All insights

Air-Gapped & On-Prem

How to Test an Air-Gap Claim in a POC

· 10 minute read

If the POC still has a hidden route, the contract will too. Here is how a procurement committee tests an air-gap claim without becoming network engineers.

Vendors have learned the phrase air-gapped. It now appears in almost every government AI proposal we read, including proposals whose architecture diagrams show a cloud brain. Procurement cannot police adjectives. Procurement can police a test. If the test is not in the bid, the adjective will win.

This is a checklist a committee can run. It is written for P2 buyers and the CISO they must drag into the room. You do not need to configure a span port yourself. You need to refuse to sign until someone you trust has watched the deny-all soak.

GFR hygiene still applies: you are testing fitness to a stated requirement, not inventing a new product on the fly. Write the test before the POC, show it to all bidders, and run the same script on each.

Write the claim so it can fail

Force the bidder to pick a sentence. 'No inbound or outbound network beyond an allow-list we publish, including install, licence, telemetry, update and support, for the duration of production.' Then define the allow-list. An empty allow-list is a true gap. A list that includes their APM is not.

TestPassFail
Install from bagNo outbound SYNsNeeds docker login or apt
7-day soak, deny-allService stays up; no callbacksAny callback or silent degrade
Restart + clock skewStill upLicence or feature flag dies
Dummy updateBag ceremony worksNeeds a tunnel
Support drillThey view your logs under escortThey demand a remote binary
Data export attemptYou can export; they cannotHidden outbound of traces
Second NIC / BMCDocumented and blockedQuiet management plane

The script — one afternoon plus a soak

  1. Day 0: freeze the image list and the vendor's network manifesto.
  2. Install on a VLAN whose default is deny. Your people control the switch, not theirs.
  3. Start a capture before the installer runs. Keep it through first successful query.
  4. Run the officer script on synthetic data. No live personal data in a POC unless the DPO wrote yes.
  5. Cut any remaining route. Leave it seven days. Do one restart on day three. Advance the clock on staging.
  6. On day eight, open the capture with the CISO. Every destination is a finding or an allow-list row.
  7. Run the dummy update from a bag the vendor did not carry in their pocket that morning.
  8. Ask support to diagnose a planted fault without a tunnel.

Scoring without theatre

  • Eligibility: fail the soak and you are out. Do not average a fail with a pretty UI.
  • Conditions: an install-time connection might be a condition if the runtime soak is clean and you accept it in writing.
  • Observations: documentation quality, bag ergonomics — these do not rescue a callback.
  • Keep the capture hash with the evaluation sheet.

Objections you will hear — and what to do with them

This test is unfair to global products.

The requirement is unfair to global products that cannot disconnect. That is the requirement. They may bid a different topology. They may not relabel it.

We need internet for the POC because the hall is not ready.

Then you are not testing an air gap. Delay the POC or test in a portable cage you control. A connected POC of an air-gap product is how adjectives survive.

The bidder is DPIIT recognised / on GeM.

Good for eligibility on other rows. Irrelevant to packets. Recognition is not a capture.

A procurement playbook for the next bid

  1. Put the claim sentence and this script in the RFP / GeM additional spec.
  2. Budget two to four weeks and a VLAN.
  3. Run all shortlisted bidders through the same script.
  4. File captures and the fail/condition/observation sheet. Do not accept a slide in lieu.

How this shows up in the file

The evaluation note should quote the claim sentence, attach the capture summary, and say pass or fail. A later objection or audit will read that page. If you cannot explain a destination, you cannot explain the award.

Questions procurement can ask without a CISO present

  1. Show the network manifesto filled, not promised.
  2. Show the bag you will use on day one of production, not a laptop.
  3. Name the last customer who ran a deny-all soak, without inventing one. 'We cannot name them' is acceptable; 'everyone does' is not.
  4. What happens to inference when your licence host is unreachable for 14 days?
  5. Who from your side will sit in our hall, and who will remain in another country looking at our traces?
  6. Which of your standard clauses on improvement and safety still apply if we never send you data?

Write the answers into the evaluation sheet the same day. Verbal answers in a POC tent evaporate. If legal needs to 'confirm', mark the row as open. Open rows at award time become the next incident's exhibit.

