Air-Gapped Deployment
Decoders work fully offline — no network syscalls of any kind. This page covers operational considerations for deploying to DoD, SCIF, industrial-control, or aviation environments.
Runtime network: zero
Bitruvius decoders make no network calls during operation. You can confirm with strace -e trace=network or the equivalent on your platform.
- No DNS
- No HTTPS
- No NTP
- No telemetry
- No update checks
- No license server (decoders are unlicensed; encoder licensing is also fully offline)
Getting the decoder into the enclave
The decoder ships as a static or shared library. Transfer it the same way you transfer any other software:
- Signed release tarballs on a cross-domain workstation, USB transfer in
- Inside your existing signed software package
- Via your organization’s approved internal artifact registry
Size is small and the library has no runtime dependencies beyond libc.
Clock: not used
Decoders don’t check clocks. Your host’s time can be wildly off; decode still works.
Audit logging
Decoders log nothing by default. If you need audit evidence of decode events, wrap the decoder call in your own logging layer.
Cryptography
Decoders don’t perform cryptography. No FIPS-module concerns on the decoder side.
For FIPS 140-3 status of the encoder side and licensing stack, contact sales — it’s covered under NDA with licensed customers.