SYSTEM NOTICE:Draconian CSP Enforced (default-src 'self'). Reverse proxy X-Forwarded-For stripping active. Zero telemetry. Your session is sovereign.
SYSTEM NOTICE:Draconian CSP Enforced (default-src 'self'). Reverse proxy X-Forwarded-For stripping active. Zero telemetry. Your session is sovereign.
SYSTEM NOTICE:Draconian CSP Enforced (default-src 'self'). Reverse proxy X-Forwarded-For stripping active. Zero telemetry. Your session is sovereign.
SYSTEM NOTICE:Draconian CSP Enforced (default-src 'self'). Reverse proxy X-Forwarded-For stripping active. Zero telemetry. Your session is sovereign.
Enterprise A4A58
1DBE7CF1376B4EB9D618D7
IronGap Technologies runs frontier-class large language models entirely on your own hardware — cryptographically bound to it, with no network egress path to exploit. Built for organizations where sending sensitive data to someone else's cloud was never an option.
Uncompromising Control.
Vault-OS is built on three unshakeable pillars. From the hardware level up, every function is designed to keep your data completely sovereign and entirely offline.
Air-Gap Security
Zero telemetry by design
ENFORCED
Zero-Cloud Bare Metal Infrastructure.
Physical AI Sovereignty.
The Compromised Paradigm
Cloud-dependent AI architectures force mission-critical data to traverse inherently vulnerable third-party APIs. They expose proprietary IP, violate international data transfer laws, and rely on multi-tenant infrastructure susceptible to Advanced Persistent Threats (APTs).
The Ground Truth (Vault-OS)
A strictly air-gapped, zero-cloud OS that binds cryptographically to your bare-metal silicon. Zero telemetry. Zero outbound API calls. It executes heavy inference directly on local VRAM, keeping cognition and data local behind your own firewall.
System Architecture
Interactive Orbital Deployment Pipeline
D4C8DCB2E03DC64FB1FC5E 4078912E34A776D2E8F35C6E08
Status: SYSTEM_SEALED
Silicon Tethering & Identity
Concatenates Motherboard UUIDs with TPM 2.0 Platform Configuration Registers (sha256:0). Generates a perpetual LICENSE.vault file cryptographically bound to the physical host.
Polymorphic Multi-Engine Inference
Hot-swappable abstraction layer managing Ollama (forced GPU offloading) and vLLM (90% VRAM pre-allocation via PagedAttention). Dynamic TensorRT-LLM routing for peak throughput.
High-Dimensional Isolated RAG
PostgreSQL pgvector restricted to VECTOR(768). Utilizes HNSW vector_cosine_ops indices with an automated +0.3 mathematical similarity boost for structured NER entities.
Autonomous Workflow Engine (Agent DAG)
An offline runtime executing directed acyclic graphs across 33 node types — local agents, Postgres queries, pgvector retrieval, sandboxed JS, vision analysis, approval gates and VRAM management. Kahn topological sorting with strict ReAct reasoning loops. No container runtime is involved at any point.
The Enclave — A Volume, Not A Folder
Your corpus, database, models and UI live on a BitLocker-encrypted virtual volume created on your own machine, under your own master password. It never receives a drive letter at any point in its life — not while being built, not while running — attaching instead to an access-controlled directory, so an unlocked enclave is never browsable by other accounts. Shutdown verifies the lock rather than assuming it, and a volume left attached by a forced kill is re-locked before anything else touches it.
An Install That Survives Losing Power
First run unpacks ~22GB into the encrypted volume. Losing power partway does not start it over: the volume is kept and only the files that did not finish are written again, compared by size so a file cut off mid-write is redone rather than trusted. The build records completion only after the last entry lands, so "a volume exists" is never mistaken for "the product is installed".
Verified First Contact
The appliance prints its certificate fingerprint on its own unlock screen and advertises it over mDNS; the client shows the same number and asks you to compare before it trusts anything. Three independent channels have to agree, and the one an attacker cannot forge is the display on the machine in front of you. Trust-on-first-use becomes a decision someone made rather than whatever answered first.
Natively Bundled Database
PostgreSQL and pgvector ship inside the appliance and run as a Windows service under NetworkService — not a container, not a dependency you install. Schema changes land in two tiers: a fresh-install script and a self-healing block that runs on every boot, so an upgraded install and a new one converge on the same schema.
Secure Group Collaboration
Multi-party encrypted messaging with the assistant as an invited participant that never answers uninvited — summoning it opens an explicit choice of how much of the room it may read. Group-local roles, per-member restrictions, slow mode, server-enforced auto-delete, and message bodies encrypted at rest like every other artifact.
Offline Speech Recognition
A multilingual Whisper model ships inside the package and runs on the appliance. It auto-detects language rather than assuming English, and like everything else here it never reaches a network — dictation on an air-gapped box is dictation that stays on the box.
