Deploy Your Way. Keep Full Control Of Your Data.
Every organisation has different security, infrastructure, and regulatory requirements. Some need a fully managed cloud deployment. Others require a private cloud, on-premises infrastructure, or completely air-gapped environments.
TeamSync deploys fully on-premises or in an air-gapped environment, including the AI models themselves. No data leaves your infrastructure, no cloud dependency, no third-party access because DocuTalk, Semantic Search, and the rest of the AI copilot run inside your own network, not a vendor's cloud.
Talk to a solutions engineer · Read the RBAC + Backup capability
What's In The Security & Deployment Surface
Sub-capability | What it does |
On-premise / air-gapped deployment | Full platform, including AI models, runs inside your own network with no external connections |
Zero-knowledge encryption | Content is encrypted so that even TeamSync cannot access it — only authorised users within your organisation can |
Ransomware detection | Monitors for suspicious access, mass downloads, and known ransomware patterns; isolates the affected area automatically |
Two-factor authentication | Built in by default, on every deployment |
IP range restrictions | Access can be limited to approved IP ranges |
Brute-force protection | Login attempts are monitored and blocked automatically |
Distributed architecture | Supports private cloud and hybrid deployments, with redundancy for availability |
Enterprise integration | Works alongside your existing enterprise applications |
What "Zero-Knowledge" Actually Means
Most vendors hold the keys to your data, even if they promise not to look. Zero-knowledge encryption removes that trust requirement entirely.
Pattern | Standard cloud platform | TeamSync |
Who can decrypt your content | The vendor, technically, even if policy says otherwise | No one but your authorised users — not even TeamSync |
Deployment location | Vendor's cloud, by default | Your infrastructure, air-gapped if required |
AI model location | Vendor's cloud servers | Deployed on-premises, alongside your data |
Threat monitoring | Often a separate add-on | Built into the platform |
Data residency guarantee | Contractual | Architectural data physically doesn't leave your environment |
The difference matters most when a regulator or auditor asks not "do you promise not to access our data," but "can you access it at all."
What The Deployment Options Cover
Capability | What it does |
Air-gapped deployment | Zero external network access; suited to classified or highly sensitive environments |
Private cloud support | Runs in your own cloud environment, under your control |
Distributed architecture | Keeps data available and redundant across your infrastructure |
Threat detection and isolation | Freezes affected areas automatically when an attack is detected, before it spreads |
Compliance-ready configuration | SOC 2, ISO 27001, FedRAMP, and HIPAA requirements supported out of the box |
What Changes For Security and IT Teams
Activity | Before | With TeamSync |
Data residency guarantee | Contractual promise | Architectural; data never leaves your environment |
AI capability without data exposure | Difficult to reconcile | Native; AI models run on-premise |
Ransomware response | Manual detection and containment | Automatic detection and isolation |
Compliance evidence for procurement | Assembled manually | Met out of the box for SOC 2, ISO 27001, FedRAMP, HIPAA |
Key custody | Often held by the vendor | Zero-knowledge; held only by your organisation |
How TeamSync Compares
Capability | TeamSync | Microsoft 365 | OpenText | Box |
|---|---|---|---|---|
On-premise deployment | ✅ | ❌ (cloud-only) | ✅ | ❌ |
Air-gapped deployment | ✅ | ❌ | Partial | ❌ |
Customer-controlled keys | ✅ native | ✅ (Purview add-on) | Partial | ✅ (Enterprise+) |
HYOK (key never leaves HSM) | ✅ | ✅ (DKE) | Partial | ❌ |
Post-quantum encryption | ✅ | Roadmap | ❌ | ❌ |
Same security model across all capabilities | ✅ | Per-product | Per-product | Per-product |
Related Capabilities
RBAC + Backup & Restore — identity federation, permissions, and backup
Compliance Audit Trail — tamper-evident audit chain across all capabilities
Intelligent Repository — the records platform that deploys in any mode