Air-gapped and sovereign networks

Air-gapped Windows log collection, with nothing to phone home to.

An on-premises log pipeline that needs no internet access to install, license or run. Your logs go to the SIEM you operate, inside the boundary you define, and nowhere else.

  • No telemetry
  • Offline licence keys
  • Updates on your schedule
  • SHA-256, Authenticode, SBOM
  • DPLens Manager, self-hosted

In short

DPLens does air-gapped Windows log collection as a normal deployment, not a special mode: it sends no telemetry, contacts no licensing service, updates only when you choose and has no vendor or cloud control plane. DPLens Manager runs inside your boundary for central configuration, fleet health, deployment and upgrades. Licence keys are signed and verified offline, releases can be checked with SHA-256 checksums, Authenticode signatures and SBOMs before they cross the gap, and logs go only to the on-premises SIEM or collector you configure.

Nothing to phone home to

Does DPLens need internet access?

No. DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. An agent that expects the internet fails in strange ways inside an enclave: licence checks that time out, update services that retry forever, telemetry that fills a proxy log. DPLens has none of these to switch off.

No telemetry

DPLens sends nothing about you, your machines or your events to us. There is no usage reporting and nothing to opt out of.

No licensing service

Keys are verified offline against a publisher key built into the program. Nothing is activated online.

Updates on your schedule

You decide when to upgrade, from a package you fetched and verified, and roll it out across the enclave with DPLens Manager.

No vendor control plane

DPLens Manager, self-hosted and air-gap capable, gives you central configuration and fleet health monitoring from inside your own boundary. It is included in every subscription.

No prerequisites

One executable and its installer. No .NET, no Java, no Visual C++ redistributable, no database to stage into the enclave first.

No surprise listeners

The local console is reachable only from the machine itself unless you allow other addresses. Syslog and NetFlow receivers listen only once you add them.

Offline licensing

How is DPLens licensed without a licensing server?

A DPLens licence key is signed and verified on the machine itself, so there is nothing to activate online. It can travel on approved transfer media or inside a deployment package without a confidentiality concern, and it cannot be altered without invalidating it.

What a key is bound to

  • One machine, locked to that system by several hardware and software identifiers – for a standalone host.
  • One or more Active Directory domains – every machine joined to a named domain or a child of it. One key licenses the enclave's domain members, including golden images and VDI clones.

Getting and applying a key

From the connected side, email contactus@dplens.com with the machine's identity (shown on the console's Licence page) or the Active Directory domain to lock it to, the number of syslog and NetFlow receivers (network sources), and the term. Carry the key in through your approved process and apply it at installation, through DPLens Manager or in the console. The agent verifies the key locally before it starts collecting.

Expiry, without a server to ask

Every key has an expiry date. DPLens warns you 30 days before it and gives 7 days' grace after it, so renewals fit around your media transfer process.

Moving software across the gap

How do I verify a release before it crosses the gap?

Every release ships with SHA-256 checksums, Authenticode signatures and CycloneDX 1.5 and SPDX 2.3 SBOMs. All of it can be checked without contacting us.

  1. Check the checksums

    Compare every file against the published SHA-256 checksums.

  2. Check the Authenticode signature

    Every full release carries an Authenticode SHA-256 signature with an RFC 3161 timestamp on every published executable, the code inside the installer and the installer itself, signed by the DPLens publisher.

  3. Review the SBOM

    The SBOM lists every component compiled into the shipped software and is the complete inventory for your vulnerability process.

  4. Transfer through your approved process

    Move the files on the media and through the checks your enclave requires, then re-run the checksum comparison on the inside before anything is installed.

  5. Let the agent check itself

    At start-up the agent checks its own signature and records the result in its tamper-evident audit trail.

Inside the enclave

Deploy and update with the tools you already have

DPLens Manager

Central configuration, fleet health monitoring, deployment and upgrades for every agent in the enclave. Self-hosted, air-gap capable and included in every subscription.

Group Policy

Assign DPLens to the machines in an organisational unit with Group Policy software installation, credentials included and protected in transit. The Group Policy guide.

Intune and Configuration Manager

Capture a configured machine into one installer package and deploy it with Intune, Configuration Manager or any software distribution tool you already run inside your boundary.

Golden images and VDI

Bake the agent and a domain key into the image. Clones prepared with sysprep detect the new machine identity, start with clean working state and record the reset in the audit trail.

Upgrades that keep state

Upgrade in place and keep configuration, licence, secrets, collection positions, cached events and audit trail.

Console where you want it

Manage agents centrally from DPLens Manager, keep the local console on the machine itself, or allow remote access from an allow-list of addresses you choose.

Data sovereignty

Where do my logs go?

Only inside the boundary you define. DPLens delivers over syslog (RFC 5424 and RFC 3164), Snare, NDJSON, the Splunk forwarder (S2S) and HTTP Event Collector protocols, and OTLP over HTTP for OpenTelemetry, to addresses you set. Inside an enclave that means your on-premises SIEM, your Splunk indexers, an on-premises OpenTelemetry Collector or your own collector. See SIEM integrations.

  • Disk-backed delivery. Each syslog, Snare, NDJSON and Splunk destination has its own on-disk cache, so a SIEM outage inside the enclave queues events instead of discarding them. Nothing is dropped silently; every drop is counted.
  • Masking before egress. Sensitive values can be redacted or hashed before they are cached or sent. See log masking and PII redaction.
  • No vendor in the data path. DPLens Ltd operates no service that sees your configuration, your events or your machine inventory. That simplifies supply-chain and third-party risk questions under NIS2 and DORA.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

FAQ

Questions buyers ask

Does DPLens need internet access at any point?

No. Installation, licensing and running need no internet access. The only outbound connections are to the destinations you configure, plus the optional public-IP enrichment lookup if you choose to add it, with an endpoint you set.

How is a licence checked without a licensing server?

The key is signed by the DPLens publisher key, whose public half is built into the program. The agent verifies the signature, the expiry and the machine or domain binding locally.

How do we update the agent?

Fetch the new release on the connected side, verify the checksums and signatures, carry it across and install it over the old version. DPLens Manager can roll the upgrade out across the enclave, or you can use Group Policy, Intune or Configuration Manager. Upgrades keep configuration, licence, secrets and collection positions, and happen only when you choose.

Can it send to a cloud SIEM?

It sends to any address you configure that speaks syslog, Snare, NDJSON, the Splunk protocols or OTLP/HTTP. Whether that is inside or outside your boundary is your decision; nothing leaves unless you configure a destination for it.

How is DPLens priced for an isolated network?

Per agent and per network source (each syslog or NetFlow receiver), with no per-GB ingestion cost; keys are verified offline. See the licensing model or contact us for a quote.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.