Monochrome terrain study of a high ridgeline.

Security / Protocols

Analysis in. Nothing out.

Every Hyperborea system is designed so that intelligence comes to the data. Below is the control set that enforces it, grouped the way an assurance review reads it.

Air-gapped by design On-node inference Zero data egress

01 / Principle

We build for operators whose data cannot leave the perimeter.

That is the constraint the architecture was derived from, and it is why there is no vendor cloud anywhere in the trust boundary of a Hyperborea deployment. Every control on this page follows from it.

02 / Control domains

Six domains of control.

These protocols apply to both Hyperborea systems — edge autonomy and threat intelligence — because both are built on the same sovereign edge platform. Each one is stated so that it can be confirmed against the system.

A / BND

Boundary & isolation

  • Systems run with no internet connection required for operation.
  • The secure-systems appliance sits behind a one-way hardware data diode: read-only ingest, no outbound network path.
  • Traffic between classification levels crosses a cross-domain guard rather than a routed connection.
  • Edge systems operate in EMCON and EW-contested theatres, where connectivity is scoped rather than assumed.
Air-gappedHardware diodeCross-domain guardEMCON

B / LOC

Data locality

  • Inference executes on the node — quantised models via llama.cpp / GGUF, on rugged edge compute.
  • Retrieval runs against a local vector store; the index never leaves the perimeter.
  • No prompts, documents or telemetry are sent to a third-party API.
  • Hyperborea does not receive, store or have access to customer operational data by default; any exception is a contractual term.
On-node inferenceLocal vector storeZero egress

C / SUP

Software supply chain

  • Systems ship as signed, reproducible build artifacts.
  • Mission rules and playbooks are Ed25519-signed, versioned artifacts — an unsigned or altered rule set will not load.
  • Decision logic contains no executable code, so a rule update cannot introduce a new execution path.
  • Systems boot and run with zero third-party credentials, on infrastructure the customer controls.
Reproducible buildsEd25519 signaturesNo code execution

D / DEC

Decision assurance

  • Mission rules are deterministic: the same inputs produce the same recommendation every time.
  • Human-in-the-loop gates stand between the system and every consequential action.
  • Each firing writes a comparison-by-comparison trace — which rule, which values, which branch.
  • Logs are immutable and replayable, so any inference can be reconstructed at any timestamp.
DeterministicHuman-in-the-loopReplayable audit

E / INT

Interoperability boundary

  • Tactical-data-link and bus adapters — Link-16, MIL-STD-1553, CoT/ATAK, STANAG — terminate behind the guard.
  • Track custody is maintained end to end, so every track in the picture carries its provenance.
  • Engagement interlocks are enforced in the common operating picture rather than in the consuming system.
Link-16MIL-STD-1553CoT / ATAKSTANAG

F / RES

Resilience & degradation

  • Nodes sync peer-to-peer. There is no central server to lose, and no single node whose failure stops the others.
  • Each node operates autonomously when comms drop, then reconciles state on reconnect.
  • Behaviour degrades gracefully as links, power or bandwidth are lost.
Peer-to-peer meshAutonomous on comms lossState reconciliation

03 / The boundary is physical

A one-way hardware data diode, enforced in silicon.

Field, sensor and mission data flow into the AI for analysis. The return path physically does not exist — there is no firewall rule to misconfigure, no exfiltration channel to exploit, and no vendor cloud in the trust boundary.

Because the control is physical rather than configured, it is inspected once rather than audited continuously.

  • Read-only ingest across the diode.
  • No outbound network path.
  • Local vector store and inference.
  • Signed, replayable decision logs.

Schematic · sovereign boundaryOne-way

Field / sensor Sovereign AI Data diode → no return path

04 / Applied to each system

How the controls land on our two systems.

The platform is shared, but the two systems sit in different places relative to the network, so their connectivity profile differs.

Uncrewed aircraft over a coastline at night, with a mesh of links drawn between dispersed nodes on the shore and at sea.
Edge autonomy Fully air-gapped

Capability 01Edge autonomy

  • Network required None
  • Inference On-node
  • Decision logic Signed, deterministic
  • Boundary Hardware diode
  • Operational data egress None
Intelligence operations centre with a global common operating picture and live multi-source feeds.
Threat intelligence Collection-scoped connectivity

Capability 02Threat intelligence

  • Network required Collection only
  • Hosting Infrastructure you control
  • Third-party credentials None
  • Analysis Local
  • Path to the air-gapped side None

Threat intelligence reads open sources, so that function necessarily touches the network. It runs on infrastructure the customer controls, boots with zero third-party credentials, and is scoped to collection — it is not a route into the air-gapped side. Security accreditation is agreed per deployment, and we supply the architecture, evidence and audit artifacts that process requires.

Request a security briefing.

We walk your security team through the trust boundary, the signing model and the audit trail in technical detail.

Contact our team