For every client who wants their own private cloud, Vavelio builds air-gapped environments. No server has direct internet access. Every update, every package, every container image flows through controlled, audited pipelines.
By default, every private cloud we build operates in an air-gapped configuration. Servers have no default route to the internet. Packages, updates, and container images are delivered through controlled proxy infrastructure — VPRS, VCRS, and VDNS — that act as the single point of controlled ingress.
Servers ship without a default gateway to the public internet. Outbound connectivity is explicitly granted, not implicitly available.
All external content — OS updates, packages, container images — enters through VPRS and VCRS proxy infrastructure. Scanned, approved, and distributed internally.
Air-gapped does not mean disconnected. It means every connection is intentional. Our proxy infrastructure (VPRS) handles OS updates. VCRS handles container images. VDNS handles DNS. Wazuh SIEM monitors every permitted connection. Nothing talks to the internet unless it goes through a gate you control, logged and auditable.