Keelforge

Screen 03 · R-001 · Layers 04 & 07

Secure model deployment in a classified enclave

Section 2.3 Technical · Critical weight · Owner T. Bracken · BID-2026-014

Gold

Requirement text

Describe your approach to secure model deployment within a classified enclave, including cross-domain solution integration, key management and continuous monitoring against Defence Standard 05-138 and NCSC secure AI guidance.

Drafted answer

draft.v3 · Drafting Agent

ClaimDeployment runs inside an accredited SECRET-level enclave with a named cross-domain solution, hardware-backed key management and continuous monitoring aligned to Defence Standard 05-138 and the NCSC secure AI guidance.

Evidence anchorDefence security clearance register signed 10 Aug 2026 · Enclave architecture reference EV-2026-0198 · NCSC alignment note EV-2026-0201.

ConfidenceHigh. Every enclave, cross-domain and key-management element is delivered on a live programme with an equivalent buyer.

Counter-viewA buyer whose accreditation regime does not recognise the specific cross-domain solution named here would require a swap; the pattern generalises but the named vendor may not.

Evidence chain

Layer 07
  • Defence security clearance register

    storage://dossier/defence-clearance-register.pdf

    signed_by R. Vance · 10 Aug 2026 · 4c19af…7b02

  • Enclave architecture reference EV-2026-0198

    storage://evidence/EV-2026-0198.pdf

    signed_by P. Adeyemi · 08 Aug 2026 · 9d20b1…c447

  • NCSC alignment note EV-2026-0201

    storage://evidence/EV-2026-0201.pdf

    signed_by H. Lindqvist · 12 Aug 2026 · e7f3aa…1190

  • Cross-domain solution vendor attestation

    storage://evidence/cds-vendor-attestation.pdf

    signed_by T. Bracken · 05 Aug 2026 · 22ac6e…d381

Discriminator injection

Layer 16

Against a competitor known to lead with cloud-native by default, sharpen the response to state that the enclave is sovereign-hosted, no cloud dependency in the trust boundary.