// COMMON QUESTIONS
Answered.
The company
What does Salian Defense do?
Salian Defense delivers turnkey accredited secure facilities to ICD-705 (facility clearance sponsorship, design, construction, accreditation, and ongoing sustainment under a single contract) and engineers air-gapped mission software (the Praesidium Suite) for those environments.
Is Salian Defense SDVOSB?
Yes. Salian Defense is a service-disabled veteran-owned small business (SDVOSB), verified through SBA VetCert. Eligible for SDVOSB set-asides, sole-source awards under threshold, and joint-venture / mentor-protégé arrangements.
How do I engage Salian Defense, and what are its identifiers?
Open a secure channel via contact@saliandefense.com or use the contact form at the end of the site. We respond within one business day. Salian Defense, Inc. is a service-disabled veteran-owned small business; CAGE 18SG4. We engage by firm-fixed-price, time-and-materials, milestone and deliverable, subscription access to accredited space and software, software licensing, or as a subcontractor or teaming partner under a prime, including IDIQ and task-order execution.
Does Salian Defense self-perform its work, or deliver through partners?
Both, by design. Salian delivers directly where it holds the capability and orchestrates a vetted network of cleared partners, licensed trades, and qualified suppliers everywhere else, always under one Salian contract, one schedule, and one accountable line. Scope is never limited to in-house headcount: anything a qualified partner can deliver, Salian can deliver, and Salian answers for the result. The client manages one relationship from initial engagement through accreditation and sustainment.
What ventures does Salian Defense run alongside the core facility business?
Salian operates the Praesidium Suite of air-gapped mission software (Pythian, Vates Cognition, Vigil, Legatus) and Project Hawk for continuous compliance automation. The team has also built RFI Hawk for federal opportunity discovery and proposal support, and Water Hawk for critical water infrastructure intelligence.
Facilities and accreditation
What standards does Salian Defense build secure facilities to?
Accredited secure facilities are delivered to ICD-705 and the associated technical specifications (TSPM), with the security plan mapped to NIST SP 800-53 and aligned to CMMC 2.0 readiness for cleared industry. We also handle facility clearance (FCL) sponsorship for entrants with no prior cleared posture.
Does Salian Defense handle modular or mobile SCIFs?
Yes. Salian coordinates vault-grade modular SCIFs, mobile and CONEX-based units, container SCIF leasing, and portable enclosures when the mission profile calls for them. We either build to ICD-705 directly or coordinate qualified suppliers under one accountable line, one schedule, and one contract.
How fast can Salian Defense reach SCIF occupancy?
Where scope allows, Salian has reached occupancy in four to six months, against an industry norm of twelve to twenty-four. Timeline depends on starting posture; Salian scopes honestly, then commits to a date it can hold.
How much does a SCIF cost to build?
There is no honest flat number. The real drivers are size, starting posture (new build, retrofit of existing space, or rescue of a stalled project), RF and acoustic requirements, region, and schedule. Salian publishes Vates Cognition, a free budgetary estimator at saliandefense.com/vates.html that returns a Rough Order of Magnitude range from a short intake, before any commitment. For a firm figure, write contact@saliandefense.com and we scope it honestly.
Does Salian Defense provide outsourced FSO, CSSO, or ITPSO support?
Yes. Salian provides co-employed Facility Security Officer (FSO), Contractor Special Security Officer (CSSO), and Insider Threat Program Senior Official (ITPSO) services through a cleared captive partner, with UL 2050 and UL 1076 specification, FOCI mitigation, ITAR/EAR advisory, and physical security engineering.
Does Salian Defense stand up and run industrial security programs?
Yes. Salian creates, maintains, and self-inspects NISP and NISPOM industrial security programs and prepares clients for DCSA security reviews under 32 CFR Part 117. We provide Facility Security Officer (FSO) support, personnel and facility clearance administration, Key Management Personnel coverage, and cleared staff augmentation sized to the program, plus counterintelligence, insider threat program development, technical surveillance countermeasures (TSCM), and FOCI mitigation.
Software and AI
What is the Praesidium Suite?
The Praesidium Suite is Salian Defense's line of six software products that share one architecture, built so the same system can run hosted and unclassified, on customer infrastructure at a CUI boundary, or fully air-gapped inside accredited space. Accreditation is granted per system and per site by the sponsoring authority; the Suite ships with the evidence package that process requires. The six are Vates Cognition (on-premise estimating and analysis; the free estimator is live on the site), Groma (ingests plans, renders 2D and 3D, and grades designs against ICD-705), Legatus (agentic workflows with human-signed approval, air-gapped), Vigil (inline AI security enforcing allow, redact, or block at the model boundary), Hawk RAG (the retrieval layer shared across the suite and the ventures, running in all three deployment profiles; in production), and Pythian (inline FPGA-based hardware encryption for operational-technology networks; a partner technology available to Salian under a white-label arrangement).
How does Salian Defense build software for air-gapped environments?
