// Command & Control · Audited & sovereign

On the record. Inside your borders.

A command-and-control platform is only as trustworthy as its evidence. Innfini writes every signal, recommendation, approval and dispatch to a tamper-evident ledger with the actor, the time and the originating evidence — and runs wherever your data is required to stay: sovereign cloud, private cloud or a fully air-gapped site with no outbound calls.

Chained
Append-only audit ledger
8
Frameworks mapped
0
Outbound calls, air-gapped
CJIS-ready NIST 800-53 ISO 27001 SOC 2 Type II Air-gap deployable
// The audit ledger

How a decision becomes evidence.

Four stages, one immutable record. Each entry carries who, when, on what basis — and is hashed against the entry before it, so any alteration breaks the chain and is visible immediately.

01 · Signal

Captured with provenance

A sensor reading, a camera detection, a call or a CAD event enters the platform with its source, timestamp and integrity hash intact.

  • Source system and device identity
  • Original timestamp, not ingest time
  • Media hashed on arrival
02 · Recommendation

Explained, not just scored

The agent's recommendation cites the sensors, thresholds, SOP and precedent it derives from, with a confidence value. Nothing acts on an unexplained score.

  • Cited signals and rules
  • SOP version referenced
  • Confidence recorded
03 · Decision

A named human, or a named policy

Approve, reject, modify, escalate — every choice is written with the operator's identity and role. Where auto-execution is enabled, the authorising policy and its approver are named instead.

  • Actor, role and session
  • Rejections recorded, with reason
  • Auto-action scoped and time-boxed
04 · Action & outcome

Executed, acknowledged, closed

Dispatches, notifications and integrations write their acknowledgements back to the same record, so the after-action report is assembled from the ledger — not reconstructed from memory.

  • Field acknowledgements
  • Closure with outcome code
  • After-action report same shift
// Authority

Who may do what — enforced server-side.

Least privilege by default, role-based and attribute-based, with hardware-key MFA for administrative actions. The roles below are a public-safety configuration; the model is the same in defense, infrastructure and port deployments.

RoleOwnsCan act onCannot
Call takerIntake, triage, caller contactOpen and classify incidents, attach evidence, set initial severityDispatch units or override AI severity
DispatcherUnit assignment and statusApprove or reject AI recommendations, assign and recall units, run SOPsChange policy thresholds or close an audited incident
Shift supervisorOperational tempo, escalationEscalate tiers, reassign across beats, authorise mutual aidAlter the audit trail or export restricted evidence
CommanderWhole-of-operation postureDeclare major incident, set auto-execution thresholds, brief agenciesAct alone — all such actions are co-signed
ObserverOversightRead-only situational access for oversight bodies and ministriesHold any operational authority
Break-glass

Emergency access outside a role's normal scope is possible — it alarms immediately, is written to the ledger with the justification given, and is reviewed after the shift. There is no silent override.

// Evidence

Chain of custody, by design.

Video, telemetry and documents attached to an incident are treated as evidence from the moment they arrive, so what a court, a regulator or an internal review sees is what the operator saw.

Integrity

Hash verification

Every media file and telemetry batch is hashed on arrival and re-verified on export. A mismatch is surfaced, never silently passed through.

Retention

Per-jurisdiction schedules

Retention and deletion rules are configured per jurisdiction and per evidence class, with legal hold that suspends deletion for named incidents.

Access

Every view is logged

Opening, playing or exporting evidence is itself a ledger entry. Restricted evidence needs an authorised role and a recorded purpose to leave the system.

// Sovereignty

Runs where the data must stay.

The same platform, the same runtime, the same audit ledger — in three deployment postures. Choose by the rules you operate under, not by what the software can do.

Posture 1

Sovereign cloud

Government-grade regions with no foreign-vendor access to customer data.

  • RegionsAWS GovCloud, Azure Government, sovereign providers in MENA and APAC
  • ResidencyData, backups and telemetry pinned to the region; export is customer-controlled
  • KeysCustomer-managed encryption keys
  • IdentityYour SSO (SAML / OIDC), SCIM provisioning, your SIEM
Posture 2

Private cloud

Dedicated tenancy inside your own cloud subscription or hosting partner.

