KORTHEXDocumentation

Docs / DEPLOYMENT

DEPLOYMENT

Air-Gapped & Self-Hosted

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

Korthex is offline-first by design - every scan engine runs entirely locally and your source code never leaves the machine. For environments where even network presence is restricted (classified networks, regulated industries, isolated build farms), Korthex supports a fully air-gapped installation profile and a self-hosted Dashboard. Air-gapped operation and the self-hosted Dashboard are Enterprise-tier features . The same binary distribution is used; the difference is in how it is licensed, configured, and updated.

Air-Gapped Installation

Air-gapped installation packages bundle every dependency the engine needs at runtime - there is no installer phase that reaches out to the internet. Activation happens through a file-based exchange with the Customer Dashboard on a second, networked device. 1. Install Korthex Choose the native installer for your platform, or use the generic archive if you prefer manual deployment. No korthex-verify tool ships today. The native installers verify the release themselves - detached Ed25519 signature, then SHA-256, fail-closed - so on an air-gapped host prefer the native installer. If you deploy the archive manually, verify its detached signature with your own tooling before extracting; there is no Korthex-supplied command for it yet. 2. Run Preflight Run korthex-preflight.exe on the airgapped machine to generate the safety status file korthex-posture.json . From here, switch to a second device with network access and the Customer Dashboard open to complete activation. 3–6. Exchange license files Upload korthex-posture.json to the Customer Dashboard In the airgapped Korthex UI, export the installation request → produces .krxreq Upload the .krxreq file to the Customer Dashboard Download the generated .krxlic file from the Customer Dashboard 7. Activate Transfer .krxlic back to the airgapped machine and import it - drag & drop into the Korthex UI, or select the file manually. Done. Korthex is now licensed and ready to run fully offline. The bundled artifacts include the runtime (JVM 21), all scan engines, the baseline registry, the CVE / KEV / EPSS cache, and the on-device Neural Network model weights. No download is performed at scan time.

PlatformNative installerArchive
Windows.msi.zip / .tar.gz + .tar.gz.sig
Linux.deb.zip / .tar.gz + .tar.gz.sig
macOS.pkg.zip / .tar.gz + .tar.gz.sig