Sovereign AI for the Defence Industrial Base
Defence manufacturers hold export-controlled engineering knowledge, classified programme data and supply chains the ministry now asks them to prove. AI on that data has to stay inside the company and respect every marking. That is what the platform is for.
Markings enforced, not advised
Classification and export markings are first-class metadata. Retrieval returns only what the engineer's clearance, nationality and programme allow, and logs the rest.
A digital thread that queries
Requirements, design, tests and evidence connected across the tools you already use. Verification status is a query, not a review-week reconstruction.
Supply chain below tier one
Parts, suppliers, sites and materials resolved into one graph, so single points of failure and jurisdiction risks are visible before the ministry asks.
A prime or a supplier lives between two pressures: the customer wants faster programmes, demonstrable security of supply and a digital thread from requirement to test evidence, while export control, classification and commercial sensitivity forbid the shortcuts. The platform lets engineering, programme and supply-chain teams use AI on their own knowledge and data, inside the company's perimeter, with the markings enforced and the log an export-control officer can rely on.
Read this if you're leading engineering, programme management, supply chain, security or IT at a defence prime, a system integrator or a supplier in the European defence industrial base.
For the defence industrial base, Scrydon is the sovereign AI and data platform that runs export-control-aware knowledge assistants, programme digital threads and supply-chain knowledge graphs inside the company's own infrastructure, with classification and export markings enforced at every retrieval and every action logged.
It runs on-premises, in a sovereign cloud or fully disconnected for classified programmes, with open-weight models served locally, so the assistant itself never becomes an export event and the platform is one the customer's security authority can accredit.
Faster programmes, stricter markings, and a customer who wants proof
The most valuable document in a defence programme is usually the one from a previous programme that solved the same problem, and it is locked behind export control: finding it means knowing it exists, then establishing whether the engineer asking is a national of a country the licence covers, at a site the licence covers, on a programme the licence covers. Public AI tools are out of the question, and even sharing across the company's own sites needs a compliance check.
Two more pressures come from the customer. Ministries and the European defence programmes now ask primes to demonstrate security of supply, where critical components come from and what happens if a source is lost, and few can answer below tier one. And every milestone review asks for the digital thread from requirement to test evidence, which today means a person walking the joins between the requirements tool, the systems-engineering model, the test system and the document vault by hand. All of it on programme data that is classified by default and has to be accredited by the customer's security authority.
Knowledge locked by export control — Decades of drawings, test reports and specifications that cannot be searched with a public tool or shared across sites without a compliance check.
Traceability across tool boundaries — Requirements, MBSE, test and document systems each hold part of the thread; the joins are spreadsheets walked by hand before every review.
Security of supply as a contract term — Ministries and European programmes ask where critical components come from and what happens if a source is lost. Few primes can answer below tier one.
Programme data classified by default — The customer's security authority has to accredit whatever runs on it. Anything that phones home is out.
Model the programme, enforce the markings, let the teams ask
The platform models the programme and the supply base in one ontology: requirements, functions, design elements, interfaces, test cases, test runs and evidence on one side; parts, suppliers, sites and materials on the other, mapped from the engineering, programme and ERP systems already in use. Every document and record carries its classification and export marking as first-class metadata, and policy decides who may retrieve what.
Engineers ask the knowledge assistant in plain language and get answers assembled only from documents their clearance, nationality, site and programme allow, with citations, and a question that would need more returns nothing from it and is logged. Programme managers query verification status instead of reconstructing it: which requirements at this baseline have no passed test, which tests are affected if an interface changes, what evidence is missing for the acceptance review. Supply-chain analysts see the knowledge graph of parts and suppliers resolved down to the tiers that matter, with concentration and jurisdiction risks ranked. Agents draft the compliance matrix, the review pack and the security-of-supply assessment; a person checks them.
- 1
Model
An ontology of requirements, design elements, tests, evidence, parts, suppliers and sites, mapped from the engineering, programme and ERP systems in use.
