Air gapped communication is the exchange of messages, voice, video, files, and operational information inside a network that is isolated from the public internet and other untrusted networks. Instead of relying on cloud messaging or conferencing services, organizations run the communication platform and its supporting services inside their own protected infrastructure.
This approach is used when communication must continue without external connectivity or when sensitive, classified, regulated, or mission-critical information cannot be exposed to ordinary internet-connected infrastructure. Typical users include defense organizations, intelligence agencies, government bodies, industrial operators, critical infrastructure providers, research facilities, and organizations operating classified or highly restricted systems.
Executive Summary
| Area | Air gapped communication |
|---|---|
| Definition | Messaging, voice, video, file sharing, and collaboration inside an isolated network |
| Main purpose | Reduce external exposure and keep communication data inside a controlled security boundary |
| Internet dependency | None for core internal communication when the system is properly designed |
| Typical deployment | On-premises servers, private infrastructure, isolated Kubernetes, or dedicated appliances |
| Common users | Defense, intelligence, government, OT and ICS environments, critical infrastructure, research |
| Core capabilities | Messaging, conferencing, files, identity, logging, administration, monitoring |
| Main advantage | Infrastructure, data, and access remain under organizational control |
| Main limitation | Updates, dependencies, identity services, backups, and administration must also work inside the isolated environment |
| Key security principle | An air gap reduces external attack paths but does not eliminate malware, insider threats, removable-media risks, or configuration errors |
The important distinction is that air gapped communication is not simply an offline version of a cloud collaboration app. A practical deployment needs its own communication servers, identity infrastructure, internal DNS, certificates, monitoring, storage, update process, and often private package or container repositories.
What Is Air Gapped Communication?
Air gapped communication refers to communication systems that function within a network intentionally separated from external or less trusted networks.
A strict physical air gap means there is no direct network connection between the protected environment and the public internet. Data entering or leaving the environment must move through a controlled mechanism such as approved removable media, transfer stations, cross-domain systems, or other security-reviewed processes.
Organizations also use the term air gapped for logically isolated or highly restricted environments. These environments may contain controlled gateways or dedicated connections between security domains, but ordinary users and applications still cannot communicate directly with the public internet.
Air Gap vs. Network Isolation
| Architecture | Internet connectivity | Data transfer outside boundary | Typical use |
|---|---|---|---|
| Physical air gap | None | Controlled physical transfer or approved gateway | Classified systems, sensitive OT environments |
| Logically isolated network | Highly restricted | Security-controlled network path | Government and enterprise restricted zones |
| Private network | May have controlled internet access | Firewall and policy controlled | Enterprise internal systems |
| Offline workstation | None | Usually removable media | Individual sensitive workflows |
| Standard on-premises network | Usually available | Normal enterprise perimeter | General business applications |
An air gap therefore describes a security architecture rather than a single product feature.
How Does Air Gapped Communication Work?
An air gapped communication architecture typically includes local messaging and video servers, internal identity services, DNS, certificate infrastructure, storage, monitoring, update repositories, and controlled mechanisms for moving data across the security boundary. These components must continue operating without relying on ordinary public internet services.
An isolated communication environment must contain the services that ordinary collaboration software normally obtains from the internet.
A typical architecture includes:
- Communication servers. Messaging, video conferencing, voice, presence, file exchange, and collaboration services run within the protected network.
- Identity services. Active Directory, LDAP, SSO, certificate systems, or other identity infrastructure authenticates users without relying on external identity providers.
- Internal network services. DNS, time synchronization, certificate authorities, storage, databases, and application dependencies remain available within the isolated boundary.
- Administration and monitoring. Logs, metrics, alerts, audit records, and configuration management must work locally.
- Update infrastructure. Software packages, container images, security updates, and dependencies are transferred through approved procedures and stored in private repositories.
- Controlled data exchange. Where communication between security zones is required, transfer is performed through approved gateways, cross-domain systems, or controlled federation.
The more complete the isolation, the more infrastructure must be reproduced inside the security boundary.
Insight 1: The communication application is only one part of an air gap.
A messaging server can run without internet access and still fail operationally if authentication, DNS, certificates, notifications, package repositories, or monitoring depend on external services. Air-gap readiness should therefore be evaluated at the architecture level, not at the application level.
Why Organizations Use Air Gapped Communication?
Organizations use air gapped communication to reduce external attack paths, keep sensitive data inside controlled infrastructure, maintain communications without internet access, and separate systems or security domains according to organizational policy.
