Glossary
Zero-egress deployment
A deployment configured so that no data can leave the environment — outbound network paths are removed or blocked by default.
A zero-egress deployment is one configured so that data cannot flow out of the environment: outbound network connections are removed, blocked or tightly constrained so there is no route by which prompts, retrieved documents, model outputs or model weights can be transmitted to an external destination. The emphasis is specifically on egress — the direction that would carry sensitive data away — as the thing that must be prevented.
The term is used because it names the precise property that matters for confidentiality. An environment can permit tightly controlled inbound access, or none at all, while still guaranteeing that nothing leaves. Enforcing zero egress means denying outbound traffic by default and permitting only explicitly reviewed exceptions, so the absence of a data-exit path is a designed and evidenced control rather than an assumption.
Zero-egress deployment sits on the spectrum between a standard on-premises deployment, which may retain some outbound connectivity for updates and supporting services, and a full air gap, which removes network connectivity altogether. It is often the pragmatic target for sensitive workloads: it delivers the assurance that data cannot leak out while still allowing the environment to be operated more conveniently than a completely isolated system. Necessary updates are handled through a controlled, audited inbound process.
Discuss a secure AI deployment
We help organisations adopt AI inside their own security and compliance perimeter — vendor-neutral, and designed around the constraints you actually operate under.
Get in touch