The 12-Pillar Tier Model

12 pillars across 3 tiers plus premium add-ons. Each tier builds on the one below it. Foundation is required; Enterprise extends; Strategic transforms.

Tier 3 — Strategic
Nation-Scale Transformation
Custom Pricing / by engagement
  • 9 COLLAPSE — 18-agent institutional failure simulation
  • 10 SGAS — Societal-scale governance simulation
  • 11 VERTICALS — 8 deep industry verticals + 13 sector templates
  • 12 FRONTIER — Nation-scale sovereign AI deployment
Tier 2 Premium Add-Ons
Advanced Modules
Custom pricing per module
  • Guardian Suite — CendiaAegis, CendiaEternal, CendiaSymbiont, CendiaVox
  • Strategic Suite — CendiaMythos, CendiaEthos, CendiaGaia
Tier 2 — Enterprise
Full Enterprise Governance
Custom Pricing / annual license
  • 4 STRESS-TEST — Crucible + RedTeam + War Games + SCGE
  • 5 COMPLY — 10 frameworks, 17 jurisdictions
  • 6 GOVERN — Constitutional Court, Veto, Dissent, Autopilot
  • 7 SOVEREIGN — 11 air-gap architecture patterns
  • 8 OPERATE — CendiaOps (19 AI department co-pilots)
Tier 1 — Foundation
Core Decision Intelligence
Custom Pricing / annual license
  • 1 THE COUNCIL — Multi-agent deliberation engine (15+ agents, 35+ modes)
  • 2 DECIDE — Chronos, PreMortem, Cascade, Ghost Board, Lens, Decision Debt
  • 3 DCII — Crisis Immunization Infrastructure (9 primitives, IISS scoring)

DCII — 9 Primitives

The The Defensible AI Platform scores institutional resilience across 9 measurable primitives. Together they produce the Institutional Immune System Score (IISS).

P1
Ledger
Immutable audit trail with blockchain-style hash chaining
P2
Notary
Cryptographic signing with customer-owned keys
P3
Vault
Unified evidence storage for decision packets
P4
Provenance
Full decision lineage and court-admissible export
P5
Timestamp
RFC 3161 external timestamp authority with blockchain anchoring
P6
MediaAuth
C2PA synthetic media authentication and deepfake detection
P7
Jurisdiction
Cross-jurisdiction compliance conflict detection (GDPR vs PIPL)
P8
Similarity
Decision pattern matching with TF-IDF semantic search
P9
Bias Mitigation
Cognitive bias detection and decision debiasing engine
Composite Output
IISS™ Score
0–1000 scale · 5-band certification

Decision Lifecycle

End-to-end flow from question to auditable, court-admissible decision record.

01
Ingest & Frame
Decision question is submitted. Context is gathered from data sources, knowledge graph, and historical decisions. The question is framed for deliberation.
Data SourcesNeo4jCendiaSimilarity
02
Council Deliberation
Multi-agent council convenes. Agents analyze in parallel, then cross-examine each other's assumptions. Dissent is captured and preserved.
The CouncilCendiaLiveCendiaDissentOllama LLM
03
Governance & Ethics Check
Ethics review, stakeholder impact (CendiaVox), and veto rules are applied. Compliance is checked against active regulatory frameworks.
CendiaVetoCendiaVoxCendiaComplianceConstitutional Court
04
Stress Test & Red Team
Decision is attacked from 8 adversarial perspectives. Cascade analysis maps second/third-order consequences. Pre-mortem identifies failure modes.
CendiaCrucibleCendiaRedTeamCendiaCascadeCendiaPreMortem
05
Synthesis & Recommendation
Final recommendation is synthesized with confidence score, key conditions, and dissenting views preserved. Executive summary is generated.
Executive SummaryCendiaRecallDecision Debt
06
Evidence & Immutable Record
Decision packet is cryptographically signed, timestamped via RFC 3161, and stored in the immutable ledger. Full provenance chain is exportable as court-admissible evidence.
CendiaLedgerCendiaNotaryCendiaVaultCendiaTimestampCendiaProvenance
07
Outcome Tracking & Learning
CendiaEcho tracks what actually happened. CendiaChronos snapshots the state for time-travel replay. IISS score is recalculated. The institution gets smarter.
CendiaEchoCendiaChronosCendiaReplayIISS

Sovereign Architecture Patterns

11 sovereign architectural patterns. Every pattern runs on your infrastructure. No cloud dependency. No data exfiltration. Full sovereign control. All 11 patterns are production-ready.