Reduced External Attack Surface
Removing ordinary internet connectivity prevents many common attack paths from reaching internal communication infrastructure directly. Public login pages, cloud APIs, internet-facing application servers, and third-party SaaS dependencies can be removed from the protected environment.
Data Sovereignty and Infrastructure Control
Messages, files, meeting media, recordings, user directories, and metadata can remain inside infrastructure controlled by the organization.
This is particularly important when data location, administrator access, or external processing cannot be delegated to a commercial cloud provider.
Operational Independence
Internal communication can continue when public internet access is unavailable, intentionally disabled, disrupted, or considered untrusted.
This is relevant to command centers, tactical environments, ships, remote industrial facilities, classified networks, and disaster-response infrastructure.
Separation of Security Domains
Different departments, classifications, facilities, or partner organizations can operate independent communication systems. Controlled gateways or federation policies can then determine which information is allowed to move between them.
Air Gapped Communication Statistics
Demand for isolated communication is increasing as organizations reassess external dependencies in high-security environments. An Element survey of IT leaders found that 64% expected their organizations' need to provide partners with access to air-gapped or isolated environments to increase over the following two to three years.
The broader threat landscape helps explain this demand. Verizon's Data Breach Investigations Report found that vulnerability exploitation accounted for 31% of breaches, third-party involvement appeared in 48%, and ransomware was present in 48% of the breaches analyzed.
These figures do not mean that air gapping prevents every breach. They show why organizations handling high-value information may reduce internet-facing services, third-party dependencies, and external trust relationships where operational requirements allow it.
What Air Gapping Does Not Protect Against?
An air gap is a security control, not an absolute security boundary.
Malware can enter isolated networks through removable media, maintenance laptops, software updates, compromised supply chains, administrator actions, or equipment transferred between network zones.
Security research has also demonstrated possible covert channels based on acoustic, electromagnetic, optical, magnetic, power, and thermal signals. The practical relevance varies significantly by threat model, but the underlying lesson is consistent: physical isolation should be combined with endpoint security, access control, monitoring, supply-chain controls, and strict operational procedures.
Insight 2: Air gapping changes the attack surface rather than eliminating it.
Internet-origin attacks become harder, but removable media, administrator privileges, supply-chain compromise, insider threats, and physical access become proportionally more important.
Core Requirements for Air Gapped Communication Software
A communication platform intended for an isolated network should be evaluated differently from an ordinary SaaS product.
| Requirement | Why it matters? |
|---|---|
| No mandatory internet connection | Core messaging and conferencing must continue without external services |
| Local identity integration | Authentication cannot depend entirely on an external cloud identity service |
| Internal update process | Security updates must be importable through controlled procedures |
| Private storage | Messages, files, recordings, and logs remain inside the protected environment |
| Local administration | Policies and users can be managed without a vendor cloud |
| Audit logging | Administrators need visibility into events and configuration changes |
| Internal voice and video | Media routing should not require public cloud relays |
| Controlled integrations | External APIs and cloud-dependent plugins must be removable or replaceable |
| High availability | Critical communication should survive server or network component failures |
| Data export controls | Information leaving the security boundary should follow approved processes |
Organizations should also determine whether the product supports multiple isolated sites, tactical networks, or communication across separate security classifications.
Air Gapped Communication vs. Conventional Cloud Collaboration
| Area | Air gapped communication | Cloud collaboration |
|---|---|---|
| Infrastructure ownership | Organization or trusted operator | Cloud provider |
| Internet required | No for internal operations | Usually yes |
| Data location | Defined by organization | Defined by provider architecture and contract |
| Updates | Imported and validated internally | Applied by provider |
| External integrations | Limited and controlled | Usually extensive |
| Administration | Internal | Shared with provider |
| Operational burden | Higher | Lower |
| Security flexibility | High | Limited by provider design |
| Best suited for | Classified, restricted, regulated, or disconnected environments | General enterprise and remote collaboration |
Cloud collaboration is usually easier to deploy and operate. Air gapped communication trades convenience for control, independence, and reduced reliance on external infrastructure.
Air Gapped Communication Platforms and Collaboration Software

There is no single best platform for every isolated environment. Some products focus on operational messaging, others on video, file collaboration, federation, or visual mission planning.
1. Mattermost
Best for: operational messaging, ChatOps, incident coordination, defense, and technical teams.
Mattermost provides self-hosted messaging and collaboration across connected, hybrid, and air-gapped environments. Its deployment documentation describes air-gapped installations where public package repositories, container registries, app stores, and SaaS APIs are unavailable.
