PRODUCT · AIR-GAP BUNDLE
For programs where the cloud isn't an option — JADC2, classified labs, sovereign air-gapped enclaves. Encrypted SSDs with full attestation manifests, an offline verifier, and the only honest way to ship attested AI behind a real boundary.
"Most AI vendors handed us a URL. We needed something we could carry through a guard."— PROGRAM MANAGER · DOD SWFT PROGRAM (paraphrased)
the problem
DoD programs operating at IL5 / IL6, sovereign government enclaves, and clinical research environments handling restricted data physically cannot use huggingface.co or any API-hosted weights. The standard procurement workaround — "we'll download it on a clean network and walk it in" — produces a model with zero provenance, zero audit trail, and zero ability to detect tampering on the way through. We solve the actual problem instead.
what's in the bundle
Self-encrypting NVMe drive with hardware AES-256 and tamper-evident seals. Capacity sized to your model selection: 4 TB for frontier-only, 22 TB for the full curated catalog, 50 TB for catalog plus quantization variants.
Curated frontier models in FP16, FP8, INT8, and INT4 variants. Every weight signed by the mirror, every quantization signed by the forge, every promotion signed by the panels.
TensorRT-LLM engines for Jetson, QNN binaries for Snapdragon, llama.cpp for AMD64, ONNX QDQ for general use. Each runtime image signed and matched to the calibration manifest.
The sf-verify tool runs entirely offline. Validates every signature, every hash, every manifest. No network access, no telemetry, no phone-home. 465 lines of Python.
Full Merkle log snapshot at delivery time. Inclusion proofs preserved. Even disconnected from our infrastructure, you can prove to your auditor what was sealed at what moment.
Every component identified — NAND flash lot, controller revision, firmware hash. Supply-chain provenance for the storage device itself, not just the bits on it.
pricing
The drives are commodity. The trust chain is the product. Annual refresh ensures the catalog stays current with the frontier without standing up a network connection on your side.
~30 frontier models + standard quantizations. Single 4 TB encrypted SSD per refresh cycle.
Top 1 000 models, all canonical quantizations, runtime binaries for all four edge platforms. 22 TB drive.
Bespoke catalog selection, additional security controls, integration with program-specific verifier infrastructure.
When you're ready to talk to a vendor who actually understands the procurement chain you're operating in, we're here.