Deployment Models
Flexible architectural options tailored to your regulatory, compliance, and sovereignty needs.
One size does not fit all in enterprise security. While growing companies benefit from our turnkey shared managed service, organisations with strict data residency requirements or sensitive IP need isolated or self-hosted infrastructure.
Dedicated Environment
A completely isolated, single-tenant ZIMA stack deployed in a dedicated cloud VPC or sovereign European / regional data centre. No sharing of database instances, search clusters, or manager processes with any other organisation.
ARCHITECTURAL CHARACTERISTICS
- 100% single-tenant compute, storage, and database cluster
- Strict geographic data residency (UK, EU, Canada, or specific region)
- Customizable telemetry retention periods (1 year, 3 years, 7 years)
- Direct integration with private internal systems and VPNs
BEST SUITED FOR
Organisations operating under stringent data sovereignty regulations, financial institutions, healthcare providers, or legal entities where telemetry mixing is explicitly prohibited.
Customer-Hosted Model
The entire ZIMA software stack is deployed directly within your own cloud account (AWS, Azure, GCP) or your on-premises VMware/Proxmox cluster. Your raw telemetry data never leaves your physical or cloud perimeter.
ARCHITECTURAL CHARACTERISTICS
- Infrastructure runs entirely on customer-owned compute and storage
- Raw event logs and telemetry never transit outside your network
- ZIMA manages detection engineering, triage, and rule tuning via secure remote access
- Customer maintains full root-level control and cryptographic keys
BEST SUITED FOR
Critical infrastructure operators, defense suppliers, government agencies, or high-security enterprises requiring absolute physical and operational data custody.
Comparative Architecture Matrix
Evaluate which model best balances your infrastructure control, compliance obligations, and operational budget.
| CRITERIA | SHARED MANAGED | DEDICATED ENVIRONMENT | CUSTOMER-HOSTED |
|---|---|---|---|
| Infrastructure Location | ZIMA Managed Cloud | Isolated Cloud VPC | Customer Datacentre / Cloud |
| Data Tenancy | Multi-tenant (Logically Isolated) | 100% Single-Tenant | 100% Single-Tenant |
| Data Leaves Customer Boundary? | Yes (Encrypted Telemetry) | Yes (To Dedicated VPC) | No (Stays Within Perimeter) |
| Maintenance & Updates | 100% Managed by ZIMA | 100% Managed by ZIMA | Joint / Managed Application Layer |
| Onboarding Timeline | Fastest (24 - 48 Hours) | 1 - 2 Weeks | 2 - 4 Weeks |
| Cost Profile | Predictable Monthly / Per-Host | Infrastructure + Retainer | Management Retainer |
Determine the Right Architecture for Your Fleet
Consult with a senior security architect to review your network topologies, regulatory mandates, and telemetry sizing.