How – Inside the AI OS: running governed agents on your own cluster, liveRegister →
NATO Data-Centric Security

Protection that travels with the data, not with the network

NATO is moving protection from the network boundary to the data object itself. Scrydon keeps classification, originator and caveats with the data, decides every access against the label, and extends the same rule to AI agents, so the labelling and binding your programme accredits has a platform that honours it.

Written for the security, risk and data protection teams who have to evidence this — not just describe it.

What it is

NATO Data-Centric Security (STANAG 4774 / 4778)

Data-centric security is the Alliance's move to protect information at the level of the data object rather than at the boundary of whichever network it happens to sit on. Two standardisation agreements carry it. STANAG 4774 defines a confidentiality metadata label: classification, originator, policy identifier and caveats expressed in a machine-readable form instead of as text in a header. STANAG 4778 defines how that label is bound to the data it describes, so that a stripped or altered label is detectable and the marking travels with the object across domains, coalitions and clouds. Together they make it possible to decide access by evaluating a label against a policy and a clearance rather than by asking which network someone is connected to, which is what cross-domain sharing, coalition exchange and Federated Mission Networking depend on. The standards describe the labels, the binding and the policies that consume them; implementing them in a system and accrediting that system is programme work, done with the national or NATO security authority. Scrydon is not a labelling or binding product and does not claim conformance to the STANAGs. What it provides is the platform behaviour data-centric security assumes: classification as first-class metadata, an access decision taken per request against the label, the same rule applied to AI agents, and a record of every decision.
At a glance
Jurisdiction
NATO and allied nations
Applies to
NATO commands, agencies and national defence organisations that exchange classified information across domains, coalitions and clouds, and the industry partners building the systems they use.
Talk to us
How we help

How Scrydon helps you comply

Controls are built into the runtime, so compliance is something you can demonstrate with evidence drawn from the platform itself — not assembled after the fact.

Classification as first-class metadata

In the ontology, classification, originator, releasability and caveats are properties of the data object rather than of the system it came from. They are carried through fusion and derivation, so an aggregated or derived value inherits the marking of its most restrictive source and keeps a trace back to that source and its timestamp. This is the property data-centric security assumes: something to bind a label to, and a guarantee that the marking does not fall off when data is combined.

Access decided per request against the label

A single policy-as-code decision point evaluates the label, the actor's clearance, the purpose and the applicable policy on every retrieval, query and export, with fail-closed defaults. Nothing is served above the clearance of the request, and an attempt to reach past it is itself recorded. Access follows the label rather than the network, which is the change the STANAGs are there to enable.

The same rule for AI agents and retrieval

Generative retrieval creates a new path across a label: a model can compose an answer from passages a reader was never cleared to see. Agents on the platform act under scoped identities and retrieval enforces clearance at the point data is read, while DLP guardrails inspect prompts, retrieved passages and outputs. Automated actors are held to the same labelling rules as people, which is the part of data-centric security most AI tooling leaves open.

Every access, release and refusal recorded

An immutable, queryable audit log captures who or what read an object, which policy decision was taken, what was released to whom and what was refused. For a programme this is the evidence that the labelling policy is actually being enforced at runtime, and the sampled record an accreditor or security authority can inspect rather than take on trust.

One model from air-gapped enclave to coalition data space

Because access is decided against the label rather than the network, an air-gapped enclave and a shared coalition data space are two settings of one policy model rather than two systems. Each nation or command publishes what it authorises, per partner and per level, and the platform runs disconnected where classification requires it. Framework evidence packs map these controls alongside ISO 27001 and the EU AI Act so the same evidence serves several reviews.

