Engineered for estates with no way out.
Seven platforms owned, engineered and maintained in India by one accountable OEM. Weights, inference, vector stores and the audit trail all run on hardware you procure, inside your perimeter.
The air gap is not a configuration flag, and it costs something. There is no remote session and no telemetry to diagnose from, so nobody at this company can look at your estate from here. When something breaks, an engineer travels; until they arrive the operator has the runbook and a diagnostic they can read on site. That constraint is why updates are an event with a date rather than a background process.
Before you book anything, what we do not do is on this page rather than in the small print.
The moment it is built for
- Nothing may leave the network, and the tender says so in the technical clauses
- The assessment has to be defensible to CAG years after the analyst has moved on
- No foreign licensing trail and no escrow exposure anywhere in the stack
- A perimeter with no route out — including for package registries, licence servers and public time
Everything that crosses the boundary.
One deployment’s perimeter. Inside it, the components that actually run. On the boundary, a countable set of crossings — each a physical artefact somebody signs for rather than a network flow. Outside it, the connections a commercial AI stack takes for granted, drawn as stubs that stop short of the wall.
Change the posture and watch which connections come back and what each one costs. Then watch the audit log and the assessment-record export, which are identical in all three: the trail is a property of the software, not of the network it sits on.
No network path off the estate at all. Every inbound crossing is a physical artefact that somebody carries, hands over and signs for.
Swipe the diagram sideways, or pick any crossing below.
Retained assessment record, exported
Crosses outThe assessment together with its working — the sources it referenced, the correlation steps applied, the confidence at the point of assessment, and whether it was asserted or referred to an analyst — written out in a form a reviewing authority can read.
- Direction
- Outbound — leaves the perimeter
- Medium
- Agreed at design. The export format itself is a field of the record, so the answer is whatever your response process needs.
- Cadence
- When a response is required — an RTI request, a CAG audit, a judicial or internal review. Not continuous, and not scheduled.
- Custody
- Yours throughout. The record is produced inside your perimeter and leaves it under your authority, never ours.
- Verified how
- Agreed at design.
- If verification fails
- Agreed at design.
What we give up for it
Nothing. This crossing is the point of the system. It is also the one thing on this diagram that is identical in all three postures — the trail is a property of the software, not of the network the software happens to sit on.
Published: trails structured for RTI and CAG response formats; reconstruction possible years later by someone else.
The boundary shown is the standard air-gapped deployment pattern. Your estate’s manifest is agreed at design and is the document your accreditor reviews — rows marked agreed at design are the ones we will not guess at on a web page.
Read the manifest as text — all 3 postures, every crossing, every connection that does not exist
The diagram above shows one posture at a time. Below is the same manifest for all 3 of them — Air-gapped, On-premise, no egress, Sovereign cloud — written out so it can be read, quoted and checked without operating the control. The counts are the same counts: they are computed from the manifest, not typed alongside it.
The invariant, stated plainly: Audit log — the working, retained — is inside the perimeter in all 3 postures, and Retained assessment record, exported is on the manifest of all 3 of them, with the same 5 rows in each. Per posture, the crossings out are: Air-gapped — Retained assessment record, exported; On-premise, no egress — Retained assessment record, exported; Sovereign cloud — Retained assessment record, exported. The trail is a property of the software, not of the network the software happens to sit on. Where a posture’s outbound count reads higher than the number of crossings out, the difference is a connection that posture restores against infrastructure you operate, listed under that posture below.
Air-gapped
No network path off the estate at all. Every inbound crossing is a physical artefact that somebody carries, hands over and signs for.
- Crossings in — 4
- Vendored dependency set; Platform update and rollback bundle; Runbooks and on-site diagnostics; A cleared engineer, in person.
- Crossings out — 1
- Retained assessment record, exported.
- Connections that do not exist — 9
- Product telemetry; Licence phone-home; Package registry pull; Hosted model API; Crash reporting; Public network time; Public DNS resolution; Remote support session; Vendor usage analytics.
