Sovereign SSE - Self-hosted Security Service Edge

Your data is none of our business.

Full inline inspection of every outbound request - firewall, DLP, CASB and ZTNA - running entirely in your own infrastructure. No vendor cloud in the path.

SBOM on every release No CLOUD Act exposure Self-host anywhere No vendor cloud
The problem

Most secure web gateways protect your network by surveilling your people. Every URL, every query, every byte - logged, retained, and turned into someone's data asset.

Logging is a liability

Every retained log is a breach waiting to happen and a subpoena waiting to land.

Latency is a tax

Cloud round-trips and decryption queues slow every user, every day.

Trust shouldn't require faith

"We don't look at your data" means nothing if the architecture still can.

Capabilities

One gateway. Every control. Nothing kept.

A complete secure web gateway - firewall, data-loss prevention, cloud app control and ZTNA - running in your own infrastructure. Allod Solutions has no access to your traffic.

Inline firewall

Rules evaluated per-domain before each connection is established - wildcard domains, categories, geo-based rules and process-aware filtering. Allow, block or proxy applied in real time with no round-trip to a vendor cloud.

Process-aware

Data Loss Prevention

Keyword lists, regex patterns and file-type detection at five configurable inspection depths - from headers-only to full body. Rule-triggered samples stored in your own S3 bucket, encrypted with an HKDF-derived key per device.

Per-device encryption

CASB controls

Discover and govern shadow IT. Sanction cloud apps, enforce tenant restrictions and stop risky uploads.

App-aware

GDPR tooling

Article 15 data export and Article 17 erasure built into the admin UI. No support ticket, no vendor involvement.

Audit-ready

Self-hosted, anywhere

Run it in your own datacenter, on a cloud provider of your choice, or both. Single node to start - scale out to multiple PoPs as your fleet grows.

Your infrastructure

Full API

Every rule, key and report is scriptable. Automate provisioning and wire ALLOD into your existing stack.

REST + webhooks
ALLOD | DAM

From shadow IT discovery to governed inventory - automatically.

When SWG observes a new application on the fleet, DAM queues it for triage. Automated probing and a local LLM do the groundwork - so your team reviews conclusions, not raw documents. No data leaves your infrastructure.

Automated vendor risk

DAM probes TLS config, hosting geography and DNS records, then fetches and parses the privacy policy and DPA. A local LLM extracts retention periods, subprocessor lists and breach notification commitments.

Privacy-first

Ownership chain monitoring

Every vendor matched against the Global LEI Index - verified legal entity and full ownership chain to ultimate parent. When an acquisition moves a vendor to a new jurisdiction, DAM detects it before your next review cycle.

GLEIF-verified

EU sanctions screening

Continuous checks against the EU consolidated sanctions list for every vendor and its ultimate parent. A match triggers an immediate alert - you find out before your legal team has to ask.

Real-time

GDPR workflows & Art. 30

Configurable review cycles - annual, contract renewal, DPIA - with structured fields and owner assignments. The Article 30 Records of Processing Activities register is built in, not bolted on.

Audit-ready
Deployment

Your PoPs. Your providers. Your rules.

With cloud SWGs you get their PoPs, their locations, their availability incidents. With ALLOD you decide where your traffic is inspected - Stockholm, Frankfurt, Tokyo, your own rack - and which provider hosts it.

All proxy nodes pull config from a single controller and enforce the same policy. Moving a node or adding a region is a matter of starting a new binary and pointing it at the controller.

Single node to start

Controller and proxy in one binary, SQLite, no external dependencies. Operational in minutes on any Linux host.

Scale out - stateless proxy nodes

Add proxy nodes in any region. Each one polls the controller for config every 30 seconds and applies rules atomically - no connection drops during updates.

Geo-aware routing built in

Agents measure latency to all proxy nodes and automatically route to the nearest healthy one - no DNS infrastructure, cloud load balancer, or global traffic manager required.

Connectors for private networks

On-prem connector daemons connect out to the controller - no inbound firewall rules needed for agents to reach internal resources.

How it works

Inspect everything. In your infrastructure.

Four steps from raw traffic to a secured request - all of it in an environment you control.

1

Route

Traffic reaches the gateway inline via transparent proxy to the infrastructure of your choice

2

Inspect

Firewall, DLP and CASB engines evaluate the request in memory - process, user, content and TLS fingerprint all considered.

3

Decide

Allow, block or proxy is applied instantly according to your policy - deterministic and explainable.

4

Log

Rule-triggered events are stored in your encrypted event log. Regular traffic is not retained. You set the retention window.

The guarantee

Zero vendor access. Full operator control.

ALLOD runs in your infrastructure. Allod Solutions has no access to your traffic, your event log or your policy - by architecture, not by promise.

0
Vendor access to your data
Not anonymized and shipped to us. Not held in a shared cloud. Not subject to a vendor's jurisdiction. Zero - because we never have it.
By the numbers

Security teams don't compromise. Neither should privacy.

0
VENDOR ACCESS TO YOUR TRAFFIC
5
DLP INSPECTION DEPTHS
30s
POLICY UPDATE PROPAGATION
3
ENDPOINT PLATFORMS
Questions

Frequently asked questions

Can Allod Solutions see our network traffic?

No. ALLOD runs entirely inside your own infrastructure. Traffic, event logs, and policies never leave your environment - Allod Solutions has no technical access to any of it.

Is ALLOD a SaaS product, or do we run it ourselves?

ALLOD is self-hosted only. It is not offered as a SaaS. You deploy it in your own data centre or private cloud, and it stays under your operational control.

How is ALLOD different from Zscaler, Netskope, or Palo Alto Prisma Access?

Cloud SSE vendors inspect your traffic by routing it through their infrastructure. ALLOD performs the same inline inspection - firewall, DLP, CASB, ZTNA - but the enforcement point runs on hardware you control, so there is no vendor cloud in the traffic path.

Does ALLOD reduce our exposure to the US CLOUD Act or FISA 702?

Yes. Because there is no US-incorporated intermediary in the data path, there is no vendor infrastructure that a CLOUD Act or FISA 702 order could compel access to. Your traffic and logs stay under your own jurisdiction.

Can ALLOD replace our VPN for remote access to internal resources?

Yes. ALLOD ZTNA gives per-resource access to internal systems without opening inbound firewall rules, using the same policy engine and event log as the rest of the proxy.

What happens if the Allod license server becomes unreachable?

Enforcement continues uninterrupted using the last-known threat feed and policy set cached on each proxy node. A temporary loss of connectivity to the license server does not open a gap in protection.

Does ALLOD integrate with our identity provider and EDR?

Yes. ALLOD supports SCIM v2 sync from Okta, Microsoft Entra ID, and Authentik, OIDC for admin login, and pushes detections to CrowdStrike Falcon as custom IOCs.

What does ALLOD DAM do for GDPR compliance?

DAM auto-populates an audit-ready GDPR Article 30 register from discovered vendor and shadow IT data, and screens vendors against EU sanctions lists - all without sending your data outside your infrastructure.

Get started

See it run in your environment.

Book a 30-minute demo with our engineering team. Bring your hardest policy - firewall, DLP, CASB or ZTNA - and we'll walk through how it works end to end.