Kanawai Sovereign AI

AI Infrastructure for Environments Where the Internet Does Not Exist

Kanawai Sovereign AI is a fully containerized AI platform purpose-built for disconnected, air-gapped, and classified environments. Deploy managed AI model routing, automated tool generation, and role-based access control on infrastructure including Google Distributed Cloud air-gapped or hardened bare-metal nodes with zero dependence on public internet connectivity.

0
Internet Required
100%
Containerized
<1 hr
Deployment
15+
Available GenAI Models
Air-Gapped by Design

Built for Disconnected Networks

Kanawai Sovereign AI operates entirely within your perimeter. No telemetry, no external API calls, no cloud dependencies. The platform runs as a self-contained, OCI-compliant containerized stack deployable on air-gapped infrastructure with no modification.

Deployment Architecture

Air Gap Boundary
No inbound or outbound connectivity
Kanawai Sovereign MCP
Containerized gateway + admin console
Model Registry
Gemma, Llama, GPT-oss, CodeGemma
RBAC + HITL Engine
Permission matrix, approval queues
Observability + Audit
Immutable logs, system health, access decisions

Zero External Dependencies

No SaaS calls, no telemetry, no license servers. Every dependency is bundled into the container image and validated before deployment.

OCI-Compliant Containers

The entire platform ships as hardened, OCI-compliant container images deployable via any Kubernetes distribution, including GDC Kubernetes.

Bare-Metal or Edge

Runs on bare-metal architecture, hardened edge nodes, or full rack deployments. Extremely lightweight with no hypervisor requirement.

Classified Network Ready

Designed for IL5+ environments including SIPR, JWICS, and coalition partner networks. No data leaves the enclave.

Model-Agnostic Routing

Your Private, Managed LLM Foundry

Kanawai Sovereign MCP standardizes tool calling across model providers using the OpenAI specification via LiteLLM. Administrators can securely host, swap, and manage open-weight models in disconnected environments, transforming GDC air-gapped into a private LLM foundry.

Model Router

MCP Server Healthy
Google Gemma 4 E2B
Deployed
local
google/gemma-4-E2B
Gemini 2.5 Flash
Available
vertex_ai
vertex_ai/gemini-2.5-flash
Meta Llama 3.3
Deployed
local
meta/llama-3.3-70b
Claude Sonnet 5
Hybrid
bedrock
bedrock/anthropic.claude-sonnet-5-v1:0

Containerized Model Registry

Models like Google Gemma, Meta Llama, and GPT-oss are pre-packaged as hardened, OCI-compliant containers. Deployed natively via the GDC Kubernetes platform.

Unified Translation Layer

Standardizes tool calling using the OpenAI specification via LiteLLM, enabling seamless interfaces with local models and Google ADK for Gemma or Gemini 2.5 Flash on GDC air-gapped rack.

Optional Hybrid Connectivity

In hybrid cloud environments, optional connectivity to AWS GovCloud Bedrock provides access to additional models such as Anthropic Claude Sonnet 5 and Opus 5.

Automated Tool Generation

From Endpoint to MCP Tool in Minutes

Kanawai Sovereign MCP automatically wraps your endpoints into MCP-compliant tools. Define the inputs and expected outputs through a visual form, and the server generates the connection logic, JSON Schema validation, and GDC network policies.

Tool Generator

3-step wizard: Define Tool, Input Fields, Preview & Compile

1
Define Tool
2
Input Fields
3
Preview & Compile
Tool Name
inventory.check_stock
Endpoint URL
https://api.internal/v1/inventory
HTTP Method
POST
Model DeploymentCode Completion (Gemma)

RBAC Manager

Permission Matrix: Assign MCP tools to GDCag/CAI service accounts

Service Account
ai.gemma.code
inventory.check
weather.forecast
MCP Admin
mcp-admin
Production AI Agent
ai-agent-prod

Role-Based Access Control

Administrators assign specific MCP tools to GDCag/CAI service accounts through a visual GUI. Every AI agent has access only to the tools and data it is explicitly authorized to use. HITL (Human-in-the-Loop) approval queues enforce accountability for destructive operations.

Easy Administration

A Single Pane of Glass for Your AI Stack

Designed specifically for disconnected, secure environments, Kanawai Sovereign MCP operates as a self-contained, containerized managed service. A low-code visual dashboard lets administrators start and stop models, adjust context windows, monitor GPU VRAM utilization, and generate secure API keys for local applications.