On the manifest — 5 crossings
| What it is | Every library, base image and model artefact the platform needs, resolved and frozen outside the estate and brought in as one set rather than fetched when something asks for it. |
|---|---|
| Medium | Agreed at design. In the air-gapped pattern it is a physical artefact rather than a network flow; the specific medium is set with your accreditor and is not something we publish. |
| Cadence | Agreed at design. It is tied to your change window, not to ours. |
| Custody | Agreed at design. Who receives the set, who signs for it and where it is held before it is opened are your procedures, not ours to state. |
| Verified how | Verified before it enters the estate — the verification step itself is agreed at design. |
| If verification fails | Agreed at design. The rule we hold to is that an unverified set does not enter; the escalation around that is written into your procedure. |
| What we give up for it | You cannot pull a fix at two in the morning. Anything that is not in the set does not exist until the next set arrives, and that includes the dependency somebody discovers they needed halfway through an incident. |
| Source | Published: dependencies vendored and verified before entering the estate. |
| What it is | A versioned build of the platform, the procedure to install it, and the procedure to put the previous version back — all of which have to work with no connectivity at either end. |
|---|---|
| Medium | Agreed at design, and in the air-gapped pattern the same physical route as the dependency set. |
| Cadence | Agreed at design. An update is scheduled against your change window rather than pushed. |
| Custody | Agreed at design. |
| Verified how | Verified before it enters the estate; the rollback path is exercised offline as part of the procedure. |
| If verification fails | Agreed at design. The estate stays on the version it is running, which is why the rollback procedure has to work without us. |
| What we give up for it | Updates are an event with a date, a window and a person present. There is no background channel over which a fix arrives quietly, so a fix you want this week is a change request, not a deployment. |
| Source | Published: update and rollback procedures that work offline. |
| What it is | Written procedures for operators who cannot call support, and diagnostics designed to be read at the machine by the person standing in front of it. |
|---|---|
| Medium | Agreed at design. |
| Cadence | Agreed at design. In practice they move with the update bundle they describe. |
| Custody | Agreed at design. |
| Verified how | Not a published specific. What is published is the design constraint: diagnostics have to be readable on site, without egress. |
| If verification fails | Agreed at design. |
| What we give up for it | If a failure mode is not in the runbook, the operator is waiting for a person to arrive. That puts an unusual amount of weight on documentation, which is a cost we would rather you saw now than discovered during an incident. |
| Source | Published: runbooks written for operators who cannot call support; diagnostics designed to be read on site, without egress. |
| What it is | An engineer inside the perimeter, working at the machine. With no session to open and no telemetry to read, this is the support path — not a fallback from it. |
|---|---|
| Medium | In person, inside the perimeter. This one is not a metaphor: it is a human being travelling to your site. |
| Cadence | Agreed at design. Response and attendance times belong in the support schedule of a contract, not on a web page. |
| Custody | Agreed at design — your access, escort and vetting procedures govern this crossing entirely. |
| Verified how | By you. We do not accredit our own people into your estate. |
| If verification fails | Agreed at design — nobody enters. |
| What we give up for it | Response time is travel time. This is the single largest operational cost of the air gap and we would rather you priced it during evaluation than discovered it during an outage. |
| Source | Published: engineers cleared to work inside the perimeter in person. |
| What it is | The assessment together with its working — the sources it referenced, the correlation steps applied, the confidence at the point of assessment, and whether it was asserted or referred to an analyst — written out in a form a reviewing authority can read. |
|---|---|
| Medium | Agreed at design. The export format itself is a field of the record, so the answer is whatever your response process needs. |
| Cadence | When a response is required — an RTI request, a CAG audit, a judicial or internal review. Not continuous, and not scheduled. |
| Custody | Yours throughout. The record is produced inside your perimeter and leaves it under your authority, never ours. |
| Verified how | Agreed at design. |
| If verification fails | Agreed at design. |
| What we give up for it | Nothing. This crossing is the point of the system. It is also the one thing on this diagram that is identical in all three postures — the trail is a property of the software, not of the network the software happens to sit on. |
| Source | Published: trails structured for RTI and CAG response formats; reconstruction possible years later by someone else. |
