GitOps.dk

Sovereign AI Platform

Air-gapped architecture for regulated and national-scale AI.

GitOps.dk

Sovereignty is not a stricter firewall. It is a different set of first principles: every capability the platform offers must be explainable, reproducible and operable by the organisation that owns it — indefinitely, without permission from anyone outside the border.

Sovereignty requirements, made concrete

  • Data never leaves the jurisdiction — including embeddings, logs and telemetry, which are data wearing disguises.
  • Models are owned artefacts: importable, signable, reproducible — never a dependency on someone else's API staying up.
  • Every operational skill required to run the platform exists in-house or is contractually transferable.
  • The audit story is self-contained: evidence is produced by the platform, not requested from a vendor.

The offline model lifecycle

Models move through the same lifecycle as any controlled artefact: acquisition through a supervised transfer zone, verification of provenance and signature, internal registry, staged promotion with evaluation gates, and retirement with records. Fine-tuning happens inside the border, on governed corpora, producing weights with the same custody chain as their base model.

Network and trust boundaries

The architecture assumes three zones: the transfer zone (the only place outside artefacts appear), the platform core (registries, reconciliation, policy, observability), and the inference planes serving workloads. Trust flows one way — inward artefacts are verified at the boundary, and nothing in the core ever initiates outward.

Reference architectureSovereign AI platform

Transfer zone

The only place outside artefacts appear.

  • Supervised import
  • Checksums and signatures
  • Provenance record
  • Named accountable human
Verified at the boundary — trust flows inward only

Platform core

Reconciles from internal Git; never initiates outward.

  • Internal registry
  • Reconciliation
  • Policy
  • Observability
  • Model lifecycle and retirement
Promotes through evaluation gates to

Inference planes

Serving and fine-tuning inside the border, on governed corpora.

  • Serving per team
  • Fine-tuning inside the border
  • Governed corpora
  • Audit: which model, which version, which team, since when

RuleModel weights are controlled material: known origin, sealed transport, chain of custody, and no unaccounted copies.

Three zones with trust flowing inward: a supervised transfer zone where outside artefacts are verified, a platform core that reconciles from internal Git, and inference planes serving governed data inside the border.

Operations and audit

Everything reconciles from internal Git, so operations inside the gap feel identical to operations anywhere else — declare, commit, converge. The audit surface is a byproduct: which model, which version, serving which team, on which data, since when. When the regulator asks, the answer is a query, not a project.

Sovereign constraints are usually framed as a tax. Built this way, they become the pitch: a platform whose every capability is owned, explained and provable — which is what 'enterprise-grade AI' should have meant all along.

Turning these ideas into a platform?

For platforms where failure has consequences.

Start an Architecture Conversation