The Iron Protocol & Hardware Quotas
A strict 9-tier RBAC matrix (from Chairman down to Tier 0) that programmatically routes silicon access and VRAM allocations, enforcing strict role quotas directly on hardware resources.
Tamper-Evident Signed Audit Logs
Security logs employ a tamper-evident chain. Each entry is hashed via SHA-256 alongside the previous log, forming a cryptographic chain signed with an RSA private key.
Hardware-Bound API Access.
Local Systems Integration.
Vault-OS exposes a completely localized, OpenAI-compatible API architecture bound strictly to your internal network. Defense contractors and enterprise engineering teams can wire it into their existing C4ISR, data-fusion, and SIEM tooling over standard local network protocols, without ever breaking the physical air-gap.
Ephemeral Cognitive Terminal.
The Vault-UI is designed under the assumption of continuous physical threat. Every cognitive session is intrinsically ephemeral.
Hardware-Routed VRAM Access
A strict 9-Tier RBAC system ensures users only have hardware-level access to the exact LLM weights and VRAM partition their clearance level dictates.
Zustand Memory Wipe
Browser state is violently eradicated upon tab close. No local storage, no cookies, no cache. The session ceases to exist the millisecond the connection drops.
Strict Incognito Operations
Chat histories are not retained on disk unless explicitly committed via cryptographically signed database insertions. Default stance: absolute amnesia.
The Ground Truth Matrix
Why consumer local AI wrappers and cloud endpoints fail the enterprise security audit.
| Metric | Vault-OS | Cloud AI APIs (e.g. OpenAI) | Standard Local Wrappers |
|---|---|---|---|
| Data Exfiltration Risk | 0% (Air-Gapped) | Extreme (API Egress) | High (Silent Telemetry) |
| Hardware Tethering | Yes (TPM 2.0 PCR) | N/A | None (Portable App) |
| Background Telemetry | None (No Network Egress Path) | Continuous | Undisclosed |
| Compliance Defensibility | Strong (PIPL/GDPR) | Weak (Vendor Dependent) | Varies |
| Works On First Boot, Offline | Yes (Models Bundled) | N/A (Network Required) | No (Downloads Weights) |
| Runtime Dependencies | None (Postgres Bundled) | Vendor Platform | Docker / Python Env |
| Data At Rest | Your Own BitLocker Volume | Vendor-Held Keys | Plain Disk |
| Access Control | 9-Tier RBAC + Per-Group Roles | Workspace Seats | None (Single User) |
| Team Collaboration | Encrypted Multi-Party Groups | Cloud-Hosted Threads | None |
| Audit Trail | Hash-Chained, RSA Signed | Vendor Dashboard | None |
| Destruction On Demand | NIST SP 800-88 Burn Switch | Deletion Request | Manual File Delete |
Engineered for
Regulatory Absolutism.
Compliance is not an afterthought; it is our fundamental architectural premise. Vault-OS is engineered to hold up under scrutiny in environments where legal or regulatory failures are fatal.
PIPL / CSL / DSL Compliance
Strong technical defensibility against cross-border data transfer violations. By executing heavy inference on localized bare-metal servers with no network egress path, cross-border data exfiltration is architecturally eliminated, not just policy-restricted.
CMMC 2.0 (Level 3)
Architected to satisfy Advanced Persistent Threat (APT) mitigation requirements for Defense Industrial Base (DIB) contractors. Complete network air-gap ensures Controlled Unclassified Information (CUI) remains isolated. Formal CMMC certification still requires your own C3PAO assessment.
GDPR / CCPA Sovereignty
Eliminates third-party subprocessor liabilities. Eradicates the need for Data Processing Agreements (DPAs) with cloud AI vendors, as PII never egresses from your sovereign infrastructure.
NIST SP 800-88 Sanitization
Integrates 'The Burn Protocol'—a cryptographic mechanism for forensic data destruction that aggressively overwrites vector databases and volatile memory to meet strict NIST Media Sanitization guidelines.
Mission-Critical Industries.
Defense & Intelligence
Air-gapped execution ensures CUI, classified intelligence, and strategic operations data never touch a public network. Architected to satisfy CMMC 2.0 Level 3 APT requirements.
Multinational Corporations
Operate AI in restricted regions without violating cross-border data transfer laws (PIPL, CSL, DSL). Hardware tethering keeps data bound to physically sovereign infrastructure.
Financial Core Infrastructure
Run predictive models, fraud detection, and algorithmic analysis on localized, PII-heavy datasets without third-party subprocessor risk or cloud API egress.
Critical Infrastructure
Power grids, telecommunications, and energy sectors require intelligence that functions independently of external internet connectivity. Uninterrupted, local inference.
Operational Parameters.
What Actually Happens.
Five things people assume the opposite of. Including the one that is not in our favour.
