Vault-OS Background Paths
Vault-OS Background Paths

SYSTEM NOTICE:Draconian CSP Enforced (default-src 'self'). Reverse proxy X-Forwarded-For stripping active. Zero telemetry. Your session is sovereign.

SYSTEM NOTICE:Draconian CSP Enforced (default-src 'self'). Reverse proxy X-Forwarded-For stripping active. Zero telemetry. Your session is sovereign.

SYSTEM NOTICE:Draconian CSP Enforced (default-src 'self'). Reverse proxy X-Forwarded-For stripping active. Zero telemetry. Your session is sovereign.

SYSTEM NOTICE:Draconian CSP Enforced (default-src 'self'). Reverse proxy X-Forwarded-For stripping active. Zero telemetry. Your session is sovereign.

Enterprise AI Infrastructure// IronGap Technologies

Enterprise A4A58
1DBE7CF1376B4EB9D618D7

IronGap Technologies runs frontier-class large language models entirely on your own hardware — cryptographically bound to it, with no network egress path to exploit. Built for organizations where sending sensitive data to someone else's cloud was never an option.

Air-Gapped by DefaultTPM 2.0 Hardware BindingSHA-256 Signed UpdatesBYOH or Turnkey Appliance
// CORE_PILLARS

Uncompromising Control.

Vault-OS is built on three unshakeable pillars. From the hardware level up, every function is designed to keep your data completely sovereign and entirely offline.

Polymorphic Engine

Dynamic vLLM/Ollama offloading

ACTIVE

Silicon Tethering

TPM 2.0 cryptographic lock

SECURED

Air-Gap Security

Zero telemetry by design

ENFORCED

Architecture Definition // Vault-OS

Zero-Cloud Bare Metal Infrastructure. Physical AI Sovereignty.

The Compromised Paradigm

Cloud-dependent AI architectures force mission-critical data to traverse inherently vulnerable third-party APIs. They expose proprietary IP, violate international data transfer laws, and rely on multi-tenant infrastructure susceptible to Advanced Persistent Threats (APTs).

The Ground Truth (Vault-OS)

A strictly air-gapped, zero-cloud OS that binds cryptographically to your bare-metal silicon. Zero telemetry. Zero outbound API calls. It executes heavy inference directly on local VRAM, keeping cognition and data local behind your own firewall.

9
Clearance Tiers
33
DAG Node Types
33
Assistant Tools
3
Local Inference Engines
0
Network Egress Paths

System Architecture

Interactive Orbital Deployment Pipeline

Hardware Base
OS Injection
Model Setup
Air-Gap Lock
Enterprise Deploy
// SYSTEM_SPECIFICATIONS

D4C8DCB2E03DC64FB1FC5E 4078912E34A776D2E8F35C6E08

Ver: 1.0.9.1
Status: SYSTEM_SEALED
ID: TPM_2.0_PCR

Silicon Tethering & Identity

TPM 2.0FINGERPRINTSILICON

Concatenates Motherboard UUIDs with TPM 2.0 Platform Configuration Registers (sha256:0). Generates a perpetual LICENSE.vault file cryptographically bound to the physical host.

01
ID: VLLM_PAGED_ATTN

Polymorphic Multi-Engine Inference

vLLMOllamaTensorRT

Hot-swappable abstraction layer managing Ollama (forced GPU offloading) and vLLM (90% VRAM pre-allocation via PagedAttention). Dynamic TensorRT-LLM routing for peak throughput.

02
ID: PGVECTOR_768D

High-Dimensional Isolated RAG

POSTGRESQLHNSWNER

PostgreSQL pgvector restricted to VECTOR(768). Utilizes HNSW vector_cosine_ops indices with an automated +0.3 mathematical similarity boost for structured NER entities.

03
ID: KAHN_DAG_RUNTIME

Autonomous Workflow Engine (Agent DAG)

AGENT DAG33 NODESRUNTIME

An offline runtime executing directed acyclic graphs across 33 node types — local agents, Postgres queries, pgvector retrieval, sandboxed JS, vision analysis, approval gates and VRAM management. Kahn topological sorting with strict ReAct reasoning loops. No container runtime is involved at any point.