- 2
Mark
Every document and record carries its classification and export marking as metadata; policy decides who may retrieve what.
- 3
Ask
Engineers, programme managers and supply-chain analysts ask in plain language; answers cite their sources and stop at the reader's entitlement.
- 4
Evidence
Compliance matrices, review packs and security-of-supply assessments are drafted from the graph, checked by a person, and logged.
The company is the perimeter, and the customer will check
For a defence supplier the company is the perimeter, and the customer will check. The platform runs on-premises, in a sovereign cloud or air-gapped on classified programme networks, with open-weight models served locally. Because the models and the indexes stay inside the company, the assistant itself never becomes an export event, and no controlled document is ever sent to an external service.
Every controlled retrieval is logged against the marking that permitted it, which is the record the export-control officer keeps and the customer asks for. Agents act under scoped identities and every action is attributed. The customer's review team gets a view of the same model limited to what it is entitled to see, without a second copy of the data. The ISO 27001 control set, the Cyber Resilience Act obligations for the products the company ships and the audit log are met by the way the platform runs, which is what makes it something the customer's security authority can accredit.
Inside the company — Models, indexes and graphs run on the company's own infrastructure or a sovereign cloud; the assistant never becomes an export event.
Disconnected for classified programmes — The full platform runs air-gapped on programme networks, with updates through the accredited channel.
Export-control log — Every controlled retrieval is logged against the marking that permitted it, which is the record the export-control officer and the customer ask for.
Scoped views for the customer — The ministry's review team sees a view limited to what it is entitled to, drawn from the same model, without a second copy.
Keep an eye on this space
What changed for your sector in European AI sovereignty, and what we learned in the field. A few times a year, no drip campaign.
Use cases for the defence industrial base
Engineering knowledge, programme traceability and supply-chain resilience on one sovereign platform.
Secure Supply Chain Logistics
Logistics
Challenge
Managing sensitive hardware transport requires real-time coordination, but cloud-based logistics platforms expose location data to foreign entities.
Solution
Sovereign agents monitor IoT sensors on edge devices, re-routing shipments based on threat data and weather, communicating only via encrypted channels.
Read more
Resilient automated logistics that functions intermittently offline and leaks no metadata to third-party providers.
Single Source of Truth for Personnel & Assets
Force Management
Challenge
Personnel records, equipment status and unit rosters live in half a dozen legacy systems that don't agree with each other, so a simple question like "which units have this equipment operational today" takes a manual reconciliation exercise.
Solution
An ontology models personnel, equipment and units as entities once, mapped from every source system, so "this unit" or "this asset" means the same thing everywhere it's referenced.
Read more
Force readiness questions that used to take a data call across multiple systems now resolve instantly against one consistent model.
Export-Control-Aware Engineering Knowledge Assistant
Engineering
Challenge
A defence manufacturer's engineering knowledge is spread across decades of drawings, test reports and specifications, much of it controlled under national export rules, ITAR or EU dual-use regulation. Engineers cannot search it with a public AI tool, and cannot share it across sites without a compliance check.
Solution
A retrieval assistant runs inside the company's own environment, indexes the engineering corpus with its classification and export markings, and answers each engineer only from documents they are cleared and licensed to see.
Read more
Engineers find the precedent in minutes instead of asking around, and every retrieval is logged against the marking that permitted it.
Sub-Tier Supplier Resilience Mapping
Supply Chain
Challenge
Primes know their tier-one suppliers and almost nothing below. A single foundry, a single coating shop or a single source of a rare material can stall a programme, and the dependency is only discovered when it fails.
Solution
Bills of material, purchase orders, supplier declarations and open sources are resolved into one knowledge graph of parts, suppliers, sites and materials, down to the tiers that matter, so single points of failure and foreign-ownership risks are visible before they bite.
Read more
A living map of the programme's real supply base, with concentration and jurisdiction risks ranked, and a defensible answer when the ministry asks about security of supply.
Programme Digital Thread from Requirement to Test Evidence
Programme Management
Challenge
A defence programme's requirements live in one tool, the design in another, the test plans in a third and the results in reports. Proving that a requirement has been verified means a person walking that chain by hand before every milestone review.
