

DISX ISOLATE
Secure isolated network environment for above OFFICIAL operations
- Home
- Secure Solutions
- Isolate
DISX Isolate is a hardened, high-assurance standalone enterprise network engineered for above OFFICIAL classified and deliberately isolated environments where internet connectivity is restricted by design.
While DISX Secure Collaboration provides a managed environment for organisations that need to collaborate securely across users, teams and programmes, DISX Isolate is designed for operating conditions where external connectivity cannot be assumed or where deliberate separation is required.
Within this controlled environment, DISX Isolate provides secure document production, enterprise services and controlled data exchange, supported by structured update management and embedded operational governance. Its deliberately air-gapped architecture enables operation above OFFICIAL where isolation forms part of the security requirement.

DISX Isolate operates as a non-internet-connected system deployed within an FSC-approved location and aligned to appropriate physical and environmental controls.
The architecture enforces separation between operational workloads and external networks. Internet access is not assumed. Data movement is deliberate and policy-controlled.
Core capabilities include:
- Hardened offline enterprise environment
- Virtualised infrastructure using Hyper-V
- Secure document creation workloads
- Policy-controlled IMPEX processes
- Optional CHECK testing
- Formal security assurance case development
DISX Isolate can be configured to suit specific programme requirements, including:
- VDI deployments using thin or zero clients
- Non-VDI deployments using secured laptops or desktops
- Resilient or non-resilient infrastructure models
- Single-user endpoint deployments for tightly scoped use cases
This flexibility allows organisations to implement isolated capability proportionate to operational need.

Core Enterprise Services
DISX Isolate provides a complete standalone enterprise environment, complete with services structured to support operational resilience and evidential assurance within high-security estates.
Data LAN
- Active Directory
- Group Policy
- DNS and DHCP
- File services
- Network Policy Server
- Certificate Authority
Management LAN
- Backup services
- Network monitoring
- Centralised logging and SIEM integration
- Vulnerability scanning
DISX Isolate supports structured IMPEX processes, typically integrated with assured media scanning solutions such as Secure File Gateway.
Files introduced into the environment are sanitised, verified and logged prior to release.
DISX Isolate introduces patches and software updates through a controlled update server model without direct internet exposure. Updates are verified, governed and deployed through structured processes.
This preserves isolation while maintaining operational currency.
Assurance Built In
The system is structured to generate and maintain artefacts required for regulated operation, including CSM compliance evidence, Secure by Design alignment and accreditation documentation.
Typical Use Cases
- Classified project teams operating with high-assurance requirements
- Engineering and design work within isolated defence environments
- Secure document production in non-internet-connected estates
- Standalone secure environments within larger accredited facilities
- Temporary or programme-specific classified enclaves



Environmental Requirements
- FSC-approved hosting location
- Appropriate security furniture and physical controls
- Optional offsite backup location where resilience is required
