H33 authority infrastructure can operate entirely inside classified, disconnected and air-gapped environments — with no runtime dependency on H33.
H33 goes to the enclave; the enclave does not come to H33. In this configuration the authority stack runs inside your boundary: no H33.ai connection, no SaaS dependency, no outbound API, no callback. You own the hardware, the network, the keys, ingress and egress, deployment and policy.
The usual objection is “we don’t permit external APIs into this environment.”
Our answer is not that our API is unusually secure. Our answer is: neither do we.
H33-API-G does not mean an Internet-accessible H33 endpoint. It is an authority protocol that operates locally, inside the enclave, between your own components. Nothing crosses the boundary because nothing needs to.
Your own hardware, HSM or KMS retains key custody. H33 supplies the local authority, governance, proof generation, verification, provenance and evidence machinery — not the secrets, and not a dependency on us.
| Environment | H33 deployment | External H33 dependency |
|---|---|---|
| Commercial / normal federal | Connected | Allowed |
| Classified private network | Enclave-Installed | None required |
| True air gap / tactical edge | Fully Air-Gapped — autonomous node | Zero |
This matches how disconnected, intermittent and low-bandwidth environments actually operate, and it matches Zero Trust: authority comes from attributes and least privilege, never from being inside a network.
H33 does not phone home to update. We publish a signed release package on the outside: code identity, artifact hash, composition identity, policy version, dependency graph, post-quantum signatures and a BIND record.
You control movement through your own approved transfer mechanism. Once it is inside, H33-BIND verifies the exact identity and H33-Root determines whether that artifact is authorized. Installation happens only if admission succeeds.
The enclave never has to trust the transfer medium to establish software authority. That is a materially different proposition from “download our latest update.”
A sensitive system performs classified computation on classified data and reaches a classified decision. None of that should leave. But you may still need to show that:
The inputs stay inside. The enclave produces cryptographic evidence and, ultimately, a compact H33-74 attestation representing the governed event — instead of exporting logs, telemetry and internal state.
H33 does not require outbound connectivity, DNS, or reachability to h33.ai.
H33 does not receive, escrow, or hold your key material. Custody stays in your HSM, KMS or enclave.
Your system does not call us to make a decision. Authority is resolved locally.
H33 does not phone home to validate entitlement or to keep operating.
Admission does not depend on how an update arrived. It depends on whether BIND and Root admit its identity.
H33 does supply the mechanism proving only authorized computation, software, identities and actions can produce accepted outcomes — inside your boundary.
The government owns the hardware. The government owns the network. The government controls the keys, ingress and egress, deployment and policy.
H33 is not another security SaaS product to be admitted into a classified environment. It is the authority mechanism that operates entirely inside the mission boundary.
Discuss an air-gapped deployment →