Does not exist in this posture — 9
| Connection | Direction of the dependency | Why it is absent | The engineering consequence | Where it comes back |
|---|---|---|---|---|
| Product telemetry | Outbound | There is no telemetry endpoint in the build. Nothing about how the platform is performing, what it is being asked or how often it is being asked leaves the estate, because there is nothing in the runtime path that emits it. | We cannot see a problem before you report it and we cannot diagnose one from our own office. Every diagnostic has to be readable on site by an operator who cannot call support, which is a real constraint on how the software is written. | In a sovereign tenancy the provider's own platform telemetry exists whatever we do — control-plane logs, metering, health. It stays inside your region and your account, and it is still a flow you now have to describe in your accreditation. |
| Licence phone-home | Outbound | Licensing is not enforced by a call to us. There is no licence server to reach, which means there is nothing to fail closed on the day the estate cannot reach it. | Commercial models that assume periodic activation do not apply here, so the commercial terms have to be written for an estate we cannot observe and cannot switch off. | Not in any of the 3 postures shown. It is absent by design, not pending. |
| Package registry pull | Inbound | Nothing resolves a dependency at install time or at run time. The mirror inside the perimeter is the only source, and it holds exactly the set that was carried in. | A dependency that was not vendored does not exist. Adding one is a change with a date and a bundle behind it, not a command somebody types. | The tenancy can reach a mirror held inside the same sovereign region. That is a foreign-dependency question your accreditor will ask: who operates the mirror, and what sits upstream of it. |
| Hosted model API | Outbound | Inference runs against weights on your storage on hardware you procured. No prompt, no document and no intercept is sent to a model somebody else operates. | You are held to models that can run on the hardware you bought, and the capability ceiling moves when the hardware does. That is a procurement conversation rather than a subscription one. | Not in any of the 3 postures shown. It is absent by design, not pending. |
| Crash reporting | Outbound | A crash writes a local artefact. It is not transmitted, because there is nowhere for it to be transmitted to. | The artefact only helps if somebody inside the perimeter can read it, and if it needs to reach us it leaves under your release procedure, at your speed. | Not in any of the 3 postures shown. It is absent by design, not pending. |
| Public network time | Inbound | A public time source is a network dependency like any other, and one that most air-gap claims quietly keep. An air-gapped estate keeps its own time instead. | Clock discipline becomes your estate's problem, and it matters more here than usual: the audit trail is written at the time it happens, and a record whose timestamps drift is harder to defend years later. | Time comes from your own servers, inside your estate or your region. Still nothing public, and still no route out. |
| Public DNS resolution | Inbound | Nothing in the runtime path resolves a name it was not already given. This is the other dependency that usually survives an air-gap claim unexamined. | Everything is addressed explicitly, which is more work at install time and one fewer thing that can be redirected under you afterwards. | Names resolve against your own resolvers. No query leaves your estate or your region. |
| Remote support session | Inbound | There is no inbound path for us to use, by construction. Support means an engineer inside the perimeter, in person. | Response time is travel time, and the runbooks have to carry the operator until somebody arrives. Choosing on-premise rather than air-gapped does not buy this back: no egress means no session either. | An administrative path into your tenancy, opened by you and closed by you. It is the one thing sovereign cloud buys back that neither of the other two postures can. |
| Vendor usage analytics | Outbound | We do not instrument the product to learn how you use it. There is no usage dataset on our side, because there is no channel over which one could be built. | Product decisions come from what you tell us in a review rather than from what we can measure. It makes the feedback loop slower, and it is the correct trade in this sector. | Not in any of the 3 postures shown. It is absent by design, not pending. |
On-premise, no egress
There is a network, and no route off it. Names and time come from your own servers. Note what it does not buy back: remote support.
- Crossings in — 6
- Vendored dependency set; Platform update and rollback bundle; Runbooks and on-site diagnostics; A cleared engineer, in person; Public network time (on infrastructure you operate); Public DNS resolution (on infrastructure you operate).
- Crossings out — 1
- Retained assessment record, exported.
- Connections that do not exist — 7
- Product telemetry; Licence phone-home; Package registry pull; Hosted model API; Crash reporting; Remote support session; Vendor usage analytics.
