Architecture
VPC peering or PrivateLink between the Astrolift management plane and your AWS account. Compute runs in your VPC, data stays in your network; users authenticate through Astrolift and work entirely through the browser.
Run · Astrolift
Astrolift’s gateway peers to your VPC. Your people connect over HTTPS and see the IDE, notebooks and agents — but the compute runs in your network and the data stays in your perimeter. Remote access, zero egress.
You have data that can’t leave your network — regulatory requirements, contractual obligations, security policy. But your team needs AI tooling, and they need to work from anywhere.
The VPC Gateway solves both. Astrolift peers to your VPC; users connect through the browser and work the IDE, notebooks and agents — but every query, notebook and agent executes in your network. Only screen updates travel back. The data stays put.
When the data must stay in your network but the people don’t have to.
VPC peering or PrivateLink between the Astrolift management plane and your AWS account. Compute runs in your VPC, data stays in your network; users authenticate through Astrolift and work entirely through the browser.
Inbound: the user connects to Astrolift, authenticates, and the session is proxied into your VPC. Compute: notebooks, agents and queries execute in your network. Outbound: only screen updates travel back — the data never leaves your perimeter.
All Zentinelle governance applies — policies enforced at the gateway, audit logs capture every action. Network-level isolation, no lateral movement, session recording available.
Stop choosing between moving fast and staying in control.
See how it works →