The dark sites, SCIFs, command centers, and secure enclaves where a single misconfigured port or writable drive is a security incident waiting to happen. From stateless zero clients to multi-domain secure KVMs and removable hard drive workstations, every product on this page was engineered around one requirement: no path for data to leave the room that isn’t supposed to.
If your team is searching for a SCIF-approved computer, a dark site workstation, or hardware that can pass a security accreditation review the first time, this is the ClearCube product line built for that job.
What Makes a Computer “Air-Gap Ready” or “SCIF-Ready”?
Government and military IT specialists evaluating hardware for a secure enclave are typically checking for a specific set of physical and firmware-level controls — not just software policy. ClearCube builds these controls directly into the hardware:
Endpoints ship with copper, fiber (SFP), or fiber-only network options, and wireless radios can be physically omitted or disabled — eliminating an entire class of RF-based exfiltration risk in TEMPEST-sensitive spaces.
Zero clients and Zero+ Clients® use soldered-down memory and components, with no accessible OS, session memory, or local storage — so there's simply nothing on the device to steal, image, or infect, even if it's physically tampered with or stolen.
Most endpoints and workstations ship with DisplayPort (DP) rather than HDMI, the connector standard preferred in secure government deployments.
Integrated smart card readers support Common Access Card (CAC), PIV, and SIPR token authentication, including models where the reader follows the active network as a user switches domains.
Choose Windows, Linux, or IGEL OS — a secure, read-only, encrypted Linux-based endpoint OS purpose-built for locked-down VDI and DaaS environments and widely deployed across federal and DoD networks.
Endpoints support network boot and centralized OS imaging, so IT can deploy, re-image, or update fleets of devices from a controlled server rather than touching each unit by hand.
Select workstations and blade PCs offer a removable, boot-capable hard drive that pops out in seconds — no cable disconnects required — so classified data at rest can be secured without physically vaulting the entire machine.
Rackmount and blade PCs support GPUs up to workstation-class cards (including multi-GPU and triple-wide configurations) for CAD, GEOINT, simulation, and other graphics-intensive classified workloads — without relying on a shared virtual GPU.
For operators who must reach more than one classified network from a single desk, ClearCube's ClientCube family provides NIAP PP 4.0-certified, hardware-isolated switching between domains — with no shared cabling or crosstalk between networks.
Hardware is designed and assembled to meet federal procurement and Trade Agreements Act requirements, and is listed on GSA Schedule through our distributor, Carahsoft.
ClearCube Product Lines for Secure Enclaves
Zero Clients & Zero+ Clients®
THE STATELESS ENDPOINT
A zero client is an endpoint with effectively no OS, memory, or local storage — it receives encrypted pixels from a centralized host rather than actual data, making it one of the most secure endpoint categories available for classified and air-gapped networks.
TERA2 Zero Clients
Use a dedicated PCoIP hardware chip to decode the display stream in fixed-function silicon. There is no writable OS layer to compromise, no local data to lose if the unit is stolen, and no software attack surface — a common requirement for the most restrictive dark site deployments.
Zero+ Clients®
Add protocol and OS flexibility (VMware Horizon/Blast, Citrix, PCoIP, Leostream, Nutanix) while keeping soldered-down components and an optional CAC reader, so IT can standardize on one device family across mixed classified and unclassified environments.
ClientCube
MULTI-DOMAIN SECURE KVM SWITCHING
Consolidates 2 to 8 zero clients and a NIAP PP 4.0-certified secure KVM into one chassis, so analysts and command staff reach SIPRNet, NIPRNet, and JWICS from a single desk. Each network path stays physically and electrically isolated, meeting NIST 800-207 Zero Trust hardware-isolation expectations, with CAC/PIV readers that can follow the active domain automatically.
