ATLAS TEK Talk to us
Classified Enclave Companion · CPU-Only · No GPU Required

ARES
AI for the enclaves where nothing else runs.

ARES is the classified companion to ATLAS - a CPU-only AI inference server built for air-gapped enclaves where no GPU exists and no cloud connection is possible. It pairs with an unclassified ATLAS hub via signed air-gap packages on DVD or one-way USB. Same STIG automation. Same remediation loop. Runs on standard server hardware.

BitNet 1.58-bit No GPU required 1.2GB model 1.5GB RAM 30+ tok/s on CPU DVD or one-way USB Ships, subs, forward bases
What is ARES?

ATLAS for the environments where "cloud-connected" is not an option.

ARES is not a separate product. It is ATLAS configured for classified enclaves - the same architecture, the same patent-pending security model, the same STIG automation pipeline - with every external dependency removed and a CPU-only LLM that runs on standard server hardware. No GPU. No cloud. No Jira. No external feeds. Everything runs inside the classified boundary.

BitNet b1.58 - No GPU Required

Microsoft's BitNet 1.58-bit ternary model runs entirely on CPU. 1.2GB model file, 1.5GB RAM footprint, 30+ tokens/second on 8 x86 cores. No AVX512 needed (AVX2 sufficient). 82% less energy than traditional inference. Designed for hardware that already exists in the enclave - no procurement, no GPU wait, no supply chain.

🔒

No External Dependencies

No cloud LLMs. No Jira. No ServiceNow. No external threat intel feeds. Internal ticketing system built in. STIG Manager runs locally. Keycloak handles auth. Every component your enclave needs, nothing it can't have. Air-gap package delivery via signed DVD or one-way USB media - zero network contact across the boundary.

🛡

Classified-Native Security

Network classification banner pinned to every page (DoDM 5200.01 Vol 2 marking conventions). Red accent theme distinguishes classified from unclassified consoles. mTLS enforcement with SCEP/EST model. CSR-based cert renewal - private keys never leave the agent. Build-time code stripping: classified hubs cannot create air-gap packages, unclassified hubs cannot import them.

📱

Internal Ticketing System

Classified enclaves rarely have external ITSM tools. ARES includes a complete ticketing system built into the hub - auto-created from STIG findings, assignable by user and group, with KPI dashboards, scheduled remediation, and POA&M/Risk Acceptance tracking that syncs to STIG Manager automatically. ISSM approves in eMASS; ARES polls and updates.

Two-Hub Architecture

An unclassified ATLAS hub feeds ARES via signed air-gap packages.

ARES is designed to pair with an unclassified ATLAS hub. The unclassified hub has GPU power, cloud access (via WebGateway), and builds air-gap packages. The classified ARES hub ingests them via DVD or one-way USB. Build-time code stripping enforces the boundary: the classified hub literally does not contain the code to create packages. The unclassified hub literally does not contain the code to import them.

UNCLASSIFIED · CUI ATLAS HUB GPU-powered Admin Console cyan theme 15+ tabs Orchestration · FastAPI · PostgreSQL · Jira/SM · KEV pipeline Local LLM Ollama tri-LLM GPU WebGW AIRGAP PACKAGE BUILDER · LLM curates patches + playbooks · RSA-SHA384 signed, multi-disk · ACAS findings + KEV intel included BUILD ONLY AIRGAP DVD / USB signed verified numbered zero net CLASSIFIED · AIRGAPPED ARES HUB CPU-only Admin Console red theme classification Orchestration · FastAPI · PostgreSQL · Internal tkts · STIG Mgr local BitNet b1.58 1.2GB CPU only NO NET AIRGAP PACKAGE INGESTER · Signature verify + hash check · LLM reviews contents · Admin approves, agent executes IMPORT ONLY BUILD-TIME CODE STRIPPING: CLASSIFIED HUB CANNOT CREATE PACKAGES · UNCLASS HUB CANNOT IMPORT THEM · AIRGAP ENFORCED IN SOFTWARE
Unclassified ATLAS hub
GPU-powered. Full LLM (Ollama, tri-model). WebGateway for sanitized cloud queries. Builds and signs air-gap packages. Curates patches, playbooks, and threat intel for the classified side. Never ingests classified data.
Classified ARES hub
CPU-only. BitNet b1.58 LLM (1.2GB, 1.5GB RAM). Internal ticketing. No WebGateway needed (no external network). Ingests signed air-gap packages via DVD or one-way USB. LLM reviews contents, admin approves, agents execute. Full STIG automation loop runs locally. Agents stay registered through sleep cycles - waking systems auto-reconnect and resume.
Build-time code stripping
The air-gap is enforced in the software itself, not just by policy. Classified hubs are built without package_builder.py. Unclassified hubs are built without package_ingester.py. A compromised hub cannot perform operations it was not built to perform.
BitNet b1.58

AI inference on whatever hardware you already have.

ARES runs Microsoft's BitNet b1.58 - a 1.58-bit ternary model that runs on standard x86 CPUs. No GPU procurement. No supply chain delays. No special hardware. If your enclave has a server with 4GB RAM and an AVX2 CPU, you have AI inference.