On the manifest — 5 crossings
| What it is | Every library, base image and model artefact the platform needs, resolved and frozen outside the estate and brought in as one set rather than fetched when something asks for it. |
|---|---|
| Medium | Agreed at design. In the air-gapped pattern it is a physical artefact rather than a network flow; the specific medium is set with your accreditor and is not something we publish. |
| Cadence | Agreed at design. It is tied to your change window, not to ours. |
| Custody | Agreed at design. Who receives the set, who signs for it and where it is held before it is opened are your procedures, not ours to state. |
| Verified how | Verified before it enters the estate — the verification step itself is agreed at design. |
| If verification fails | Agreed at design. The rule we hold to is that an unverified set does not enter; the escalation around that is written into your procedure. |
| What we give up for it | You cannot pull a fix at two in the morning. Anything that is not in the set does not exist until the next set arrives, and that includes the dependency somebody discovers they needed halfway through an incident. |
| Source | Published: dependencies vendored and verified before entering the estate. |
| What it is | A versioned build of the platform, the procedure to install it, and the procedure to put the previous version back — all of which have to work with no connectivity at either end. |
|---|---|
| Medium | Agreed at design, and in the air-gapped pattern the same physical route as the dependency set. |
| Cadence | Agreed at design. An update is scheduled against your change window rather than pushed. |
| Custody | Agreed at design. |
| Verified how | Verified before it enters the estate; the rollback path is exercised offline as part of the procedure. |
| If verification fails | Agreed at design. The estate stays on the version it is running, which is why the rollback procedure has to work without us. |
| What we give up for it | Updates are an event with a date, a window and a person present. There is no background channel over which a fix arrives quietly, so a fix you want this week is a change request, not a deployment. |
| Source | Published: update and rollback procedures that work offline. |
| What it is | Written procedures for operators who cannot call support, and diagnostics designed to be read at the machine by the person standing in front of it. |
|---|---|
| Medium | Agreed at design. |
| Cadence | Agreed at design. In practice they move with the update bundle they describe. |
| Custody | Agreed at design. |
| Verified how | Not a published specific. What is published is the design constraint: diagnostics have to be readable on site, without egress. |
| If verification fails | Agreed at design. |
| What we give up for it | If a failure mode is not in the runbook, the operator is waiting for a person to arrive. That puts an unusual amount of weight on documentation, which is a cost we would rather you saw now than discovered during an incident. |
| Source | Published: runbooks written for operators who cannot call support; diagnostics designed to be read on site, without egress. |
| What it is | An engineer inside the perimeter, working at the machine. With no session to open and no telemetry to read, this is the support path — not a fallback from it. |
|---|---|
| Medium | In person, inside the perimeter. This one is not a metaphor: it is a human being travelling to your site. |
| Cadence | Agreed at design. Response and attendance times belong in the support schedule of a contract, not on a web page. |
| Custody | Agreed at design — your access, escort and vetting procedures govern this crossing entirely. |
| Verified how | By you. We do not accredit our own people into your estate. |
| If verification fails | Agreed at design — nobody enters. |
| What we give up for it | Response time is travel time. This is the single largest operational cost of the air gap and we would rather you priced it during evaluation than discovered it during an outage. |
| Source | Published: engineers cleared to work inside the perimeter in person. |
| What it is | The assessment together with its working — the sources it referenced, the correlation steps applied, the confidence at the point of assessment, and whether it was asserted or referred to an analyst — written out in a form a reviewing authority can read. |
|---|---|
| Medium | Agreed at design. The export format itself is a field of the record, so the answer is whatever your response process needs. |
| Cadence | When a response is required — an RTI request, a CAG audit, a judicial or internal review. Not continuous, and not scheduled. |
| Custody | Yours throughout. The record is produced inside your perimeter and leaves it under your authority, never ours. |
| Verified how | Agreed at design. |
| If verification fails | Agreed at design. |
| What we give up for it | Nothing. This crossing is the point of the system. It is also the one thing on this diagram that is identical in all three postures — the trail is a property of the software, not of the network the software happens to sit on. |
| Source | Published: trails structured for RTI and CAG response formats; reconstruction possible years later by someone else. |
Present in this posture, on infrastructure you operate — 2
| Connection | Direction | What it is here |
|---|---|---|
| Public network time | Inbound dependency | Time comes from your own servers, inside your estate or your region. Still nothing public, and still no route out. |
| Public DNS resolution | Inbound dependency | Names resolve against your own resolvers. No query leaves your estate or your region. |
Does not exist in this posture — 7
| Connection | Direction of the dependency | Why it is absent | The engineering consequence | Where it comes back |
|---|---|---|---|---|