Key requirements

What STANAG 4774 / 4778 asks of you

  • Express confidentiality labels as machine-readable metadata rather than free text in a header.
  • Bind the label to the data object so that stripping or altering it is detectable.
  • Preserve classification, originator and caveats as data crosses domains, coalitions and clouds.
  • Decide access by evaluating the label against clearance and policy, not by network location.
  • Apply the marking of the most restrictive source to derived, fused and aggregated data.
  • Hold automated actors, including AI agents and retrieval, to the same labelling rules as people.
  • Record access, release, refusal and downgrade decisions so enforcement can be audited and accredited.
Where the line sits

What we provide, and what stays yours

No vendor can be compliant on your behalf. We build the controls into the platform and produce the evidence; the assessment of your own deployment stays with you. Here is the split, stated plainly, so it does not surface late in a security review.

Scrydon provides

  • Controls enforced in the runtime by default, rather than left to configuration.
  • An immutable, queryable record of what ran, on whose authority, and against which data.
  • Evidence packs mapped to the obligations set out on this page.
  • Documented architecture and data flows your assessors can read.
  • Deployment inside your own perimeter — up to fully disconnected.

You remain responsible for

  • Classifying your own systems and data under the framework.
  • Your risk assessment, data protection impact assessment and conformity assessment.
  • Who you grant access to, and on what basis.
  • Your incident response and reporting obligations.
  • The operational security of the environment you run it in.
FAQ

Frequently asked questions

Is Scrydon certified against STANAG 4774 and 4778?+
No, and we would be careful about any vendor who says otherwise. These are standardisation agreements implemented within a system and accredited by a national or NATO security authority for a specific deployment, not a product certification you can buy off the shelf. Scrydon helps you meet them rather than claiming to be them: classification, originator and caveats are first-class metadata carried with the data, every access is decided against the label by a single policy decision point, AI agents and retrieval are held to the same rule, and every decision is recorded for the accreditor. Implementing the label profile and binding your programme mandates, and accrediting the result, stays with you and your security authority.
Can the platform honour labels produced by our existing labelling and binding tooling?+
That is the intended shape. Scrydon is not a labelling or binding product and does not seek to replace the components a programme has already accredited. Classification, releasability and caveats are modelled as properties of the data object, so labels applied upstream are carried through the ontology, preserved through fusion and derivation and used as the input to the access decision. Where a programme mandates specific components, the integration work is mapping their label into the platform's policy model, which is the same work as mapping any national system.
What does data-centric security change once AI is in the picture?+
It closes a gap that classic network separation never had to consider. A retrieval system can compose one answer from many documents, so an answer can cross a label even when every source document is stored correctly. On this platform clearance is enforced at the point data is retrieved rather than after generation, agents act under identities scoped to a nation, domain and system set, and DLP guardrails inspect prompts, retrieved passages and outputs. See AI Governance for how those controls are configured and evidenced.
How do labels survive fusion and derived data?+
Fusion is where markings are most often lost, because a derived value has no natural owner. In the ontology every fused value keeps a trace back to its originating source and timestamp and inherits the marking of its most restrictive contributor, so a common operating picture assembled from several nations carries the releasability each nation set rather than flattening to the lowest common denominator or, worse, to nothing.
Does this work on an air-gapped classified network?+
Yes, and that is the normal case rather than a special mode. The full platform, including open-weight models, retrieval and agents, runs air-gapped with updates through the accredited channel and clearance enforced at retrieval. The same policy model then governs a shared coalition data space, so a nation runs one stack at home and in the coalition cell.
How does this relate to ISO 27001 and the EU AI Act?+
They overlap more than they compete. ISO 27001's information-classification, labelling and data-leakage-prevention controls describe the same discipline in management-system language, and the EU AI Act's logging, human-oversight and data-governance duties are satisfied by the same audit log and policy decision point. Evidence packs map the platform's controls to all of them at once, so a control evidenced for a defence accreditation does not have to be evidenced again for ISO 27001 or the EU AI Act.

Or write to us

Tell us what you are working on and who should reply. A person reads it and replies within one business day.

We only use these details to reply to you. Privacy policy

Prefer to write? Email hello [at] scrydon.com and we will get back to you.