What is an Air-Gap?

An air-gap is a security measure that physically isolates a computer or network from unsecured networks, including the internet. It's the only way to guarantee that data cannot be accessed remotely.

THE PRINCIPLE

No Cable, No Connection, No Access

The term "air-gap" refers to the physical gap of air between a secure system and any network connection. If there's no cable connecting the system to the internet, there's no way for remote attackers—or foreign courts—to access the data.

This isn't a software firewall. This isn't a VPN. This isn't encryption (though we use that too). This is the physical absence of a network connection.

You cannot hack what you cannot reach.

Why Air-Gap Matters for Data Sovereignty

1

Immune to Remote Attacks

Ransomware, nation-state hackers, zero-day exploits—none of these matter if the system has no network connection.

2

Immune to Legal Compulsion

The CLOUD Act allows US courts to compel American companies to produce data. But they can only compel access to data they can reach.

3

Verifiable Security

With cloud services, you trust the provider's claims. With an air-gapped system, you can physically verify that no network cable is connected.

4

Complete Audit Trail

All data that enters or leaves an air-gapped system must be physically transferred, creating an inherent audit trail.

How Air-Gap Works in Practice

An air-gapped AI system like the Tacitus Cortex requires thoughtful workflows for data transfer.

Data Ingestion

1

Documents are collected on a secure workstation and copied to an encrypted USB drive.

2

The USB drive is physically carried to the Cortex and inserted.

3

The Cortex scans, verifies, and ingests the documents.

Software Updates ("Supply Drop")

Without internet access, updates are delivered via signed packages on encrypted USB drives.

Security Beyond the Air-Gap

The air-gap is the foundation, but the Cortex includes multiple additional security layers:

Encryption at Rest

All data stored on the Cortex is encrypted with AES-256.

TPM 2.0

Hardware-based key storage and boot-time integrity verification.

RAID Storage

Mirrored drives ensure data survives hardware failure.

Common Questions

Isn't this inconvenient compared to cloud?

There's a trade-off. Cloud is more convenient; air-gap is more secure. For most document workflows, the extra step of USB transfer is minimal.

What about AI model updates?

Model updates are part of the Supply Drop system. When better AI models become available, we package them into signed update bundles.

What if I need something less extreme?

That's what Cloud Bridge is for. It provides jurisdictional sovereignty without the operational overhead of an air-gapped system.

Ready for Maximum Security?

The Cortex brings air-gapped AI infrastructure to your server room.