ZERO EGRESS • PASSIVE FLOW LOG FORENSICS • 100% SELF-HOSTED APPLIANCE

System & Technical Architecture

Under the hood of the AIPrunr Sovereign Appliance. Engineered in Go and C++ for ultra-high throughput network flow log ingestion, passive heuristic classification, and zero-egress local analytics.

SYSTEM DATA FLOW DIAGRAM (AIR-GAPPED APPLIANCE BOUNDARY) 100% READ-ONLY APIs
AIPrunr Detailed Technical Architecture Blueprint

Core Architectural Components

🛰️ Ingestion Engine

High-concurrency Go service connecting to AWS Cost Explorer, Azure Cost Management, GCP Billing, and VMware vSphere ESXi hypervisors. Normalizes disparate telemetry into a single unified schema.

🧠 Heuristic Engine

The core intelligence pipeline. Correlates 30-day billing records with real-time VPC/NSG Flow Logs to identify "Zombie" resources—workloads billed continuously with zero active network traffic.

🔒 Encrypted Storage

Self-contained PostgreSQL database running locally inside the appliance. All cloud API credentials, access tokens, and asset tables are encrypted at rest using AES-256-GCM envelope encryption.

🛡️ Zero Egress Boundary

The entire appliance sits behind your corporate firewall or inside your private VPC. Contains zero inbound listening ports to the internet and emits zero phone-home diagnostic telemetry.

4-Stage Passive Forensic Pipeline

01

Read-Only Connect

Connects via Read-Only Cloud IAM or vCenter service account. Zero agents installed.

02

Flow Log Ingestion

Pulls VPC, NSG, and ESXi flow logs passively to build live network topology maps.

03

Traffic Classification

Filters out DNS, NTP, and agent noise to isolate true unutilized zombie assets.

04

JIT Remediation

De-provisions idle workloads safely with 1-click instant Unkill restoration switches.

View Security & Compliance Policy → Contact Architecture Team