Plan the Control Path First
SafeSquid becomes a production control only when the proxy is sized, reachable, monitored, and able to preserve enforcement evidence. Poor planning causes dropped sessions, weak audit trails, certificate failures, and emergency routing changes during rollout. This page is the map. Each stage links to the page that carries the detail.Work the stages in order
Decisions made out of order tend to be remade. Sizing before the architecture is chosen, or policy design before the licence tier is settled, produces rework that surfaces during rollout rather than during planning.
Choose the deployment scenario
1
Choose new appliance deployment
New VM or hardware appliance
Use the Appliance Builder when a dedicated disk and bootable ISO workflow are approved.
2
Choose cloud or hybrid egress
Cloud or hybrid egress
Use cloud deployment when security groups, route tables, snapshots, and egress paths are owned.
3
Choose managed Linux server
Existing managed Linux server
Use Linux install only when OS hardening, dependencies, monitoring, and rollback are already owned.
4
Choose cluster or DR design
Cluster or DR design
Add HA or DR planning when uptime requirements need failover, configuration sync, and tested restore.
Capture planning evidence
Store these artifacts before installation begins:- Sizing worksheet or change record.
- Network placement diagram.
- Firewall and routing approval.
- Log retention target.
- Activation key storage reference.
- Rollout and rollback plan.
- DR or rebuild assumptions.
Troubleshoot planning gaps
Next steps
- Choose an Architecture - start here for a new deployment.
- Deployment Checklist - convert the plan into install readiness checks.
- Production-Readiness Checklist - the condition the deployment must eventually meet.

