Salian Defense
INITIATING SECURE CHANNEL
SALIAN DEFENSE
I
THRESHOLD
SESSION
PUBLIC
CHANNEL
TLS 1.3 · ENCRYPTED
DEPTH · ADVANCE
0000.00 M
PROGRESS
HEAD BEARING
000.0°
CREDENTIALS
SDVOSB · CAGE 18SG4
PRACTICE
FACILITIES · SOFTWARE · INTEGRATION
LOCAL TIME
00:00
I.ENTRY

SALIAN
DEFENSE

Custodes Ancilium

You stay on the mission. We build and accredit the secure facility it runs in, and we engineer the air-gapped software built to run inside it. End to end. Cleared. Turnkey.

SDVOSB · ICD-705 · NIST 800-53 · CMMC 2.0 READY · CAGE 18SG4
HUD ANALYSIS · ARTIFACT 02 EXTRACTING
II.SECURE FACILITIES

Your SCIF.
Built and accredited.

A specificatione ad operationem

Come with nothing: no clearance, no site, no drawings. We carry the whole path. One team. One contract.

Scope your facility
// Capability · Vault

No prior cleared posture required. We sponsor and walk the facility clearance (FCL) process with you, from the SF-328 through the DCSA review, so a first-time entrant can stand up cleared work on a credible timeline.

Email us about FCL sponsorship ▸

We build all of it to ICD-705 and the current technical specifications (TSPM): SCIFs, SAPFs, and closed areas. Fixed, mobile, or modular, set wherever the mission is. We work to whatever contract vehicle and billing structure fits the program: fixed-price, cost-reimbursable, time-and-materials, or other. You see the scope before the first wall goes up.

Email us about a build ▸

Shielding designed, installed, and verified by measurement against the attenuation your accreditation requires. We hand you the test results, not a promise.

Email us about RF and TEMPEST ▸

We assemble the accreditation evidence and stay in the room for the review. The package is built to be defensible, and we present it with you rather than handing you a binder and stepping back.

Email us about accreditation ▸

Accreditation is a beginning, not an end. We stay on for re-inspections, configuration changes, and the day-to-day that keeps a facility in good standing for the life of the program.

Email us about sustainment ▸

We engage from a blank site or step into a failed or partially built effort. Recovering stalled projects is not a favor we do reluctantly. It is a specialty.

Email us about a rescue ▸

Where scope allows, we have reached occupancy in roughly four to six months against an industry norm of twelve to twenty-four. Your timeline depends on starting posture. We scope it honestly, then commit to a date we can hold.

Scope your timeline ▸
III.MISSION SOFTWARE

Software that
runs offline.

Six products · one architecture · three profiles

Six products. One architecture. Three deployment profiles: hosted and unclassified, CUI-safe on your own infrastructure, or fully air-gapped inside accredited space. The air-gapped profile makes no outbound call. Ever. Only metadata crosses a boundary, never controlled content, and every pass-or-fail verdict is deterministic code with an immutable audit trail rather than a model's opinion. Accreditation is granted per system by the sponsoring authority, and the Suite ships with the evidence package that process requires.

// Suite · Praesidium

Ask it what a secure facility costs and it answers in minutes instead of weeks. Vates Cognition turns a short program intake into a defensible budgetary Rough Order of Magnitude for SCIF and secure-facility work, and the range tightens with every answer you give it. It runs on your own hardware: the model, its weights, and every inference trace stay inside your boundary. Built for program offices sizing a budget line, security officers and ISSMs testing whether a build is affordable at all, capture teams qualifying a pursuit before they write to it, and primes pressure-testing a number before they bid it. The estimator is live on this site, free to use.

