AI Infrastructure for Environments Where the Internet Does Not Exist
Kanawai Sovereign AI is a fully containerized AI platform purpose-built for disconnected, air-gapped, and classified environments. Deploy managed AI model routing, automated tool generation, and role-based access control on infrastructure including Google Distributed Cloud air-gapped or hardened bare-metal nodes with zero dependence on public internet connectivity.
Built for Disconnected Networks
Kanawai Sovereign AI operates entirely within your perimeter. No telemetry, no external API calls, no cloud dependencies. The platform runs as a self-contained, OCI-compliant containerized stack deployable on air-gapped infrastructure with no modification.
Deployment Architecture
Zero External Dependencies
No SaaS calls, no telemetry, no license servers. Every dependency is bundled into the container image and validated before deployment.
OCI-Compliant Containers
The entire platform ships as hardened, OCI-compliant container images deployable via any Kubernetes distribution, including GDC Kubernetes.
Bare-Metal or Edge
Runs on bare-metal architecture, hardened edge nodes, or full rack deployments. Extremely lightweight with no hypervisor requirement.
Classified Network Ready
Designed for IL5+ environments including SIPR, JWICS, and coalition partner networks. No data leaves the enclave.
Your Private, Managed LLM Foundry
Kanawai Sovereign MCP standardizes tool calling across model providers using the OpenAI specification via LiteLLM. Administrators can securely host, swap, and manage open-weight models in disconnected environments, transforming GDC air-gapped into a private LLM foundry.
Model Router
Containerized Model Registry
Models like Google Gemma, Meta Llama, and GPT-oss are pre-packaged as hardened, OCI-compliant containers. Deployed natively via the GDC Kubernetes platform.
Unified Translation Layer
Standardizes tool calling using the OpenAI specification via LiteLLM, enabling seamless interfaces with local models and Google ADK for Gemma or Gemini 2.5 Flash on GDC air-gapped rack.
Optional Hybrid Connectivity
In hybrid cloud environments, optional connectivity to AWS GovCloud Bedrock provides access to additional models such as Anthropic Claude Sonnet 5 and Opus 5.
From Endpoint to MCP Tool in Minutes
Kanawai Sovereign MCP automatically wraps your endpoints into MCP-compliant tools. Define the inputs and expected outputs through a visual form, and the server generates the connection logic, JSON Schema validation, and GDC network policies.
Tool Generator
3-step wizard: Define Tool, Input Fields, Preview & Compile
RBAC Manager
Permission Matrix: Assign MCP tools to GDCag/CAI service accounts
Role-Based Access Control
Administrators assign specific MCP tools to GDCag/CAI service accounts through a visual GUI. Every AI agent has access only to the tools and data it is explicitly authorized to use. HITL (Human-in-the-Loop) approval queues enforce accountability for destructive operations.
A Single Pane of Glass for Your AI Stack
Designed specifically for disconnected, secure environments, Kanawai Sovereign MCP operates as a self-contained, containerized managed service. A low-code visual dashboard lets administrators start and stop models, adjust context windows, monitor GPU VRAM utilization, and generate secure API keys for local applications.
System Overview
Quick Actions
Recent Errors
Immutable Audit Trails and System Health
Every tool invocation, access decision, and model interaction produces an immutable audit record. System health metrics track active tools, active models, namespaces, GPU utilization, and security status in real time without requiring any external monitoring service.
Audit Log Stream
| Timestamp | Service Account | Tool | Action | Status |
|---|---|---|---|---|
| Jul 31, 06:21:05 PM | ai-agent-prod | weather.get_forecast | access_check | Allowed |
| Jul 31, 06:20:59 PM | ai-agent-prod | weather.get_forecast | access_check | Denied |
| Jul 31, 06:18:32 PM | mcp-admin | inventory.check_stock | invocation | Allowed |
| Jul 31, 06:15:11 PM | mcp-admin | ai.gemma.code | access_check | Allowed |
System Metrics
Security Status
Official Cloud Partners
As official partners of Google Cloud, Microsoft Azure, and AWS, Kanawai Sovereign AI supports deployment across the most trusted infrastructure for defense and public sector workloads.
Google Distributed Cloud Air-Gapped Appliance
Air-GappedSingle edge appliance with contained compute for disconnected edge and forward-deployed locations. Kanawai deploys as a containerized workload on the GDC air-gapped appliance.
Google Distributed Cloud Air-Gapped Rack
Air-GappedMulti-rack deployments with GPU acceleration for model serving. Supports Gemini 2.5 Flash via Google ADK and local open-weight models through LiteLLM.
Google Classified AI
ClassifiedPurpose-built infrastructure for classified workloads. Kanawai Sovereign MCP runs natively within the Classified AI stack with full RBAC and audit compliance.
Azure Government
Gov CloudDeploy Kanawai on Azure Government regions with FedRAMP High and DoD IL5 compliance. Supports Azure OpenAI deployments within sovereign boundaries.
Bare-Metal Architecture
EdgeAs a fully containerized platform, Kanawai Sovereign AI is extremely lightweight and runs directly on bare-metal servers without a hypervisor dependency.
AWS GovCloud
Gov CloudKanawai Sovereign AI deploys within AWS GovCloud as a fully containerized workload, with native support for AWS CodeDeploy and AppConfig for automated, repeatable deployments across isolated government regions.
Purpose-Built for National Security
Kanawai Sovereign AI exists because defense and intelligence organizations deserve AI infrastructure that respects their operational constraints instead of asking them to compromise on security to access capability.
Zero Trust Architecture
Every service account, tool invocation, and model access decision is authenticated, authorized, and logged. No implicit trust, no ambient authority.
Low-Code Administration
Start and stop models, adjust context windows, monitor GPU VRAM utilization, and generate secure API keys through a visual dashboard. No CLI required.
Full Observability
Immutable audit logs, access decision analytics, system health metrics, and compliance monitoring. Every action produces a defensible record.
Model Agnostic
Host Google Gemma, Meta Llama, GPT-oss, CodeGemma, or any open-weight model. Swap models without changing application code.
Ship as Containers
The entire platform, including models, ships as hardened OCI containers. Air-gap validated. No runtime downloads, no external registries.
Operational Intelligence
Track tool usage, model performance, and access patterns to understand how AI is being used across your classified environment.
Stop Guessing. Start Knowing.
Schedule a demo today and discover how Kanawai AI transforms your data into answers and automated action.