Removable Hard Drive Workstations
FOR SITES THAT VAULT DATA DAILY
Built originally for a customer vaulting entire workstations at the end of every shift, ClearCube’s removable hard drive line lets IT pop out a boot-capable 2.5″ drive in seconds instead of disconnecting and re-cabling a full PC. Available across:
NUC-R Mini PC
Compact desktop NUC with a removable drive, vPro, and TPM 2.0
SRW & PRW Rackmount Workstations
1U/2U rackmount systems with dual removable drive bays
EdgeCube SFF Desktop
Small-form-factor desktop with optional removable drive and CAC reader
A-Series Blade PC
Dual removable drive bays accessible without pulling the blade from the chassis
Rackmount & Blade PCs
COMPUTE CENTRALIZED IN THE SECURE DATA CENTER
Moving processing power off the desk and into a controlled data center or IT closet is itself a core air-gap security strategy: no functioning PC sits exposed at an unattended desk, and a lost or compromised endpoint holds no data. ClearCube rackmount and blade PCs support GPU options up to A5000/A6000-class cards, dense 6U chassis configurations, and dedicated 1:1 hardware — avoiding the resource contention and attack-surface concerns of shared virtual GPUs in classified environments.
Thin Clients & NUCs with IGEL OS
FULL OS FLEXIBILITY
For sites that want the flexibility of a full endpoint OS without sacrificing lockdown, ClearCube thin clients and NUC-based mini PCs support IGEL OS — a secure, encrypted, read-only Linux endpoint operating system — alongside Windows 11, with PXE boot support for centralized, hands-off imaging across the fleet.
Government & Military Use Cases
Zero clients and Zero+ Clients keep classified processing in the data center, not on the desk, with no local storage for an intruder — physical or digital — to target.
ClientCube lets a single operator securely reach SIPR, NIPR, and JWICS from one keyboard, mouse, and display set, without stringing separate cable runs and PCs for every network.
Removable hard drive workstations cut daily vault-and-restore procedures from a multi-cable disconnect to a five-second drive swap — across dozens or hundreds of seats.
Compact, removable-drive and zero client configurations relocate quickly for tactical or expeditionary deployments, with the data volume secured independently of the rest of the kit.
Multiple operators can share a single workstation chassis, each authenticating with their own CAC/PIV credential or removable drive, without provisioning a dedicated machine per person.
GPU-equipped rackmount and blade PCs deliver dedicated graphics performance for visualization-heavy workloads that can’t rely on a shared or virtualized GPU.
Government & Military Use Cases
Frequently Asked Questions
A “dark site” or air-gapped computer is hardware deployed in a facility that is physically isolated from the internet and other outside networks — common in SCIFs, classified data centers, and command centers. These systems typically eliminate wireless radios, local writable storage, and any other pathway that could allow data to leave the isolated network.
Yes. Zero clients are one of the most common endpoint types deployed inside SCIFs because they have no local OS, memory, or storage — all processing and data stay on the centralized host in the data center, and the endpoint itself has effectively no attack surface even if it's tampered with or removed from the space.
Vaulting a full workstation means disconnecting power, video, network, and peripheral cables — then re-cabling everything the next shift. A removable, boot-capable hard drive lets IT secure the actual classified data in seconds, while the rest of the workstation, monitors, and cabling stay untouched and ready to go.
Yes. Most ClearCube zero clients, Zero+ Clients, and ClientCube multi-domain switches offer integrated or optional smart card readers that support CAC, PIV, and SIPR token authentication, including configurations where the reader automatically follows the active network domain.
IGEL OS is a widely deployed, encrypted, read-only Linux endpoint operating system used extensively across federal and DoD VDI/DaaS environments. ClearCube thin clients, NUCs, and Zero+ Clients support IGEL OS alongside Windows and standard Linux, giving IT a locked-down OS option without moving to a fully proprietary device.
Yes. ClearCube rackmount and blade PCs support dedicated, workstation-class GPUs (up to A5000/A6000-class and triple-wide configurations) for CAD, GEOINT, and simulation workloads — delivering dedicated graphics performance without relying on a shared or virtualized GPU pool.
A NIAP PP 4.0-certified secure KVM, like the one built into ClearCube's ClientCube, physically and electrically isolates each network path while sharing a single keyboard, mouse, and display set — letting an operator switch domains without any risk of data crossing between them.
Talk to ClearCube About Your Secure Enclave
Contact our government solutions team to discuss which zero clients, ClientCube configurations, removable-drive workstations, or rackmount PCs fit your SCIF, dark site, or air-gapped network.