Try the Project Estimator ▸

Hand Groma a PDF floor plan, a point-cloud scan, or a paragraph describing what you need, and it builds the model. It authors an IFC4 model, renders a dimensioned 2D plan and a navigable 3D walkthrough that runs fully air-gapped, then grades the design against ICD-705: buildingSMART IDS 1.0 plus nine deterministic checks, from wall layering and slab-to-slab continuity to alarm response class and Fixed Facility Checklist completeness. Run it forward and it designs instead: a constraint solver places the layout on a fixed seed, authors the model, and prices it as a ranged AACE-classed estimate. Out comes the engineer handoff package, from gap analysis and Construction Security Plan draft to quantity takeoff, annotated DXF, and zone diagram. The rulebook is data, not code. Rulesets, cost tables, and report manifests register per facility type and dispatch fail-loud, never falling back to the wrong domain, so the same engine reaches past accredited space into other regulated builds, and takes on a new domain by registering a ruleset rather than by rewriting the engine. Built for FSOs, the technical staff behind an Accrediting Official, architects and engineers, design-build contractors, and program offices. Reach for it to walk a space before you build it, triage a facility someone else stalled, or put a defensible layout and number behind a funding request. The verdict is deterministic code, never a model’s opinion; every artifact is a ratifiable draft, and the Accrediting Official’s determination stays non-delegable.

Email us about Groma ▸

Legatus is what an AI agent looks like when it has to work inside accredited space. It takes an analyst’s intent, decomposes it into a multi-step workflow, drives models and tools through a controlled registry, and stops at a human signature before any sensitive action. Classification is a first-class type here, not a label bolted on: a four-tuple of level, compartments, dissemination, and originator rides every state transition, and the graph compiler refuses to build a workflow whose ceiling sits below a state that workflow can actually reach. It fails closed at compile time instead of leaking at run time. Identity, policy, audit, and inference all run self-hosted with no calls home, and every approval lands as a signature in a write-once store. Built to the control set for DoD Impact Levels IL4 through IL6; accreditation at a given Impact Level is granted per system by the sponsoring authority. All seven engineering phases are complete and the product ships today. Built for intelligence and defense analysts working inside the fence, ISSMs, RMF and ATO teams, and program security. Reach for it when a workflow is valuable enough to automate but an unsupervised action would be unacceptable: mapping control requirements to live evidence, drafting an accreditation narrative against sensitive scan output, or taking a task from an outside system where only signed proof, never content, crosses the boundary.

Email us about Legatus ▸

Your people are going to use AI. Vigil decides what it is allowed to see. It sits inline between the application and the model, inspects the request in the path, and enforces allow, redact, or block before anything reaches the far side. Not a dashboard and not a log to read on Monday: an enforcement point that acts. Verdicts are content-free by construction, and a sensitive-content wrapper refuses to serialize raw material into logs, tracebacks, or crash dumps, so the security layer never becomes the leak. Detection is deterministic across identifiers, payment numbers, cloud access keys, and private keys, behind a policy engine that runs advisory or enforcing. It is an embedded provider behind a vendor-neutral interface, so it drops into an application without becoming another system to run. Built for ISSMs, CISOs, and program security officers carrying CUI or CMMC obligations who want their people to have AI without the exposure. Reach for it when a team wants a commercial model but controlled content must never reach it, or when an assessor wants to see policy enforced in the path rather than audited after the fact.

Email us about Vigil ▸

Most retrieval finds paragraphs that mention your topic. Hawk RAG connects them. Ask which agencies issue task orders under a given vehicle that touch a given technology, and plain vector search returns three unrelated hits; Hawk RAG walks the relationship. It runs semantic search, a knowledge graph traversed by recursive query, and a lexical full-text path, then fuses all three by reciprocal rank so contract numbers and program names survive alongside meaning. One inexpensive routing call decides which paths a question actually needs, so the expensive retrieval only runs where it earns its cost. It is the retrieval layer the whole portfolio shares, and the clearest proof of the one-architecture claim: the same package runs hosted behind RFI Hawk and Water Hawk, CUI-safe on customer infrastructure behind Project Hawk, and inside the accreditation boundary as an internal service that Legatus queries through its controlled tool registry under a CUI ceiling. In that third profile it is never a hosted service and never calls out on its own, because it ships no vendor AI model SDK: the operator chooses the model at deploy time, including a local one. Multi-tenant with row-level isolation and per-tenant budgets. Built for analysts working across large procurement, regulatory, and program corpora, and teams building on any product in the portfolio. Reach for it when the question is relational rather than factual and the answer lives between documents instead of inside one. In production across the portfolio.

