Defense · CMMC / ITAR

Frontier-class AI inside the authorization boundary.

Air-gapped, on-premise open-weight models give program and engineering teams serious AI assistance while Controlled Unclassified Information and ITAR-controlled technical data stay on systems you own and your cleared US-personcleared, Controlled Goods–registered personnel administer. No public API, no external party in the inference path, no route to the internet.

The problem

Public AI APIs are outside the boundary by definition.

Defense contractors face the sharpest version of the AI adoption problem. CMMC assessment asks one structural question of every system that touches CUI: is it inside an environment meeting NIST SP 800-171 controls? A public AI API is not. ITAR asks a harder one: is controlled technical data ever accessible to systems or persons outside your authorization? Route a prompt through a commercial cloud and the answer stops being provably no.

The consequences are not hypothetical — export-control violations carry criminal exposure, and CMMC certification now gates contract eligibility across the DoD supply chain. Yet the engineering upside of AI is largest exactly here: dense specifications, long test campaigns, legacy code, and program documentation are the workloads long-context models handle best.

Canadian firms in the defense supply chain carry the same discipline through ITAR flow-downs, the Controlled Goods Program, and CMMC requirements arriving via US prime contracts. The engineering upside of AI is largest exactly here: dense specifications, long test campaigns, legacy code, and program documentation are the workloads long-context models handle best.

So most programs sit in an unstable equilibrium: AI banned in the environments where it would matter most, while the workforce watches the rest of the industry accelerate. The resolution is not a waiver. It is an architecture in which the question “does data leave?” has a one-word answer.

The architecture

Owned weights, sealed network, cleared operators.

Open weights are static files: downloaded, checksummed, audited, and incapable of transmitting anything. We deploy them on hardware inside your assessed environment — fully air-gapped, with no telemetry, no license-check callbacks, and no dependency that needs a route out. Inference, retrieval over program documentation, and in-environment fine-tuning all run behind the same boundary your existing controls already defend.

Access control mirrors program structure: per-program enclaves, role-based access, and full audit logging. Where policy requires Western-origin models, the bench is Llama and Mistral; where capability governs, GLM-5.2 and Kimi K3 lead. Model origin is a governance choice — and in this architecture, it is yours.

Deployment blueprint

The air-gapped knowledge system, on paper.

The closest published blueprint: a precision manufacturer’s fully air-gapped deployment — per-project access controls, controlled technical data never leaving authorized systems. The same pattern scales to program enclaves.

Read the air-gapped blueprint

Questions we get

Frequently asked questions

Are CMMC-compliant AI tools possible with cloud APIs?

Rarely, and never simply. CMMC assesses whether Controlled Unclassified Information stays within systems that meet NIST SP 800-171 controls. A public AI API places CUI on infrastructure outside your assessment scope, which either fails the control outright or drags the vendor into your boundary with FedRAMP-level requirements. An on-premise open-weight deployment keeps inference entirely inside the assessed environment — the AI system inherits your existing boundary instead of breaking it.

How does ITAR constrain AI tool choice?

ITAR-controlled technical data cannot flow through systems outside your authorization — including foreign-operated or foreign-accessible cloud services, and including many US cloud services whose support and operations staff are not verified US persons. Self-hosted open weights sidestep the entire analysis: the model is a static file running on your systems, administered by your cleared personnel, with no external party in the inference path.

Can an open-weight model of Chinese origin be used on defense programs?

That is a governance decision, and sovereignty means you get to make it. Open weights are static files — audited, checksummed, incapable of transmitting anything, and run fully air-gapped. But where program rules or procurement policy require Western-origin models, we deploy Llama, Mistral, and other alternatives. Model origin is a selectable parameter of the architecture, not a constraint imposed by a vendor.

Does air-gapped operation cripple the model?

No. Inference, retrieval over program documentation, and fine-tuning all run without any route to the internet. What you give up is live web access; what you keep is everything defense engineering teams actually need — reasoning over specifications, code, test data, and program records at up to 1M tokens of context. Model updates arrive by controlled media transfer on your schedule.

Bring AI inside the boundary.

The two-week sovereignty assessment maps your controlled-data classes, authorization boundaries, and workloads — and hands you a written architecture with a real cost model.

Book a sovereignty assessment