The platform supports public and private channels, direct messages, threads, role-based access controls, audit capabilities, and operational workflows. Air-gapped deployments require internal alternatives for functions that normally depend on external services. Push notifications can require a private push proxy, plugins may need to be imported manually, SMTP should be hosted internally, and cloud AI services need self-hosted alternatives.
Strengths: operational messaging, documented air-gap deployment, ChatOps workflows, RBAC, audit capabilities.
Limitations: supporting infrastructure, plugins, updates, notifications, and integrations require internal administration.
2. Pexip
Best for: secure video conferencing, defense communications, and environments with existing SIP or H.323 systems.
Pexip focuses on self-hosted and controlled video communication. Its defense-oriented deployment options include private and disconnected environments where video communication needs to remain available without ordinary public cloud dependencies.
Interoperability is a major part of the platform. Pexip supports SIP and H.323 systems and can fit into environments that already operate video endpoints, meeting-room equipment, or mission communication infrastructure.
Strengths: video-focused architecture, interoperability, disconnected deployment support, policy and access controls.
Limitations: organizations that need persistent team messaging and document collaboration may require additional software.
3. Nextcloud Talk
Best for: organizations that need communication alongside files, documents, and private productivity tools.
Nextcloud Talk combines chat, voice, video conferencing, file sharing, and collaboration within the broader Nextcloud environment. The self-hosted model allows organizations to keep communication and content inside infrastructure they control.
This approach is useful when an isolated environment needs more than messaging. Files and communication can operate under the same collaboration stack rather than relying on several public cloud services.
Strengths: messaging, video, files, broad collaboration scope, self-hosting.
Limitations: a larger collaboration stack creates more internal services, dependencies, storage, and maintenance responsibilities.
4. Rocket.Chat
Best for: self-hosted messaging, extensibility, defense environments, and organizations that need customizable communication workflows.
Rocket.Chat documents deployment in air-gapped environments where normal access to cloud services is unavailable. Administrators can review cloud-dependent functionality and disable or replace components that cannot operate inside the isolated network.
Organizations can deploy private applications and integrate internally hosted services. Video communication can also be provided through compatible self-hosted integrations such as Pexip or Jitsi, depending on the architecture.
Strengths: messaging, customization, private applications, DLP options, documented isolated deployment.
Limitations: mobile push notifications, marketplace functions, updates, and some integrations require alternative internal implementations.
5. TrueConf Server
Best for: organizations that need enterprise video conferencing and messaging inside a closed network.
TrueConf Server can operate inside an isolated network perimeter without requiring public internet access for internal communication. Users can access video conferencing, messaging, file exchange, screen sharing, and other communication functions within infrastructure controlled by the organization.
The platform supports customer-controlled deployment, persistent messaging, large video meetings, and federation between independent TrueConf Server installations where administrators explicitly allow communication. Each deployment can retain its own users, policies, infrastructure, and administration.
TrueConf also supports SIP and H.323 interoperability, which is useful for environments with existing video endpoints, PBX systems, MCUs, and conference-room infrastructure.
Strengths: video conferencing, persistent messaging, closed-network operation, federation, SIP/H.323 interoperability, customer-controlled infrastructure.
Limitations: organizations remain responsible for server infrastructure, identity services, monitoring, updates, backups, redundancy, and other parts of the isolated environment.
6. Wire
Best for: encrypted messaging and conferencing in enterprise and government environments.
Wire provides an on-premises enterprise deployment model that can be used in highly controlled environments, including isolated infrastructure. The platform combines messaging, file exchange, voice, and conferencing with strong encryption.
For strict air-gap deployments, organizations need to review functions that assume external users, mobile services, or external federation and determine which components are allowed inside the security architecture.
Strengths: encrypted messaging, meetings, self-hosted deployment, enterprise administration.
Limitations: external collaboration and mobile workflows require careful planning in completely disconnected environments.
7. Element Server Suite Pro
Best for: federated secure messaging, multi-site isolated networks, sovereign communication, and cross-domain architectures.
Element Server Suite Pro is based on Matrix and supports deployment in secured and air-gapped networks. Air-gapped bundles can be moved into isolated environments and hosted through private registries rather than requiring access to public container repositories.
Federation is a key differentiator. Independent organizations or sites can operate separate Matrix environments while exchanging permitted communication through controlled federation. This can support architectures where each organization must maintain its own infrastructure and trust boundary.
Element also supports encrypted messaging, voice and video, enterprise identity integration, access controls, auditing, and organization-controlled data retention.
Strengths: federation, Matrix interoperability, encrypted communication, air-gap deployment bundles, multi-site architecture.