A bidder who becomes hostile at these questions is giving you information. Hostility is cheaper before the work order than after.

This article is a field guide, not legal, procurement, electrical or engineering advice. Confirm numbers, duties and designs against the current Gazette, CERT-In directions, your SDC / NIC / campus standards, a site survey and your counsel before you file them.

How to prove this on a rack, not on a slide

“How to Test an Air-Gap Claim in a POC” only matters if a CISO can fail it. A P2 Procurement should be able to point at a cable, a registry, a licence file, a PDU reading or a SIEM index and say: this is the control. If the only evidence is a brochure that mentions “verify air gap POC”, you do not have the control.

If the POC still has a hidden route, the contract will too. Here is how a procurement committee tests an air-gap claim without becoming network engineers. Air-gap and on-prem programmes die in the second month, when the first update, the first crash, or the first GPU lead-time slip arrives. Budget the boring path — media, offline licence, local registry, local traces — in the same note as the model name.

On-prem is not air-gapped. An India region is not either. Write the forbidden path (outbound HTTPS, licence phone-home, crash reporter, hidden model API) as a numbered list and test it with the internet off. Whatever still dies was a dependency you did not draw.

  1. Draw the data path for one user-visible answer under “verify air gap POC”.
  2. Disable outbound internet on staging and run the demo script.
  3. List every remaining hop: update, licence, registry, NTP, DNS, SIEM.
  4. Give each hop an owner inside the department, not only the SI.
  5. Minute the restore or the media-transfer once before go-live.

Close this loop before the next CAB

Put “How to Test an Air-Gap Claim in a POC” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P2 Procurement, not “the vendor.”

Revisit the item when the model, the GeM term, the region, or the SI changes. “verify air gap POC” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.

POC pass/fail in one page

Pass only if: outbound internet off, demo script completes, traces land in your SIEM, no undeclared SNI, licence still valid, and a restore of the index was minuted. Anything else is a condition, not a pass.

Do not let the SI redefine pass as 'the chatbot answered.' Answering through a hidden API is a fail with good UX.

What the next noting must contain

“How to Test an Air-Gap Claim in a POC” belongs in a file, not only in a search result. A P2 Procurement should be able to point at one artefact that proves “verify air gap POC”: a packet capture, a processing schedule, a scored evaluation row, a dated notice, or a refusal rule. If the only evidence is a slide, you have a heading.

If the POC still has a hidden route, the contract will too. Here is how a procurement committee tests an air-gap claim without becoming network engineers. DPDP 2023 does not define sovereign AI and does not write a blanket localisation rule for every model hop. CERT-In’s 28 April 2022 directions still set specified incident clocks and 180-day log retention in India for in-scope events. The November 2025 AI governance text is guidance, not a statute. A Proprietary Article Certificate, when it is lawful, lives in GFR Rule 166 — not Rule 161.

Write three dated sentences under C2 Air-Gapped & On-Prem: what was decided, which designation owns it after the next posting order, and when it will be re-checked. Unsigned sentences are souvenirs. Dated sentences are controls.

  • Name the designation that owns “verify air gap POC”, plus a deputy.
  • Attach one artefact a stranger can open next year.
  • Name the instrument you are actually using — Act, direction, GFR clause, GeM term, or guideline paragraph.
  • Leave unsourced percentages, GMV slides and house forecasts out of the noting.
  • Revisit when the model, the SI, the notice, the region or the posting changes.

Questions this usually raises

How long should an air-gap POC run?
Long enough to include install, a soak with outbound denied, a restart, a dummy update, and a support drill. In practice that is usually two to four weeks, not a two-hour demo. A demo is not a POC.
Who must be in the room for the network-off test?
Someone who can read a proxy log (CISO or SDC), the process owner, procurement, and the vendor. If the vendor refuses a network-off test, the claim is already false.
What if they need the internet only to install?
Then installation is not air-gapped. Require an install from the bag. If they cannot, write the claim down as 'runtime only, install connected' and decide if that is acceptable. Do not let them keep the word air-gapped unmodified.
Can we score this on GeM with a checkbox?
A checkbox without a test will be ticked. Put the test script in the bid document. GeM is a channel; it is not a packet capture. Do not invent platform GMV figures to justify skipping the test.

Sources