INDUSTRY — AEROSPACE & DEFENSE · PRIMES, SUBS, DEFENSE TECH & NATIONAL-SECURITY TEAMS

Deploy AI on controlled programs without leaving policy at the paperwork layer.

The Mission Authorization Gateway anchors the mission-critical boundary; browser and agent enforcement covers the rest of the enterprise. Your export-control and CUI policy is enforced at the point of use. Enforcement is deterministic and fail-closed, and no AI model makes the enforcement decision—so the program can govern AI use before data or actions cross the boundary.

A program environment / flight line
PLATE P-01 — PROGRAM ENVIRONMENT / FLIGHT LINE
FIG. 1 — THE EXPORT-CONTROL FAILURE MODE AI INTRODUCED

A Technology Control Plan describes what should happen. It doesn't intercept the keystroke.

DOCUMENTATION & ASSESSMENT LAYER
— Technology Control Plans, ITAR/EAR classification, CUI marking
— CMMC / NIST SP 800-171 control mapping and evidence
— Supplier flow-down clauses and attestations
— Records a DCSA or contracting officer can review
NECESSARY. NOT SUFFICIENT. A CONTROL PLAN DOESN'T STOP A PASTE.
RUNTIME ENFORCEMENT LAYER — CONTAINMENT.AI
✓ Inspects AI chat submissions at the browser, before they leave the endpoint
✓ Authorizes agent actions pre-execution, against your policy
✓ Deterministic and fail-closed
✓ Tamper-evident, signed, replayable audit of the decision core
ENFORCEMENT HAPPENS AT THE KEYSTROKE, NOT AT THE AUDIT.
THE ALPHABET YOUR PROGRAM ANSWERS TO
ITAR 22 CFR §120–130 EAR 15 CFR §730–774 CUI 32 CFR §2002 NIST SP 800-171 CMMC 2.0 DFARS 252.204-7012
ENFORCEMENT RECEIPTS FEED EACH — DESIGNED TO MAP, STATED PRECISELY ON COMPLIANCE. A RECEIPT IS EVIDENCE YOUR CONTRACTING OFFICER CAN REVIEW; IT IS NOT A CERTIFICATION.
FIG. 2 — THE TWO BOUNDARIES A PROGRAM HAS TO HOLD
PROGRAM SIDE
ENGINEER'S BROWSER
a stress engineer pastes ITAR-controlled airframe analysis into a public chat window
CHAT FIREWALL
CONTAINMENT
DETERMINISTIC RULING
point-of-use policy on the prompt · classification and export-control rules · tamper-evident record
PUBLIC SIDE
PUBLIC AI
only ALLOW-ruled submissions leave the program · a denied paste never reaches the provider
PROGRAM NETWORK
AGENT OR TOOL CALL
an agent acts on program data — a tool call, a command, a boundary-crossing request
GATEWAY
CONTAINMENT
DETERMINISTIC RULING
fail-closed policy core · ALLOW, DENY, MODIFY, STEP_UP or DEFER · signed decision record
MISSION BOUNDARY
BEYOND THE BOUNDARY
only ALLOW-ruled actions cross · denied or ambiguous actions do not · air-gap-capable architecture
Two surfaces, one policy discipline. The browser boundary is available today; the Gateway is in staging — Trust states each.
CONCRETE EXAMPLE
A stress engineer pastes an ITAR-controlled airframe analysis into a public LLM to "summarize the findings." A Technology Control Plan doesn't help. The runtime layer is built to block the submission — and write a tamper-evident record of the decision.
illustrative · policy: export-control-v4 · rule: itar_technical_data_in_prompt · submission denied · decision record written
FIG. 4 — WHERE YOU SIT IN THE SUPPLY CHAIN

Same CUI, different scale. Each has its own entry point.

ENTRY POINT 01 · PRIMES & TIER-1
Org-wide AI governance
Thousands of engineers, dozens of programs, one shadow-AI surface. Deterministic enforcement across the enterprise, anchored by the Mission Authorization Gateway at the mission-critical boundary.
Enterprise path →
ENTRY POINT 02 · SMALL SUBS
The same CUI, a fraction of the staff
Flow-down clauses hand you prime-grade obligations without prime-grade budgets. Start with a scoped plan sized to your seat in the chain, and step up to the Gateway as the boundary hardens.
See current availability →
ENTRY POINT 03 · NATSEC & IC TEAMS
Classified-adjacent programs
A higher sensitivity floor and environments the cloud can't reach. Brief on the Gateway's cross-domain architecture, built for the most sensitive mission boundaries.
Gateway briefing →
A SUBSET OF THE A&D BASE — NATIONAL SECURITY & THE IC
Classified-adjacent work is A&D with a higher data-sensitivity floor.
The failure mode is the same paste; the consequence is steeper. Deterministic, point-of-use enforcement, with an on-prem, air-gap-capable Gateway architecture for the most sensitive environments. AARM v1.0 alignment is self-attested in a public, per-requirement record.
FIG. 5 — WHAT THE PROGRAM GETS

The business outcome: AI stays on the program, and the obligations stay enforced.

Engineers keep their AI tools
Blanket bans push AI use into the shadows. Point-of-use enforcement lets the program say yes to AI — with its configured export-control policy applied to every governed submission and agent action.
Evidence, not testimony
Every ruling writes a signed, tamper-evident receipt. When a contracting officer or DCSA assessor asks how AI touches controlled data, you hand them the record — not a policy memo.
FLAGSHIP
The mission boundary, anchored
The Mission Authorization Gateway holds the controlled end of the program — deterministic edge action authorization, on-prem, air-gap-capable — while browser and agent enforcement covers the enterprise.
MANAGED PILOT AVAILABLE — SCOPED, PAID, DEPLOYED WITH OUR ENGINEERS.
ASSURANCE ROADMAP —
Designed against the high-assurance and cross-domain standards your programs run on, with formal verification and certification pathways underway. We publish milestone status as it stands — the canonical record your diligence team can hold us to: Trust · Compliance.
30-MINUTE BOUNDARY REVIEW
Watch the runtime layer intercept a paste that matches a configured export-control policy — with the audit log written as the decision is made.
✓ Scoped, paid design-partner pilot — set with you at the briefing
✓ Sized by deployment instance and mission — fee credited toward year-one Enterprise
Request a 30-minute Program Boundary Review
Bring one AI workflow, one consequential action, or one data boundary.