Limitations: enterprise deployments require careful administration of Matrix, Kubernetes, identity, storage, and supporting infrastructure.
8. Bluescape
Best for: visual collaboration, mission planning, intelligence workflows, and teams working with maps, imagery, documents, and shared visual information.
Bluescape supports private infrastructure and air-gapped deployment models. Its focus differs from conventional team messengers because it provides shared visual workspaces where users can organize documents, imagery, plans, maps, and operational content.
In complex environments, Bluescape can complement communication platforms rather than replace them. It can be combined with messaging and video tools to create a broader mission collaboration stack.
Strengths: visual workspace, mission planning, content collaboration, deployment in controlled environments.
Limitations: usually more valuable as one component of a broader communication architecture than as a standalone messaging platform.
Air Gapped Communication Platforms Compared
| Platform | Primary focus | Best fit | Air-gap support | Messaging | Video | Distinctive capability |
|---|---|---|---|---|---|---|
| Mattermost | Operational messaging | Operational and technical teams | Yes | Core | Available | ChatOps and mission workflows |
| Pexip | Video communication | Secure video environments | Yes | Limited | Core | SIP/H.323 interoperability |
| Nextcloud Talk | Collaboration suite | Teams needing files and communication together | Yes | Yes | Yes | Files and productivity integration |
| Rocket.Chat | Messaging | Extensible self-hosted communication | Yes | Core | Through supported integrations | Extensible internal apps |
| TrueConf Server | Unified communications | Organizations needing video and messaging in one platform | Yes | Yes | Core | Video plus messaging and federation |
| Wire | Secure communication | Government and encrypted enterprise collaboration | Yes | Core | Yes | Encrypted enterprise collaboration |
| Element | Federated messaging | Multi-site and federated isolated networks | Yes | Core | Yes | Matrix federation and multi-site architecture |
| Bluescape | Visual collaboration | Mission planning and visual workflows | Yes | Limited | Through integrations | Mission planning and visual workspace |
The main difference is not simply which product offers more features. The correct choice depends on which communication workload must remain available inside the isolated network.
Insight 3: The best air-gapped platform is often a stack rather than one application.
A defense environment may use one system for operational chat, another for standards-based video, and another for visual mission planning. The security architecture should define how these components exchange data instead of forcing every workload into a single product.
How to Choose Air Gapped Communication Software?

Start with the isolation requirement before comparing user-interface features.
1. Define the Security Boundary
Document which users, servers, facilities, devices, and network segments belong inside the air gap.
Determine whether the deployment is physically disconnected, logically isolated, or connected to other security zones through controlled gateways.
2. Identify External Dependencies
Ask whether the product requires any of the following for normal operation:
- vendor licensing servers;
- external push services;
- public DNS;
- public certificate services;
- cloud identity providers;
- external TURN or STUN servers;
- SaaS APIs;
- app stores or package repositories.
Every mandatory dependency can weaken or complicate the isolated architecture.
3. Check Update and Supply-Chain Procedures
Air-gapped software still needs security updates.
The organization needs a controlled process to download updates outside the protected network, validate them, scan them, approve them, move them across the boundary, and deploy them internally.
Products that provide documented offline bundles or private-registry workflows can simplify this process.
4. Test Internal Voice and Video Dependencies
Real-time communication often depends on media relays, STUN, TURN, or other network services.
Verify whether these services can be hosted entirely inside the protected network. An application that supports offline messaging but relies on external infrastructure for conferencing is not a complete air-gapped communication solution.
5. Evaluate Identity and Administration
Users should be manageable through local identity infrastructure.
Administrators should also be able to control permissions, retention, logging, federation, recordings, integrations, and file sharing without accessing a vendor cloud portal.
Operating Air Gapped Communication Over Time
Initial installation is only the first stage. Long-term operation is usually the more difficult problem.
Administrators need procedures for:
| Operational task | Air-gap requirement |
|---|---|
| Software updates | Secure offline import and verification |
| Vulnerability response | Internal inventory and patch process |
| User management | Local directory or identity system |
| Certificate renewal | Internal certificate infrastructure |
| Monitoring | Local monitoring and alerting |
| Backups | Protected internal or offline backup storage |
| Log retention | Internal SIEM or audit archive |
| Mobile access | Approved devices and internal connectivity |
| Integrations | Self-hosted or security-approved services |
| Disaster recovery | Secondary isolated infrastructure or protected backups |
A product should therefore be evaluated not only on whether it installs without internet access, but also on whether it can be maintained without gradually introducing uncontrolled external dependencies.
Insight 4: Maintenance is where many air gaps become porous.