Email us about Hawk RAG ▸

Some of the most critical equipment in the country cannot take an agent. Turbines, relays, controllers, the vendor-locked boxes running processes nobody may interrupt: no patch, no software, no re-certification. Pythian encrypts those links anyway. FPGA-based encryption that installs inline as an appliance between devices, so it needs no code changes, no operating-system modification, and nothing on the endpoint. Sub-millisecond added latency, per manufacturer specification. Built for operators of critical infrastructure and industrial control systems, utilities, and programs running equipment that will never accept software. Reach for it when the segment you need to protect is full of legacy or vendor-locked devices, or when adding encryption in software would break a validated configuration you are not permitted to change. Pythian is a partner technology available to Salian under a white-label arrangement; Salian integrates and delivers it rather than manufacturing it. Validation status, form factor, and supply-chain provenance are provided under NDA against a specific requirement.

Email us about Pythian ▸
IV.ENGINEERING

Tell us what you need.
We build it for you.

Ad mensuram

Off-the-shelf software assumes the internet. Inside an accredited or air-gapped facility, that assumption breaks. So we build to your environment instead of asking you to bend to ours. You describe the mission. We engineer the tool.

> salian build --to-spec
  [ok] environment scoped
  [ok] evidence packaged
> salian status
  operational
// How we build

We start with the mission and the constraints, not a product demo. You tell us what the tool has to do and where it has to live. We tell you what it takes.

Email us what you're building ▸

On-prem, fully air-gapped, or cloud-connected where authorized. We build for the boundary you actually operate in, including environments with no outbound network at all.

Email us about your environment ▸

Software for accredited spaces is only finished when the paperwork is. We deliver the accreditation evidence alongside the build so it can pass review, not just run.

Email us about accreditation evidence ▸

We stay on after delivery. Updates, fixes, and changes happen on your schedule and inside your boundary, for the life of the program.

Email us about long-term support ▸

For air-gapped work we build a high-fidelity twin of your enclave and prove the baseline on the unclassified side at full speed. Once it is known-good, it transfers across the boundary. Your team keeps its collaboration on the networked mirror, and protected content never crosses.

Email us about the digital twin ▸
V.OUR NAME

Keepers of
the shields.

Unum inter duodecim

The Salii were the warrior-priests of Mars, charged with a sacred duty: to guard the shields of Rome. Chief among them the ancile, said to have fallen from the sky as a sign Rome would endure. To keep it from being stolen, eleven identical copies were forged: twelve shields in all, indistinguishable, so no enemy could ever single out the true one. You cannot steal what you cannot single out.

The Salii never marched to war. Their duty was to keep the shields ready, so those who did could prevail. That is ours. We don't run your mission. We arm it: the accredited facilities, the air-gapped software, the cleared engineering the work demands. You do what you do best, and we make sure you are outfitted to accomplish it. We are the armorer. The mission is yours.

// The unit

The people who build and accredit your space are cleared before they begin. The standard is the entry condition, not the goal.

We measure ourselves on facilities that pass and dates that hold. The proof is the delivery record, not the pitch.

The Salii were chosen for the duty, not the reward. We hire the same way. If that sounds like you, the door is open.

Join the unit ▸

Our mark is a shield set against the spear of Mars. Look at it straight on and it reads as a shield: something held, something defended. Turn it on its side and the same form becomes an eye, open and watching. That second reading is deliberate. Our founder came up inside the intelligence community, building the machine-learning systems and sensor platforms behind the work people call the eye in the sky. The mark carries both halves: the shield that protects, and the eye that sees.

VI.AFFILIATED VENTURES

Built to scratch
our own itch.

Porta Avium

Each of these started as a problem we hit doing the core work and solved properly instead of working around. They run on the architecture the Praesidium Suite runs on, which is the whole point of showing them to you: this is that architecture working in the open, where you can go look at it. Hosted, CUI-safe, air-gapped. One codebase, three profiles.

They are separate ventures, not a product line, and you can buy one without buying anything else from us. We list them here because the fastest way to judge how we build is to use something we built.

Try RFI Hawk
// Ventures

Finds live federal RFIs across SAM.gov, GSA, and agency portals, then helps you answer them properly. It reads the requirement behind the notice rather than matching keywords, and drafts against what the government actually asked for. Built for capture teams and small businesses who cannot staff a full-time search. Reach for it when the pipeline problem is finding the right notice early enough to do something about it. Hosted and unclassified; there is a free tier.