The enclave never gets a drive letter
Not at first run, not while running. It attaches to an access-controlled directory under the install root, so an unlocked enclave is not browsable by other accounts on the machine and does not appear in Explorer.
An interrupted install resumes
Losing power partway through the ~22GB unpack does not start it over. The encrypted volume is kept and only the files that did not finish are written again — checked by size, so a file cut off mid-write is redone rather than trusted.
Shutdown proves the enclave is sealed
Locking is verified, not assumed, and retried. If the enclave is still readable the shutdown says so instead of reporting a clean exit — and the next start refuses to continue until it can lock it.
You can verify the appliance you connected to
The appliance prints its certificate fingerprint on its own unlock screen and advertises it over the network. The client shows the same number before you trust it, so first contact is a comparison you make rather than a connection you hope about.
We cannot recover your master password
IronGap holds no copy of it and no key to your enclave. If it is lost the data is unrecoverable — by you and by us. That is the guarantee, and it cuts both ways.
The Appliance, and the Way In.
Vault-OS is the sovereign appliance. Vault-Ecosystem is the client your people actually use — it finds the appliance on the LAN by itself, so there is no address to hand out and nothing to expose.
Vault-OS — The Appliance
One elevated process that owns everything: the inference engines, a natively bundled PostgreSQL, the encrypted enclave and the console it serves itself. Windows is downloadable now. Install it, watch it boot, and watch it refuse to run without a valid licence — the proof-of-concept is the product.
Download Vault-OSVault-Ecosystem — The Client
Chat, documents, workflows and secure group collaboration, on the desktop and in your hand. It discovers the appliance over mDNS on the local network and speaks to nothing else — no broker, no relay, no account with us.
Explore the EcosystemRequest a Security Audit
Schedule a compliance review and hardware audit with the IronGap engineering team through the Secure Communications Enclave.
Open Secure Communications EnclaveWhat Vault-OS Is
Vault-OS by IronGap Technologies is an air-gapped, on-premises AI server appliance and offline LLM software platform. It runs large language models entirely on customer-owned local hardware, with no outbound API calls and no cloud dependency. Every installer bundles a complete model stack — a tool-capable multimodal chat model, a vision model, an embedding model and offline Whisper speech recognition — so the appliance answers on first boot without downloading anything. It additionally runs any vLLM or Ollama-compatible open weights the customer supplies (Llama 3, Mixtral, Qwen and others), with optional TensorRT-LLM routing. A local retrieval-augmented generation (RAG) pipeline uses PostgreSQL with pgvector and HNSW indexing for on-premises vector search over ingested documents. PostgreSQL is bundled inside the appliance and runs as a native service; there is no container runtime, no Docker dependency and no image to pull.
Beyond single-user chat, Vault-OS provides an autonomous workflow and agent engine executing directed acyclic graphs across 33 node types, 33 assistant tools, a nine-tier role-based access control matrix, and secure multi-party group collaboration with encrypted messages, group-local roles, per-member restrictions, polls, scheduled messages and server-enforced auto-delete timers. Data at rest lives on a BitLocker-encrypted virtual volume created on the customer's own machine under their own master password, mounted to an access-controlled directory rather than a drive letter. IronGap holds no copy of that password and cannot recover the data.
Vault-Ecosystem is the companion client application. It discovers the Vault-OS appliance on the local network by mDNS, so there is no address to configure and no external service in the path. Vault-OS is available for Windows today with Linux and macOS in development; Vault-Ecosystem is available for Windows with Linux, macOS, Android and iOS in development. Downloads: https://iron-gap.com/downloads.
The license is cryptographically bound to the physical server via TPM 2.0 hardware attestation (with a fallback hardware-signature mode using motherboard UUID, MAC address, and CPU serial), so the software will not run on a different machine than the one it was licensed to. Two deployment models are available: a Bring-Your-Own-Hardware (BYOH) software license for customer-procured servers, and a Turnkey Appliance Enclave where IronGap procures, assembles, and ships a pre-configured GPU server node. Full pricing structure: https://iron-gap.com/pricing. Full technical architecture: https://iron-gap.com/whitepaper.
Target use cases: defense and intelligence organizations processing classified or export-controlled data, financial firms protecting proprietary trading models and order flow, biotech and healthcare organizations analyzing genomic or patient data under HIPAA/GDPR data-handling requirements, and any enterprise or government entity subject to data-residency or cross-border transfer restrictions that rule out public cloud AI APIs.
IronGap Technologies is an independent, founder-led company. Vault-OS is designed, built, and maintained by M. Taha Halakooei, Founder/CEO & Chief Architect (LinkedIn: https://www.linkedin.com/in/taha-halakooei). Company: LinkedIn https://www.linkedin.com/company/irongap-technologies/, GitHub https://github.com/IronGap-Technologies. Full profile and licensing details: https://iron-gap.com/about.