NERVE is live across local, private and approved-cloud deployments. Book an evaluation
Deployment profiles
Consistent contracts across different operating environments.
NERVE separates product semantics from infrastructure adapters, so local, private and approved-cloud profiles preserve the same search, common-model and evidence contracts. The environment changes. What a citation means does not.
All three profiles available
Three profiles
Pick the shape that matches your environment
Each profile arranges the same logical services differently. Selecting one changes the topology and the notes below it. The essential points are also stated in the comparison table, so nothing depends on the interaction.
Logical topology
Single protected host
API
Workers
Queue
Search
Object store
Compact local node
A protected host, or a small set of hosts, co-locates the logical services. Object storage, search, the queue and the workers all run locally, so the whole source-to-search chain can be exercised inside one boundary.
It suits development, evaluation, smaller holdings and disconnected operation, within capacity measured for the environment. Sizing is agreed during acceptance against your real volumes.
Sized during acceptance
Side by side
The essential differences, without interaction.
The selector above is a convenience. The table below carries the same information for anyone reading linearly, with assistive technology, or on a narrow screen.
Best suited to
Built for it. Offline mode blocks external connectors before transport.
Acceptance
Capacity is measured for your environment during acceptance, not assumed.
Each environment is accepted against your own volumes and boundaries.
Accepted alongside your provider approval.
Operating modes
Online and offline behaviour.
Offline mode is a policy control inside the application. It changes what NERVE is permitted to attempt, and the boundary is enforced before transport rather than after it.
Available
Available
Available
Available
Available
Available
Optional, under your approval.
Optional, under your approval.
Controlled release acceptance.
Shared responsibility
Application Offline mode is one policy control. It stops NERVE from attempting outbound transport for sources, enrichment and update retrieval, and the block is verifiable at the application boundary.
An actual air gap depends on far more than one application setting. It depends on network controls, host controls, identity and time sources, the software-update route, removable-media handling and the operational controls around all of them. Those controls sit with the deploying organisation, and NERVE cannot assert them on its behalf.
A separate point, stated plainly: Framer hosts this explanatory website. The hosting of this site is unrelated to the deployment boundary of the NERVE product.
Running it
Built for the parts of operations nobody demonstrates.
Large inputs, saturated queues, restores and upgrades are where information platforms usually fail quietly. NERVE treats each of them as a first-class behaviour with a defined durable result.
01
Streaming large inputs
Large images and packages move through dedicated streaming paths, so a submission is never limited by what a browser can hold in memory. Bytes are committed as they arrive.
02
Stage-specific scaling
Parser, media, indexing and export workloads scale against their own demand. A heavy media backlog does not starve ordinary document throughput.
03
Durable queue pressure
When a queue or worker pool saturates, admission slows visibly and the pressure is reported. Work is never dropped quietly to keep a dashboard green.
04
Backup manifests
Backups are described by a manifest that names what was captured, so a restore can be checked against the objects, metadata and lineage it is supposed to contain.
05
Historical key availability
Keys used by earlier acquisitions stay available for as long as the material they protect is retained. An old original stays readable after a key rotation.
06
Fresh restore
A restore is exercised into a clean environment, rather than replayed over a running one, so recovery is proven against the backup rather than against surviving local state.
07
Upgrade compatibility
Canonical envelopes are versioned, so an upgrade reads records written by earlier versions. Parser packs can be pinned or rolled back independently of the platform.
Indexes are acceleration, not the record
Search indexes are rebuildable acceleration state, derived entirely from canonical records. That is why a restore is judged on resolvable citations rather than on a running process: bringing a service back up is not the same thing as proving the evidence came back with it.
Operational ownership
Fourteen accountable roles, named before go-live.
A deployment only works when every one of these has an owner. We walk through them with you during acceptance, so nothing important turns out to belong to nobody.
Infrastructure
Hosts, networks, storage and the capacity the deployment runs on.
Identity
Accounts, authentication, workload identity and the human authority behind a request.
Sources
Which systems are in scope, and who confirms a route is approved.
Legal and licence authority
Whether the organisation may acquire and retain this material by this route.
Handling
Protective handling bands and the mapping that assigns them.
Retention
Retention schedules, holds and authorised disposition decisions.
Credentials and keys
Secret storage, rotation and historical key availability.
Scanning
The malware scanning service, its availability and its quarantine policy.
Package approval
Which parser packs and capability packs are approved for installation.
Backup
Backup schedules, manifests and the fresh-restore exercise.
Search
Index configuration, rebuilds and publication-state policy.
Provider approval
Which infrastructure and enrichment providers are permitted, and for what.
Incidents
Detection, response and the route for reporting a governance failure.
Release acceptance
Accepting each release into the environment before it carries real material.
Next step
Pick the profile that matches your estate.
An evaluation starts with your operating constraints: the network boundary, the identity model, the sources in scope and the volumes you actually hold. We size the deployment against measured capacity and agree the acceptance evidence up front.