| Product telemetry | Outbound | There is no telemetry endpoint in the build. Nothing about how the platform is performing, what it is being asked or how often it is being asked leaves the estate, because there is nothing in the runtime path that emits it. | We cannot see a problem before you report it and we cannot diagnose one from our own office. Every diagnostic has to be readable on site by an operator who cannot call support, which is a real constraint on how the software is written. | In a sovereign tenancy the provider's own platform telemetry exists whatever we do — control-plane logs, metering, health. It stays inside your region and your account, and it is still a flow you now have to describe in your accreditation. |
| Licence phone-home | Outbound | Licensing is not enforced by a call to us. There is no licence server to reach, which means there is nothing to fail closed on the day the estate cannot reach it. | Commercial models that assume periodic activation do not apply here, so the commercial terms have to be written for an estate we cannot observe and cannot switch off. | Not in any of the 3 postures shown. It is absent by design, not pending. |
| Package registry pull | Inbound | Nothing resolves a dependency at install time or at run time. The mirror inside the perimeter is the only source, and it holds exactly the set that was carried in. | A dependency that was not vendored does not exist. Adding one is a change with a date and a bundle behind it, not a command somebody types. | The tenancy can reach a mirror held inside the same sovereign region. That is a foreign-dependency question your accreditor will ask: who operates the mirror, and what sits upstream of it. |
| Hosted model API | Outbound | Inference runs against weights on your storage on hardware you procured. No prompt, no document and no intercept is sent to a model somebody else operates. | You are held to models that can run on the hardware you bought, and the capability ceiling moves when the hardware does. That is a procurement conversation rather than a subscription one. | Not in any of the 3 postures shown. It is absent by design, not pending. |
| Crash reporting | Outbound | A crash writes a local artefact. It is not transmitted, because there is nowhere for it to be transmitted to. | The artefact only helps if somebody inside the perimeter can read it, and if it needs to reach us it leaves under your release procedure, at your speed. | Not in any of the 3 postures shown. It is absent by design, not pending. |
| Remote support session | Inbound | There is no inbound path for us to use, by construction. Support means an engineer inside the perimeter, in person. | Response time is travel time, and the runbooks have to carry the operator until somebody arrives. Choosing on-premise rather than air-gapped does not buy this back: no egress means no session either. | An administrative path into your tenancy, opened by you and closed by you. It is the one thing sovereign cloud buys back that neither of the other two postures can. |
| Vendor usage analytics | Outbound | We do not instrument the product to learn how you use it. There is no usage dataset on our side, because there is no channel over which one could be built. | Product decisions come from what you tell us in a review rather than from what we can measure. It makes the feedback loop slower, and it is the correct trade in this sector. | Not in any of the 3 postures shown. It is absent by design, not pending. |
Sovereign cloud
Your own tenancy inside an Indian region. A registry, a clock and a support session come back — and you take on the provider control plane and its telemetry.
- Crossings in — 7
- Vendored dependency set; Platform update and rollback bundle; Runbooks and on-site diagnostics; Package registry pull (on infrastructure you operate); Public network time (on infrastructure you operate); Public DNS resolution (on infrastructure you operate); Remote support session (on infrastructure you operate).
- Crossings out — 2
- Retained assessment record, exported; Product telemetry (on infrastructure you operate).
- Connections that do not exist — 4
- Licence phone-home; Hosted model API; Crash reporting; Vendor usage analytics.
On the manifest — 4 crossings
| What it is | Every library, base image and model artefact the platform needs, resolved and frozen outside the estate and brought in as one set rather than fetched when something asks for it. |
|---|---|
| Medium | Agreed at design. In the air-gapped pattern it is a physical artefact rather than a network flow; the specific medium is set with your accreditor and is not something we publish. |
| Cadence | Agreed at design. It is tied to your change window, not to ours. |
| Custody | Agreed at design. Who receives the set, who signs for it and where it is held before it is opened are your procedures, not ours to state. |
| Verified how | Verified before it enters the estate — the verification step itself is agreed at design. |
| If verification fails | Agreed at design. The rule we hold to is that an unverified set does not enter; the escalation around that is written into your procedure. |
| What we give up for it | You cannot pull a fix at two in the morning. Anything that is not in the set does not exist until the next set arrives, and that includes the dependency somebody discovers they needed halfway through an incident. |
| Source | Published: dependencies vendored and verified before entering the estate. |
| What it is | A versioned build of the platform, the procedure to install it, and the procedure to put the previous version back — all of which have to work with no connectivity at either end. |
|---|---|
| Medium | Agreed at design, and in the air-gapped pattern the same physical route as the dependency set. |
| Cadence | Agreed at design. An update is scheduled against your change window rather than pushed. |
| Custody | Agreed at design. |
| Verified how | Verified before it enters the estate; the rollback path is exercised offline as part of the procedure. |
