Protection that travels with the data, not with the network
NATO is moving protection from the network boundary to the data object itself. Scrydon keeps classification, originator and caveats with the data, decides every access against the label, and extends the same rule to AI agents, so the labelling and binding your programme accredits has a platform that honours it.
Written for the security, risk and data protection teams who have to evidence this — not just describe it.
NATO Data-Centric Security (STANAG 4774 / 4778)
- Jurisdiction
- NATO and allied nations
- Applies to
- NATO commands, agencies and national defence organisations that exchange classified information across domains, coalitions and clouds, and the industry partners building the systems they use.
How Scrydon helps you comply
Classification as first-class metadata
In the ontology, classification, originator, releasability and caveats are properties of the data object rather than of the system it came from. They are carried through fusion and derivation, so an aggregated or derived value inherits the marking of its most restrictive source and keeps a trace back to that source and its timestamp. This is the property data-centric security assumes: something to bind a label to, and a guarantee that the marking does not fall off when data is combined.
Access decided per request against the label
A single policy-as-code decision point evaluates the label, the actor's clearance, the purpose and the applicable policy on every retrieval, query and export, with fail-closed defaults. Nothing is served above the clearance of the request, and an attempt to reach past it is itself recorded. Access follows the label rather than the network, which is the change the STANAGs are there to enable.
The same rule for AI agents and retrieval
Generative retrieval creates a new path across a label: a model can compose an answer from passages a reader was never cleared to see. Agents on the platform act under scoped identities and retrieval enforces clearance at the point data is read, while DLP guardrails inspect prompts, retrieved passages and outputs. Automated actors are held to the same labelling rules as people, which is the part of data-centric security most AI tooling leaves open.
Every access, release and refusal recorded
An immutable, queryable audit log captures who or what read an object, which policy decision was taken, what was released to whom and what was refused. For a programme this is the evidence that the labelling policy is actually being enforced at runtime, and the sampled record an accreditor or security authority can inspect rather than take on trust.
One model from air-gapped enclave to coalition data space
Because access is decided against the label rather than the network, an air-gapped enclave and a shared coalition data space are two settings of one policy model rather than two systems. Each nation or command publishes what it authorises, per partner and per level, and the platform runs disconnected where classification requires it. Framework evidence packs map these controls alongside ISO 27001 and the EU AI Act so the same evidence serves several reviews.
What STANAG 4774 / 4778 asks of you
- Express confidentiality labels as machine-readable metadata rather than free text in a header.
- Bind the label to the data object so that stripping or altering it is detectable.
- Preserve classification, originator and caveats as data crosses domains, coalitions and clouds.
- Decide access by evaluating the label against clearance and policy, not by network location.
- Apply the marking of the most restrictive source to derived, fused and aggregated data.
- Hold automated actors, including AI agents and retrieval, to the same labelling rules as people.
- Record access, release, refusal and downgrade decisions so enforcement can be audited and accredited.
Frequently asked questions
Is Scrydon certified against STANAG 4774 and 4778?+
Can the platform honour labels produced by our existing labelling and binding tooling?+
What does data-centric security change once AI is in the picture?+
How do labels survive fusion and derived data?+
Does this work on an air-gapped classified network?+
How does this relate to ISO 27001 and the EU AI Act?+
Prefer to write? Email hello [at] scrydon.com and we will get back to you.