Skip to content

Control Deployment

You run everything in your environment. Data never leaves your site.

Overview

  • Compute: Your infrastructure
  • Storage: Your S3-compatible storage (BYOB required)
  • AI: Your API keys or local LLM (BYOA required)
  • Support: Priority email, documentation

Why Control?

Control deployment is designed for organizations that:

  • Must maintain compliance certifications (FedRAMP, SOC 2, HIPAA, PCI-DSS, ITAR, CJIS)
  • Have data residency requirements
  • Operate in regulated industries
  • Need air-gapped or isolated deployments
  • Want complete control over infrastructure

Requirements

Infrastructure

  • Kubernetes cluster (recommended) or bare metal/VM
  • S3-compatible storage (MinIO for on-prem, or cloud S3)
  • Network connectivity between components
  • TLS certificates

Sizing

Scale CPU Memory Storage
Small (< 1GB/day) 4 cores 8 GB 100 GB
Medium (1-10 GB/day) 8 cores 16 GB 500 GB
Large (10-100 GB/day) 16 cores 32 GB 2 TB
Enterprise (100+ GB/day) Contact us Contact us Contact us

Installation

1. Get license

Contact sales@bytefreezer.com for a Control license key.

2. Deploy storage

If using MinIO for on-prem S3:

helm repo add minio https://charts.min.io/
helm install minio minio/minio \
  --set rootUser=admin \
  --set rootPassword=changeme \
  --set persistence.size=500Gi

3. Deploy bytefreezer

helm repo add bytefreezer https://charts.bytefreezer.com
helm install bytefreezer bytefreezer/bytefreezer \
  --set license.key=YOUR_LICENSE_KEY \
  --set storage.endpoint=http://minio:9000 \
  --set storage.bucket=bytefreezer \
  --set storage.accessKey=admin \
  --set storage.secretKey=changeme \
  --set ai.provider=openai \
  --set ai.apiKey=YOUR_API_KEY

4. Deploy proxies

On each system you want to monitor:

helm install bytefreezer-proxy bytefreezer/proxy \
  --set control.endpoint=https://control.internal:8080 \
  --set control.token=YOUR_TOKEN

Air-Gapped Installation

For environments without internet access:

1. Download offline bundle

On a connected system:

bytefreezer-cli download-bundle --version latest --output bundle.tar.gz

2. Transfer to air-gapped environment

Use approved media transfer process.

3. Load images

tar -xzf bundle.tar.gz
./load-images.sh

4. Install from local registry

helm install bytefreezer bytefreezer/bytefreezer \
  --set global.imageRegistry=registry.internal:5000 \
  --set license.key=YOUR_LICENSE_KEY \
  # ... other config

Compliance

Control deployment preserves your existing certifications:

  • FedRAMP: Air-gapped option, no data egress
  • SOC 2: Your controls remain intact
  • HIPAA: PHI never leaves your environment
  • PCI-DSS: Cardholder data stays in your CDE
  • ITAR: No data export, defense contractor compliant
  • CJIS: Criminal justice data stays in boundary

See Certifications for details.

Next Steps