Diagrid
Back to all questions
Run-Anywhere Operations

What security considerations apply when running agent workloads in air-gapped environments with Catalyst?

Catalyst enforces workload identity via SPIFFE-compatible certificates and MCP tool authorization policies, which work offline if PKI is locally managed. All inter-service communication uses mutual TLS, and secrets are stored in a local vault. You must configure network egress rules to block unintended outbound calls. The platform itself does not require internet access once deployed, reducing attack surface.

Was this article helpful?

Your feedback helps improve Diagrid's FAQ experience.

Keep reading

More Diagrid FAQ articles

View all