Solution
An ontology of requirements, design elements, tests and evidence connects the tools already in use, so verification status is a query over the graph and the gaps are visible continuously rather than at the review.
Read more
Milestone reviews prepared from a live model, every requirement traceable to its evidence, and change impact known the day a requirement moves.
What Defence Industrial Base has to comply with
The regulations that decide whether AI can run on this data at all. Each page lists what the framework asks and which platform controls answer it — properties and refusals, not a checklist.
ISO 27001 · ISO/IEC 27001
Applies to: Any organisation that operates an information security management system — routinely required of software vendors, service providers and regulated enterprises by customers, regulators and procurement.
How the platform supports itCRA · Cyber Resilience Act
Applies to: Manufacturers, importers and distributors of products with digital elements — hardware and software — placed on the EU market, including software vendors and the organisations that build connected products on top of them.
How the platform supports itAI Act · EU AI Act
Applies to: Providers, deployers, importers and distributors placing AI systems on the EU market or whose AI output is used in the EU.
How the platform supports itISO 42001 · ISO/IEC 42001
Applies to: Any organisation that develops, provides or uses AI systems and wants a certifiable management system for doing so responsibly — providers and deployers preparing for the EU AI Act in particular.
How the platform supports it
What these outcomes actually run on
A defence supplier's architect asks how markings are enforced at retrieval, how the digital thread is modelled and whether it runs on a classified programme network. These are the pages that answer those questions.
Enterprise RAG
Retrieval grounded in your ontology, so answers cite the record they came from.
Ontology Based Data Platform
The semantic layer that turns tables into the entities your business talks about.
Sovereign Foundations
The zero-trust foundation the whole platform sits on — the same stack from air-gapped to cloud.
Air-Gapped
The full platform running offline, on networks with no route to the internet.
AI Governance
Policy, data-loss prevention and audit applied to every AI action, with the evidence an assessor can read.
Identity
Federated identity and zero-trust access — for people and for agents, under the same policy.
Frequently asked questions
How does the platform enforce ITAR and EU dual-use export controls on engineering documents?+
Does using an AI assistant on controlled data create an export event?+
Can the platform give us a digital thread without replacing our engineering tools?+
How do we demonstrate security of supply below tier one?+
Can the customer's security authority accredit this?+
Is this only for primes, or also for smaller suppliers?+
Do you partner on tenders and framework contracts?+
Prefer to write? Email hello [at] scrydon.com and we will get back to you.
Keep going
Three routes from here: the rules you will be measured against, the platform these outcomes run on, and the sessions where we walk through them.
The rules that apply
Each regulation, what it asks, and the controls the platform provides for it.
The platform behind it
The AI Operating System, Analytics and Sovereign Foundations, page by page.
Every use case
All of them in one place, grouped by the sector that knows them best.
How – Inside the AI OS: running governed agents on your own cluster, live
17 Sept 2026, 09:00
Part 2 of the Sovereign AI series, for engineers and architects. No slides after minute five: an agent gets an identity and scoped permissions, calls tools over governed MCP, retrieves from the ontology rather than raw tables, runs inside the sandbox and is stopped when it steps outside policy, and everything lands in the audit trail — then the same stack brought up on a disconnected network. Properties and refusals, shown rather than claimed.
Other parts of Defence
The other dedicated pages under Defence, and the sector overview they hang off.
NATO & Allied Interoperability
Coalition operations and exercises: one common picture with per-nation releasability, agents across domains and nations, and lessons that carry from one exercise to the next.
Read the pageDefence Departments & Organisations
Ministries, headquarters and agencies: the defence back office of personnel, logistics, procurement and finance, automated on classified networks with legacy systems wrapped and every decision accountable.
Read the pageDuring Missions
Operations, command and control, ISR and the tactical edge: one common operational picture, a live battlespace twin and multi-domain agents under command approval, on disconnected networks.
Read the page