Teams often design a disconnected production network but later create exceptions for software updates, licensing, monitoring, mobile notifications, or remote support. Each exception can become a permanent network dependency unless it is designed and governed explicitly.
Common Air Gapped Communication Use Cases
Defense and Intelligence
Classified command environments may require messaging and conferencing that remain inside networks dedicated to a specific security classification.
Multi-site deployments may also require controlled federation or cross-domain transfer mechanisms.
Critical Infrastructure and Industrial Systems
Power generation, manufacturing, energy, transportation, and industrial-control environments may separate operational technology from ordinary enterprise networks.
Internal communication tools can allow engineers and operators to coordinate without moving operational information into consumer or public-cloud services.
Government and Law Enforcement
Agencies can use isolated communication infrastructure for sensitive investigations, protected operations, crisis coordination, or networks subject to strict security controls.
Research and Intellectual Property
Laboratories and engineering organizations working with highly sensitive prototypes, algorithms, defense technologies, or proprietary designs may isolate communication from ordinary corporate networks.
Incident Response and Out-of-Band Communication
An isolated collaboration environment can also serve as a separate communication channel during a cyberattack.
If the main enterprise environment is compromised, an independent communication system can allow the incident-response team to coordinate without relying on infrastructure that may be under attacker control.
Air Gapped Communication Best Practices
Keep the architecture as simple as the security requirement allows. Every additional service, integration, plugin, and gateway adds another dependency that needs to be maintained and reviewed.
Use least privilege for both users and administrators. Administrative access to communication infrastructure should be tightly controlled, logged, and separated from ordinary user activity.
Treat removable media and imported updates as security-sensitive workflows. Files crossing the air gap should pass through approved scanning, verification, and transfer procedures.
Test communication during actual isolation. Disconnect external connectivity during acceptance testing and confirm that authentication, messaging, video, DNS, certificates, logs, backups, and administration continue to function.
Conclusion
Air gapped communication allows organizations to run messaging, voice, video, file exchange, and collaboration without depending on the public internet or ordinary cloud infrastructure. Its main benefits are infrastructure control, predictable data location, reduced external exposure, and operational independence. These advantages make the architecture relevant to defense, intelligence, government, critical infrastructure, industrial systems, research, and other high-assurance environments.
The difficult part is not simply installing a self-hosted messenger inside an isolated network. A complete air-gapped communication environment must also provide local identity, media routing, administration, monitoring, certificates, update distribution, backups, and controlled data-transfer processes. Platforms such as Mattermost, Pexip, Nextcloud Talk, Rocket.Chat, TrueConf Server, Wire, Element, and Bluescape solve different parts of this problem, so selection should begin with the communication workload and security architecture rather than a generic feature checklist.
FAQ
What is air gapped communication?
Air gapped communication is messaging, voice, video, file exchange, or collaboration that operates inside a network isolated from the public internet or other untrusted networks. The communication platform and its required infrastructure are hosted within the protected security boundary.
Can video conferencing work in an air-gapped network?
Yes. Video conferencing can work without internet access if the conferencing server, media routing, identity services, DNS, certificates, and any required TURN or similar services are hosted internally. Platforms such as TrueConf Server and Pexip are designed for deployment models where video communication can remain inside controlled infrastructure.
Is an air-gapped network completely secure?
No. Air gapping reduces many network-based attack paths but does not eliminate risks from removable media, insiders, compromised updates, maintenance devices, physical access, or supply-chain attacks. Endpoint protection, access control, monitoring, and operational security remain necessary.
Can two air-gapped networks communicate with each other?
Yes, but communication requires a deliberately controlled architecture. Organizations can use approved gateways, cross-domain systems, private links, or controlled federation between isolated environments while keeping ordinary internet access disabled.
How are software updates installed in an air-gapped network?
Updates are normally downloaded in a connected environment, verified, scanned, approved, and transferred into the isolated network using an authorized process. Some products provide offline deployment bundles or private-registry workflows to simplify this process.
What is the difference between air gapped and on-premises communication?
On-premises means the organization hosts the software on its own infrastructure, but that infrastructure may still have internet access. Air gapped communication adds a stronger isolation requirement in which the communication environment operates without ordinary connectivity to external networks.
What should I look for in an air-gapped collaboration platform?
Look for true offline operation, internal identity integration, locally hosted messaging and media services, audit logging, private storage, offline update procedures, controlled integrations, and clear documentation for isolated deployment. The platform should continue functioning when external connectivity is physically unavailable rather than merely restricted by policy.



Top comments (0)