Isolation & Air-Gap

01
Data Diode
Unidirectional gateway — import only, no exfiltration
02
QR Air-Gap Bridge
Transfer decisions across air gaps via QR code sequences
03
Shadow Council
Parallel deliberation on isolated network with sync protocol
04
Portable Instance
Self-contained deployment on removable media

Cryptography & Trust

05
TPM Attestation
Hardware root of trust verification for compute nodes
06
CendiaKey
Customer-owned key management with HSM integration
07
CendiaBlackBox
Tamper-evident sealed execution environment
08
TimeLock
Time-locked encryption for embargoed decisions

Resilience & Integrity

09
CendiaWitness
Independent verification of decision integrity
10
CendiaMirror
Real-time replication for disaster recovery
11
CendiaVault
Encrypted evidence storage with AES-256 at rest
12
Canary Tripwire
Intrusion detection via decision integrity canaries

Network & Federation

13
Federated Mesh
Multi-site federation without centralized data store
14
CendiaMesh
Service mesh for zero-trust inter-service communication
15
CendiaMirage
Decoy infrastructure to mislead attackers
16
CendiaGlass
Transparent audit layer for all network traffic

AI & Inference

17
Local RLHF
On-premise reinforcement learning from human feedback
18
Deterministic Replay
Bit-exact reproduction of any past inference
19
Decision DNA
Portable decision fingerprint for cross-system verification
20
CendiaOracle
Deterministic AI oracle for policy-bound inference
21
CendiaLegacy
Long-term archival with format migration guarantees

Industry Verticals

8 deep industry verticals with full agent stacks, compliance mappings, and decision schemas. 13 additional sector templates in active development. Flagship verticals highlighted in gold.

Legal
Flagship
Sports
Flagship
Defense
Flagship
🏥
Financial
Agents + Modes
🏧
Healthcare
Agents + Modes
🏫
Government
Agents + Modes
Energy
Agents + Modes
💻
Technology
Agents + Modes
🚀
Aerospace
Agents + Modes
🏭
Manufacturing
Agents + Modes
📚
Education
Agents + Modes
🏠
Real Estate
Agents + Modes
📷
Media
Agents + Modes
📱
Telecom
Agents + Modes
🚕
Automotive
Agents + Modes
💉
Pharmaceutical
Agents + Modes
Insurance
Agents + Modes
🚲
Transportation
Agents + Modes
🌾
Agriculture
Agents + Modes
🛇
Nonprofit
Agents + Modes
🏘
Construction
Agents + Modes
🏖
Hospitality
Agents + Modes
🛍
Retail
Agents + Modes
🏙
Smart City
Agents + Modes
💼
Professional Svcs
Agents + Modes
Industrial Svcs
Agents + Modes
🛠
Core Platform
Cross-vertical
🔬
Meta / R&D
Internal
🛠
Internal Ops
Internal

SGAS — 5 Agent Classes

The Synthetic Governance Agent System runs societal-scale simulations with 5 distinct agent classes, orchestrated by a central coordinator.

Central Coordinator
SGAS Orchestrator
👥
Institutional
Simulate organizations, governments, and regulatory bodies at macro scale
🔍
Observer
Monitor simulation dynamics, detect emergent patterns, flag anomalies
Decision
Execute governance decisions within simulated institutional frameworks
😈
Adversarial
Attack governance structures, exploit weak policies, stress-test resilience
🌐
Meta-Governance
Govern the governance — ensure simulation rules and agent behaviors remain valid

Trust & Evidence Chain

Every decision passes through a cryptographic chain of custody. From deliberation to court-admissible evidence in 6 steps.

💬
Deliberation
Council produces reasoning, dissent, and recommendation
📝
Ledger
Immutable hash-chained record created
🔒
Notary
Cryptographic signature with customer-owned keys
🕐
Timestamp
RFC 3161 external timestamp authority
🗃
Vault
Encrypted evidence bundle stored with AES-256
📜
Provenance
Court-admissible export with full lineage

Compliance Framework × Jurisdiction Matrix

10 compliance frameworks mapped against 17 supported jurisdictions. Gold = full coverage. Dim gold = partial. Dark = not applicable.

Framework US EU UK CA AU JP KR SG BR IN CH AE SA CN DE FR IL
SOC 2
GDPR
HIPAA
FedRAMP
ISO 27001
DORA
EU AI Act
NIST AI RMF
PCI-DSS
CMMC / ITAR
Full coverage Partial / mapped Not applicable

Multi-Model AI Architecture

“Right Brain for the Right Job.” 8 purpose-built AI model slots, each optimized for a specific task type. All running locally via Ollama on your infrastructure. No API calls to external providers.

