Visca
Solutions/Industry

Public sector

Classified and sensitive data never leaves the boundary — so the entire stack has to run inside it, air-gapped.

For government and defense workloads, the data — classified material, citizen records, mission information — cannot leave the boundary under any circumstance, which rules out every hosted AI vendor before the conversation starts. Sovereignty is the precondition, not a feature. But assembling a self-hosted stack from disparate open-source projects and vendors, each with its own update path that wants to phone home, is a non-starter in an air-gapped facility. Visca is the whole stack — open-weight models, identity, scoped access, and a tamper-evident record — as one ecosystem that runs self-managed inside the boundary, up to and including fully air-gapped, with controls a federal reviewer recognizes.

Why the data can't leave

Hosted AI is out. A stitched stack is the only thing left — and it breaks here.

No public cloud, no outbound dependency

For classified and sensitive workloads, the runtime cannot phone home. Updates must arrive as offline packages; nothing leaves the boundary.

Identity and authority, end to end

Every action by every automated actor must be attributable to an authorizing principal, with a chain back to a human — non-negotiable for accountability in government.

Controls a reviewer recognizes

Bespoke security stories don't clear authorization. Controls need to map to recognized frameworks, with evidence.

One ecosystem, not a stitched stack

One self-hosted ecosystem, applied to public sector.

Sigil

Authority traceable to a human root

Every actor's Sigil chains its lineage back to the principal that authorized it. Accountability is structural, not a logging convention.

Warrant

Scoped, consented, audited access

Capability Grants with human-in-the-loop consent flows for consequential actions, scoped and time-bound, audited on both sides.

Chronicle

Tamper-evident record of record

Cryptographically chained audit that an investigator can trust and an authorizing official can sign against.

Lattice Runtime

Air-gapped operation

The runtime runs self-managed with no outbound dependency. Updates delivered via offline packages. Same primitives, isolated facility.

What you get

Outcomes.

Relevant frameworks

FedRAMP (roadmap)NIST 800-53DoD IL4 / IL5 (roadmap)FIPS 140-3 alignment

Visca Cloud has not yet completed formal certification against these frameworks; the stack is architected to meet them and audits are in progress. See the compliance roadmap.

In practice

An air-gapped analysis estate

Inside an isolated facility, analysts run autonomous workflows over sensitive data. The runtime never reaches the internet; updates arrive on signed offline media. Every action carries a Sigil chained to an authorizing officer, every data access is a consented Capability Grant, and the Chronicle is the authoritative, tamper-evident record the authorizing official signs against.

Other industries

The whole stack. Self-hosted. One ecosystem.

The entire agent stack, inside your own walls.

Models, identity, tools, voice, payments, runtime, and audit — as one integrated ecosystem, self-hosted, sovereign, air-gapped. Nothing stitched from vendors. Nothing leaves your perimeter. Open at the core. No license rug-pulls, ever.