  • IsolationSingle-tenant, your VNET / VPC, your perimeter controls
  • KeysCustomer-managed keys; HSM-backed custody where required
  • UpdatesSigned releases on your change window
  • OversightFull ledger and SIEM forwarding under your control
Posture 3

Air-gapped on-premises

Full Innfini stack on customer-owned Kubernetes, with no phone-home and no external dependencies.

  • ClusterRKE, EKS Anywhere, OpenShift or AKS-HCI — bare metal or hypervisor
  • AIInnfini LLMs and ML run locally; no hosted-model fallback
  • CryptoHSM-backed key custody, FIPS 140-2 Level 3; mTLS between every service
  • UpdatesCryptographically signed bundles via air-gap media, offline licence validation
  • SupportForward-deployed engineers on site; remote assist only via approved channels
Operates degraded

When a site loses connectivity, edge nodes keep deciding. Decisions are written to the local ledger and reconciled on reconnect — the chain stays continuous across the outage.

// Compliance

Mapped to the frameworks your auditors use.

Status is stated plainly. Where an assessment is still in progress, it says so.

Law enforcement

CJIS

CJIS-ready security posture for criminal-justice data. Used by Dubai Police force-wide.

Ready posture
Federal baseline

NIST SP 800-53

Control mapping across access, audit and accountability, configuration and incident response. Documented baseline for federal-grade deployments.

Controls mapped
US federal cloud

FedRAMP Moderate

Third-party (3PAO) assessment underway for government-cloud authorisation of federal civilian workloads.

Assessment underway
Information security

ISO/IEC 27001

Certified information-security management system across product, infrastructure and operations.

Certified
Service controls

SOC 2 Type II

Annual independent audit with continuous monitoring of security, availability and confidentiality controls.

Audited annually
Health

HIPAA

Health-system deployments run under signed Business Associate Agreements with PHI safeguards and audit trails.

BAA-backed
Privacy

GDPR & CCPA

Regional data-residency controls, with right-to-access and right-to-delete workflows built into the platform.

Built in
Life sciences

21 CFR Part 11

Electronic signatures, audit trails and access controls compliant with FDA Part 11.

Compliant
// Security architecture

The controls behind the claims.

01

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit, mTLS between every internal service. Customer-managed keys for private cloud and on-prem.

02

Identity and access

SSO via SAML / OIDC, SCIM provisioning, role- and attribute-based access control, hardware-key MFA enforced for administrative actions.

03

Audit and provenance

Every operator action, agentic decision and data access on a tamper-evident ledger. Decision rationale traceable end to end.

04

Vulnerability management

Continuous SAST, DAST and SCA. Quarterly third-party penetration testing and a coordinated-disclosure programme with researcher rewards.

05

Incident response

24/7 SOC on a follow-the-sun rotation, documented runbooks, customer notification within 24 hours of a confirmed material incident.

06

Signed supply chain

Releases are signed; air-gapped sites verify bundles cryptographically before install and validate licences offline.

// For the auditor

What you can take away.

Oversight should not require a data-extraction project. These are standard outputs of the platform.

  1. Incident ledger export — the complete chained record for any incident or time window, with hash verification, in machine-readable and printable form.
  2. After-action report — assembled from the ledger the same shift: timeline, signals, recommendations, decisions, actors, outcomes.
  3. Evidence pack — media and telemetry with custody trail, verified hashes and the access log for each item.
  4. Observer access — read-only situational access for oversight bodies, with no operational authority and its own audit trail.
  5. Control evidence — SIEM forwarding, access reviews and configuration baselines aligned to NIST 800-53 and ISO 27001 programmes.
ControlImplementation
Immutable audit logAppend-only, cryptographically chained. Actor, timestamp and originating evidence on every entry.
Explainable AIEach recommendation cites its sensors, thresholds, SOP and precedent, with a confidence value.
Human accountabilityAuto-execution opt-in per action type, scoped and time-boxed; the authorising policy and approver stay named.
Role-based accessLeast privilege, enforced server-side. Break-glass alarms immediately and is reviewed.
Data protectionEncryption in transit and at rest, customer key custody, per-jurisdiction residency and retention.

Audited and sovereign is not a feature toggle. It is the way Innfini is built — the same ledger, the same roles and the same controls whether it runs in a government cloud, your own data centre or a site that has never seen the internet.

Bring your auditors to the demo.

A walkthrough of the ledger, the roles and the deployment posture that fits your jurisdiction — with your security team in the room.