FLAGSHIP THE AUTHORIZATION BOUNDARY · HIGH-ASSURANCE TIER

The gateway that stands between AI intent and mission effect.

FORMERLY THE HIGH-ASSURANCE GATEWAY — ARCHITECTURE AND ASSURANCE STATUS UNCHANGED

The flagship. MAG provides deterministic action authorization and output conformance at consequential AI boundaries. It canonicalizes a proposed action, evaluates it against versioned mandatory policy, and permits, constrains, denies, or quarantines the action before execution.

The staging build emits Ed25519-signed, hash-chained decision receipts. The status table below and the Trust record state exactly what runs today, what requires deployment tailoring, and what remains on the roadmap.

An uncrewed aerial platform on the floor of a dim hangar, a single overhead spotlight throwing the airframe into silhouette — the class of platform whose actions the Mission Authorization Gateway sits in front of.
PLATE P-04 — AUTONOMOUS PLATFORM / HANGARCONTAINMENT.AI
Mission Authorization Gateway — the break A proposed AI-mediated action arrives from the untrusted side and is captured in flight; its session terminates at the gateway wall. Inside the break, a deterministic decision core evaluates the action against versioned policy and emits a signed, hash-chained audit receipt. On the mission side, only approved actions are issued — nothing that arrived with the request crosses over. Rulings are ALLOW, DENY, MODIFY, STEP_UP or DEFER. FIG. A — THE BREAK MISSION AUTHORIZATION GATEWAY UNTRUSTED SIDE PROPOSED ACTION PROMPT · TOOL CALL · COMMAND THE ACTION IS CAPTURED IN FLIGHT THE BREAK DECISION CORE versioned policy deterministic fail-closed AUDIT & REPLAY EVERY RULING SIGNED AND CHAINED TO THE LAST NO SESSION CROSSES MISSION SIDE MISSION EFFECT EXACTLY WHAT POLICY APPROVED · NOTHING THAT ARRIVED WITH IT ONLY APPROVED ACTIONS ARE ISSUED RULING — ALLOW DENY MODIFY STEP_UP DEFER EVERY RULING EMITS A SIGNED, HASH-CHAINED RECEIPT
FIG. A — THE BREAKCONTAINMENT.AI
FIG. 1 — DETERMINISTIC EVALUATION, IN DETAIL
STAGE DETAIL — DETERMINISTIC EVALUATION
The flow is canonicalized into a stable representation and evaluated against a versioned policy bundle. Ambiguity resolves to DENY; the same input, policy, and context produce the same ruling. When those exact inputs are retained, the policy decision can be re-evaluated. Air-gap-capable architecture, designed for DDIL; the status table below states exactly what runs today.
RULING: ALLOW · DENY · MODIFY · STEP_UP · DEFER — SAME INPUT + POLICY + CONTEXT, SAME RULING
FIG. 2 — DESIGN PRINCIPLES

Built against cross-domain requirements, with the remaining gaps published.

PRINCIPLE 01
No AI model makes the enforcement decision
The enforcement decision is pure policy evaluation. Models may inform upstream context; they never hold the gavel.
PRINCIPLE 02
Fail closed, by default
Lost connectivity, malformed input, or policy ambiguity resolves to DENY. Designed for DDIL and disconnected operation.
PRINCIPLE 03
Verifiable, then verified
Parsers engineered for formal verification from day one, with verification actively underway — assurance you'll be able to check, not just believe.
FIG. 3 — CAPABILITY STATUS, STATED PRECISELY

Here is what runs now, what is being verified, and what still depends on hardware.

CAPABILITYSTATUS
Diode interface and simulated driver IMPLEMENTED
Protocol breaks — no session crosses the boundary IMPLEMENTED · SOFTWARE
Deterministic and fail-closed IMPLEMENTED
Ed25519-signed, hash-chained Gateway decision receipts LIVE ON STAGING
Edge action authorization and output conformance APIs IMPLEMENTED · STAGING
Client-side receipt verifier and published staging key AVAILABLE
Physical Owl data-diode driver PENDING VENDOR SDK
Formal verification of the parsing path IN PROGRESS
NSA cross-domain standards DESIGNED AGAINST
FedRAMP / ATO pathways ROADMAP
VERIFY A GATEWAY STAGING RECEIPT LOCALLY · CURRENT PRODUCT AND ASSURANCE STATUS LIVES ON TRUST.
FIG. 4 — DEPLOYMENT CONTEXTS
CROSS-DOMAIN
DESIGNED FOR DDIL
OT / ICS BOUNDARIES
AIR-GAP-CAPABLE ARCHITECTURE
EGRESS-BLOCKED RUNTIME MODE — CI-PROVEN IN TEST · PRODUCTION ON-PREM: ROADMAP
MISSION-CRITICAL
Aerospace & Defense → Industrial & OT → Robotics & Autonomy →
FIG. 5 — DEPLOYMENT PROFILES

One gateway. Three deployment profiles.

The same decision core, tailored to the boundary it defends. Pick the profile that matches yours.

PROFILE 01 / AUTONOMY
Autonomy & Tactical Edge
UAS/UxS, C2, OT, sensor tasking, navigation, data release, and payload-adjacent control paths.
PROFILE 02 / FRONTIER
Frontier Agent Control
Evaluation sandboxes, long-horizon agents, tools, credentials, destinations, egress, and protected infrastructure.
PROFILE 03 / CROSS-DOMAIN
Cross-Domain & DDIL
Protocol breaks, local deterministic policy, signed evidence, and disconnected mission boundaries.
FIG. 7 — MISSION BRIEFS

One gateway, two briefs. Take the one written for your boundary.

BRIEF 01 / FRONTIER
MAG — Frontier Agent Control
Deterministic authorization for model-evaluation environments, frontier-agent runtimes, multi-agent systems, and consequential external actions.
DOWNLOAD PDF →
BRIEF 02 / AUTONOMY
MAG — Autonomy & Tactical Edge
Control-path authorization before UAS/UxS, C2, sensor-to-effector, ISR, and mission-boundary actions.
DOWNLOAD PDF →
DOWNLOADS ARE DIRECT — NO FORM.
ASSURANCE ROADMAP —
The edge enforcement profile and signed receipt chain are implemented, and formal verification is underway. Milestone status lives on the Trust page.