SYSTEM NOTICE:Draconian CSP Enforced (default-src 'self'). Reverse proxy X-Forwarded-For stripping active. Zero telemetry. Your session is sovereign.
SYSTEM NOTICE:Draconian CSP Enforced (default-src 'self'). Reverse proxy X-Forwarded-For stripping active. Zero telemetry. Your session is sovereign.
SYSTEM NOTICE:Draconian CSP Enforced (default-src 'self'). Reverse proxy X-Forwarded-For stripping active. Zero telemetry. Your session is sovereign.
SYSTEM NOTICE:Draconian CSP Enforced (default-src 'self'). Reverse proxy X-Forwarded-For stripping active. Zero telemetry. Your session is sovereign.
Enterprise 361415
C7889393CBEBB1217D6CAA
Vault-OS runs frontier-class large language models entirely on your own hardware — cryptographically bound to it, with no network egress path to exploit. Built for organizations where sending sensitive data to someone else's cloud was never an option.
Uncompromising Control.
Vault-OS is built on three unshakeable pillars. From the hardware level up, every function is designed to keep your data completely sovereign and entirely offline.
Air-Gap Security
Zero telemetry by design
ENFORCED
Zero-Cloud Bare Metal Infrastructure.
Physical AI Sovereignty.
The Compromised Paradigm
Cloud-dependent AI architectures force mission-critical data to traverse inherently vulnerable third-party APIs. They expose proprietary IP, violate international data transfer laws, and rely on multi-tenant infrastructure susceptible to Advanced Persistent Threats (APTs).
The Ground Truth (Vault-OS)
A strictly air-gapped, zero-cloud OS that binds cryptographically to your bare-metal silicon. Zero telemetry. Zero outbound API calls. It executes heavy inference directly on local VRAM, keeping cognition and data local behind your own firewall.
System Architecture
Interactive Orbital Deployment Pipeline
0DE62CB2C5867243C376D1 27610BBEDDBE7DEA410D04ADDF
Status: SYSTEM_SEALED
Silicon Tethering & Identity
Concatenates Motherboard UUIDs with TPM 2.0 Platform Configuration Registers (sha256:0). Generates a perpetual LICENSE.vault file cryptographically bound to the physical host.
Polymorphic Multi-Engine Inference
Hot-swappable abstraction layer managing Ollama (forced GPU offloading) and vLLM (90% VRAM pre-allocation via PagedAttention). Dynamic TensorRT-LLM routing for peak throughput.
High-Dimensional Isolated RAG
PostgreSQL pgvector restricted to VECTOR(768). Utilizes HNSW vector_cosine_ops indices with an automated +0.3 mathematical similarity boost for structured NER entities.
Autonomous Workflow Engine (Agent DAG)
An offline runtime executing directed acyclic graphs of local agents, Postgres query tasks, and sandboxed JS nodes. Implements Kahn topological sorting and strict ReAct reasoning loops.
The Iron Protocol & Hardware Quotas
A strict 9-tier RBAC matrix (from Chairman down to Tier 0) that programmatically routes silicon access and VRAM allocations, enforcing strict role quotas directly on hardware resources.
Tamper-Evident Signed Audit Logs
Security logs employ a tamper-evident chain. Each entry is hashed via SHA-256 alongside the previous log, forming a cryptographic chain signed with an RSA private key.
Hardware-Bound API Access.
Local Systems Integration.
Vault-OS exposes a completely localized, OpenAI-compatible API architecture bound strictly to your internal network. Defense contractors and enterprise engineering teams can wire it into their existing C4ISR, data-fusion, and SIEM tooling over standard local network protocols, without ever breaking the physical air-gap.
Ephemeral Cognitive Terminal.
The Vault-UI is designed under the assumption of continuous physical threat. Every cognitive session is intrinsically ephemeral.
Hardware-Routed VRAM Access
A strict 9-Tier RBAC system ensures users only have hardware-level access to the exact LLM weights and VRAM partition their clearance level dictates.
Zustand Memory Wipe
Browser state is violently eradicated upon tab close. No local storage, no cookies, no cache. The session ceases to exist the millisecond the connection drops.
Strict Incognito Operations
Chat histories are not retained on disk unless explicitly committed via cryptographically signed database insertions. Default stance: absolute amnesia.
