Defense & national security AI

Autonomy with a record.

When an autonomous system acts, reviewers need a durable record tied to the consequential decision. The Glacis architecture is designed to bind reported actions, declared resource access, and configured control outcomes to a signer and stated coverage boundary. Selected sensitive content can be excluded from the portable record; trusted collection, surrounding system telemetry, and deployment architecture establish source truth, coverage, and actual data flows.

This page describes the architecture conceptually. A fuller defense brief is available under NDA.

What runtime evidence means here

Designed so your own reviewers can check the evidence.

Tamper-evident operation

The concept: each in-scope action routed through a configured path can produce a signed, hash-chained receipt. The chain binds the reported sequence and policy fields; it does not establish source truth or complete coverage. An interior alteration breaks later links relative to a retained checkpoint, while end truncation requires external anchoring or a later checkpoint to detect.

Tool-permission boundaries

The concept: local controls mediate what an agent may touch. Covered events routed through a supported path can emit a signed report of an allow, deny, or escalation outcome. Verification checks bounded record properties; deployment and coverage evidence establish which actions actually traversed the boundary.

Verification without disclosure

The concept: a portable record can carry hashes and selected claims instead of full content. A reviewer with the required trust material can check supported signatures, covered-field integrity, and disclosed linkage while the deployment team separately confirms which prompts, outputs, and operational data remained inside its boundary.

This page keeps to the concepts. A fuller technical brief is available under NDA, through the team.

Bring one autonomous workflow.

For a configured, supported path, runtime coverage can apply controls to a named workflow and produce signed records that reviewers can inspect at /verify.