Who we serve

Built for organizations where security and control matter.

Government, public sector, private sector, defense and intelligence, and the providers that serve them — anyone who wants the speed of agentic AI without giving up control of their environment, their data, or their decisions.

Government

Not every agency runs the same way. DIRVA deploys in two postures.

A county IT department and a classified defense network need the same capabilities under very different constraints. DIRVA runs as the same platform in both — what changes is how it's connected, updated, and allowed to reach out.

Connected postureGovernment, public & private sector
Disconnected postureDefense, intelligence & classified
Typical environments
Federal civilian agencies · state and local government · education, public health, utilities · regulated private-sector enterprises
Defense and intelligence · classified networks · SCIFs and other high-side enclaves
Network
On-premises appliance inside the agency boundary; connected to agency cloud tenants (M365 GCC, Azure Government)
Fully air-gapped. No outbound path exists; nothing depends on outside connectivity
Updates & intelligence
Vulnerability definitions, CVE intelligence and rule packs pulled on a schedule under your policy
Delivered offline via approved removable media or an internal mirror; stored locally
AI models
Local or private models where configured; agency-approved hosted models allowed under policy
Local models only, running inside the enclave
Data flow
Security data stays inside the boundary; only policy-approved feeds cross it
No data leaves the enclave — ever
Integrations
SIEM, EDR, ITSM, scanners, M365 GCC and Azure Gov via API and MCP
In-enclave tools via API and MCP; legacy and network gear over SSH, PowerShell and NETCONF
Approval & evidence
Human approval on every action with impact; every run recorded for continuous monitoring
Same — plus autonomy scoped per action and per enclave, and complete records for review

Connected posture

Federal civilian, state and local: inside your boundary, connected on your terms.

For agencies that operate connected networks, cloud tenants and shared services. DIRVA sits on your infrastructure, integrates with your tooling, and reaches outside the boundary only for feeds you've approved.

AGENCY NETWORK BOUNDARYYOUR ENVIRONMENTDIRVA APPLIANCEYOUR SECURITY STACKEndpointsServersApplicationsCloudRepositoriesNetworkSIEMEDR / XDRITSM / ticketingThreat IntelScannersM365 GCC / Azure GovDIRVA EnterpriseON-PREMISES VIRTUAL APPLIANCEDiscoveryVulnerability IntelligenceAgentic AIRAGMCP · APIAutomation EngineRemediationGOVERNANCE · BUILT INPolicy engineHuman approvalAudit logPII redactionAI models · local, private, or agency-approved hostedPOLICY-CONTROLLEDOUTBOUNDSecurity data stays inside · only policy-approved feeds cross the boundary (vulnerability definitions, threat intelligence, updates)
  • Inside your boundary, integrated with your tenantOn-premises appliance connected to M365 GCC, Azure Government and the security tools you already run.
  • Continuous monitoring, evidence includedLive dashboards of exposure, vulnerability posture and configuration state refresh on schedule and keep every run's record.
  • Outbound only where you allow itVulnerability definitions, CVE intelligence and updates are pulled on your schedule under your policy — never security data.
  • Human approval on every actionAgents propose; authorized staff approve. Role-based control over who can approve or widen an agent's scope.
  • No PII to any modelFindings are minimized and redacted inside the platform before a prompt is built — local, private or approved hosted models alike.
  • Built for lean teamsRoutine investigation, enrichment, ticketing and re-verification carried by agents, so a small team covers a large estate.

Disconnected posture

Defense, intelligence and classified: fully air-gapped, nothing leaves the enclave.

For SCIFs, high-side networks and any environment where an outbound connection is not an option. The same platform, sealed: local models only, offline updates, and a complete record of every agent decision for review.

ACCREDITATION BOUNDARY · CLASSIFIED ENCLAVEYOUR ENVIRONMENTDIRVA APPLIANCEYOUR SECURITY STACKEndpointsServersApplicationsCloudRepositoriesNetworkSIEMEDR / XDRTicketingThreat Intel (offline)ScannersNetwork devicesDIRVA EnterpriseON-PREMISES VIRTUAL APPLIANCEDiscoveryVulnerability IntelligenceAgentic AIRAGMCP · APIAutomation EngineRemediationGOVERNANCE · BUILT INPolicy engineHuman approvalAudit logPII redactionAI models · local only · inside the enclaveNO EXTERNALDEPENDENCYAir-gapped · updates and rule packs delivered offline via approved media · nothing leaves the enclave
  • Air-gapped by designNo outbound path exists. Vulnerability definitions, CVE intelligence and rule packs are delivered offline and stored inside the enclave.
  • Local models onlyAI runs on models inside the boundary. Nothing is sent to any hosted service, and no PII reaches any model regardless.
  • Autonomy scoped per action, per enclaveRecommend, approve, or a narrow pre-approved scope — set by you, revocable instantly, logged every time.
  • Complete, reviewable recordsAgent reasoning, tool calls, inputs and outputs retained for review and tied to each finding.
  • Mission-system reachDirect access to legacy and network infrastructure over SSH, PowerShell and NETCONF under scoped credentials.
  • Evidence for authorizationEvery run's record supports continuous monitoring and incident review; documentation for your authorization process is available on request.

