The enterprise-grade, local-first AI platform for confidential documents — grounded Q&A, executive reports, diagrams, and unified assurance without sending data to public cloud AI.
*Reference pilot metrics — see live capabilities on your deployment.
Teams need AI speed, but regulated and confidential work cannot use public chatbots.
Client IP, PHI, classified material, and board materials cannot leave the perimeter — yet analysts still reach for ChatGPT.
No citations, no audit trail, no acceptable-use enforcement — manual PDF search does not scale.
Per-token cloud bills grow with every analyst; air-gapped sites pay twice (blocked AI + manual work).
Separate RAG tools, report writers, and governance spreadsheets — none integrated with SSO or RBAC.
One workbench: ingest, ask, deliver, and prove — on hardware you control.
Web search and URL scrape off in offline/air-gap profile. Optional hybrid mode when policy allows.
RAG with source citations, anti-hallucination prompts, hybrid search and reranking.
Portal auth, RBAC, Prometheus, Docker, SAML/OIDC, unified assurance APIs.
Built for defense, BFSI, healthcare, and government — not repurposed from a consumer chatbot.
| vs public cloud AI | vs generic RAG tools |
|---|---|
| No mandatory data egress | Integrated reports + diagrams + chat |
| Predictable infra cost (your GPU/CPU) | Single analyst workbench + API |
| Offline / air-gap capable | Audit log + RBAC + portal |
| Unified assurance & GRC repository | OWASP LLM + EU AI Act workflows |
| IDE integration (Cursor / VS Code) | Enterprise ML & SLHP scheduler |
Full stack from SLM inference to board-ready assurance evidence.
| Layer | What you get | Evidence |
|---|---|---|
| LLM / SLM runtime | LM Studio (primary); failover URL; streaming SSE; OpenAI gateway; model routing (auto/fast/quality); autostart & recover | GET /health |
| RAG & knowledge | ChromaDB + local embeddings; PDF/DOCX/XLSX/CSV; token-aware chunking; hybrid + rerank; evaluate API | POST /rag_query |
| Documents & visuals | DOCX/PPTX reports; Mermaid/PlantUML → PNG/SVG; spreadsheet & documentation assist | POST /generate_report |
| User portal | Sign-in, plans, OAuth, OTP/TOTP, API keys, IDE bundle, usage ledger | /app · /login |
| Security | RBAC, API keys, OIDC/SAML, PII scan, prompt guard, SSRF-safe scrape, tenant encryption | GET /governance/assurance/posture |
| Governance & GRC | 25+ frameworks offline; OWASP LLM; EU AI Act; audit chain; WORM archive; SLHP scheduler | /governance |
| Enterprise ML | Datasets, training jobs, model registry, learning profiles, stack completion tracker | /enterprise |
| Observability | Health, readiness, Prometheus metrics, structured audit log, session tracking | /metrics |
| CyberShield CVA AI pentest | Playbook, next-gen STRIDE/design review, 19-agent roster, orchestrator, evidence replay, continuous validation — CPA/CVA/XDR gated | GET /assist/ai-pentest/status |
sovereign_chat, sovereign_rag_query)start.bat)Proven patterns from pilots and reference deployments.
| ID | Scenario | Primary outcome | Modules |
|---|---|---|---|
| UC-01 | Internal policy & compliance Q&A | Sourced answers in minutes, audit-ready | RAG · Portal · Audit |
| UC-02 | Consulting / client confidentiality | Zero document egress; faster exec summaries | Reports · Air-gap · API keys |
| UC-03 | Air-gapped government lab | AI assist with web features disabled | Offline mode · Approved models |
| UC-04 | OT / industrial operations | Assurance evidence + deployment templates | Governance · OT blueprints |
| UC-05 | Financial services model risk | Grounded policy interpretation | RAG · EU AI Act workflow |
| UC-06 | Developer productivity (sovereign) | IDE chat without cloud API keys | MCP · Continue · Aider bundle |
| UC-07 | Executive reporting | DOCX/PPTX from natural language | Reports · Diagrams |
| UC-08 | Security & GRC evidence | Live assurance dashboard for auditors | /governance/assurance |
| UC-09 | CyberShield CVA continuous validation | Governed AI pentest planning with CPA proxy and evidence replay | CVA runtime · MCP · CPA |
Reference scenarios from internal pilots — customize with your logos and signed quotes.
Challenge: Consultants used personal cloud AI on client contracts — GDPR and contract risk.
Results: 0 egress incidents · ~40% faster first-draft summaries · full audit log for partners.
Stack: Docker · LM Studio 7B-class · web search off · API key per analyst.
Challenge: Policy answers took 2–4 hours of manual PDF search.
Results: Median answer time under 5 minutes with citations; silent when context insufficient.
Stack: RAG over internal policy corpus · RBAC · enrollment.
Challenge: No outbound network; analysts blocked from AI assist entirely.
Results: Full workbench offline after model install; web scrape/search disabled by policy.
Stack: Offline profile · approved SLM catalog · local embeddings.
Challenge: Ungoverned AI tools on plant floor documentation.
Results: 98% unified assurance composite · 97 AI trust index · OT deploy templates.
Stack: IEC 62443 frameworks · assurance APIs · SLHP scheduler.
We build offline-capable, enterprise-grade AI workbenches for organizations that cannot rely on public cloud LLMs. Our platform combines local inference (LM Studio and OpenAI-compatible runtimes), production RAG, document generation, IDE integration, and an integrated governance command center — so legal, security, and engineering teams share one source of truth.
The product ships with an offline GRC repository (NIST AI RMF, ISO 42001, OWASP LLM Top 10, EU AI Act, IEC 62443, and 20+ industry packs), unified assurance scoring, and a user portal with IDE integrations for Cursor and VS Code — no cloud API keys required in the editor.
Mission: Make sovereign AI practical on a laptop or private server — with evidence auditors and CISOs can trust.
/health + audit logConsulting · Compliance · Government · Defense · BFSI · Healthcare · OT/industrial · Any org blocking public ChatGPT.
16GB+ RAM · Windows/Linux · Python 3.10+ or Docker · LM Studio with approved SLM (e.g. google/gemma-3-1b).
| Edition | Deployment | Highlights |
|---|---|---|
| Community | Local install | Core chat, RAG, reports, diagrams |
| Pro | Docker + portal | Enrollment, API keys, governance viewer, IDE integration |
| Enterprise | SSO + private server | Full GRC, assurance admin, enterprise ML, multi-tenant, SLA-ready ops |
Cost illustration (10 analysts, year 1): hardware $2K–5K amortized vs $6K–24K avoided cloud API spend — see pilot metrics.