users
  • Incident response for compromised runner
  • Data flow diagram reviewed by security
  • Conservative pilot scope defined
  • Regulated workflow representative scenario documented
  • Egress denial default verified
  • Upgrade cadence aligned with change windows

Related guides

01Evidence and control

Evidence leaders, auditors, and the board can actually use.

Every verification run, policy evaluation, approval, and outcome is recorded as durable evidence, exportable for release reviews, compliance packs, and executive readouts.

PROVENANCE

Who, what, why

Every decision attributable to policy and a named approver.

AUDIT-READY

Compliance pack

  • SOC 2
  • ISO
  • evidence trail.

CADENCE

Scheduled

Generated automatically on your schedule.

AUDIT-READY/reports
Zof AI reports page with four template cards, Weekly Release Summary, Coverage Trends, Risk Assessment Report, and Compliance Evidence Pack, each with Generate and Schedule actions, plus tabs for Generated Reports, Saved Views, and Scheduled.
Reports · /reports · four enterprise templates · live from the product.
Secure Deployment Checklist | Zof AI