Prove what you publish: restricted networks
Control how updates enter your network
This page describes how the product works today. It contains no customer names, quotes, or measured results. Where a number belongs, we say what is still needed to produce one.
- added Record which approved sources supplied your packages.
- added Serve frozen package sets inside your network.
- added See what changed between one snapshot and the next.
The failure mode is a restricted network where each server fetches updates independently and nobody can reconstruct the installed package set.
Who it serves
Built for engineers who control outbound access and need a reliable record of which packages were approved for internal delivery.
The problem in the field
Restricted networks still need software updates. When every machine reaches upstream independently, versions drift and outbound access becomes difficult to control. Teams need an internal source of approved package sets.
How it helps
Package-Master runs inside your network. Your deployment initiates sync with approved upstream sources through controlled outbound access, freezes mirrored packages into snapshots, and publishes them to internal machines. Changes between snapshots are listed for you. Physical transfer into fully disconnected networks is in development.
When it fails
Without outbound access, upstream sync and advisory updates stop. Already stored packages remain available inside your network. The physical transfer workflow for a fully disconnected deployment is not ready today. Package-Master depends on PostgreSQL; operate and back up that database as a production dependency.
Measured impact
No measured customer results are published yet.
What you can hand over
You can show which snapshot is live inside the network, what it contains, and how it differs from the previous one. Package-Master does not certify your organization and does not produce audit reports.
Questions a hostile engineer asks
- Is air-gapped deployment available now?
- Restricted-network deployment with controlled outbound sync is available today. Physical transfer into fully disconnected networks is in development.
- Does anything phone home for licensing?
- No. Offline licensing is part of the Sovereign plan. Nothing needs to reach us to keep running.
- How does advisory data get in?
- Through the same controlled outbound access. The feeds need outbound HTTPS to the issuers. A deployment with no outbound path does not populate advisory data. The full statement of that boundary is on the supported page.
- Do you need access to our network?
- No. We have no route in and want none. Deployment is run by your team.
- Where is this built?
- In Canada. It is a product of 1001379963 Ontario Inc. It runs inside your network, so your package data stays where you put it.
Related solutions
- Control where your software comes from One allow-list. No machine quietly pulling from a stranger's repository.
- Check which snapshots carry a flawed package A flaw is published. See which of your sets hold the package, from the snapshot record.
- Put the same packages on every machine Point every machine at one frozen set. Stop drift before it starts.
Run Scout on one environment
Start on a connected environment. No secrets required.
Run Scout on one environment