Skip to content
Sentinel AI Sentinel AI

For defence

Prove it never left.

Inference runs in-country on Sky47 Ascend NPUs in region pk-isb-1, on hardware outside the reach of US export controls. Sensitive traffic is pinned there whatever the routing policy.

The Qila build goes further than pinning. The external-provider client is compiled out — not disabled, absent. There is no setting that could turn it back on.

Commercial build versus the Qila defence build The commercial build contains an external-provider client that an operator can enable or disable, so its off-country path exists but is switched off by default. The Qila defence build is compiled without that client: the external path is absent from the binary, so there is no setting that could turn it on. COMMERCIAL BUILD Mesh pipeline auth · guardrails · meter Sovereign route always present External provider client present · opt-in · off by default QILA DEFENCE BUILD Mesh pipeline auth · guardrails · audit Sovereign route the only route External provider client NOT IN THE BINARY A setting can be wrong. A component that was never compiled in cannot be switched on.
A setting can be wrong. A component that was never compiled in cannot be switched on — which is the difference between a policy and a guarantee.

Why absence, and not a switch

Every sovereignty claim eventually reduces to one question: what happens when someone misconfigures it?

A toggle answers that badly. It says the off-country path exists, is reachable, and is one wrong value away from being live — and no amount of process removes that from a threat model. Removing the component at build time answers it properly: there is no path, so there is no misconfiguration that opens one.

That is why the claim here is phrased as absence rather than assurance.

What sovereignty rules out

Two exposures a foreign-hosted model carries by construction, and this build does not:

  • No foreign CLOUD-Act reach. Data held by a US-jurisdiction provider is reachable by that jurisdiction regardless of where the servers sit. In-country inference on in-country hardware removes the question rather than answering it.
  • No remote kill-switch. A dependency on an export-controlled provider is a switch someone else owns. Ascend hardware and an in-country build mean capability cannot be withdrawn as policy.

Aligned with the direction of the National AI Policy 2025: indigenous capability, built and operated inside the perimeter.

What ships in the enclave

  • Air-gapped — runs with no external connectivity.
  • Internal CA — TLS and identity terminate on an in-enclave certificate authority, so nothing reaches out for a public certificate.
  • Accreditation-grade auditSentinel Watch provides the evidence trail: metadata only, never prompt or response bodies.
  • Classified traffic is not usage-metered — deliberately. Counting it is itself a leak, so the enclave does not.
  • Flat annual licence — custom deployment, no per-token accounting.

Trust is earned, never seized

Sovereign infrastructure is not a thing you can sensibly buy on a slide. The engagement is deliberately built so that every stage is small enough to refuse.

A phased engagement with an exit at every gate Phase 0 is a scoped session and live demonstration on your hardware, with no procurement commitment. Phase 1 delivers one operational workflow against one agreed success metric. Phase 2 scales and hardens, transferring runbooks and training as it goes. A go/no-go gate sits between each phase, and the engagement can be exited at any of them. EACH PHASE IS ENTERED ONLY BY CLEARING THE GATE BEFORE IT Phase 0 · days scoped session, live demo on your hardware nothing leaves GATE Phase 1 · one workflow a problem you choose, one agreed success metric go / no-go at the end GATE Phase 2 · scaled & hardened widens only after the gate cleared runbooks + train-the-trainer handover is the goal Exit at any gate — fixed scope, no open-ended engagement, and delivery risk sits with the vendor
The commitment never accumulates. Each phase is entered only by clearing the gate before it, and every gate is also an exit — which is what makes a first step on sovereign infrastructure something you can actually authorise.

Phase 0 — days. A scoped session and a live demonstration on your hardware, inside your perimeter. Nothing leaves. No procurement commitment, and the only decision at the end is whether there is one workflow worth doing next.

Phase 1 — one workflow, end to end. A single operational problem you choose, delivered against one agreed success metric, with a go / no-go gate at the end. Engineers work alongside your operators against real workflows, not against a specification written months earlier.

Phase 2 — scaled and hardened. The system widens only after the gate before it was cleared on evidence. Runbooks, documentation and train-the-trainer transfer as it goes, so capability accumulates on your side rather than ours.

What that means commercially

  • Fixed-scope phases — no open-ended engagement, and an exit at every gate.
  • Milestone-gated — delivery risk sits with the vendor, not the defence budget.
  • Joint IP from day one — the platform, the data and the roadmap stay inside the institution.
  • Handover is the goal, not the exception — your certified engineers run the system and we step back to advisory. An engagement that cannot end is a dependency, which is the thing this whole page exists to avoid.

Every claim on this page is citable, and the sources are available on request.

Governance you can hand to an assessor

The evidence trail is yours to read, not just ours: Sentinel Watch is scoped to your own traffic for a defence account, so the audit an assessor asks for does not require going through us — and it never exposes another tenant’s rows.

Sentinel Watch records what was served, by which model, and whether it stayed in-country — and counts guardrail refusals separately from served traffic, so a refused request is never mistaken for one that ran. It is observe-only: no provider can be enabled from it, because in this build there is nothing to enable.

Read how the boundary is drawn in Sovereignty, and the enclave detail in Sentinel Sovereign.

Underneath, it is the Sentinel Mesh gateway — the same one described under For telcos & builders, built without the parts this posture forbids.

Who builds and holds it

Delivered by Mercurial Minds, with cleared Pakistani engineers drawn from NUST, MCS, EME and Air University alongside retired technical officers. The intent is an engineering partner embedded with your operators and a route to an independent in-house team — not a black box you cannot inspect, and not a dependency you can never exit.

Talk to defence → · How sovereignty is proved →