Industry · Defense

Air-gapped AI for
classified missions.

Disconnected, hardware-isolated AI for classified and mission-critical environments where no data may leave and no connectivity to external systems is acceptable.

The challenge

Defense AI demands zero egress
and maximum hardware isolation.

Defense and classified environments have zero tolerance for data leaving the network. Commercial AI APIs fail this requirement by design — they require internet connectivity and process data on infrastructure you do not control.

Commercial cloud AIUltraviolet Defense AI
Connectivity requirement Requires internet access for every call. Zero outbound — runs fully disconnected.
Hardware isolation Software-level isolation only. Hardware TEE — CPU encrypts workload memory.
Classification compatibility Incompatible with classified environments. Designed for classified and air-gapped deployment.
Attestation Trust-us model; no cryptographic proof. Hardware attestation proves workload integrity.
How Ultraviolet solves it

Leading with Cube AI.

Leads with

Cube AI

Sovereign AI Platform

The complete AI stack packaged for air-gapped, classified deployment — inference, RAG, guardrails, and governance with zero outbound connectivity.

  • Full air-gapped operation after deployment
  • AMD SEV-SNP / Intel TDX hardware isolation
  • Mission-critical deployment hardening
  • Same governance model in all environments
Explore Cube AI
Supported by

Cocos AI

Hardware TEE isolation and remote attestation — the cryptographic proof that workload memory is sealed from the host.

Explore Cocos AI
FAQ

Common questions,
answered precisely.

What is air-gapped AI deployment for defense?

Air-gapped AI deployment means running the complete AI stack — inference, retrieval, guardrails, governance, and audit — with zero network connectivity. No inbound or outbound internet access. After initial deployment via offline media transfer, the system operates fully disconnected. Cube AI is designed for this mode: all capabilities function in the disconnected state, with audit logs exportable via offline channels.

Why can't defense organizations use commercial cloud AI?

Commercial cloud AI requires internet connectivity and processes workloads on infrastructure outside the defense organization's control. For classified and mission-critical environments, this fails two hard requirements: (1) no data may traverse an uncontrolled network path; (2) no third party may have access to the infrastructure processing classified content. Air-gapped, hardware-isolated on-premise AI eliminates both failure modes.

What is hardware TEE isolation and why does it matter for defense?

A Trusted Execution Environment is a hardware-isolated region inside the CPU where computation is encrypted in memory, invisible to the host OS, hypervisor, and any other process on the hardware. For defense AI, TEE isolation means that even a compromised host OS cannot access the AI workload's memory — model weights, prompts, and outputs remain sealed. Cocos AI manages TEE provisioning and remote attestation for the full Ultraviolet stack.

What is remote attestation and how is it used in defense AI?

Remote attestation is a cryptographic process where the CPU hardware generates a signed report proving that a specific, unmodified software workload is running inside a genuine TEE. For defense AI, attestation provides the technical evidence that the correct, approved AI system is running — rather than a compromised or modified version. Attestation reports serve as audit artifacts for security accreditation processes.

How are model weights protected in a defense deployment?

When Cube AI runs inside an AMD SEV-SNP or Intel TDX TEE, model weights are loaded into hardware-encrypted TEE memory. The host OS, hypervisor, and any privileged process outside the enclave see only ciphertext. The weights can also be sealed to the enclave — encrypted with a key bound to the enclave's identity — so they cannot be read even if the storage media is removed.

Can Cube AI meet CMMC requirements?

CMMC (Cybersecurity Maturity Model Certification) requirements for AI systems used by defense contractors depend on the classification level and the data processed. On-premise Cube AI deployment addresses core CMMC technical controls: access control (RBAC, domain isolation), audit and accountability (complete queryable audit trail), configuration management (version-controlled model and guardrail deployments), and system and communications protection (no data egress by default). Specific CMMC level applicability requires assessment against your CUI or classified data handling requirements.

— Get started

Classified environments
deserve classified infrastructure.

Talk to the team about defense deployments, air-gap requirements, and hardware isolation configurations.

Apache 2.0 · Deploy anywhere · No vendor lock-in