DIRVA for Government

Advanced AI-powered cybersecurity without surrendering control of your environment.

DIRVA runs inside your accreditation boundary, on models you choose, with a person approving every action and a complete record of everything its agents do. Built for agencies, defense and intelligence organizations, and the integrators that support them.

Inside the boundary

Deployed where your data already lives.

One picture of a DIRVA deployment in a government enclave: your systems feed the appliance, the appliance drives the tools you already operate, and nothing crosses the boundary.

ACCREDITATION BOUNDARY · ENCLAVEYOUR ENVIRONMENTDIRVA APPLIANCEYOUR SECURITY STACKEndpointsServersApplicationsCloudRepositoriesNetworkSIEMEDR / XDRITSM / ticketingThreat IntelScannersM365 GCC / Azure GovDIRVA EnterpriseON-PREMISES VIRTUAL APPLIANCEDiscoveryVulnerability IntelligenceAgentic AIRAGMCP · APIAutomation EngineRemediationGOVERNANCE · BUILT INPolicy engineHuman approvalAudit logPII redactionAI models · local or private · air-gap capableNO EXTERNALDEPENDENCYAir-gap capable · vulnerability definitions and rule packs stored locally · nothing leaves the enclave

Why government teams choose DIRVA

Control is the requirement, not a feature.

  • Runs inside your accreditation boundaryAn on-premises virtual appliance on your infrastructure. No security data leaves the enclave for core operation.
  • Air-gap capableVulnerability definitions, CVE intelligence and code rule packs are stored locally, so DIRVA works in disconnected environments.
  • Models you controlLocal or private model support where configured. You decide which models run, and where. No PII is ever sent to any model — findings are minimized and redacted inside the platform first.
  • A person approves every actionAgents propose; authorized personnel approve. Role-based control over who can approve, change policy, or widen an agent's scope.
  • Evidence for oversight, automaticallyEvery proposal, approval, command and result is recorded and tied to the finding — continuous-monitoring evidence and incident review material without extra work.
  • Works with what you already operateSIEM, EDR, ITSM, scanners, M365 GCC and Azure Government via API and MCP; servers and network devices directly over SSH, PowerShell and NETCONF. No rip-and-replace.

How it applies

Mission-oriented security operations.

Concrete ways agencies put DIRVA to work — each governed, logged and inside the boundary.

Continuous monitoring, not periodic reports

Live dashboards of exposure, vulnerability posture and configuration state refresh on schedule, with every run's evidence retained — the artifacts a continuous-monitoring program needs, produced as a by-product of operations.

Learn more

Baseline and hardening compliance

Agents check servers, network devices, cloud and M365 GCC settings against your hardening baseline and show exactly which checks pass and which fail — and re-verify on demand.

Vulnerability posture across enclaves

Scans and CVE intelligence matched to the products actually in your environment, prioritized by exploitability and reachability, tracked to validated closure.

Investigation and response with approval

Agents gather evidence across your tools and draft the remediation; execution waits for an authorized approver, then is validated and recorded.

Software and supply-chain risk

Dependency and static code scanning with secret detection across mission repositories, with new findings flagged run over run.

Legacy and network infrastructure

Direct access over SSH, PowerShell and NETCONF reaches the systems that have no modern API — under the same scoped credentials and approvals.

Oversight and assurance

Designed for environments that answer to auditors.

DIRVA is built to operate under risk-management and continuous-monitoring practices: enforced least privilege for agents and people, approval gating on actions with impact, complete and tamper-evident run records, and no dependence on external services for core operation.

We do not display certifications or assessments that have not been formally completed. Compliance documentation is published in the Trust Center as it becomes available; contact us for the current status and supporting documentation for your authorization process.

FAQ

Questions government teams ask first.

Yes. DIRVA is designed for controlled and air-gapped environments: vulnerability definitions, CVE intelligence and rule packs are stored locally, and core operation requires no outbound connectivity. Optional feeds can be enabled under your policy.

DIRVA supports a controlled model architecture, including local or private models where configured. Model selection is a deployment decision made with your team. No PII reaches any model — findings are minimized and redacted inside the platform before a prompt is built.

Only users with the appropriate role. Actions with operational impact are approval-gated by default; who can approve, change policy or widen an agent's scope is governed by RBAC and logged.

Every run keeps its full record: what was checked, every command and every result, plus every agent proposal, policy decision and human approval — tied to the finding it relates to and retained under a configurable policy.

We publish assessments and certifications in the Trust Center only once they are formally completed. Contact us for the current status and for documentation to support your authorization package.

Get started

Bring DIRVA inside your boundary.

Talk to our team about deployment inside your enclave, model options, approval workflows, and the evidence your authorization process needs.