Skip to content
MITHRIL

Sovereign and public-sector compute

MITHRIL · GOVERNMENT

AI-assisted software must pass through procurement and audit chains that assume a human wrote every line, while the systems themselves hold data a state cannot afford to expose.

Approach

The host grants only capabilities admitted as inspectable data before execution, and every artifact resolves to a canonical graph digest. The toolchain runs without a JVM and asks for no ambient network: one pinned, signed release installs on an air-gapped site, and the conformance suite - not a vendor claim - says what the compiler admits.

Proof
  • NIST SSDF (SP 800-218) asks for provenance and release integrity: content-addressed artifacts and admission receipts are that evidence in machine-readable form
  • Air-gapped operation stated and tested by the language itself: the toolchain is JVM-free and artifacts are content-addressed
  • Executable proof on this site: a .mith application and its web library, compiled and served from the public compiler