| If verification fails | Agreed at design. The estate stays on the version it is running, which is why the rollback procedure has to work without us. |
| What we give up for it | Updates are an event with a date, a window and a person present. There is no background channel over which a fix arrives quietly, so a fix you want this week is a change request, not a deployment. |
| Source | Published: update and rollback procedures that work offline. |
| What it is | Written procedures for operators who cannot call support, and diagnostics designed to be read at the machine by the person standing in front of it. |
|---|---|
| Medium | Agreed at design. |
| Cadence | Agreed at design. In practice they move with the update bundle they describe. |
| Custody | Agreed at design. |
| Verified how | Not a published specific. What is published is the design constraint: diagnostics have to be readable on site, without egress. |
| If verification fails | Agreed at design. |
| What we give up for it | If a failure mode is not in the runbook, the operator is waiting for a person to arrive. That puts an unusual amount of weight on documentation, which is a cost we would rather you saw now than discovered during an incident. |
| Source | Published: runbooks written for operators who cannot call support; diagnostics designed to be read on site, without egress. |
| What it is | The assessment together with its working — the sources it referenced, the correlation steps applied, the confidence at the point of assessment, and whether it was asserted or referred to an analyst — written out in a form a reviewing authority can read. |
|---|---|
| Medium | Agreed at design. The export format itself is a field of the record, so the answer is whatever your response process needs. |
| Cadence | When a response is required — an RTI request, a CAG audit, a judicial or internal review. Not continuous, and not scheduled. |
| Custody | Yours throughout. The record is produced inside your perimeter and leaves it under your authority, never ours. |
| Verified how | Agreed at design. |
| If verification fails | Agreed at design. |
| What we give up for it | Nothing. This crossing is the point of the system. It is also the one thing on this diagram that is identical in all three postures — the trail is a property of the software, not of the network the software happens to sit on. |
| Source | Published: trails structured for RTI and CAG response formats; reconstruction possible years later by someone else. |
Present in this posture, on infrastructure you operate — 5
| Connection | Direction | What it is here |
|---|---|---|
| Product telemetry | Outbound dependency | In a sovereign tenancy the provider's own platform telemetry exists whatever we do — control-plane logs, metering, health. It stays inside your region and your account, and it is still a flow you now have to describe in your accreditation. |
| Package registry pull | Inbound dependency | The tenancy can reach a mirror held inside the same sovereign region. That is a foreign-dependency question your accreditor will ask: who operates the mirror, and what sits upstream of it. |
| Public network time | Inbound dependency | Time comes from your own servers, inside your estate or your region. Still nothing public, and still no route out. |
| Public DNS resolution | Inbound dependency | Names resolve against your own resolvers. No query leaves your estate or your region. |
| Remote support session | Inbound dependency | An administrative path into your tenancy, opened by you and closed by you. It is the one thing sovereign cloud buys back that neither of the other two postures can. |
Does not exist in this posture — 4
| Connection | Direction of the dependency | Why it is absent | The engineering consequence | Where it comes back |
|---|---|---|---|---|
| Licence phone-home | Outbound | Licensing is not enforced by a call to us. There is no licence server to reach, which means there is nothing to fail closed on the day the estate cannot reach it. | Commercial models that assume periodic activation do not apply here, so the commercial terms have to be written for an estate we cannot observe and cannot switch off. | Not in any of the 3 postures shown. It is absent by design, not pending. |
| Hosted model API | Outbound | Inference runs against weights on your storage on hardware you procured. No prompt, no document and no intercept is sent to a model somebody else operates. | You are held to models that can run on the hardware you bought, and the capability ceiling moves when the hardware does. That is a procurement conversation rather than a subscription one. | Not in any of the 3 postures shown. It is absent by design, not pending. |
| Crash reporting | Outbound | A crash writes a local artefact. It is not transmitted, because there is nowhere for it to be transmitted to. | The artefact only helps if somebody inside the perimeter can read it, and if it needs to reach us it leaves under your release procedure, at your speed. | Not in any of the 3 postures shown. It is absent by design, not pending. |
| Vendor usage analytics | Outbound | We do not instrument the product to learn how you use it. There is no usage dataset on our side, because there is no channel over which one could be built. | Product decisions come from what you tell us in a review rather than from what we can measure. It makes the feedback loop slower, and it is the correct trade in this sector. | Not in any of the 3 postures shown. It is absent by design, not pending. |
The boundary shown is the standard air-gapped deployment pattern. Your estate’s manifest is agreed at design and is the document your accreditor reviews — rows marked agreed at design are the ones we will not guess at on a web page.
What is actually running
Seven platforms, and where each one runs.
These are the platforms deployed inside Indian government and defence estates. Aedrix, our construction platform, is owned by us too and is not one of them — which is why this number and the one on the products page count different things.
