Amastan · Pilot RC1 · System Specifications

Amastan AI-SWG — System Specifications

Hardware, network, capacity by user scale, security properties, and documentation set for architects and procurement.

Product: Amastan AI Secure Web Gateway
Release: Pilot RC1
Audience: IT architects, security engineers, procurement
Updated: 2026-08-23

1. Product summary

Amastan is a self-hosted AI Secure Web Gateway. It inspects outbound web traffic, applies allow / block / optional Remote Browser Isolation (RBI) decisions, and keeps verdicts and logs on infrastructure you control.

Verdicts: Allow · Block · Isolate (RBI)

2. What the platform includes

AreaWhat you get
Web filteringAllow / block / optional safer remote browse (RBI)
AI assistHelps judge unknown or grey-zone websites
ManagementOperator console (React Admin UI), Keycloak-ready OIDC
IdentityLDAP / Active Directory for user-aware policy
Data on sitePolicy cache, decision logs, optional vector / object stores as configured
ObservabilityPrometheus, Grafana, Loki / Promtail
Optional licensedDLP, Shadow IT / unofficial cloud apps, email-link controls

3. Deployment model

4. Recommended sizing (lab & by named users)

Lab / pilot profiles

ProfilevCPURAMDiskNotes
Lab eval8+32 GB200+ GBFunctional demo + QA
Small pilot1664 GB500 GB+Light production-like load
HA pilot2× nodes64 GB each500 GB+ eachDual-node HA pattern

Capacity by named users (system-test planning)

Named users Peak concurrent (est.) Nodes vCPU / node RAM / node Disk / node
500~50–1001 (HA optional)12–1648–64 GB500 GB
2,000~200–4002 (HA)1664 GB1 TB
4,000~400–8002 (HA)2496 GB1.5 TB
10,000~1,000–2,0002–332128 GB2 TB
20,000~2,000–4,0003–432–48128–192 GB4 TB
Exact sizing depends on concurrent users, TLS intercept policy, RBI rate, and ML model mix. Validate with a scoped load test during the pilot before procurement lock-in.

5. Network & ports (typical lab)

ServicePort (host)Purpose
HTTP(S) proxy80 / 443User web traffic
Sidecar API8010Classify / health (internal)
Admin UI8080Operator console
IdentityKeycloak (as deployed)Admin / directory

Harden exposure before production; do not publish management ports to the internet.

6. Identity & integrations

7. Security properties

8. Pilot appliance artifact

ItemValue
Imageai-swg-v1.0.1-pilot-rc1-sanitized.qcow2
Formatqcow2 (KVM/QEMU)
IntegritySHA-256 published with download entitlement
AccessRequest via official site contact (not anonymous public mirror)

9. Documentation set

DocumentContents
User / Client GuideFirst login, dashboard, day-2 operator flows
Admin GuideDeployment, HA, identity, policies, capacity, roadmap
System SpecificationsThis document
CISO One-PagerExecutive brief (EN / FR / AR)

10. Roadmap (high level)

Next step: Request a pilot · email kabdi.kalboddine@gmail.com

© Amastan — Pilot RC1 system specifications. Verify before production procurement. Print → Save as PDF if needed.