Open RFI Hawk ▸

Scores every public water system in the United States on chemical-supplier exposure and discharge posture, from public sources only. The output is a decision-grade brief, not a dashboard to interpret. Built for utilities, regulators, insurers, and anyone underwriting infrastructure risk. Reach for it when you need to know which systems are exposed and why, and you need the reasoning to survive scrutiny.

Open Water Hawk ▸

Turns staying compliant into something continuous instead of something you rediscover before an assessment. It maps your obligations, tracks the evidence behind each one, and flags drift before an assessor would, without ever touching your controlled content. This is the CUI-safe profile of the shared architecture: it runs on your infrastructure, at your boundary. Built for ISSMs, FSOs, and anyone carrying a CMMC or NIST obligation. Reach for it when the evidence exists but nobody can prove it on demand.

Open Project Hawk ▸

All three sit on Hawk RAG, the retrieval layer described in the Praesidium section. That is what makes the ventures worth pointing at: the same package runs hosted behind RFI Hawk and Water Hawk, CUI-safe on customer infrastructure behind Project Hawk, and inside the accreditation boundary as a service Legatus queries under a CUI ceiling. One architecture at all three profiles, and two of the three are running in public where you can check.

VII.CONTACT

Initiate a secure channel.

Tuti · Probati · Electi

Tell us what you're protecting. We'll tell you how we'd approach it and what it takes. Typical response in one business day.

DIRECT LINE · contact@saliandefense.com
CALL · (202) 753-9835
SALIAN DEFENSE · SDVOSB · CAGE 18SG4
VIEW FULL CAPABILITIES STATEMENT ▸
PROJECT HAWK · COMPLIANCE, AUTOMATED
Compliance that watches itself. It maps your obligations, tracks the evidence, and flags drift before an assessor would, without ever touching your controlled content.
SEE PROJECT HAWK ▸
GROMA · FACILITY DESIGN, AUTOMATED · PRAESIDIUM SUITE
From a short program intake, Groma drafts the facility package: a budgetary ROM, an ICD-705 layout concept, initial drawings, a bill of materials, and construction and security plan drafts. In reverse, it checks an as-designed or as-built model against the closed-storage requirement set and returns a gap report. Every output is a draft a person ratifies. It never touches classified or controlled content.
SECURE FACILITY RESOURCES
MORE FROM US
Three ventures, one architecture, demonstrated at all three deployment profiles: RFI Hawk hosted, Project Hawk CUI-safe on your own infrastructure, Legatus fully air-gapped.
INVESTOR MATERIALS
REVIEW & SIGN NDA TO ACCESS ▸
// COMMON QUESTIONS

Answered.