Where a platform has a page, the row links to it. Where it does not, the row says so.
| Platform | What it is | Where it runs | Status |
|---|---|---|---|
| HoloMap | VR mission planning built from your own GIS, at terrain scale. | Air-gapped | In service with the Indian Armed Forces |
| Amara | AIS- and radar-fused maritime picture, drawn head-up for the officer on watch. | On board, receive-only | In service on Indian Navy ships |
| Jatayu | Trajectory inference and group detection from sparse, irregular intercepts. | Air-gapped | In production |
| Intfuzon | Multi-channel signal fusion into tracked entities, with confidence attached per correlation. | Air-gapped | In production · no dedicated page |
| NOSTRA | Distributed analytics over national collection volumes, with audit trails as a first-class output. | On-premise / air-gapped | In production · GeM-approved · no dedicated page |
| Bhaasha | Translation and transcription across Indic languages and English. | On-premise — no external call in the inference path | In production |
| PlugSafe | Detection over a CCTV estate you already own, rather than cameras you have to replace. | On-premise, air-gap capable | In production |
The record
What “RTI- and CAG-ready” actually is.
It is a retained record with a known shape. Below are its fields and what each one holds — field names and semantics only. There is no specimen record here, no example identifiers and no officer names, because an invented one would tell you nothing true.
Fields of a retained assessment
- Assessment identifier
- Stable reference for the assessment, so a later request resolves to exactly one record.
- Produced at
- When the assessment was written — not when it was exported or last touched.
- Producing component and version
- Which platform component produced it, at which build. The component identifies itself; it is not attributed afterwards.
- Model / weights hash
- Which weights were resident at the time. Weights change; the record has to say which ones ran.
- Source records referenced
- The inputs the assessment rests on, held against it rather than alongside it.
- Correlation steps applied
- The chain from sources to conclusion — the working, in the order it was done.
- Confidence at point of assessment
- The figure as it stood when the assessment was made, not recomputed later against better information.
- Routing decision
- Whether the conclusion was asserted, or referred to an analyst because confidence fell below the threshold your programme set.
- Reviewing officer
- Who reviewed it, where your process requires review. Recorded as a role and an identity your estate already manages.
- Retention class
- How long the record is held and under whose schedule. Yours to set.
- Export format
- The form the record is written out in when a response is required.
The three rules behind it
The working is stored, not just the answer
An assessment is the conclusion plus the evidence and the inference that produced it. In this sector an assessment nobody can reconstruct is worth nothing, however plausible it looked on the day.
Low confidence is referred, never asserted
Below the threshold your programme sets, the case goes to an analyst. The system does not produce a confident-sounding answer it cannot support, because that is the failure mode that costs a programme its credibility.
The trail is written at the time
It cannot be reconstructed afterwards, and we will not pretend otherwise. Reconstruction years later by somebody who was not there only works if the record was written as the work happened, by the component that did it.
How you buy this
Three routes, and what we file.
We are the OEM in all three. That is the answer to the question the technical bid asks first, and it is the reason the support obligation does not move when the contracting party does.
GeM
Government e-Marketplace
We are GeM-listed, and NOSTRA is GeM-approved. Where a catalogue entry fits the requirement this is the shortest route and the one that puts least paperwork on your side. Catalogue identifiers are not published here — ask and we will send the current entry against your reference.
Tender
We respond as the OEM
Not through a reseller, which matters the moment the technical bid asks who owns the source. For the technical bid we supply:
- A clause-by-clause compliance matrix against your technical specification
- Copies of our certificates — CMMI Level 5, ISO/IEC 27001:2022, ISO 22301:2019
- The deployment architecture for the posture you are specifying, air-gapped or otherwise
- Engineers who sit through the technical review, rather than a bid team who cannot answer it
PSU / SI subcontract
Underneath a prime
Where a public-sector undertaking or a systems integrator holds the prime contract, we deliver as the OEM beneath it. The IP, the support obligation and the accountability for the platform stay with us rather than dissolving into the prime.
The engagement, in six steps
- 01Problem Discovery
- 02Solution Design
- 03User Validation
- 04ROI & Impact Assessment
- 05PoC Demonstration
- 06Procurement & Scale
Briefings and demonstrations are held on your premises, on your infrastructure, under NDA. We do not ask you to bring an estate to us, and there is nothing to connect to at our end.
Read this before you shortlist us
What we do not do.
