PRIVATE RUNNER · DEPLOYMENT

Run validations safely across cloud, private, and hybrid environments.

SaaS, customer-deployed runner, private broker, or dedicated enterprise — the same governance across every model, with mutual TLS and expiring authorization.

MUTUAL TLSSIGNED WORKEXPIRING AUTHSCOPED TARGETS
5
Deployment models
SaaS · runner · broker · private · dedicated
100%
Runner comms
mutual TLS, signed work
0
Data exfiltration
evidence stays in your boundary
PRODUCT · RUNNER FLEET

Your runners, your rules, our governance.

See every runner, its health, its scope, and its live activity — SaaS, VPC, or air-gapped.

app.hayrok.io / runners
LIVE
HAYROK
Overview
Runners 3
Policy
Logs
Runners
SaaS · customer VPC · private / isolated — same governance everywhere
HAYROK SAAS Healthy
runner-saas-01
us-east-1
JOBS 12/32 mTLS ✓
CUSTOMER VPC Healthy
runner-vpc-04
eu-west-1 · in-vpc
JOBS 4/8 mTLS ✓
PRIVATE / ISOLATED Healthy
runner-priv-02
on-prem · air-gapped bridge
JOBS 0/4 mTLS ✓
Runner activity · runner-vpc-04
● healthy · 128d uptime
12:04:31 [OK] Signed work request received · scope=prod · ttl=3600s
12:04:31 [EXEC] Scenario EXP-014 · exploit agent · policy=safe
12:04:33 [OK] Recon complete · 214 assets discovered
12:04:47 [GATE] Approval requested · sensitive action detected
12:05:12 [OK] Approval granted by security-lead@corp
12:05:14 [EXEC] Payload delivered · WAF response captured
12:05:15 [OK] Evidence uploaded · sha256:8f19…c2b4 · 142 artifacts
12:05:16 [DONE] Cleanup verified · runner returned to idle
EXECUTION MODELS

Pick the model that fits your architecture.

All models maintain policy enforcement, evidence collection, identity controls, and auditable workflows.

01
SaaS Runner
Hayrok-managed execution for approved externally accessible targets and supported validation activities.
02
Customer Runner
Customer-deployed runner used to perform validation inside internal networks, cloud workloads, and Kubernetes.
03
Private Broker
Controlled communication layer between the Hayrok control plane and customer-hosted execution infrastructure.
04
Private Runner
Highly isolated execution for sensitive, regulated, private, or restricted networks.
05
Dedicated Enterprise
Dedicated architecture for stronger isolation, data residency, or operational control.
06
CI/CD Runner
Execute validation as part of your delivery pipeline for change-triggered coverage.
"
Our regulated data never left the boundary. The runner accepted signed work, returned signed evidence, and gave us a full audit trail. Regulators loved it.
KN
Katarina Novak
CISO · European Bank
RUNNER SAFETY

Every runner respects the same guardrails.

Mutual TLS. Signed work. Expiring authorization. Scoped targets. Stop controls. Complete logs.

Mutual TLS
Runner communications authenticate services and encrypt traffic between trusted components.
Network isolation
Outbound-only, allowed destinations, network segments, DNS restrictions, private connectivity.
Execution controls
Signed work requests, expiring authorization, tool allowlists, concurrency limits, cleanup.
TRUSTED BY SECURITY TEAMS AT
Nexpro
atlas.fi
LinnINC
Expedier
BY THE NUMBERS

Deployment control for the most sensitive programs

Private Runner is the deployment mode Fortune 500 programs choose when execution, credentials, and evidence must stay inside their own environment.

CUSTOMER-DEPLOYED RUNNERS
120+
across regulated tenants
DATA CROSS-BOUNDARY EVENTS
0
credentials never leave customer VPC
AUDIT EVENTS / DAY
3.8B
shipped to customer SIEMs
REGIONS SUPPORTED
40+
wherever customer cloud runs
REGULATED-PROGRAM LEADERS ON PRIVATE RUNNER

Regulated-program leaders on Private Runner

"Outbound-only, mTLS-signed work requests, and credentials that never leave our VPC — Private Runner is why our regulator-facing systems can be validated at all."
IM
Isla McKenzie
CISO · Nexpro
"Executing sensitive validation inside our own environment with the Hayrok control plane orchestrating the run is the best of both models."
TK
Tobias Klein
Head of Cloud Security · Nexpro
"Our security operations get every audit event from the runner into Splunk within seconds. No black-box execution — everything is inspectable."
AK
Aditi Kapoor
VP Security Engineering · Expedier Payments
ENTERPRISE-READY BY DEFAULT

Private Runner is used across regulated industries where cross-border data movement, sovereignty, or data-classification rules constrain execution location.

Visit the Security & Trust Center
COMPLIANCE
Audit-ready programs
SOC 2 · ISO 27001 · GDPR · CCPA · HIPAA-friendly · PCI-DSS-aligned
IDENTITY
Enterprise SSO & SCIM
OIDC · SAML · SCIM · IdP federation · MFA policy
DEPLOYMENT
Regional data residency
US · EU · UK · Private Runner in customer VPC · CMK options
SECURITY
Encryption everywhere
TLS 1.3 · AES-256 at rest · Managed secrets · CMK options
ENTERPRISE ROLLOUT

Runner deployed inside customer VPC and mTLS-attested in the first week.

A dedicated Enterprise Deployment team runs a repeatable playbook — security review, tenant setup, integrations, scoped pilot, and executive readout.

WEEK 1
VPC prerequisites
Network, IAM, and secret-store prerequisites confirmed with customer engineering.
WEEK 2
Runner deployment
Runner container deployed inside customer VPC; mTLS attested.
WEEK 3
SIEM forwarding
Runner audit forwarded to customer SIEM; retention validated.
WEEK 4
Production authorization
Time-boxed production runs authorized under Private Runner.
ENTERPRISE FAQ

Questions we hear from Fortune 500 buyers

How do we deploy Private Runner inside our own VPC?+
A container image is deployed inside the customer VPC with outbound-only network configuration. mTLS attestation to the Hayrok control plane completes the join.
Can Private Runner integrate with our HSM or KMS?+
Yes. Enterprise Private Runner supports BYO-KMS integrations for secret material, encryption keys, and mTLS attestation.
Where do audit events go?+
Directly to the customer SIEM in near real time. Hayrok retains a minimal control-plane subset for orchestration purposes only.
Can Private Runner run air-gapped?+
Air-gapped deployment is available for public-sector and defense customers under specific engagement terms.

Run validations where they belong.

Talk to us about the deployment model that fits your architecture, regulatory profile, and data boundaries.