1.2GB
Model file size
1.5GB
RAM footprint
30+
tokens/sec on 8 cores
2.4B
parameters
82%
less energy than GPU inference
0
GPUs required

Model: microsoft/BitNet-b1.58-2B-4T-gguf · I2_S quantization · 4T training tokens · MIT license · AVX2 or AVX512 required

ARES vs ATLAS

Same engine. Different fuel.

ATLAS and ARES share the same codebase, the same patent-pending security model, and the same STIG automation pipeline. The difference is what runs inside the boundary - and what doesn't.

ATLAS

Unclassified · CUI · Cloud-connected
  • GPU-powered LLM (Ollama, tri-model architecture)
  • WebGateway sanitization for external queries
  • External threat intel feeds (CISA KEV, NVD)
  • Jira or ServiceNow integration
  • Cyan accent theme
  • Builds and signs air-gap packages
  • Cloud-connected (via WebGateway)

ARES

Classified · Air-gapped · CPU-only
  • BitNet b1.58 CPU-only LLM (no GPU)
  • No WebGateway (no external network)
  • No external feeds (air-gap package delivery)
  • Internal ticketing system (no Jira needed)
  • Red accent theme + classification banner
  • Ingests signed air-gap packages via DVD or one-way USB
  • Fully air-gapped (zero network contact)
Shared Architecture

What both ATLAS and ARES include

· mTLS agent authentication (SCEP/EST model)
· CSR-based cert auto-renewal (NIST SP 800-57)
· HMAC-SHA256 signed command dispatch
· Per-agent trust levels (read-only / write / admin)
· LLM-generated STIG remediation playbooks
· Full remediation loop: detect → think → remediate → verify
· Insider threat detection (UAM, 32 CFR 117)
· PQC readiness scanning (CNSA 2.0)
· NIST 800-53r5 CCI crosswalk (3,550 mappings)
· POA&M and Risk Acceptance tracking
· STIG Manager sync
· Admin console with 15+ tabs
· Air-gap package signing (RSA-SHA384)
· Full audit trail (every action logged)
· Cross-signed CA rotation via DVD
· Windows and Linux agents
Deployment Scenarios

Built for the enclaves where no other AI can run.

ARES is designed for tactical environments - ships, subs, forward bases, classified command posts - where standard server hardware is all you have and no cloud connection is possible. A single unclassified ATLAS hub can feed multiple ARES enclaves via signed air-gap packages.

Shipboard Networks

Afloat networks with no internet uplink. ARES runs on existing shipboard servers. STIG scans run locally, playbooks execute locally, tickets track locally. Unclassified shore station ATLAS hub sends weekly air-gap packages with patches and intel via DVD or one-way USB. Agents remain registered and resume automatically when systems wake - sleep is not a disconnect.

🎯

Forward Bases

Tactical networks in austere environments. No GPU hardware, limited power, no cloud. ARES runs on standard ruggedized servers with 4GB RAM. BitNet's 82% energy efficiency matters when power is constrained.

🔒

SCIF / SAP Enclaves

Sensitive Compartmented Information Facilities. No external connections of any kind. ARES provides AI-driven STIG remediation, insider threat detection, and compliance tracking entirely within the SCIF boundary. Internal ticketing replaces Jira/ServiceNow.

📡

Tactical Edge

Disconnected tactical networks (DIL-grade environments). ARES runs on minimal hardware. The 1.2GB model fits on a single DVD. Deployed in minutes, not days. Same STIG automation, same audit trail, same security model as the full ATLAS platform.

Internal Ticketing

No Jira. No ServiceNow. No problem.

Classified enclaves rarely have external ITSM tools. ARES includes a complete ticketing system built into the hub - auto-created from STIG findings, assignable by user and group, with KPI dashboards, scheduled remediation, and POA&M/Risk Acceptance tracking that syncs to STIG Manager automatically. Install-time choice: internal, Jira, or ServiceNow (future). A ticketing system is required - "none" is not an option.

Auto-Creation

STIG scan finds a finding → LLM generates a playbook → ticket auto-created with full context. No manual entry needed.

Assignment

Assign tickets to individual admins, groups (Windows admin, Linux admin, network admin), or to ATLAS itself for auto-resolution.

Scheduled Remediation

Approve a ticket with a scheduled execution time. The playbook runs at the scheduled window - not before, not after.

KPI Dashboard

Pending, approved, executed, resolved, denied, MTTR, auto-resolution rate, scheduled remediations - all at a glance.

POA&M Requests

Request a Plan of Action and Milestones. ISSM approves in eMASS. ARES polls STIG Manager and updates the ticket when approved.

Risk Acceptance

Request a Risk Acceptance (SAR). ISSM reviews in eMASS. ARES auto-resolves the ticket when STIG Manager shows acceptance.

If your enclave can't touch the cloud,
you need ARES.

Tell us your classification level and enclave size. We'll set up a classified sandbox that matches.

EIN 41-5149481 · DUNS 144981302 · SAM.gov Active · SBA.gov Approved · Louisiana, USA · Patent Pending