The company
What does Salian Defense do?
Salian Defense delivers turnkey accredited secure facilities to ICD-705 (facility clearance sponsorship, design, construction, accreditation, and ongoing sustainment under a single contract) and engineers air-gapped mission software (the Praesidium Suite) for those environments.
Is Salian Defense SDVOSB?
Yes. Salian Defense is a service-disabled veteran-owned small business (SDVOSB), verified through SBA VetCert. Eligible for SDVOSB set-asides, sole-source awards under threshold, and joint-venture / mentor-protégé arrangements.
How do I engage Salian Defense, and what are its identifiers?
Open a secure channel via contact@saliandefense.com or use the contact form at the end of the site. We respond within one business day. Salian Defense, Inc. is a service-disabled veteran-owned small business; CAGE 18SG4. We engage by firm-fixed-price, time-and-materials, milestone and deliverable, subscription access to accredited space and software, software licensing, or as a subcontractor or teaming partner under a prime, including IDIQ and task-order execution.
Does Salian Defense self-perform its work, or deliver through partners?
Both, by design. Salian delivers directly where it holds the capability and orchestrates a vetted network of cleared partners, licensed trades, and qualified suppliers everywhere else, always under one Salian contract, one schedule, and one accountable line. Scope is never limited to in-house headcount: anything a qualified partner can deliver, Salian can deliver, and Salian answers for the result. The client manages one relationship from initial engagement through accreditation and sustainment.
What ventures does Salian Defense run alongside the core facility business?
Salian operates the Praesidium Suite of air-gapped mission software (Pythian, Vates Cognition, Vigil, Legatus) and Project Hawk for continuous compliance automation. The team has also built RFI Hawk for federal opportunity discovery and proposal support, and Water Hawk for critical water infrastructure intelligence.
Facilities and accreditation
What standards does Salian Defense build secure facilities to?
Accredited secure facilities are delivered to ICD-705 and the associated technical specifications (TSPM), with the security plan mapped to NIST SP 800-53 and aligned to CMMC 2.0 readiness for cleared industry. We also handle facility clearance (FCL) sponsorship for entrants with no prior cleared posture.
Does Salian Defense handle modular or mobile SCIFs?
Yes. Salian coordinates vault-grade modular SCIFs, mobile and CONEX-based units, container SCIF leasing, and portable enclosures when the mission profile calls for them. We either build to ICD-705 directly or coordinate qualified suppliers under one accountable line, one schedule, and one contract.
How fast can Salian Defense reach SCIF occupancy?
Where scope allows, Salian has reached occupancy in four to six months, against an industry norm of twelve to twenty-four. Timeline depends on starting posture; Salian scopes honestly, then commits to a date it can hold.
How much does a SCIF cost to build?
There is no honest flat number. The real drivers are size, starting posture (new build, retrofit of existing space, or rescue of a stalled project), RF and acoustic requirements, region, and schedule. Salian publishes Vates Cognition, a free budgetary estimator at saliandefense.com/vates.html that returns a Rough Order of Magnitude range from a short intake, before any commitment. For a firm figure, write contact@saliandefense.com and we scope it honestly.
Does Salian Defense provide outsourced FSO, CSSO, or ITPSO support?
Yes. Salian provides co-employed Facility Security Officer (FSO), Contractor Special Security Officer (CSSO), and Insider Threat Program Senior Official (ITPSO) services through a cleared captive partner, with UL 2050 and UL 1076 specification, FOCI mitigation, ITAR/EAR advisory, and physical security engineering.
Does Salian Defense stand up and run industrial security programs?
Yes. Salian creates, maintains, and self-inspects NISP and NISPOM industrial security programs and prepares clients for DCSA security reviews under 32 CFR Part 117. We provide Facility Security Officer (FSO) support, personnel and facility clearance administration, Key Management Personnel coverage, and cleared staff augmentation sized to the program, plus counterintelligence, insider threat program development, technical surveillance countermeasures (TSCM), and FOCI mitigation.
Software and AI
What is the Praesidium Suite?
The Praesidium Suite is Salian Defense's line of six software products that share one architecture, built so the same system can run hosted and unclassified, on customer infrastructure at a CUI boundary, or fully air-gapped inside accredited space. Accreditation is granted per system and per site by the sponsoring authority; the Suite ships with the evidence package that process requires. The six are Vates Cognition (on-premise estimating and analysis; the free estimator is live on the site), Groma (ingests plans, renders 2D and 3D, and grades designs against ICD-705), Legatus (agentic workflows with human-signed approval, air-gapped), Vigil (inline AI security enforcing allow, redact, or block at the model boundary), Hawk RAG (the retrieval layer shared across the suite and the ventures, running in all three deployment profiles; in production), and Pythian (inline FPGA-based hardware encryption for operational-technology networks; a partner technology available to Salian under a white-label arrangement).
How does Salian Defense build software for air-gapped environments?
Salian builds a high-fidelity digital twin of the target classified enclave and runs engineering, configuration, validation, and dry runs on the unclassified, networked side at full speed. Once the baseline is proven, it transfers into the air-gapped environment as known-good work. The Praesidium platform is built to run fully offline, with no outbound network traffic, no software-as-a-service in the runtime path, and no telemetry leaving the building.