Public sector

Enterprise-grade security operations for teams that don't have enterprise-sized staff.

State and local government, education, public health and utilities face the same threats as federal agencies with a fraction of the people. DIRVA's agents carry the routine work — continuously, on your own infrastructure.

  • Continuous monitoring without a monitoring teamLive dashboards of exposure, vulnerability posture and configuration state refresh on schedule and keep their evidence.
  • Compliance baselines, checked by agentsHardening and configuration checks across servers, network gear and Microsoft 365 — re-verified on demand.
  • Fits the tools you haveWorks with existing scanners, SIEM, ticketing and M365 GCC; no rip-and-replace.
  • Predictable costA stronger model designs; a cheaper, faster model handles routine refreshes. Runs on your appliance, not a metered cloud.
External attack surface · production ranges Refreshed 12s ago · next run 06:00 · run #418
Critical3+1 since last run
High11−2 since last run
Open ports184+2 new
Hosts62+1 newly exposed
Changed since last run
  • New10.40.12.7 TCP/22 open · OpenSSH 9.6 · Ubuntu 22.04
  • New10.40.18.3 TCP/8443 open · nginx 1.24
  • Hostvpn-edge-02 first seen this run
Needs attention first
  • 10.0CVE-2024-3094 build-runner-07 Investigated · evidence · fix proposed
  • 9.8CVE-2024-6387 vpn-edge-02 Investigated · evidence
  • 8.1CVE-2023-44487 api-gw-03
Rescan now Re-verify this finding Collect evidence Buttons run the instructions you wrote · every run keeps its full transcript

Private sector

For regulated enterprises that need audit-ready control over what AI is allowed to do.

Finance, healthcare, energy, critical infrastructure and any enterprise answerable to auditors, regulators or a board. Private-sector deployments run the connected posture: inside your boundary, integrated with your tenant, outbound only where you allow it.

Audit-ready by default

Every proposal, approval and action is logged with evidence and tied to the finding — ready for compliance review without extra work.

Contextual prioritization

Findings ranked by exploitability, reachability and business impact — not just a CVSS number — so teams fix what matters first.

Data stays inside

On-premises deployment, your choice of models, and no PII ever sent to any model.

Across the whole estate

Endpoints, servers, cloud, repositories and network infrastructure — one lifecycle from detection to validated closure.

DevSecOps built in

Dependency and code scanning with secret detection, findings routed into the trackers developers already use.

Existing stack, not a new one

SIEM, EDR, ITSM and cloud platforms via API and MCP; legacy systems over SSH, PowerShell and NETCONF.

Security providers

Operate DIRVA inside each customer's environment — their data stays put.

MSSPs, MDR providers and integrators deliver AI-assisted vulnerability intelligence and automation to the customers they protect, without moving customer data into a shared platform.

  • Per-customer deploymentA DIRVA appliance inside each supported customer environment; data never leaves the customer boundary.
  • Consistent workflows across customersStandardize investigation, remediation and reporting; run the same dashboards everywhere.
  • Evidence per customerEach customer's runs, approvals and outcomes are recorded in their own environment for their own audits.
  • Integration, not migrationWorks with whatever tooling each customer already has.

Partner program

Technology partners, integrators and resellers — talk to us.

Learn more

Government customers

Deliver DIRVA into enclaves and accreditation boundaries.

Learn more

Oversight and assurance

Designed for environments that answer to auditors.

DIRVA is built to operate under risk-management and continuous-monitoring practices: enforced least privilege for agents and people, approval gating on actions with impact, complete run records, and no dependence on external services for core operation.

We do not display certifications or assessments that have not been formally completed. Compliance documentation is published in the Trust Center as it becomes available; contact us for the current status and supporting documentation for your authorization or audit process.

FAQ

Questions we're asked first.

Yes. DIRVA is designed for controlled and air-gapped environments: vulnerability definitions, CVE intelligence and rule packs are stored locally, and core operation requires no outbound connectivity. Optional feeds can be enabled under your policy.

DIRVA supports a controlled model architecture, including local or private models where configured. Model selection is a deployment decision made with your team. No PII reaches any model — findings are minimized and redacted inside the platform before a prompt is built.

Only users with the appropriate role. Actions with operational impact are approval-gated by default; who can approve, change policy or widen an agent's scope is governed by RBAC and logged.

Every run keeps its full record: what was checked, every command and every result, plus every agent proposal, policy decision and human approval — tied to the finding it relates to and retained under a configurable policy.

We publish assessments and certifications in the Trust Center only once they are formally completed. Contact us for the current status and for documentation to support your authorization or audit package.

Get started

Bring DIRVA inside your boundary.

Talk to our team about deployment in your environment, model options, approval workflows, and the evidence your oversight process needs.