Solution · Classified & sovereign AI
For militaries, intelligence agencies and their contractors already running air-gapping, on-prem hosting and clearance-based access control. The Suite adds the interior layer that stack handles by trust: a per-output verdict against a signed library, a hardware default-deny gate, and a third-party-verifiable attestation, sized to a nation-state-adjacent threat model via graduated tiers.
What's different about this one
Use-Governance Monitor · illustrative data · KA-2312 drifting this cycle
How this is an embodiment of the Semantic Enforcement Suite
This is the same architecture screen-for-screen, re-instrumented for the defence/intelligence use-governance case. The reference build (Aggregate Drift) is the template; this app mirrors it exactly: same design system, same multi-persona switcher, same chrome, same viz/record/ledger idioms.
Same taxonomy. Suite (the offering) · Engine (the verdict logic on the Attestation screen) · Appliance (the unit bolted down on the hardware/interlock screens). The three tiers (Rules ships now / Distribution certify / Semantic under experiment) are modes of the Appliance.
The governed application is a staff assistant. "Kestrel Assist" is the enforcement point, a chat surface where you watch governance happen: a prompt-side gate strip (use-auth ✓/deflect, inbound-disclosure ✓/block) between the user bubble and the model call, and a response-side gate strip (outbound-disclosure ✓/redact, prohibited-activity ✓/block) between the model output and the displayed bubble.
Same persona seats: Use-Governance Monitor (runtime), Semantic Library (authoring), Enforcement Engine (attestation + hardware), Oversight Report (commissioning roll-up), Inspector Review (independent verify-without-trusting). The switcher is the org chart.
The Intent-Trajectory layer. The distinctive high-security addition: the monitor shows not just per-exchange verdicts but a heading + confidence + expandable meaning events, "no single exchange breached; the trajectory did", and a reviewer sees why and can disagree.
What's different about this one
Open-weight model, on-prem, no external inference path. Root-of-trust status and measured-image hash shown on the tier/posture strip. All verdict computation stays inside the boundary.
Two gate strips per exchange (slate for prompt-side, copper for response-side), each firing a distinct control: use-authorisation, inbound-disclosure, outbound-disclosure (redact), prohibited-activity (block).
A reviewer adjudicates an inference, a heading with confidence and the meaning events behind it, with an explicit mandate to disagree. Guardrails: attribute to the sequence, never the psychology; the heading is a signal, never the enforcement reason.
AUSTEO-style caveats and scope banners rendered as first-class constraint metadata.
Mirroring clearance compartmentation: author ≠ operator ≠ inspector ≠ governed user, enforced technically, not by policy.
The external authoring model receives drift evidence, not data, reference-vector deltas and novelty summaries, never live inputs or outputs. The refresh loop →
The three canonical sessions
Every exchange within its brief; clean verdicts across the board.
A legitimate question outside the current envelope; routed to review, not answered blind.
No single exchange breached; the trajectory did, gated at the set level.
These appear identically across Monitor, Engine ledger, Oversight roll-up, and as the scripted Kestrel Assist drift-walk conversation, that consistency is what makes the demo read as one system.
What we don't claim
This must not imply: that it governs weapons, targeting or force (out of scope); that the semantic tier is proven (it is under experiment, caveat-tagged); or that a token equals safety or discharges meaningful human control.
The software tier is tamper-evident, not non-bypassable, for the nation-state threat model this is the material limit; the hardware tier is the answer where physical non-bypassability is required.
One Suite, many operations
This governs information use and disclosure. It does not govern targeting, fire-control, or any actuation of force. Demonstration scenario.