System Overview

Kanawai AI Sovereign MCP
Unified MCP gateway and administration console for ACME Gov
Healthy
3
Registered Tools
2
Service Accounts
8
Model Providers
2
Total Invocations
Quick Actions
Create New Tool
Auto-generate MCP-compliant tools from endpoint definitions
Manage Permissions
Assign MCP tools to GDCag service accounts
Configure Model Provider
Add local, Vertex AI, or Bedrock model routing
View Audit Logs
Review tool invocation history and security events
Recent Errors
No Recent Errors
All tool invocations are executing successfully.
Observability

Immutable Audit Trails and System Health

Every tool invocation, access decision, and model interaction produces an immutable audit record. System health metrics track active tools, active models, namespaces, GPU utilization, and security status in real time without requiring any external monitoring service.

Audit Log Stream

TimestampService AccountToolActionStatus
Jul 31, 06:21:05 PMai-agent-prodweather.get_forecastaccess_checkAllowed
Jul 31, 06:20:59 PMai-agent-prodweather.get_forecastaccess_checkDenied
Jul 31, 06:18:32 PMmcp-admininventory.check_stockinvocationAllowed
Jul 31, 06:15:11 PMmcp-adminai.gemma.codeaccess_checkAllowed

System Metrics

3
Active Tools
1
Active Models
1
Active Namespaces
2
Audit Events
Security Status
MCP Protocol GatewayOperational
JWT AuthenticationActive
RBAC EngineActive
Output SanitizerEnabled
HITL EngineReady
Audit Logging2 events
Deployment Platforms

Official Cloud Partners

As official partners of Google Cloud, Microsoft Azure, and AWS, Kanawai Sovereign AI supports deployment across the most trusted infrastructure for defense and public sector workloads.

Google Cloud Partner
Microsoft Azure Partner
AWS Partner

Google Distributed Cloud Air-Gapped Appliance

Air-Gapped

Single edge appliance with contained compute for disconnected edge and forward-deployed locations. Kanawai deploys as a containerized workload on the GDC air-gapped appliance.

Google Distributed Cloud Air-Gapped Rack

Air-Gapped

Multi-rack deployments with GPU acceleration for model serving. Supports Gemini 2.5 Flash via Google ADK and local open-weight models through LiteLLM.

Google Classified AI

Classified

Purpose-built infrastructure for classified workloads. Kanawai Sovereign MCP runs natively within the Classified AI stack with full RBAC and audit compliance.

Azure Government

Gov Cloud

Deploy Kanawai on Azure Government regions with FedRAMP High and DoD IL5 compliance. Supports Azure OpenAI deployments within sovereign boundaries.

Bare-Metal Architecture

Edge

As a fully containerized platform, Kanawai Sovereign AI is extremely lightweight and runs directly on bare-metal servers without a hypervisor dependency.

AWS GovCloud

Gov Cloud

Kanawai Sovereign AI deploys within AWS GovCloud as a fully containerized workload, with native support for AWS CodeDeploy and AppConfig for automated, repeatable deployments across isolated government regions.

Purpose-Built for National Security

Kanawai Sovereign AI exists because defense and intelligence organizations deserve AI infrastructure that respects their operational constraints instead of asking them to compromise on security to access capability.

Zero Trust Architecture

Every service account, tool invocation, and model access decision is authenticated, authorized, and logged. No implicit trust, no ambient authority.

Low-Code Administration

Start and stop models, adjust context windows, monitor GPU VRAM utilization, and generate secure API keys through a visual dashboard. No CLI required.

Full Observability

Immutable audit logs, access decision analytics, system health metrics, and compliance monitoring. Every action produces a defensible record.

Model Agnostic

Host Google Gemma, Meta Llama, GPT-oss, CodeGemma, or any open-weight model. Swap models without changing application code.

Ship as Containers

The entire platform, including models, ships as hardened OCI containers. Air-gap validated. No runtime downloads, no external registries.

Operational Intelligence

Track tool usage, model performance, and access patterns to understand how AI is being used across your classified environment.

Stop Guessing. Start Knowing.

Schedule a demo today and discover how Kanawai AI transforms your data into answers and automated action.

K
K