Signed, inventoried artifacts
Every container, model and configuration is signed with a software bill of materials, verifiable offline on the receiving side before anything is installed.
Continuous Delivery & Fleet Assurance
Ship to the high side without shipping the risk
Capability that cannot be updated becomes a liability within a year. CONDUIT makes delivery into classified and disconnected environments routine: artifacts are signed and inventoried, policy gates run before anything is promoted, rollouts are staged, and rollback is one step rather than an incident.
Signed
Every artifact, verified offline
Staged
Ring-based fleet promotion
One step
Rollback to last known good
Full
Version and patch visibility
Capabilities
Every container, model and configuration is signed with a software bill of materials, verifiable offline on the receiving side before anything is installed.
Vulnerability thresholds, evaluation results, configuration policy and change approvals are enforced as gates, not as a checklist someone completes afterwards.
| Ring | Scope | Version | Health | Progress | State |
|---|---|---|---|---|---|
| Ring 0 | Integration | 2026.8.3 | COMPLETE | ||
| Ring 1 | Controlled environments | 2026.8.3 | COMPLETE | ||
| Ring 2 | High-side | 2026.8.3 | PROMOTING | ||
| Ring 3 | Deployed nodes (18) | 2026.8.2 | AWAITING RING 2 | ||
| Ring 4 | Air-gapped | 2026.8.1 | SCHEDULED |
Promotion is health-gated. Ring 3 cannot start while Ring 2 is mid-promotion, and any degradation against service objectives holds the rollout automatically rather than waiting for someone to notice.
Promote by ring across environments and edge nodes, watch health as it goes, and hold or reverse automatically when service objectives degrade.
Know the exact version, configuration, patch state and health of every environment and every deployed node, including nodes that have been offline for days.
| Gate | Requirement | Result | Blocking | Evidence |
|---|---|---|---|---|
| Artifact signing | All artifacts signed and attested | PASS | Yes | Signature chain |
| Bill of materials | Complete SBOM, resolvable offline | PASS | Yes | SBOM manifest |
| Vulnerability | No unmitigated high severity | PASS | Yes | Scan report |
| Model evaluation | No regression beyond threshold | PASS | Yes | Evaluation run |
| Configuration policy | Policy-as-code checks satisfied | PASS | Yes | Policy report |
| Change approval | Named approver recorded | PASS | Yes | Approval record |
Gates block, they do not warn. A failing gate stops promotion for every downstream ring, including deployed nodes that will not reconnect for days — because a bad update on an unreachable node is the expensive kind.
Deploys where you work
CONDUIT runs identically in commercial cloud, sovereign cloud, on-premises, high-side and fully air-gapped estates, and degrades predictably at the tactical edge.
Works with
PLINTIR BASTION
Accredited Sovereign & High-Side Hosting
Runs the suite in sovereign cloud, on-premises, high-side and air-gapped environments with separate key hierarchies, zero-trust controls and an accreditation path already walked.
Explore
PLINTIR OUTPOST
Tactical Edge Intelligence
Runs the mission picture, local search and on-device inference on a disconnected field node for days, then synchronises safely — surfacing conflicts instead of silently overwriting them.
Explore
PLINTIR NEXUS
Intelligence Data Fabric & Mission Ontology
Connects classified, legacy, streaming and geospatial sources into one governed mission model, so analysts stop reconciling spreadsheets and start answering questions.
Explore
Next step
We run briefings on a real mission problem you bring, not a scripted demonstration. Bring the question your analysts cannot currently answer.