PRODUCT · AIR-GAP BUNDLE

Frontier AI delivered on hardware. Verified offline. Loaded into the SCIF without a single network round-trip.

For programs where the cloud isn't an option — JADC2, classified labs, sovereign air-gapped enclaves. Encrypted SSDs with full attestation manifests, an offline verifier, and the only honest way to ship attested AI behind a real boundary.

"Most AI vendors handed us a URL. We needed something we could carry through a guard."
— PROGRAM MANAGER · DOD SWFT PROGRAM (paraphrased)

the problem

Cloud-hosted AI doesn't pass the SCIF door.

DoD programs operating at IL5 / IL6, sovereign government enclaves, and clinical research environments handling restricted data physically cannot use huggingface.co or any API-hosted weights. The standard procurement workaround — "we'll download it on a clean network and walk it in" — produces a model with zero provenance, zero audit trail, and zero ability to detect tampering on the way through. We solve the actual problem instead.

what's in the bundle

Hardware media engineered for the procurement chain you actually have to defend.

Encrypted SSD

Self-encrypting NVMe drive with hardware AES-256 and tamper-evident seals. Capacity sized to your model selection: 4 TB for frontier-only, 22 TB for the full curated catalog, 50 TB for catalog plus quantization variants.

Sealed weights

Curated frontier models in FP16, FP8, INT8, and INT4 variants. Every weight signed by the mirror, every quantization signed by the forge, every promotion signed by the panels.

Runtime binaries

TensorRT-LLM engines for Jetson, QNN binaries for Snapdragon, llama.cpp for AMD64, ONNX QDQ for general use. Each runtime image signed and matched to the calibration manifest.

Offline verifier

The sf-verify tool runs entirely offline. Validates every signature, every hash, every manifest. No network access, no telemetry, no phone-home. 465 lines of Python.

Snapshot witness chain

Full Merkle log snapshot at delivery time. Inclusion proofs preserved. Even disconnected from our infrastructure, you can prove to your auditor what was sealed at what moment.

Hardware bill of materials

Every component identified — NAND flash lot, controller revision, firmware hash. Supply-chain provenance for the storage device itself, not just the bits on it.

0
network connections required
After delivery, never connects to anything. Air-gap really means air-gap.
100%
of bundle verifiable offline
Every signature, every hash, every chain element. Run sf-verify; get PASS or FAIL.
9
witness panel signatures
Stored alongside weights. Verifier checks them locally; no panel callouts needed.
12 mo
maximum sealed validity
Bundles refresh annually. New media, new attestation chain, ongoing currency.

pricing

Hardware cost-plus, attestation by subscription.

The drives are commodity. The trust chain is the product. Annual refresh ensures the catalog stays current with the frontier without standing up a network connection on your side.

Frontier-Only
$20K/ yr

~30 frontier models + standard quantizations. Single 4 TB encrypted SSD per refresh cycle.

  • Top 30 frontier base weights
  • Standard INT4 / INT8 / FP8 quants
  • One refresh shipment per year
  • sf-verify CLI included
  • Bundle hash published to public log
Inquire
Program-of-Record
$100K+/ yr

Bespoke catalog selection, additional security controls, integration with program-specific verifier infrastructure.

  • Bespoke model selection
  • FIPS 140-3 hardware option
  • Monthly refresh available
  • On-site bundle generation
  • Dedicated engineering liaison
  • Source-code escrow
Contact us

The only frontier model store designed to be carried through a guard.

When you're ready to talk to a vendor who actually understands the procurement chain you're operating in, we're here.