Analytics in an enclave that allows no cloud
The operator (an anonymized, fictional organization in this demo) manages spare parts and equipment for land and air platforms across three depots. Its networks are air-gapped by design: no internet connectivity, no cloud services, strict control over every piece of software that enters the enclave.
Data lived in an Oracle ERP, a SQL Server warehouse management system at each depot, a Postgres maintenance database, RFID gate events on a Kafka bus, and a steady stream of CSV extracts from partners delivered on approved media. Readiness reporting, meaning whether the critical parts for each platform were available where they were needed, was compiled weekly by hand in spreadsheets and was out of date by the time it reached commanders.
Most analytics tools were simply not an option. They assumed a cloud backend, phoned home for licensing or updates, or could not be accredited for the enclave.
> Air-gapped usually means a decade behind. With Kimo, our depots run analytics that most connected organizations would envy.
Defense logistics operator · Europe
How the defense logistics operator set up Kimo
Kimo Defense Intelligence ships as a signed, self-contained bundle. The operator’s security team verified the signatures and the software bill of materials, transferred the bundle on approved media and installed it on its own servers at each depot, with no outbound network access. Licensing is offline, telemetry is disabled at build time, and updates arrive quarterly as signed bundles through the same controlled process.
The data cell connected the Oracle ERP, the three SQL Server WMS instances, the maintenance database and the RFID stream, and set up a watched folder for partner CSV drops. A readiness model joins demand from maintenance plans with stock, inbound movements and lead times, and computes days of cover and availability for the critical parts list of each platform.
Each depot sees its own picture; headquarters sees all three through a federated view, with role-based access that mirrors the operator’s clearance structure. Every query and export is logged locally for audit.
- Day 101/03Signed bundle verified
Signatures and SBOM checked; installed on the operator’s servers at three depots.
- Day 602/03Sources wired in the enclave
Oracle ERP, 3× SQL Server WMS, Postgres maintenance, RFID on Kafka, CSV drops.
- Day 1103/03First readiness dashboard
Critical parts availability and days of cover per platform and depot.

