Sovereign reference architecture

From siloed tools to connected intelligence.

One stack, inside your perimeter. Hover or tap any layer to see what it does.

View as

Your perimeter

L6People

L5Govern & prove

L4Act

L3Reason & remember

L2Ingest & enrich

L1Your estate

Your existing estateKept and connected
EDR / AVFirewallIdentityEmailCloudExisting SIEM

Outside

T+--:--

Press play to watch the stack work together.

Illustrative scenario

What changes for your organisation

Four moves. Each one builds on the last.

  1. Connect

    One sovereign data foundation.

    Data in a dozen silosEvery source in one place, under your policy

    OpenETL · RelataDB

  2. Reason

    Your own AI, on your own hardware.

    AI that sends data outLocal models every team and agent shares

    Token Factory

  3. Act

    Agents take the volume.

    Teams buried in alerts and documentsAgents triage, search and draft. People decide

    C3 · ThreatMap · Autonous

  4. Prove

    Every action governed and evidenced.

    Audits rebuilt by handSigned policy, hash-chained audit, evidence on demand

    AgentSight · ScaleRisk

Every product reads from the same data and the same models, so each one you add makes the others smarter. That is connected intelligence.

Under the hood

What your engineers will ask first.

Deployment
On-premise in six to eight weeks, air-gapped in eight to twelve. Sovereign cloud where you choose it.
Models
Local models by default, from a named, self-hostable stack. Bring your own where you prefer.
Integration
Your identity provider and tooling, an OpenAI-compatible API and SDKs, and audit export to your SIEM.
Security
Identity, encryption, role and attribute control, and a hash-chained audit log. Fail-closed.
Updates
Signed offline updates. No telemetry, no callback, no internet dependency.
Assurance
ISO 27001 certified. SOC 2 and PCI DSS-ready products.

What it modernises

Keep your tools. Retire the silos between them.

ProductWhat it doesInstead of
C3Brochure · ResearchThe agentic SOC: agentic SOAR and AI analysts, above your SIEM.Rule-based SOAR playbooks · tier-1 alert queues
RelataDBWebsite · ResearchThe security data lake with an ontology: query an actor across your estate as a graph.SIEM search and correlation indexes
ThreatMapWebsite20+ intelligence sources through one normalised API, ready for agents over MCP.A separate integration per intel vendor
AgentSightWebsite · ResearchEvery policy is signed. Every agent tool call is enforced.Shadow AI and agent actions no one can prove
ScaleRiskBrochure · ResearchOne control set, every framework, evidence captured once.GRC spreadsheets and audit scrambles
Token FactoryLLM inference inside your perimeter, shared by every agent and team.Cloud AI APIs that send data out

Kept and connected: your EDR, firewall, identity, email, cloud and existing SIEM.

The question is not whether you can run a model. It is whether you can govern, audit and defend one.

Get a demo