High-Security Control Stack · Triodian

How it fits your security stack

The inside layer your existing security stack is missing.

Militaries, intelligence agencies and their contractors already run a mature, layered set of controls. Those controls are the precondition for deploying any AI capability, not something an AI product replaces. The Suite adds the one capability conventional practice handles weakly: a deterministic, independently-verifiable constraint on what a model may emit or do, enforced by a mechanism the model itself cannot influence.

Talk to us → The Semantic Enforcement Suite →

The standard stack answers "can data get out, and who may ask the system anything?" The Suite answers the question the standard stack leaves to trust: given that the model runs inside the boundary, did its output stay within the rules, and can we prove it to a third party without trusting the operator?

The controls you already run

Strong at the perimeter and at access. Silent on the model's own behaviour.

Network isolation / air-gappingKeeps the system off untrusted networks.
On-premise / self-hosted modelsRuns the model on infrastructure you own.
Data-loss prevention & egress filteringBlocks known-bad content leaving by known channels.
Cross-domain solutions / data diodesEnforces one-way movement between classification domains.
Access control & least privilegeLimits who may query and what they may retrieve.
Provenance & supply-chain vettingValidates weights and components before deployment.
Sandboxing & constrained executionContains what a running process can reach.
Human-in-the-loop & output reviewPuts a person between output and action, sampled.
Logging, audit & red-teamingRecords activity and probes for weaknesses.

The consistent weak point is the model's own behaviour, guardrails, drift monitors and advisory safety layers are probabilistic and software-mediated, so a privileged or compromised component can bypass them, and a model that is merely persuaded can exceed its brief in ways no perimeter control sees.

The gap this fills

Treat the model as untrusted. Keep the rules under your own authority.

The model that produces output is treated as untrusted; the rules that govern it are authored, signed, and version-bound under the customer's own authority.

Deterministic enforcement, not advisory guardrails

A separate enforcement layer between model and output; a hardware default-deny gate no software at any privilege can remove.

Remediation, not just refusal

A bounded convergence loop; default-deny only when reconciliation fails.

Proof a third party can check

Hash-linked, hardware-root-anchored attestation; conventional logs are written by the same trust domain they attest to.

Separation of duties as architecture

Persona seats separated by keys and bounded views; no single person can technically occupy two sides.

What each layer gains

Not instead of your stack. Inside it.

Standard practiceWhat it provides todayWhat the Suite adds
Air-gap / on-premise hostingKeeps data inside the boundary; model runs locally.Assumes and requires it; all verdict computation stays on-premise, no live output crosses the boundary.
Access control / need-to-knowLimits who may query and what is retrieved.Architectural separation of the governance roles themselves, enforced by keys and bounded surfaces.
DLP / egress filteringBlocks classified content leaving via known channels.Governs the model's own outputs by meaning, not just keyword, before they are emitted at all.
Supply-chain vetting of weightsValidates weights before deployment; static.Continuously governs a model that may drift or be manipulated after deployment, treating it as untrusted at runtime.
Guardrails / advisory safetyProbabilistic, software-mediated, bypassable.Deterministic verdicts with a hardware default-deny gate the model cannot influence.
Human-in-the-loop reviewManual, sampled, after the fact.Manufactures explicit review points (abstention, novel-but-authorised routing) and records the disposition lineage.
Logging / auditOperator-written; trusts the operator.Operator-independent, cryptographically verifiable per-output attestation a third party can check.

Match the control to the threat

Two tiers. Honest about the line between them.

Attested Semantic Compare

Software · now

Software, confidential enclave

Tamper-evident: verdict bound to inputs and library version; substitution detectable. Deployable today on commodity confidential-compute.

Available now; protects the rule set and generates deployment evidence. A privileged enclave compromise remains within its threat model.

Deterministic Governance Architecture

Hardware

Dedicated hardware datapath

Non-bypassable: forbidden output physically prevented from emission by a hardware default-deny gate, independent of software at any privilege level.

Where physical non-bypassability is required, the nation-state-adjacent case.

The software tier raises the bar substantially over a monolithic checker but remains software executing in a trusted domain; only the hardware tier claims the physical guarantee. Size the tier to the adversary rather than assume the software tier carries the hardware promise.

Keeping the update path from leaking data

The library refreshes on evidence, never on your data.

01

The governed model's prompts and outputs never leave the boundary; all verdict computation is on-premise.

02

The external authoring model receives drift evidence, not data, reference-vector deltas, novelty summaries, drift descriptors, never live inputs or outputs.

03

The authored library is proposed, not authoritative, signed under customer authority, validated before load, never reaching the verdict path directly; if the external model is unreachable, governance continues against the last-signed library, only refresh pauses.

What we don't claim

The honest boundary, stated in full.

Scope is information use, not force

Governs disclosure and actuation of information; not targeting or fire-control.

The software tier is tamper-evident, not non-bypassable

For a nation-state threat model this is the material limit; the hardware tier is the answer where physical non-bypassability is required.

The demonstration artifact is non-functional

The scope-confirmation app shows the concept with mock data; the semantic tier is under experiment; hardware values are representative.

The authoring model tests provenance, not correctness of the world

A signed, validated library is version-bound, not a guarantee the concept is complete; the independent control envelope, not the divergence trigger, is the actual gate.

Bootstrapping inherits priors

An internally-improved authoring lineage carries a fading imprint of its seed model's value priors; human-authored constraints must remain the anchor it is periodically re-validated against.

The Suite is not unusual for this audience, it is built for it. It presupposes the standard high-security stack and slots in at the single point that stack handles by trust rather than by construction: the behaviour of the AI system itself.

Talk to us →
The Suite High-Security solution Status
Scope

This concerns governance of information use and disclosure. It does not govern targeting, fire-control, or any actuation of force. Any operational scenario is a demonstration scenario.