What software can run inside a SCIF?
Software can run inside a SCIF if it needs no outbound network connection, ships with the accreditation evidence its reviewing authority requires, and can be installed and updated inside the boundary rather than pulled from a vendor cloud. Most commercial software fails the first condition because it assumes a live internet connection for licensing, updates, or telemetry. Salian engineers the Praesidium Suite to those constraints and also builds bespoke tools to a customer's specific enclave. Accreditation is granted per system and per site by the sponsoring authority; the Suite ships with the evidence package that process requires.
Does the Praesidium Suite work fully air-gapped?
The Praesidium Suite is built so the same architecture runs in three deployment profiles: hosted and unclassified, CUI-safe on customer infrastructure, or fully air-gapped inside accredited space. In the air-gapped profile there is no software-as-a-service in the runtime path, no outbound network traffic, and no telemetry leaving the building. The three affiliated ventures demonstrate the same architecture at each profile: RFI Hawk hosted, Project Hawk CUI-safe on customer infrastructure, Legatus air-gapped. Accreditation is granted per system and per site by the sponsoring authority; the Suite ships with the evidence package that process requires.
How does Salian Defense automate ICD-705 compliance checking?
Groma, a product in the Praesidium Suite, encodes ICD-705 and its implementing technical specification as buildingSMART IDS 1.0 plus nine deterministic geometry and documentation checks, runs them against an as-designed or as-built IFC4 model, and returns a gap report. The pass-or-fail verdict is produced by deterministic code, never by model output: language models read messy inputs and phrase findings, but they never decide compliance. Every result is a draft that a credentialed human reviews and ratifies, and the Accrediting Official's determination remains non-delegable. Groma reasons over business, program, and facility metadata plus public standards, and never touches classified or controlled content. Under development.
What is Groma?
Groma is a spec-aware ICD-705 compliance and design engine in Salian Defense's Praesidium Suite, and it works in both directions. In reverse it reconstructs an IFC4 model from a plain-English description, a structured plan, or a floor-plan image, then checks it against buildingSMART IDS 1.0 plus nine deterministic checks: wall layering, slab-to-slab continuity, duct penetrations, door lock, door acoustic, access-controlled entrance, alarm response class, window treatment, and Fixed Facility Checklist completeness. Forward it solves a layout with a deterministic constraint solver, authors the IFC4 model, and prices it as a ranged AACE-classed estimate. Every output is a ratifiable draft a credentialed human signs off; Groma never decides, accredits, or certifies, and the Accrediting Official's determination is non-delegable. Accreditation is granted per system by the sponsoring authority, and the Suite ships with the evidence package that process requires.
What is Legatus?
Legatus is a workflow orchestrator in Salian Defense's Praesidium Suite that decomposes an analyst's intent into a multi-step workflow, calls models and tools through a controlled registry, and stops at a human for approval before any sensitive action. A classification label travels with every state transition, and the compiler refuses to build a workflow whose step ceiling sits below a state the workflow can actually reach. Legatus is built to the control set for DoD Impact Levels IL4 through IL6; accreditation at a given Impact Level is granted per system by the sponsoring authority.
What is Vigil?
Vigil is an inline AI security layer in Salian Defense's Praesidium Suite that inspects what flows between an application and a language model and enforces allow, redact, or block at that boundary. It sits in the request path and acts on what it finds; it is not monitoring software and it is not telemetry. It is an embedded, swappable provider rather than a standalone application. It ships deployment-profile resolution, content-free scan contracts, a deterministic detector set covering identifiers, payment numbers, cloud access keys, and private keys, an advisory-or-enforce policy engine with allow, redact, and block precedence, and a redaction transformer. Accreditation is granted per system by the sponsoring authority, and the Suite ships with the evidence package that process requires.
How does Salian Defense prevent CUI from reaching an AI model?
Two mechanisms, at different layers. Vigil sits inline between the application and the model and enforces allow, redact, or block on every request, so controlled content is caught in the request path rather than discovered afterward in a log. Separately, every Praesidium product is built around a metadata membrane: products reason over business, program, and facility metadata plus public standards, and controlled content does not enter the pipeline at all. The combination of a public standard and business metadata is what makes the analysis safe to run outside an accredited boundary.
What DoD Impact Levels does Salian Defense software support?
Legatus is built to the control set for DoD Impact Levels IL4 through IL6, and accreditation at a given Impact Level is granted per system by the sponsoring authority. That distinction is deliberate: designed-for describes the control set and architecture the software was built against, while accredited-at describes a determination only an Authorizing Official can make for a specific system in a specific environment. Salian delivers accreditation evidence alongside the software so a reviewing authority can make that determination, but does not claim it on the software's behalf.
SCROLL TO ADVANCE
CLICK to look · WASD to roam · SHIFT to run · ESC to release