Document collaboration inside an isolated network.
Air-gapped document collaboration runs inside an isolated network using offline installation packages and internal services. OfficeDocs supports this deployment path; confirm the configured storage, identity and AI endpoints stay inside your boundary before acceptance.
OfficeDocs is a self-hosted document collaboration suite for real-time docs, writers, spreadsheets, presentations, forms and tables, with configurable AI agents built into every product, deployed into a private cloud you control.
Free plan
5 users
Team plan
$5 per user per month
Annual billing
20% off
Deployment
single-node or high-availability Kubernetes
Why an air gap changes the design, not the features
An offline deployment needs a plan for installation, licence activation, upgrades and optional AI services. Identify these dependencies before installation, then validate the configured system with outbound access denied.
OfficeDocs installs from offline image packages and the deployment guide documents the isolated path explicitly, alongside the online one. The installer accepts an external middleware address instead of bundling its own, so the suite can be pointed at infrastructure that already exists on the isolated side.
Four things, and all of them are ordinary files. That matters because it means the deployment can be built and refreshed through whatever controlled transfer process your environment already uses, rather than requiring a network connection to be opened.
The installer binary for the architecture you run, amd64 or arm64
The offline image tarball, which carries the container images the deployment needs
The licence file, obtained separately and activated from the operations platform
Any external middleware packages, if you are running MySQL, Redis, MongoDB or Kafka yourself
Because a licence is a file rather than a phone-home check, enabling the suite on an isolated network does not require a temporary connection. The free perpetual licence for teams of up to five people is issued the same way.
AI without outbound access
The usual casualty of an air gap is AI assistance, because hosted model APIs are unreachable by definition. The AI configuration layer in OfficeDocs points at an endpoint you specify, which on an isolated network means a model served inside the enclave.
Review all configured services: base model, image model, embeddings and online search. Each enabled endpoint must be reachable inside the enclave; leave online search unconfigured when no internal service is available. Disabling search alone does not stop a hosted model or embedding endpoint from receiving context. If no model is available in the enclave, use the collaboration features without AI.
It is more useful to be specific than to claim nothing changes. Three categories of feature depend on reaching the public internet and stop working on an isolated network.
Third-party integrations that call out to an external service on the user behalf
Public link sharing to recipients outside the enclave, for the obvious reason
Any AI model that is only available as a hosted API rather than something you can run
Everything in the collaboration core — real-time co-editing, comments and suggestions, version history, document-level permissions, audit logs, forms, spreadsheets, presentations and search — is internal traffic and works normally.
Validate an isolated deployment
Use a representative workspace and record the results before accepting the environment.
Prepare the installer, offline images, licence file and middleware through your approved transfer process.
Install the suite and verify the licence in the operations platform before publishing the configuration.
With internet egress denied, have two internal users edit a document, comment, reopen it and check version history.
Test each enabled AI capability and inspect network logs for attempted external connections; correct or disable any external endpoint.
Rehearse a backup restore and an offline upgrade in a test environment, and keep the acceptance record with the runbook.
The failure mode of air-gapped systems is not the initial install; it is that nobody can upgrade or diagnose them two years later. Two things in the operations platform are aimed squarely at that.
Upgrades are applied by uploading an installation package, with the platform running its own compatibility checks before it starts — so the transfer process produces a reviewable event rather than an automatic change. And when something does go wrong, the operations platform carries the diagnostic surface inside the enclave: service and real-time logs, middleware inspection, cluster management, container packet capture and a monitoring metrics reference, with no external observability service required.
The architecture you are deploying on, amd64 or arm64
A controlled transfer process for files, and who signs it off
Whether middleware is bundled in the package or already present in the enclave
A licence file requested in advance, not during the install window
A decision on whether an in-enclave model endpoint will be available for AI
A backup target inside the enclave, tested with a restore
Frequently asked questions
Can you run document collaboration in an air-gapped network?
Yes. It requires a deployment that can be installed from offline image packages, performs no licence call-out at runtime, and does not depend on a hosted model endpoint. OfficeDocs documents the offline installation path and supports external middleware on the isolated side.
How does AI work in an air-gapped deployment?
Configure internal endpoints for every AI capability you enable, including models and embeddings, and leave internet-dependent search disabled. Verify the configuration with outbound access denied. If no compatible model is available inside the boundary, use the collaboration features without AI.
What has to be transferred across the air gap?
The installation package, the offline image tarball, the licence file and any middleware you run externally. All four are ordinary files, which is why the deployment can be built and refreshed through a controlled transfer process rather than a network connection.
Does an air-gapped deployment lose any features?
You lose the features that are inherently online: third-party integrations that call out, public link sharing to the internet, and any AI model that is only available as a hosted API. Real-time editing, comments, version history, permissions, audit logs and search all work normally.
How are upgrades handled without internet access?
The operations platform accepts an uploaded installation package and runs its compatibility checks before applying it. On an isolated network the package is brought across by the same controlled transfer used for the original installation, so upgrades follow a reviewable process rather than an automatic one.