QueryRouter → Task Classifier → Tier Gate → Ollama
Natural language query is classified by intent, routed to the optimal model slot, and tier-gated based on your license level
Large
llama3.3:70b
70B · 128K ctx
Complex strategy, board-level analysis
Flagship
qwen3:32b
32B · 32K ctx
General deliberation, council agents
Reasoning
deepseek-r1:32b
32B · 128K ctx
Compliance, risk analysis, logic chains
Coder
qwen3-coder:30b
30B · 131K ctx
SQL generation, data transforms, code
Fast
llama3.2:3b
3B · 128K ctx
Classification, routing, quick lookups
Vision
qwen3-vl:30b
30B · multimodal
Document OCR, image analysis, charts
Translator
qwen2.5:32b
32B · 128K ctx
100+ languages, RTL, glossary-aware
Embed
qwen3-embed:4b
4B · 2560-dim
Semantic search, RAG, similarity

Evidence Packet Anatomy

What’s inside a Regulator’s Receipt™. Every layer is independently verifiable. This is what you hand to the auditor.

Decision Packet
run_id: 2026-0221-1430-a7f3b2
🔗
Merkle Root
SHA-256 integrity tree — any single leaf change invalidates the root. Tamper-proof by construction.
🤖
Agent Contributions
Each agent’s analysis, vote, confidence score, and reasoning chain. CFO, CLO, CISO, CTO, Ethics, Risk, Strategy…
⚠️
Dissenting Opinions
Preserved, timestamped, non-suppressible. Tracked to outcome for institutional learning.
📎
Evidence Citations
Source documents, data points, and knowledge base references — each with content hash and retrieval timestamp.
🛠️
Tool Call Traces
Every external tool invoked during deliberation: database queries, API calls, calculations — with inputs, outputs, and duration.
🔓
Policy Gate Results
Which compliance frameworks were checked, which rules triggered, what approvals were required and obtained.
🎯
IISS Score Snapshot
Institutional Immune System Score at time of decision — 9 primitive scores, weighted composite, certification band.
🖌️
Digital Signature
KMS/HSM-backed signature (AWS KMS, HashiCorp Vault, Azure Key Vault, or local). Post-quantum ready (Dilithium, SPHINCS+).

Deployment Stack

Everything runs on your infrastructure. Every component is a recognized, auditable technology. Nothing proprietary in the data path.

Presentation
React SPA
Dashboard, Council UI, DCII tabs
WebSocket
Live deliberation streaming
API & Auth
Express REST
59+ API endpoints
JWT + Keycloak
SSO, RBAC, Casbin policy
Rate Limiter
CSRF, Helmet, OWASP
AI Layer
Ollama
8 local AI models · no cloud calls
Qdrant
2560-dim vector search · RAG
Data
PostgreSQL
Prisma ORM
Neo4j
Knowledge graph
Redis
Cache · sessions
ClickHouse
Analytics · OLAP
MinIO
Object storage
Security & Integrity
PostQuantum KMS
Dilithium · SPHINCS+
Apache Tika
Document extraction
ClamAV
Malware scanning
OpenTelemetry
Observability · tracing
🔒 Nothing leaves this box. Your keys. Your data. Your infrastructure.

License Tier Model Gating

Each license tier unlocks progressively more powerful AI models. Automatic downgrade ensures graceful degradation. No feature breaks — just smaller models.

Pilot
$50K · 90 days
Max model size14B
Flagshipqwen2.5:14b
Reasoningdeepseek-r1:14b
Fastllama3.2:3b
Embedqwen3-embed:4b
Large (70B)
Coder
Vision
Consensus
Red-team
Enterprise
$150K–$500K / year
Max model size32B
Flagshipqwen3:32b
Reasoningdeepseek-r1:32b
Fastllama3.2:3b
Embedqwen3-embed:4b
Large (70B)
Coderqwen3-coder:30b
Visionqwen3-vl:30b
Consensus
Red-team
Sovereign
$500K–$1.5M / year
Max model size70B+
Flagshipqwen3:32b
Reasoningdeepseek-r1:32b
Fastllama3.2:3b
Embedqwen3-embed:4b
Large (70B)llama3.3:70b
Coderqwen3-coder:30b
Visionqwen3-vl:30b
Consensus
Red-team

Ready to explore?

See it running on your infrastructure

Request Technical Briefing →