Every one of these comes up eventually — in a technical review, in a clarification round, or on the day something breaks. You may as well have them now and decide whether we are worth a meeting at all.
We do not claim classified work
This page describes platforms, deployment postures and procurement routes. It does not describe programmes, and it will not. Where work exists that cannot be discussed, its absence from a marketing page is the correct outcome rather than an oversight.
We are an OEM, not an accrediting body
Your authority to operate is yours, granted by your own authority against your own controls. What we supply towards it is the architecture documentation, the compliance matrix, copies of our certificates, and engineers who sit through the review. We cannot grant an ATO and will not imply that we can.
Air-gapped means you lose remote support
No session, no telemetry, nothing for us to look at from here. When something breaks, somebody travels. Diagnostics are designed to be read on site and runbooks are written for an operator who cannot call support, because that is the actual situation rather than a contingency.
Updates are an event, not a background process
Dependencies are vendored and verified before they enter the estate. An update has a date, a window, a bundle and a person present, with a rollback procedure that works offline. There is no channel over which a fix arrives quietly, and a fix you want this week is a change request.
Not every platform has a public page
Intfuzon and NOSTRA do not. Their capability detail sits on the defence page, where the buyer for it actually lands. We would rather say so in the table than build two thin pages to make the grid look even.
Some numbers do not belong on a web page
Certificate numbers, GeM catalogue identifiers and customer names beyond what is already public are not on this site. They come in the compliance pack, against a tender reference, to a named recipient.
If this was not the estate you meant
Public sector & urban governance
Housing & Urban AI on SAP S/4HANA, citizen request handling at civic volumes, GIS and anomaly analytics, and Bhaasha across Indian languages. We are currently engaged with CIDCO on Housing & Urban AI.
Every platform we own
Including the ones that have nothing to do with a perimeter — Aedrix for construction, document processing, voice. Owned end to end and deployable inside your own estate.
Sovereign deployment — the questions procurement asks
Yes, and air-gapped is the normal deployment rather than a variant of it. In that posture four things cross inbound — the vendored dependency set, the platform update and rollback bundle, the runbooks and on-site diagnostics, and a cleared engineer in person — and one thing crosses outbound, the retained assessment record when a response is required. Each is a physical artefact in somebody's custody rather than a network flow. The manifest for your estate is agreed at design and is the document your accreditor reviews.
In the air-gapped posture there is no package registry pull, no licence phone-home, no hosted model API, no crash reporting, no public NTP, no public DNS, no remote support session and no vendor analytics. Those are the dependencies that usually survive an air-gap claim unexamined, so they are named individually rather than covered by a sentence. The platforms are Indian-OEM with no licensing trail to a foreign vendor and no escrow exposure. In a sovereign-cloud posture some of them come back — the diagram on this page shows exactly which, and what that costs you.
Three routes. GeM, where we are listed and where NOSTRA is GeM-approved. Tender, where we respond as the OEM rather than through a reseller and supply a clause-by-clause compliance matrix, certificate copies, the deployment architecture for your posture, and engineers who attend the technical review. Or as an OEM subcontractor underneath a PSU or systems integrator holding the prime contract. Catalogue identifiers and certificate numbers are sent against a tender reference rather than published here.
The conclusion plus its working: the sources referenced, the correlation steps applied, the confidence at the point of assessment, the producing component and version, the model weights that were resident, the routing decision — asserted or referred to an analyst — and the reviewing officer where your process requires one. Retention is a field of the record and the schedule is yours to set, because it is your retention policy rather than ours. The trail is written at the time by the component doing the work; it cannot be reconstructed afterwards.
Runbooks written for an operator who cannot call support, diagnostics designed to be read on site without egress, update and rollback procedures that work offline, and engineers cleared to work inside the perimeter in person. What does not exist is a remote session or telemetry we can read from outside, so response time is travel time. This is the largest operational cost of the air gap and it is better priced during evaluation than discovered during an outage.
That is the normal shape of it. A PoC demonstration is the fifth step of the six-step engagement, after problem discovery, solution design, user validation and an ROI and impact assessment, and before procurement and scale. Briefings and demonstrations are held on your premises, on your infrastructure, under NDA.
Tell us about the estate, not about AI.
The posture you are accrediting, the assessments you have to be able to defend, and the route you are buying through. That is a short conversation, and it is enough for both of us to know whether a briefing is worth the day.
On your premises, on your infrastructure, under NDA.