04
ID: BITLOCKER_VHDX

The Enclave — A Volume, Not A Folder

BITLOCKERNO DRIVE LETTERVERIFIED LOCK

Your corpus, database, models and UI live on a BitLocker-encrypted virtual volume created on your own machine, under your own master password. It never receives a drive letter at any point in its life — not while being built, not while running — attaching instead to an access-controlled directory, so an unlocked enclave is never browsable by other accounts. Shutdown verifies the lock rather than assuming it, and a volume left attached by a forced kill is re-locked before anything else touches it.

05
ID: RESUMABLE_UNPACK

An Install That Survives Losing Power

RESUMABLEINTEGRITYFIRST RUN

First run unpacks ~22GB into the encrypted volume. Losing power partway does not start it over: the volume is kept and only the files that did not finish are written again, compared by size so a file cut off mid-write is redone rather than trusted. The build records completion only after the last entry lands, so "a volume exists" is never mistaken for "the product is installed".

06
ID: THREE_CHANNEL_PIN

Verified First Contact

TOFU DEFEATEDFINGERPRINTPAIRING

The appliance prints its certificate fingerprint on its own unlock screen and advertises it over mDNS; the client shows the same number and asks you to compare before it trusts anything. Three independent channels have to agree, and the one an attacker cannot forge is the display on the machine in front of you. Trust-on-first-use becomes a decision someone made rather than whatever answered first.

07
ID: PG_SERVICE_ACL

Natively Bundled Database

POSTGRESNO DOCKERSELF-HEALING

PostgreSQL and pgvector ship inside the appliance and run as a Windows service under NetworkService — not a container, not a dependency you install. Schema changes land in two tiers: a fresh-install script and a self-healing block that runs on every boot, so an upgraded install and a new one converge on the same schema.

08
ID: GROUP_CHAT_RBAC

Secure Group Collaboration

GROUPSRBACENCRYPTED

Multi-party encrypted messaging with the assistant as an invited participant that never answers uninvited — summoning it opens an explicit choice of how much of the room it may read. Group-local roles, per-member restrictions, slow mode, server-enforced auto-delete, and message bodies encrypted at rest like every other artifact.

09
ID: WHISPER_LOCAL

Offline Speech Recognition

WHISPERMULTILINGUALLOCAL

A multilingual Whisper model ships inside the package and runs on the appliance. It auto-detects language rather than assuming English, and like everything else here it never reaches a network — dictation on an air-gapped box is dictation that stays on the box.

010
ID: 9_TIER_MATRIX

The Iron Protocol & Hardware Quotas

RBAC9_TIERSVRAM

A strict 9-tier RBAC matrix (from Chairman down to Tier 0) that programmatically routes silicon access and VRAM allocations, enforcing strict role quotas directly on hardware resources.

011
ID: SHA256_CHAIN

Tamper-Evident Signed Audit Logs

RSASHA-256AUDIT

Security logs employ a tamper-evident chain. Each entry is hashed via SHA-256 alongside the previous log, forming a cryptographic chain signed with an RSA private key.

012
Integration Protocol // API Layer

Hardware-Bound API Access.
Local Systems Integration.

Vault-OS exposes a completely localized, OpenAI-compatible API architecture bound strictly to your internal network. Defense contractors and enterprise engineering teams can wire it into their existing C4ISR, data-fusion, and SIEM tooling over standard local network protocols, without ever breaking the physical air-gap.

Data Fusion PlatformData Layer
Air-Gapped IntranetNetwork
Vault-OSINTERNAL API
SIEM PlatformSecurity
PostgreSQLLocal DB
Vault-UI // Session Active
Memory Wipe Protocol ArmedZustand State: Volatile

Ephemeral Cognitive Terminal.

The Vault-UI is designed under the assumption of continuous physical threat. Every cognitive session is intrinsically ephemeral.

  • Hardware-Routed VRAM Access

    A strict 9-Tier RBAC system ensures users only have hardware-level access to the exact LLM weights and VRAM partition their clearance level dictates.

  • Zustand Memory Wipe

    Browser state is violently eradicated upon tab close. No local storage, no cookies, no cache. The session ceases to exist the millisecond the connection drops.

  • Strict Incognito Operations

    Chat histories are not retained on disk unless explicitly committed via cryptographically signed database insertions. Default stance: absolute amnesia.

The Ground Truth Matrix

Why consumer local AI wrappers and cloud endpoints fail the enterprise security audit.

