

DISX ISOLATE
Secure isolated network environment for high-assurance operations
DISX Isolate is a hardened, standalone enterprise network engineered for classified and deliberately isolated environments where internet connectivity is restricted by design.
In operating conditions where external connectivity cannot be assumed, DISX Isolate provides a controlled enterprise environment with structured update management and embedded operational governance.
It enables secure document production, enterprise services and controlled data exchange within a deliberately air-gapped architecture designed for high-assurance operation.

DISX Isolate operates as a non-internet-connected system deployed within an FSC-approved location and aligned to appropriate physical and environmental controls.
The architecture enforces separation between operational workloads and external networks. Internet access is not assumed. Data movement is deliberate and policy-controlled.
Core capabilities include:
- Hardened offline enterprise environment
- Virtualised infrastructure using Hyper-V
- Secure document creation workloads
- Policy-controlled IMPEX processes
- Optional CHECK testing
- Formal accreditation case development
DISX Isolate can be configured to suit specific programme requirements, including:
- VDI deployments using thin or zero clients
- Non-VDI deployments using secured laptops or desktops
- Resilient or non-resilient infrastructure models
- Single-user endpoint deployments for tightly scoped use cases
This flexibility allows organisations to implement isolated capability proportionate to operational need.

Core Enterprise Services
DISX Isolate provides a complete standalone enterprise environment, complete with services structured to support operational resilience and evidential assurance within high-security estates.
Data LAN
- Active Directory
- Group Policy
- DNS and DHCP
- File services
- Network Policy Server
- Certificate Authority
Management LAN
- Backup services
- Network monitoring
- Centralised logging and SIEM integration
- Vulnerability scanning
DISX Isolate supports structured IMPEX processes, typically integrated with assured media scanning solutions such as Secure File Gateway.
Files introduced into the environment are sanitised, verified and logged prior to release.
DISX Isolate introduces patches and software updates through a controlled update server model without direct internet exposure. Updates are verified, governed and deployed through structured processes.
This preserves isolation while maintaining operational currency.
Assurance Built In
The system is structured to generate and maintain artefacts required for regulated operation, including CSM compliance evidence, Secure by Design alignment and accreditation documentation.
Typical Use Cases
- Classified project teams operating with high-assurance requirements
- Engineering and design work within isolated defence environments
- Secure document production in non-internet-connected estates
- Standalone secure environments within larger accredited facilities
- Temporary or programme-specific classified enclaves
Environmental Requirements
- FSC-approved hosting location
- Appropriate security furniture and physical controls
- Optional offsite backup location where resilience is required



