Air-gapped operations
Bookend needs no outbound connection to work. Air-gapped mode changes three things.
1. Metering
Section titled “1. Metering”metering.air_gapped = true (wizard step 9, System → Metering & license, or Settings → Other options) stops the heartbeat. Each quarter an administrator generates the signed usage report from System → Metering & license and delivers it by whatever channel the bank permits (Metering and licensing). The report is signed with the install’s own key, so it can be verified without any connection back to the install.
2. Releases
Section titled “2. Releases”Releases are always pulled by the bank, never pushed. For an air-gapped host, transfer the release bundle (the images in one tar archive, SHA256SUMS, the release notes, the validation pack and VERIFY.md) on approved media. Check the checksums (sha256sum -c SHA256SUMS) and, when the bundle carries a signature file, verify it as VERIFY.md describes; then docker load the images and follow Upgrade.


3. Mail and core
Section titled “3. Mail and core”The SMTP relay and the core endpoint are inside the bank’s network by definition; nothing changes. If there is no relay at all, disable email-link sign-in (auth.login_otp_enabled = false), keep password sign-in, and add users with a password rather than an emailed invite. Escalations are still recorded on the loan before any mail is attempted.
What still works exactly the same
Section titled “What still works exactly the same”Everything else: intake, extraction, reconciliation, execution checks, review, boarding through jXchange (inside the network) or file export, wires, evidence packets, diagnostics, audit, the API and the MCP server. The evidence chain is verifiable offline by design. The optional AI model for drafting document templates is off unless you configure one, and a local model inside the network works.