MetricVault-OSCloud AI APIs (e.g. OpenAI)Standard Local Wrappers
Data Exfiltration Risk
0% (Air-Gapped)
Extreme (API Egress)High (Silent Telemetry)
Hardware Tethering
Yes (TPM 2.0 PCR)
N/ANone (Portable App)
Background Telemetry
None (No Network Egress Path)
ContinuousUndisclosed
Compliance Defensibility
Strong (PIPL/GDPR)
Weak (Vendor Dependent)Varies
Works On First Boot, Offline
Yes (Models Bundled)
N/A (Network Required)No (Downloads Weights)
Runtime Dependencies
None (Postgres Bundled)
Vendor PlatformDocker / Python Env
Data At Rest
Your Own BitLocker Volume
Vendor-Held KeysPlain Disk
Access Control
9-Tier RBAC + Per-Group Roles
Workspace SeatsNone (Single User)
Team Collaboration
Encrypted Multi-Party Groups
Cloud-Hosted ThreadsNone
Audit Trail
Hash-Chained, RSA Signed
Vendor DashboardNone
Destruction On Demand
NIST SP 800-88 Burn Switch
Deletion RequestManual File Delete
COMPLIANCE_PROTOCOL_ACTIVE //
Legal Defensibility

Engineered for
Regulatory Absolutism.

Compliance is not an afterthought; it is our fundamental architectural premise. Vault-OS is engineered to hold up under scrutiny in environments where legal or regulatory failures are fatal.

SECURE_PROTOCOL_1

PIPL / CSL / DSL Compliance

Strong technical defensibility against cross-border data transfer violations. By executing heavy inference on localized bare-metal servers with no network egress path, cross-border data exfiltration is architecturally eliminated, not just policy-restricted.

SECURE_PROTOCOL_2

CMMC 2.0 (Level 3)

Architected to satisfy Advanced Persistent Threat (APT) mitigation requirements for Defense Industrial Base (DIB) contractors. Complete network air-gap ensures Controlled Unclassified Information (CUI) remains isolated. Formal CMMC certification still requires your own C3PAO assessment.

SECURE_PROTOCOL_3

GDPR / CCPA Sovereignty

Eliminates third-party subprocessor liabilities. Eradicates the need for Data Processing Agreements (DPAs) with cloud AI vendors, as PII never egresses from your sovereign infrastructure.

SECURE_PROTOCOL_4

NIST SP 800-88 Sanitization

Integrates 'The Burn Protocol'—a cryptographic mechanism for forensic data destruction that aggressively overwrites vector databases and volatile memory to meet strict NIST Media Sanitization guidelines.

// TARGET_ENVIRONMENTS

Mission-Critical Industries.

MILITARY_GRADE

Defense & Intelligence

Air-gapped execution ensures CUI, classified intelligence, and strategic operations data never touch a public network. Architected to satisfy CMMC 2.0 Level 3 APT requirements.

CMMC 2.0
Air-Gapped
PIPL_ALIGNED

Multinational Corporations

Operate AI in restricted regions without violating cross-border data transfer laws (PIPL, CSL, DSL). Hardware tethering keeps data bound to physically sovereign infrastructure.

PIPL
Data Sovereignty
ZERO_TRUST

Financial Core Infrastructure

Run predictive models, fraud detection, and algorithmic analysis on localized, PII-heavy datasets without third-party subprocessor risk or cloud API egress.

Zero-Trust
No Subprocessors
SCADA_ISOLATION

Critical Infrastructure

Power grids, telecommunications, and energy sectors require intelligence that functions independently of external internet connectivity. Uninterrupted, local inference.

Offline Inference
SCADA
Intelligence Briefing

Operational Parameters.

Straight Answers

What Actually Happens.

Five things people assume the opposite of. Including the one that is not in our favour.

The enclave never gets a drive letter

Not at first run, not while running. It attaches to an access-controlled directory under the install root, so an unlocked enclave is not browsable by other accounts on the machine and does not appear in Explorer.

An interrupted install resumes

Losing power partway through the ~22GB unpack does not start it over. The encrypted volume is kept and only the files that did not finish are written again — checked by size, so a file cut off mid-write is redone rather than trusted.

Shutdown proves the enclave is sealed

Locking is verified, not assumed, and retried. If the enclave is still readable the shutdown says so instead of reporting a clean exit — and the next start refuses to continue until it can lock it.

