Guardian OS Sovereign

Sovereignty is incomplete
without execution control.

Controlling which models run, and where they run, does not by itself control what those systems are permitted to execute. Execution authority is a separate control, and it can be held inside the boundary.

The third sovereignty

Model, compute and execution sovereignty

Model sovereigntyCompute sovereigntyExecution sovereignty

Model sovereigntyWhich models run, and where their weights sit.
Compute sovereigntyWhich infrastructure they run on, and under whose jurisdiction.
Execution sovereigntyWhich proposed transitions are permitted to execute — and who holds that authority.
Enforced in the deployment

The same kernel.
With the network taken away.

The deployment profile changes where enforcement runs, who signs policy and who holds the evidence. It does not change the control contract.

Hash-linked evidence chainSix records step up and along an isometric run: proposal, policy, verdict, approval, execution and evidence. Each record is linked to the one before it by a hash, and the final record is marked verified. An alteration to any record breaks the linkage.01PROPOSAL02POLICY03VERDICT04APPROVAL05EXECUTION06EVIDENCECHAIN VERIFIED
Hash linkage — each record hashes the previousVerified record

The same proposal against the same policy state reproduces the same verdict. A record that has been altered fails chain verification.

  • 01Signed local policy bundles
  • 02Ed25519 signature verification
  • 03Signing key outside the protected environment
  • 04No required external control plane
  • 05No required cloud database
  • 06No required network
  • 07Local evidence generation
  • 08Local evidence rendering
  • 09Fail-closed operation
  • 10Tamper refusal
  • 11Customer-controlled execution authority
  • 12Customer-controlled evidence custody
  • 13Isolated deployment
  • 14Sovereign deployment profile
  • 15Air-gapped operation
Deployment profiles
cloudhybridprivate cloudon premsovereignair gapped
Current status

Acceptance-testable.
Not yet field-validated.

Verified in CI

  1. 01External network access removed during sovereign CI execution.
  2. 02Signed local policy bundles enforced without a database, control plane or network connection.
  3. 03Offline-clean interface with zero required external fonts, analytics, embeds or telemetry loads.
  4. 04Governance evidence, attestations and control mappings generated locally.
  5. 05Tampered policy bundles fail closed and load zero active policies.
  6. 06Acceptance tooling verifies a live unauthorised action and its resulting evidence chain.

Not done yet

  1. 01No deployment has run on customer hardware yet. The install media, images and acceptance suite exist; a witnessed site record does not.
  2. 02No third-party accreditation. No Common Criteria evaluation, no NCSC assurance, no FedRAMP authorisation, no ATO.
  3. 03No independent penetration test of the codebase has been commissioned.
  4. 04No identity provider of our own — Guardian OS sits behind the estate's existing IdP.
Claim boundary

Guardian OS Sovereign is acceptance-testable, not field-validated. Everything in the left column is enforced by code and asserted by a test in CI. Everything in the right column is work that has not been done. No accreditation is claimed until one is held.

Who this is for

Institutions that must retain
control of how AI operates.

National governmentDepartments and central authorities deploying governed AI across public administration, national programmes and shared services.
Defence and national securityOrganisations operating under mission, security, isolation and evidence requirements that cannot depend on public-cloud assumptions.
Critical infrastructureOperators responsible for energy, communications, transport, water and other nationally important systems.
Public-sector healthcareNational and regional healthcare bodies requiring controlled AI operation, traceable evidence and protected deployment boundaries.
Sovereign technology programmesProgrammes establishing national AI capability while retaining policy authority, evidence custody and operational control inside the jurisdiction.
Highly regulated institutionsOrganisations whose governance or security requirements demand private, on-premises or air-gapped deployment.
Programme position

Configure a platform that exists,
or build one first.

The figures below are illustrative rather than quoted programme costs. Actual investment varies materially by scope, accreditation, deployment boundary and organisation size.

CapabilityBuild internallyGuardian OS
Time to capability2–4 year platform programmePlatform available today
Illustrative engineering investment£5M–£30M+ depending on scope and organisation sizeConfigure and integrate an existing platform
Governance kernelBuild, validate and maintain internallyRuntime Governance kernel already implemented
Specialist capabilityRecruit and retain specialist engineering teamsExisting platform plus configuration and integration
Operating responsibilityOngoing platform ownership and redevelopmentOngoing platform operation, policy configuration and assurance

This compares a multi-year internal platform programme with configuring an existing governed operating architecture. It is not a guaranteed savings claim.

Sovereign Intelligence Packs

Mission domains
without a second platform.

Sovereign Intelligence Packs add domain policies, workflows, evidence mappings and reporting structures while preserving one Runtime Governance kernel.

National SecurityMission-specific policy, approval, evidence and reporting structures for national-security operating environments.
Defence OperationsGovernance content for controlled workflows, delegated authority, constrained execution and evidence preservation.
Critical InfrastructureDomain controls for nationally important systems where availability, reachability and operational boundaries must remain explicit.
Public SectorReusable governance workflows, accountability structures and executive reporting for departments, agencies and public programmes.
National HealthcareGovernance content for national and regional healthcare systems, including controlled data use, evidence mapping and human oversight.

Keep execution authority
inside the boundary.