Classified assistants
Search, summarization and drafting for enclaves that can never connect out.
AI for networks with no route to the internet: classified enclaves, controlled unclassified environments and plant-floor OT. Models, software and updates arrive on signed, scanned media.
An air gap changes everything about how software is built and delivered. Nothing can phone home, download a model, fetch a package or send telemetry. Every dependency has to be inside the boundary on day one.
We build and test in a mirrored environment outside the gap, then deliver signed, reproducible bundles with checksums and a software bill of materials, ready for your transfer and scanning process.
| Network | No outbound route required at any time |
|---|---|
| Delivery | Signed, reproducible bundles with SBOM and checksums |
| Telemetry | None leaves the boundary; monitoring stays local |
| Programs | Built to support CMMC, ITAR and agency ATO packages |
| Staffing | Cleared engineers available for some engagements |
Search, summarization and drafting for enclaves that can never connect out.
Deployments for CUI and export-controlled data under CMMC and ITAR programs.
Maintenance and quality assistants on isolated OT networks.
Self-contained systems that travel and run fully offline.
Air-gapped AI runs on a network with no route to the internet at any time. That rules out habits most AI software depends on. Nothing can download a model, pull a container, install a package, check a license server or send telemetry. Every model file, library and dependency has to be inside the boundary before the system starts.
Most commercial AI tools assume a live connection somewhere in the chain. An air-gapped LLM has to be built and tested for disconnected operation from the first day, which is why we treat it as its own discipline within private AI.
Each of these settings has its own transfer rules, hardware limits and accreditation process. We design around the ones you already follow, and pair the deployment with custom AI development so the application on top is built for offline use as well.
We start by mirroring the target environment outside the boundary, with the same operating system, GPU model, driver versions and security settings. All development and testing happens there. When a release is ready, we package the models, container images and dependencies into a reproducible bundle with checksums, signatures and a software bill of materials.
The bundle goes through your approved transfer process, whether that is a cross-domain solution or scanned removable media. Inside the boundary it installs with no network access. Model and software updates follow the same path on a schedule you set, so nothing inside ever reaches out for a download.
Air-gapped systems often have to use hardware that is already accredited inside the boundary, or wait through a long approval to add more. We size models to what is already there first. Quantized and smaller open-weight models from the Llama, Qwen, Mistral and Gemma families can run on modest GPUs and still do useful search and drafting work.
Where new equipment is justified, we write vendor-neutral specs for servers with cards such as the L40S, RTX 6000, H100 or H200, including power and cooling requirements for the site. Field kits get the same treatment at a smaller scale.
An air-gapped AI system still needs logs, alerts and access control, and all of it has to stay local. Users authenticate against the identity service inside the enclave. The gateway enforces roles and document permissions and records every prompt, retrieved passage, answer and action to the local log platform or SIEM. Dashboards for GPU use, latency and quality run inside the boundary, and no telemetry leaves it.
For authorization, LLM.co provides architecture, data-flow and control documentation to support your ATO package or CMMC assessment. Cleared engineers are available for some engagements. The authorization decision stays with your authorizing official.
Reproduce the target environment, including OS, hardware and policies, outside the gap.
Models, containers and dependencies packaged with checksums, signatures and an SBOM.
Delivered on media through your approved cross-domain or sneakernet process.
Scheduled update bundles for models and software, never live downloads.
Air-gapped AI is an AI system that runs on a network with no connection to the internet. The models, software, data and logs all live inside the boundary, and updates arrive on approved media. It is used in classified enclaves, controlled environments and isolated operational-technology networks.
Yes. Open-weight models such as Llama, Qwen, Mistral and Gemma are files that run on local GPUs with no outside connection. The work is in packaging every dependency in advance, removing any component that tries to call out, and testing the full system in a mirrored disconnected environment before delivery.
As signed bundles on your approved media or cross-domain path, on a schedule you set. Each bundle includes checksums, signatures and a software bill of materials for your scanning process. Nothing inside the boundary downloads updates on its own.
For focused tasks, often modest hardware. Quantized models can run on modest GPUs already inside the boundary. Larger models and many concurrent users need data-center GPUs such as the NVIDIA H100 or H200. We size to existing accredited hardware first and recommend new equipment only where the evaluation results call for it.
We provide architecture diagrams, data-flow diagrams, a software bill of materials and control documentation to support your authorization package or assessment. The authorization decision stays with your authorizing official, and certification stays with your assessor.
Often, with smaller or quantized models. Older GPUs limit model size and speed, so we test candidate models on matching hardware in the mirrored environment and show you the evaluation scores before anything crosses the boundary.
No system is fully secure. Removing the network route closes the remote paths most attacks rely on and keeps data away from vendors. Risk remains at the transfer point and with users inside, which we address with signed, scanned bundles, role- and document-level access, and full audit logging to your local SIEM, designed to fit your existing security controls.
Cleared engineers are available for some engagements. Where we cannot staff the clearance an engagement requires, we build and test in the mirrored environment and hand your cleared personnel installation runbooks and documentation for work inside the boundary.
Tell us the workflow and where the data lives. An engineer, not a salesperson, replies within one business day with a first take on architecture and cost.