You can verify the appliance you connected to

The appliance prints its certificate fingerprint on its own unlock screen and advertises it over the network. The client shows the same number before you trust it, so first contact is a comparison you make rather than a connection you hope about.

We cannot recover your master password

IronGap holds no copy of it and no key to your enclave. If it is lost the data is unrecoverable — by you and by us. That is the guarantee, and it cuts both ways.

Two Halves, One System

The Appliance, and the Way In.

Vault-OS is the sovereign appliance. Vault-Ecosystem is the client your people actually use — it finds the appliance on the LAN by itself, so there is no address to hand out and nothing to expose.

Vault-OS — The Appliance

One elevated process that owns everything: the inference engines, a natively bundled PostgreSQL, the encrypted enclave and the console it serves itself. Windows is downloadable now. Install it, watch it boot, and watch it refuse to run without a valid licence — the proof-of-concept is the product.

Download Vault-OS

Vault-Ecosystem — The Client

Chat, documents, workflows and secure group collaboration, on the desktop and in your hand. It discovers the appliance over mDNS on the local network and speaks to nothing else — no broker, no relay, no account with us.

Explore the Ecosystem
Secure_Terminal_Uplink

Request a Security Audit

Schedule a compliance review and hardware audit with the IronGap engineering team through the Secure Communications Enclave.

Open Secure Communications Enclave

What Vault-OS Is

Vault-OS by IronGap Technologies is an air-gapped, on-premises AI server appliance and offline LLM software platform. It runs large language models entirely on customer-owned local hardware, with no outbound API calls and no cloud dependency. Every installer bundles a complete model stack — a tool-capable multimodal chat model, a vision model, an embedding model and offline Whisper speech recognition — so the appliance answers on first boot without downloading anything. It additionally runs any vLLM or Ollama-compatible open weights the customer supplies (Llama 3, Mixtral, Qwen and others), with optional TensorRT-LLM routing. A local retrieval-augmented generation (RAG) pipeline uses PostgreSQL with pgvector and HNSW indexing for on-premises vector search over ingested documents. PostgreSQL is bundled inside the appliance and runs as a native service; there is no container runtime, no Docker dependency and no image to pull.

Beyond single-user chat, Vault-OS provides an autonomous workflow and agent engine executing directed acyclic graphs across 33 node types, 33 assistant tools, a nine-tier role-based access control matrix, and secure multi-party group collaboration with encrypted messages, group-local roles, per-member restrictions, polls, scheduled messages and server-enforced auto-delete timers. Data at rest lives on a BitLocker-encrypted virtual volume created on the customer's own machine under their own master password, mounted to an access-controlled directory rather than a drive letter. IronGap holds no copy of that password and cannot recover the data.

Vault-Ecosystem is the companion client application. It discovers the Vault-OS appliance on the local network by mDNS, so there is no address to configure and no external service in the path. Vault-OS is available for Windows today with Linux and macOS in development; Vault-Ecosystem is available for Windows with Linux, macOS, Android and iOS in development. Downloads: https://iron-gap.com/downloads.

The license is cryptographically bound to the physical server via TPM 2.0 hardware attestation (with a fallback hardware-signature mode using motherboard UUID, MAC address, and CPU serial), so the software will not run on a different machine than the one it was licensed to. Two deployment models are available: a Bring-Your-Own-Hardware (BYOH) software license for customer-procured servers, and a Turnkey Appliance Enclave where IronGap procures, assembles, and ships a pre-configured GPU server node. Full pricing structure: https://iron-gap.com/pricing. Full technical architecture: https://iron-gap.com/whitepaper.

Target use cases: defense and intelligence organizations processing classified or export-controlled data, financial firms protecting proprietary trading models and order flow, biotech and healthcare organizations analyzing genomic or patient data under HIPAA/GDPR data-handling requirements, and any enterprise or government entity subject to data-residency or cross-border transfer restrictions that rule out public cloud AI APIs.

IronGap Technologies is an independent, founder-led company. Vault-OS is designed, built, and maintained by M. Taha Halakooei, Founder/CEO & Chief Architect (LinkedIn: https://www.linkedin.com/in/taha-halakooei). Company: LinkedIn https://www.linkedin.com/company/irongap-technologies/, GitHub https://github.com/IronGap-Technologies. Full profile and licensing details: https://iron-gap.com/about.