Inference Distribution Network

Sovereign Edge IDN

A UK / EU-controlled air-gapped hosting platform for sensitive AI, data and cyber workloads. The Inference Distribution Network provides the sovereign substrate for local inference, RAG, model hosting, telemetry, audit evidence and controlled data movement.

Built across five platform layers (physical sovereign PoP, air-gapped compute, high-speed data fabric, sovereign storage and Sneakernet control), the IDN is designed so customer datasets, models, prompts, embeddings, logs, telemetry and encryption keys remain inside the approved UK / EU region. No inbound or outbound network connectivity is enabled by default. Ingress and egress are governed through signed manifests, encrypted media, malware scanning, hash verification and approved export controls.

The problem

Sovereignty is now an operational requirement

Sovereignty is no longer a policy concern alone. It now reaches into the systems that run critical AI workloads: cloud infrastructure, identity, telemetry, software supply chains, model hosting, operational support and evidence custody.

AI also changes what must be protected. Prompts, model outputs, embeddings, RAG corpora, inference logs and runtime telemetry can reveal the subject matter of sensitive work, even when the original files remain protected.

For regulated organisations, the question is no longer simply where data is stored. It is where AI is processed, where tokens travel, where evidence is retained, who can operate the environment, and whether the full execution path can be governed, audited and defended.

Reference architecture

Five layers, one sovereign boundary

The initial design uses High Performance Compute, 200 GbE RoCE fabric, external NVMe-oF storage, immutable audit storage and a separate sneakernet kiosk for controlled ingress and egress.

01

Physical sovereign PoP

Secure cage, access control, CCTV, tamper-evident seals and two-person operating procedures.

02

Air-gapped compute

High Performance Compute for local AI inference and RAG, with no external API exposure.

03

High-speed data fabric

200 GbE RoCE fabric supporting inter-node traffic and NVMe-oF storage access.

04

Sovereign storage

Customer-isolated namespaces, model library, KV-cache support and WORM audit storage.

05

Sneakernet control

Encrypted media, signed manifests, malware scanning, hash verification and review or redaction.

Operating model

From controlled ingress to evidence-safe egress

01

Controlled ingress

Kiosk and signed manifests, malware scan and hash check.

02

Air-gapped compute

Local AI inference and RAG with no external API exposure.

03

Minimal telemetry

Privacy-gateway tokenisation and field-level encryption.

04

Sovereign evidence

WORM audit, UK / EU-controlled HSM keys, tamper-evident chain.

05

Controlled egress

Two-person review, redaction and approved exports only.

Security by design

Security embedded, not bolted on

The Sovereign Edge IDN enforces security by design with the HEX 165 STPM Engine providing runtime security as a native platform service. The emphasis stays on the hosting environment: the security layer exists to protect the PoP, minimise telemetry, anonymise sensitive metadata and preserve audit evidence inside the boundary.

Native IDN servicePurpose inside the hosting environment
STPM Engine (eBPF MicroSensor)Captures minimal kernel-level security events from Linux hosts and Kubernetes nodes.
Privacy GatewayAnonymises, tokenises, classifies and minimises data before it leaves the monitored asset.
Sovereign CollectorReceives and normalises telemetry only within a UK / EU-controlled environment.
Detection EngineAutonomous detection without exposing unnecessary raw data. MITRE ATT&CK mapped.
Human Authorisation ConsoleHuman-in-the-loop control for sensitive decisions, with break-glass and dual approval.
Sovereign Evidence VaultEncrypted audit and evidence in the chosen UK / EU location, with legal hold and retention policy.
Sovereign Hosted

Policy and Controls

Inside the IDN by design

  • Customer datasets, prompts, embeddings, RAG corpora and model weights
  • Telemetry, audit evidence and encryption keys
  • Raw security context, topic-bearing file paths and sensitive operational metadata
  • Runtime monitoring, detection, policy evaluation and evidence retention

What the IDN does not do by default

  • No external API exposure for customer-facing inference, unless a cross-domain solution is designed and accredited
  • No default packet payload capture, file-content collection or keystroke logging
  • No automatic outbound telemetry, vendor callback or internet-connected update path
Open standards, closed boundary

Open at the protocol layer

The IDN uses open standards for portability and assurance, while the operating model keeps all processing, keys, telemetry and audit evidence inside the boundary.

OTLP / OpenTelemetry OCSF Sigma STIX / TAXII OPA / Rego SPIFFE / SPIRE TLS 1.3 / mTLS NIST SP 800-92 aligned

Start with a sovereign pilot

A tightly scoped IDN pilot proves air-gap operations, evidence custody and customer data separation, then provides the foundation for larger regional or sector deployments.

Book a Briefing