Salian builds a high-fidelity digital twin of the target classified enclave and runs engineering, configuration, validation, and dry runs on the unclassified, networked side at full speed. Once the baseline is proven, it transfers into the air-gapped environment as known-good work. The Praesidium platform is built to run fully offline, with no outbound network traffic, no software-as-a-service in the runtime path, and no telemetry leaving the building.
What software can run inside a SCIF?
Software can run inside a SCIF if it needs no outbound network connection, ships with the accreditation evidence its reviewing authority requires, and can be installed and updated inside the boundary rather than pulled from a vendor cloud. Most commercial software fails the first condition because it assumes a live internet connection for licensing, updates, or telemetry. Salian engineers the Praesidium Suite to those constraints and also builds bespoke tools to a customer's specific enclave. Accreditation is granted per system and per site by the sponsoring authority; the Suite ships with the evidence package that process requires.
Does the Praesidium Suite work fully air-gapped?
The Praesidium Suite is built so the same architecture runs in three deployment profiles: hosted and unclassified, CUI-safe on customer infrastructure, or fully air-gapped inside accredited space. In the air-gapped profile there is no software-as-a-service in the runtime path, no outbound network traffic, and no telemetry leaving the building. The three affiliated ventures demonstrate the same architecture at each profile: RFI Hawk hosted, Project Hawk CUI-safe on customer infrastructure, Legatus air-gapped. Accreditation is granted per system and per site by the sponsoring authority; the Suite ships with the evidence package that process requires.
How does Salian Defense automate ICD-705 compliance checking?
Groma, a product in the Praesidium Suite, encodes ICD-705 and its implementing technical specification as buildingSMART IDS 1.0 plus nine deterministic geometry and documentation checks, runs them against an as-designed or as-built IFC4 model, and returns a gap report. The pass-or-fail verdict is produced by deterministic code, never by model output: language models read messy inputs and phrase findings, but they never decide compliance. Every result is a draft that a credentialed human reviews and ratifies, and the Accrediting Official's determination remains non-delegable. Groma reasons over business, program, and facility metadata plus public standards, and never touches classified or controlled content. Under development.
What is Groma?
Groma is a spec-aware ICD-705 compliance and design engine in Salian Defense's Praesidium Suite, and it works in both directions. In reverse it reconstructs an IFC4 model from a plain-English description, a structured plan, or a floor-plan image, then checks it against buildingSMART IDS 1.0 plus nine deterministic checks: wall layering, slab-to-slab continuity, duct penetrations, door lock, door acoustic, access-controlled entrance, alarm response class, window treatment, and Fixed Facility Checklist completeness. Forward it solves a layout with a deterministic constraint solver, authors the IFC4 model, and prices it as a ranged AACE-classed estimate. Every output is a ratifiable draft a credentialed human signs off; Groma never decides, accredits, or certifies, and the Accrediting Official's determination is non-delegable. Accreditation is granted per system by the sponsoring authority, and the Suite ships with the evidence package that process requires.
What is Legatus?
Legatus is a workflow orchestrator in Salian Defense's Praesidium Suite that decomposes an analyst's intent into a multi-step workflow, calls models and tools through a controlled registry, and stops at a human for approval before any sensitive action. A classification label travels with every state transition, and the compiler refuses to build a workflow whose step ceiling sits below a state the workflow can actually reach. Legatus is built to the control set for DoD Impact Levels IL4 through IL6; accreditation at a given Impact Level is granted per system by the sponsoring authority.
What is Vigil?
Vigil is an inline AI security layer in Salian Defense's Praesidium Suite that inspects what flows between an application and a language model and enforces allow, redact, or block at that boundary. It sits in the request path and acts on what it finds; it is not monitoring software and it is not telemetry. It is an embedded, swappable provider rather than a standalone application. It ships deployment-profile resolution, content-free scan contracts, a deterministic detector set covering identifiers, payment numbers, cloud access keys, and private keys, an advisory-or-enforce policy engine with allow, redact, and block precedence, and a redaction transformer. Accreditation is granted per system by the sponsoring authority, and the Suite ships with the evidence package that process requires.
How does Salian Defense prevent CUI from reaching an AI model?
Two mechanisms, at different layers. Vigil sits inline between the application and the model and enforces allow, redact, or block on every request, so controlled content is caught in the request path rather than discovered afterward in a log. Separately, every Praesidium product is built around a metadata membrane: products reason over business, program, and facility metadata plus public standards, and controlled content does not enter the pipeline at all. The combination of a public standard and business metadata is what makes the analysis safe to run outside an accredited boundary.
What DoD Impact Levels does Salian Defense software support?
Legatus is built to the control set for DoD Impact Levels IL4 through IL6, and accreditation at a given Impact Level is granted per system by the sponsoring authority. That distinction is deliberate: designed-for describes the control set and architecture the software was built against, while accredited-at describes a determination only an Authorizing Official can make for a specific system in a specific environment. Salian delivers accreditation evidence alongside the software so a reviewing authority can make that determination, but does not claim it on the software's behalf.