Deployment
Three ways to run Inlinea, one product
The same platform in each: the same Control Center, the same Workspace, the same policy model.
Global footprint
147 cities, 58 countries, 7 areas
Every city in the catalogue is a place Inlinea can stand up and operate a dedicated environment for you, so residency in your jurisdiction never means running the platform yourself.
Global load balancing and multi-PoP failover
One address for your organisation, steered to the nearest healthy point of presence, with automatic failover between them. Every tenant keeps a persistent disk, daily snapshots and automated replacement underneath.
What runs where
What stays in your tenant, and what never leaves the device
Your tenant runs every platform component. Devices send control traffic to it; application traffic on the agent path never passes through Inlinea in readable form.
Your people
- Managed devices with the Inlinea Agent
- Browsers, with the Inlinea extension where you require it
Your tenant, in your region
- Edge
- Inlinea server: identity, policy, signalling and relay
- Control Center
- Workspace
- ZERA gateway
- Session engine for Secure Sessions
Your private site
- One connector: an Inlinea Agent acting as a routing device
- Your applications, desktops and servers
- Control trafficSign-in, policy and signalling between devices and your tenant. This is what leaves a device for Inlinea.
- The agent pathEncrypted end to end between devices, directly or through a relay. Inlinea cannot read it.
- The ZERA pathThe ZERA gateway in your tenant terminates TLS to enforce policy, then reaches the application over the encrypted private network. Nothing opens inbound at your site.
Data residency
Where each kind of data lives
Stated per data class, so a procurement questionnaire can be answered from this page.
| Data | Where it lives | Who controls it |
|---|---|---|
| Identity, groups, Access Rules and configuration | Your tenant's control plane, on its persistent disk | Your administrators, through roles you define |
| Audit, ZERA Access and Browser Security logs | Your tenant, kept for the retention you set | Your administrators |
| Traffic Logs | Off until you switch collection on, then sent only to your tenant | Your administrators |
| Session Evidence | Recorded by the ZERA gateway and stored in your tenant, with your retention and size limits | Your administrators |
| Application traffic on the agent path | Encrypted end to end between devices, never readable by Inlinea | Only the two devices |
| Application traffic through ZERA | Terminated by the ZERA gateway in your tenant to enforce policy | Your Access Rules |
| Backups | Daily snapshots of your tenant's disk | Inlinea, as your operator |
Sovereign Outlinks
Your traffic leaves from your addresses
Send a group's internet traffic out through exit gateways on your own devices, with a second gateway for failover, so SaaS allowlists see your own addresses.
Regulation
Built for the frameworks regulators name
The controls are built in today. Inlinea's own formal status for each framework is shown as it stands, never rounded up.
| Framework | Why it matters | Inlinea's status |
|---|---|---|
| NCA Essential Cybersecurity Controls (ECC) | The Kingdom's baseline for government and critical sectors. | Planned |
| NCA Cloud Cybersecurity Controls (CCC) | Required for cloud services to Saudi government entities. | Planned |
| CST cloud service provider registration | The Kingdom's regulatory framework for cloud services. | Planned |
| Personal Data Protection Law (PDPL) | Personal data of people in the Kingdom. | Planned |
| SAMA Cyber Security Framework | Banks and insurers. | Planned |
| ISO/IEC 27001 | The global baseline buyers ask for first. | Planned |
| SOC 2 Type II | US and multinational procurement. | Planned |
| General Data Protection Regulation (GDPR) | Personal data in the European Union. | Planned |