EnclaveDeck/by Federal AI

One secure AI interface for every mission system.

Investigate, plan, approve, execute, and verify, from one governed workspace.

EnclaveDeck turns fragmented OEM consoles, command lines, and monitoring tools into one governed operator workspace, without sending mission data to a public cloud. The tools stay authoritative. The operator stops being the integration layer.

Delivered by Cleared FDEs No cloud control plane Local models Evidence before action Vendor agnostic
01Observe

Collect cited evidence from authoritative systems.

02Plan

Show the systems, actions, dependencies, and expected result.

03Approve

Expose the operational diff, risk, identity, and rollback.

04Execute

Run a typed, allowlisted action through delegated authority.

05Verify

Prove the intended state with independent product checks.

DeploymentOne instance per security boundary · no cloud control plane
IntegrationAPI → MCP → SDK → SSH/CLI → deterministic browser, in that order
AuthorityLocal policy broker · delegated identity · typed, allowlisted actions
ReleaseSigned offline releases and System Packs · design-partner pilots open
One visible trust loop · simulated

The AI never disappears behind a spinner and says it fixed production.

Operators see what the system observed, how it reasoned, what will change, which identity will act, and how success will be measured.

IL6-SIM · disconnected · local model · read only SIMULATED · public deterministic demonstration
Operator intent · describe the outcome

One mission thread. Every source preserved.

EnclaveDeck selects the systems, builds the evidence chain, and stops before any consequential action.

SIMULATED. This public demonstration is deterministic and simulated. It does not contain customer credentials or control live infrastructure. Private deployments replace simulated adapters with customer-approved System Packs inside the relevant security boundary.
The operating model

Cursor changed how engineers work with code. EnclaveDeck does it for operations.

The operator states the mission outcome. EnclaveDeck selects the authoritative systems, builds a plan, and preserves every source.

AOutcome-first

The operator states the mission outcome. EnclaveDeck selects the authoritative systems, builds a plan, and preserves every source.

BInterface-agnostic

Typed APIs and MCP first, structured SSH and CLI next, and deterministic browser workflows only for the unsupported long tail.

CGoverned by design

The model reasons. A local policy broker authorizes. Deterministic adapters execute. Independent checks verify the resulting state.

System Packs

Deep operating knowledge, not a pile of thin connectors.

Each System Pack teaches EnclaveDeck how an OEM system actually works, versions, interfaces, action schemas, verification, and rollback. Federal AI FDEs build customer-specific Packs for proprietary and legacy systems.

SIEM platform

Foundation
SIEM and observability

Search, correlate, and cite operational evidence through REST API, SDK, and native query language.

Read-first posture; searches are cited into the evidence chain.

Apache NiFi

Foundation
Data flow

Inspect flows, queues, and provenance through the NiFi REST and Registry APIs.

Version-aware Pack with write actions disabled until explicitly approved.

Cisco Infrastructure

Foundation
Network and identity

Interrogate network state through Catalyst Center, RESTCONF, NETCONF, and structured SSH.

Network changes require explicit approval with rollback prepared.

SolarWinds Platform

Foundation
Infrastructure monitoring

Query infrastructure health and history through SWIS, SWQL, and the Orion SDK.

Monitoring remains authoritative; EnclaveDeck correlates, not replaces.

Linux and SSH

Foundation
Host operations

Collect host and service evidence through OpenSSH, Paramiko, and Ansible patterns.

No credential material is inserted into the model prompt.

Custom OEM System

Planned
Proprietary applications

Customer-specific Packs for proprietary and browser-only legacy systems, built by Federal AI FDEs.

Scoped as a forward-deployed integration engagement.
The product shift

Keep the OEM tools. End the swivel-chair workflow.

EnclaveDeck does not pretend the original systems disappear. It makes them feel like one coherent operating environment while preserving native ownership, permissions, and evidence.

DimensionCurrent workflowEnclaveDeck
Starting pointOpen the first OEM consoleDescribe the mission outcome
ContextReconstructed manually across toolsAssembled from authoritative sources
Change reviewCommands, screenshots, and ticketsOne exact cross-system operational diff
AuthorityVaries by tool and operator habitLocal policy plus delegated identity
CompletionCommand returned successfullyExpected state independently verified
EvidenceCopied into a ticket after the workCaptured as the work occurs
Air-gap native

Security is the architecture, not a deployment checkbox.

Each security boundary receives its own EnclaveDeck instance, model endpoint, policy, evidence ledger, and approved System Packs. Movement between domains remains the responsibility of the customer's accredited cross-domain process.

, No required outbound telemetry

Production deployments do not require a public-cloud control plane.

, Delegated identity

Customer identity, role-based access, and local credential brokerage remain authoritative. No hidden superuser layer.

, Policy separate from reasoning

The model recommends. A local policy broker authorizes. The model is never the security boundary.

, Signed offline releases

Signed releases and System Packs move through the customer's approved software-movement controls.

, Local model routing

Locally approved inference and customer-owned storage, inside the boundary.

Public product boundary

EnclaveDeck is designed to integrate with the customer's approved identity, policy, vault, logging, and software-movement controls. This site does not claim any accreditation, authorization, cross-domain capability, or OEM endorsement. Autonomy is granted per action class and environment, approval-gated execution, typed actions, deterministic adapters, and independent verification.

Design-partner pilot

Give us one painful workflow and the systems inside the boundary.

We will map the current cycle time, build the first read-only mission thread, and prove whether one operator can reach a cited answer materially faster. Need the last mile built? Add a Federal AI FDE deployment team.