JetPatch governs Windows and Linux patching from one console — across the full connectivity spectrum, from restricted egress to fully air-gapped. No outbound connection from a server or endpoint, ever.
Restricted egress, partial isolation, and full air-gap aren't three different products — they're the same JetPatch architecture, with the outbound connection controlled as tightly as your policy requires.
Outbound traffic is limited to specific, whitelisted destinations. Only the JetPatch Manager is permitted to reach vendor update sources — on a schedule you control — while every server and endpoint remains fully internal.
Specific network segments have no outbound path at all. The Manager operates from a segment that does, syncing verified content into the isolated segments over internal-only connections — no exceptions carved into the isolated zone itself.
No segment has any outbound connectivity. The Manager's connection to vendor sources runs on a scheduled, audited window, and every server and endpoint downstream stays completely sealed from the outside world.
Wherever your policy sits on this spectrum, the architecture underneath it doesn't change.
Windows and Linux need different mechanisms to stay isolated. JetPatch already knows both, so you don't have to design either from scratch.
Building your own local Linux repository infrastructure for an isolated environment usually means a separate mirror server per distribution. The Unified Linux Repository replaces all of it with one host JetPatch already knows how to run.
reposync and createrepo jobs, maintained and debugged by your own team.JetPatch is not a vendor-hosted SaaS product. It's installed and runs entirely inside your own infrastructure.
JetPatch is installed software — it does not run in JetPatch's cloud, and no patch data ever leaves your environment through a hosted backend.
The platform does not send usage or environment data outside your network. What stays inside your environment, stays inside your environment.
Deploy on-premises or inside your own private cloud tenancy — the architecture is the same either way, and you control where it lives.
Every framework still asks the same question: are all systems patched on a defined cadence, and can you prove it? JetPatch answers that for the systems that are hardest to prove — the isolated ones.
A.12.6.1 — Management of technical vulnerabilities, with audit-ready reporting across every isolated segment.
Article 21 — Patch management as a mandatory measure, documented the same way regardless of connectivity posture.
Requirement 6.3 — Security vulnerabilities addressed, with evidence generated automatically as part of every patch cycle.
This page covers the architecture and the value. For more detail on any of these topics, click through to the dedicated page below.
The full 12-step Windows mechanism — from Manager to local update store to endpoint.
See the Windows mechanism →Advisory-level patching and the Unified Linux Repository, distribution by distribution.
See the Linux repository model →20+ operating systems from one console. The full platform picture.
See the full platform →Tell us about your environment — restricted egress, partially isolated, or fully air-gapped — and we'll show you exactly how JetPatch handles it.