Skip to content

In-VPC Deployments

In-VPC (Virtual Private Cloud) deployments place the DeepIntShield data plane in your cloud boundary. Configured model providers, identity systems, telemetry destinations, and an optional managed control plane may still require explicit egress; review the deployment data-flow diagram and contract for your topology.

Available targets depend on the purchased deployment package and the networking features of the target. Confirm the supported architecture with DeepIntShield before committing infrastructure:

Google Cloud Platform
Amazon Web Services
Microsoft Azure
Cloudflare
Vercel
  • Network Isolation: Private ingress and controlled egress within your VPC policies
  • Data Sovereignty: Keep gateway-side processing in your controlled environment; configured upstream and export destinations remain part of the data flow
  • Compliance Controls: Can support regulated deployments when configured and operated with the required organizational controls; obtain a compliance and legal review for your use case
  • Zero Trust Architecture: Implements principle of least privilege with granular access controls
  • Low Latency: Direct communication between services within your network
  • High Availability: Multi-zone deployment with automatic failover capabilities
  • Contracted Availability: Service levels, if purchased, are defined by the applicable order form and SLA
  • Custom Networking: Configure subnets, routing, and security groups to your specifications
  • Resource Management: Full control over compute, storage, and network resources
  • Scaling Policies: Define auto-scaling rules based on your usage patterns

The figures below apply only when they appear in your executed SLA; the deployment architecture by itself does not create an availability guarantee.

  • Example contracted target: 99.95% monthly uptime for covered core components
  • Downtime Calculation: (Total Minutes - Downtime Minutes) / Total Minutes × 100
  • Partial Downtime: Reduced functionality counted as 50% downtime

The following components are monitored for SLA compliance:

  • Gateway instance
  • Log ingestion pipeline

SLA excludes downtime due to:

  • Scheduled maintenance (14-day advance notice)
  • Downstream provider incidents
  • Client hardware/software/network issues
  • Third-party AI provider outages
  • Client misuse or unauthorized modifications
  • Critical Support: Coverage hours and response targets follow the purchased support plan
  • Multiple Channels: Platform, your DeepIntShield support contact, or Slack Connect
  • Audit Trail: Detailed logs for any data access during troubleshooting
  • Scheduled Maintenance: 14-day advance notice for major updates
  • Security Patches: Immediate or 14-day delayed application (your choice)
  • Continuous Updates: Regular feature improvements with 7-day advance notice
  • VPC with appropriate CIDR ranges
  • Kubernetes cluster (GKE, EKS, or AKS)
  • Container registry access
  • DNS configuration for internal routing
  1. Infrastructure Setup: Configure VPC, subnets, and security groups
  2. Cluster Preparation: Set up Kubernetes cluster with required permissions
  3. DeepIntShield Installation: Deploy using provided Helm charts or manifests
  4. Configuration: Apply your specific settings and integrations
  5. Validation: Run connectivity and performance tests
  6. Go Live: Begin routing production traffic
  • Development: 2 vCPU, 4GB RAM minimum
  • Production: 4+ vCPU, 8GB+ RAM recommended
  • High Availability: Multi-zone deployment with load balancing
  • Horizontal Pod Autoscaling: Based on CPU/memory utilization
  • Vertical Pod Autoscaling: Automatic resource adjustment
  • Cluster Autoscaling: Node pool expansion/contraction