Governed AI for environments where the network path is the threat model.
Twhyne runs entirely on hardware you control — including hardware with no network path at all. Permission-before-retrieval, trust-labeled answers, and a tamper-evident audit ledger, in enclaves where cloud AI cannot follow.
What air-gapped means here.
Air-gapped is not a firewall rule. It means no route exists between the system and any external network. The Twhyne Appliance is built for that definition: no radios on the board, updates as signed offline media, and a runtime with no external dependency at inference time. Encrypted-but-connected is a different product tier — we say which is which.
Every claim carries its status. None moves without a change request.
Read it as a ladder. What the software enforces today, what the appliance adds in development, and what is on the roadmap — each rung labeled with its status, so a program office can tell shipping from planned at a glance.
Software, running today
- Local runtime, no cloud dependency
- Permission-before-retrieval with chunk-level ACLs
- Trust labels on every answer
- Hash-chained audit ledger
- 312-task suite runnable by the evaluator
Twhyne Appliance
- Immutable signed OS image on a DISA-STIG-configured base
- Secure Boot + TPM-measured-boot attestation
- Signed model artifacts verified at load
- Documented HW/SW BOM to component level
- Tamper-evident chassis
Not yet built
- Signed user identity (CAC/PIV-compatible)
- Node-to-node federation with attestation-gated peering and provenance-carrying knowledge exchange
- Third-party security review
We would rather show the ledger than write the paragraph.
Every answer names its production method and its sources. Every boundary crossing is logged to a hash-chained ledger. Supply-chain discipline extends below the software: components sourced through authorized distribution only, receipt-verified, custody-controlled to sealed chassis, with a complete SBOM/HBOM. We would rather show the ledger than write the paragraph.
A defined task envelope, stated plainly.
Twhyne operates within a deliberately narrow envelope: verified answers to defined tasks, each one reproducible through a suite the evaluator runs directly. That constraint is what allows the system to cite its sources, record its reasoning, and refuse when the authorizing evidence is absent. A program office knows precisely what it is accrediting.
We state our limits with the same precision as our capabilities. No system can promise zero leakage or replace a formal security review, and we don't claim otherwise. Every safeguard we ship is something you can check against the ledger and the benchmark — evidence a reviewer can reproduce, not assurances taken on faith.
Request the assurance architecture document.
Written for a program office: the enforced-now controls, the appliance's in-development attestation path, and the supply-chain discipline — with the boundaries stated plainly.