Sovereign Security AI
Security AI that stays under your control
We don't hand control of security to an outside AI.
This does not mean refusing outside AI. We use the models we need, while making sure core knowledge, tools, procedures and judgment keep building up without being tied to any one model or provider. That way we can carry out, check and control the work ourselves, and switch models when we need to.
If the model changes, does our security capability go with it? Reviewed
No. It stays in people, tools, data and procedures, and keeps growing.
What it means
Sovereign Security AI is the ability to carry out, verify, control and keep improving real security work on a foundation of AI you can govern.
We make full use of capable models, and where models are constrained we make up for it with tools, knowledge and verification.
- People
Experts who understand the situation, spot new problems, judge results and take responsibility for them
- Knowledge
Expert knowledge and field experience linked to sources and context, and attack and defense techniques
- Tools
Tools for attack, assessment, analysis and validation, used by people and by AI agents
- Data
Evaluation datasets, quality standards, work history and evidence
- Procedures
Playbooks, roles and permissions, approval and stop procedures, and verification standards
The best model is not always available
Security work has to carry on in each of these situations.
- Cost
Running every task on the most advanced model may not be affordable.
- Provider policy
When a provider changes its usage policy or terms, work in progress can suddenly be blocked.
- Data sovereignty
Some work involves customer data or test results that must not be sent to an outside model.
- Isolated networks
In networks cut off from the internet, outside models cannot be reached.
- Regulation
Industry and national rules may decide which models and which ways of handling data are allowed.
Built as an ecosystem, not by one organization
Sovereign Security AI does not come from strengthening one model or agent. It means building, developing and sustaining a security ecosystem that holds up in a fast-changing AI era.
- People who keep growing as experts
Even as AI takes on more of the work, people who understand the situation, find new problems, judge results and take responsibility remain essential. We keep developing people as security experts, so capability builds up in the organization.
- Security within reach
Without depending on one model, security work can continue where cost or an isolated network rules out the most advanced models. Organizations short on budget are reached through Pay It Forward.
To build this capability inside your organization: with your team we build tools, knowledge environments and AI workflows with a person approving, and the results, methods and records stay with you.
The parts of this ecosystem and the six-step flow they work in.
This describes the direction of our research and ways of working. The models, tools and environments used in an engagement are agreed for that work.
Even if a model goes away, your security capability stays and keeps developing.
We are preparing a structure where security capability lives in people, tools, data, agents and ways of working, not in one model.