Semantic Enforcement · High-Security · Triodian

Solution · Classified & sovereign AI

A hard limit on what a classified AI can reveal, one the model itself cannot switch off.

For militaries, intelligence agencies and their contractors already running air-gapping, on-prem hosting and clearance-based access control. The Suite adds the interior layer that stack handles by trust: a per-output verdict against a signed library, a hardware default-deny gate, and a third-party-verifiable attestation, sized to a nation-state-adjacent threat model via graduated tiers.

Discuss a sovereign deployment → See the control stack →

What's different about this one

The distinctive machinery of the sovereign case.

Use-Governance Monitor, three Kestrel sessions in flight with the KA-2312 intent-trajectory plane and exchange timeline

Use-Governance Monitor · illustrative data · KA-2312 drifting this cycle

How this is an embodiment of the Semantic Enforcement Suite

The Suite re-pointed from a commercial book to a sovereign AI system.

This is the same architecture screen-for-screen, re-instrumented for the defence/intelligence use-governance case. The reference build (Aggregate Drift) is the template; this app mirrors it exactly: same design system, same multi-persona switcher, same chrome, same viz/record/ledger idioms.

Same taxonomy. Suite (the offering) · Engine (the verdict logic on the Attestation screen) · Appliance (the unit bolted down on the hardware/interlock screens). The three tiers (Rules ships now / Distribution certify / Semantic under experiment) are modes of the Appliance.

The governed application is a staff assistant. "Kestrel Assist" is the enforcement point, a chat surface where you watch governance happen: a prompt-side gate strip (use-auth ✓/deflect, inbound-disclosure ✓/block) between the user bubble and the model call, and a response-side gate strip (outbound-disclosure ✓/redact, prohibited-activity ✓/block) between the model output and the displayed bubble.

Same persona seats: Use-Governance Monitor (runtime), Semantic Library (authoring), Enforcement Engine (attestation + hardware), Oversight Report (commissioning roll-up), Inspector Review (independent verify-without-trusting). The switcher is the org chart.

The Intent-Trajectory layer. The distinctive high-security addition: the monitor shows not just per-exchange verdicts but a heading + confidence + expandable meaning events, "no single exchange breached; the trajectory did", and a reviewer sees why and can disagree.

Built on the Semantic Enforcement Suite →

What's different about this one

The distinctive machinery of the sovereign case.

Sovereign posture

Open-weight model, on-prem, no external inference path. Root-of-trust status and measured-image hash shown on the tier/posture strip. All verdict computation stays inside the boundary.

Prompt-side and response-side lanes

Two gate strips per exchange (slate for prompt-side, copper for response-side), each firing a distinct control: use-authorisation, inbound-disclosure, outbound-disclosure (redact), prohibited-activity (block).

Intent-trajectory reviewing

A reviewer adjudicates an inference, a heading with confidence and the meaning events behind it, with an explicit mandate to disagree. Guardrails: attribute to the sequence, never the psychology; the heading is a signal, never the enforcement reason.

Releasability caveats

AUSTEO-style caveats and scope banners rendered as first-class constraint metadata.

Separation of duties by keys

Mirroring clearance compartmentation: author ≠ operator ≠ inspector ≠ governed user, enforced technically, not by policy.

Data-egress discipline in the refresh loop

The external authoring model receives drift evidence, not data, reference-vector deltas and novelty summaries, never live inputs or outputs. The refresh loop →

The three canonical sessions

One story, told the same way on every screen.

KA-2291

Nominal

Every exchange within its brief; clean verdicts across the board.

KA-2304

Novel-but-authorised

A legitimate question outside the current envelope; routed to review, not answered blind.

KA-2312

Recognised-drift

No single exchange breached; the trajectory did, gated at the set level.

These appear identically across Monitor, Engine ledger, Oversight roll-up, and as the scripted Kestrel Assist drift-walk conversation, that consistency is what makes the demo read as one system.

What we don't claim

This must not imply: that it governs weapons, targeting or force (out of scope); that the semantic tier is proven (it is under experiment, caveat-tagged); or that a token equals safety or discharges meaningful human control.

The software tier is tamper-evident, not non-bypassable, for the nation-state threat model this is the material limit; the hardware tier is the answer where physical non-bypassability is required.

One Suite, many operations

Likeness Attestation →

High-Security (you are here)

Operational Assurance →

Discuss a sovereign deployment.

Talk to us →
The Suite The control stack Status
Scope

This governs information use and disclosure. It does not govern targeting, fire-control, or any actuation of force. Demonstration scenario.