The Ground Truth Matrix
Why consumer local AI wrappers and cloud endpoints fail the enterprise security audit.
| Metric | Vault-OS | Cloud AI APIs (e.g. OpenAI) | Standard Local Wrappers |
|---|---|---|---|
| Data Exfiltration Risk | 0% (Air-Gapped) | Extreme (API Egress) | High (Silent Telemetry) |
| Hardware Tethering | Yes (TPM 2.0 PCR) | N/A | None (Portable App) |
| Background Telemetry | None (No Network Egress Path) | Continuous | Undisclosed |
| Compliance Defensibility | Strong (PIPL/GDPR) | Weak (Vendor Dependent) | Varies |
Engineered for
Regulatory Absolutism.
Compliance is not an afterthought; it is our fundamental architectural premise. Vault-OS is engineered to hold up under scrutiny in environments where legal or regulatory failures are fatal.
PIPL / CSL / DSL Compliance
Strong technical defensibility against cross-border data transfer violations. By executing heavy inference on localized bare-metal servers with no network egress path, cross-border data exfiltration is architecturally eliminated, not just policy-restricted.
CMMC 2.0 (Level 3)
Architected to satisfy Advanced Persistent Threat (APT) mitigation requirements for Defense Industrial Base (DIB) contractors. Complete network air-gap ensures Controlled Unclassified Information (CUI) remains isolated. Formal CMMC certification still requires your own C3PAO assessment.
GDPR / CCPA Sovereignty
Eliminates third-party subprocessor liabilities. Eradicates the need for Data Processing Agreements (DPAs) with cloud AI vendors, as PII never egresses from your sovereign infrastructure.
NIST SP 800-88 Sanitization
Integrates 'The Burn Protocol'—a cryptographic mechanism for forensic data destruction that aggressively overwrites vector databases and volatile memory to meet strict NIST Media Sanitization guidelines.
Mission-Critical Industries.
Defense & Intelligence
Air-gapped execution ensures CUI, classified intelligence, and strategic operations data never touch a public network. Architected to satisfy CMMC 2.0 Level 3 APT requirements.
Multinational Corporations
Operate AI in restricted regions without violating cross-border data transfer laws (PIPL, CSL, DSL). Hardware tethering keeps data bound to physically sovereign infrastructure.
Financial Core Infrastructure
Run predictive models, fraud detection, and algorithmic analysis on localized, PII-heavy datasets without third-party subprocessor risk or cloud API egress.
Critical Infrastructure
Power grids, telecommunications, and energy sectors require intelligence that functions independently of external internet connectivity. Uninterrupted, local inference.
Operational Parameters.
Request a Security Audit
Schedule a compliance review and hardware audit with the IronGap engineering team through the Secure Communications Enclave.
Open Secure Communications EnclaveWhat Vault-OS Is
Vault-OS by IronGap Technologies is an air-gapped, on-premises AI server appliance and offline LLM software platform. It runs large language models (Llama 3, Mixtral, Qwen, and other vLLM/Ollama-compatible open weights) entirely on customer-owned local hardware, with no outbound API calls and no cloud dependency. A local retrieval-augmented generation (RAG) pipeline uses PostgreSQL with pgvector and HNSW indexing for on-premises vector search over ingested documents.
The license is cryptographically bound to the physical server via TPM 2.0 hardware attestation (with a fallback hardware-signature mode using motherboard UUID, MAC address, and CPU serial), so the software will not run on a different machine than the one it was licensed to. Two deployment models are available: a Bring-Your-Own-Hardware (BYOH) software license for customer-procured servers, and a Turnkey Appliance Enclave where IronGap procures, assembles, and ships a pre-configured GPU server node. Full pricing structure: https://iron-gap.com/pricing. Full technical architecture: https://iron-gap.com/whitepaper.
Target use cases: defense and intelligence organizations processing classified or export-controlled data, financial firms protecting proprietary trading models and order flow, biotech and healthcare organizations analyzing genomic or patient data under HIPAA/GDPR data-handling requirements, and any enterprise or government entity subject to data-residency or cross-border transfer restrictions that rule out public cloud AI APIs.
IronGap Technologies is an independent, founder-led company. Vault-OS is designed, built, and maintained by M. Taha Halakooei, Founder/CEO & Chief Architect (LinkedIn: https://www.linkedin.com/in/taha-halakooei). Company: LinkedIn https://www.linkedin.com/company/irongap-technologies/, GitHub https://github.com/IronGap-Technologies. Full profile and licensing details: https://iron-gap.com/about.