ARES is the classified companion to ATLAS - a CPU-only AI inference server built for air-gapped enclaves where no GPU exists and no cloud connection is possible. It pairs with an unclassified ATLAS hub via signed air-gap packages on DVD or one-way USB. Same STIG automation. Same remediation loop. Runs on standard server hardware.
ARES is not a separate product. It is ATLAS configured for classified enclaves - the same architecture, the same patent-pending security model, the same STIG automation pipeline - with every external dependency removed and a CPU-only LLM that runs on standard server hardware. No GPU. No cloud. No Jira. No external feeds. Everything runs inside the classified boundary.
Microsoft's BitNet 1.58-bit ternary model runs entirely on CPU. 1.2GB model file, 1.5GB RAM footprint, 30+ tokens/second on 8 x86 cores. No AVX512 needed (AVX2 sufficient). 82% less energy than traditional inference. Designed for hardware that already exists in the enclave - no procurement, no GPU wait, no supply chain.
No cloud LLMs. No Jira. No ServiceNow. No external threat intel feeds. Internal ticketing system built in. STIG Manager runs locally. Keycloak handles auth. Every component your enclave needs, nothing it can't have. Air-gap package delivery via signed DVD or one-way USB media - zero network contact across the boundary.
Network classification banner pinned to every page (DoDM 5200.01 Vol 2 marking conventions). Red accent theme distinguishes classified from unclassified consoles. mTLS enforcement with SCEP/EST model. CSR-based cert renewal - private keys never leave the agent. Build-time code stripping: classified hubs cannot create air-gap packages, unclassified hubs cannot import them.
Classified enclaves rarely have external ITSM tools. ARES includes a complete ticketing system built into the hub - auto-created from STIG findings, assignable by user and group, with KPI dashboards, scheduled remediation, and POA&M/Risk Acceptance tracking that syncs to STIG Manager automatically. ISSM approves in eMASS; ARES polls and updates.
ARES is designed to pair with an unclassified ATLAS hub. The unclassified hub has GPU power, cloud access (via WebGateway), and builds air-gap packages. The classified ARES hub ingests them via DVD or one-way USB. Build-time code stripping enforces the boundary: the classified hub literally does not contain the code to create packages. The unclassified hub literally does not contain the code to import them.
ARES runs Microsoft's BitNet b1.58 - a 1.58-bit ternary model that runs on standard x86 CPUs. No GPU procurement. No supply chain delays. No special hardware. If your enclave has a server with 4GB RAM and an AVX2 CPU, you have AI inference.
Model: microsoft/BitNet-b1.58-2B-4T-gguf · I2_S quantization · 4T training tokens · MIT license · AVX2 or AVX512 required
ATLAS and ARES share the same codebase, the same patent-pending security model, and the same STIG automation pipeline. The difference is what runs inside the boundary - and what doesn't.
ARES is designed for tactical environments - ships, subs, forward bases, classified command posts - where standard server hardware is all you have and no cloud connection is possible. A single unclassified ATLAS hub can feed multiple ARES enclaves via signed air-gap packages.
Afloat networks with no internet uplink. ARES runs on existing shipboard servers. STIG scans run locally, playbooks execute locally, tickets track locally. Unclassified shore station ATLAS hub sends weekly air-gap packages with patches and intel via DVD or one-way USB. Agents remain registered and resume automatically when systems wake - sleep is not a disconnect.
Tactical networks in austere environments. No GPU hardware, limited power, no cloud. ARES runs on standard ruggedized servers with 4GB RAM. BitNet's 82% energy efficiency matters when power is constrained.
Sensitive Compartmented Information Facilities. No external connections of any kind. ARES provides AI-driven STIG remediation, insider threat detection, and compliance tracking entirely within the SCIF boundary. Internal ticketing replaces Jira/ServiceNow.
Disconnected tactical networks (DIL-grade environments). ARES runs on minimal hardware. The 1.2GB model fits on a single DVD. Deployed in minutes, not days. Same STIG automation, same audit trail, same security model as the full ATLAS platform.
Classified enclaves rarely have external ITSM tools. ARES includes a complete ticketing system built into the hub - auto-created from STIG findings, assignable by user and group, with KPI dashboards, scheduled remediation, and POA&M/Risk Acceptance tracking that syncs to STIG Manager automatically. Install-time choice: internal, Jira, or ServiceNow (future). A ticketing system is required - "none" is not an option.
STIG scan finds a finding → LLM generates a playbook → ticket auto-created with full context. No manual entry needed.
Assign tickets to individual admins, groups (Windows admin, Linux admin, network admin), or to ATLAS itself for auto-resolution.
Approve a ticket with a scheduled execution time. The playbook runs at the scheduled window - not before, not after.
Pending, approved, executed, resolved, denied, MTTR, auto-resolution rate, scheduled remediations - all at a glance.
Request a Plan of Action and Milestones. ISSM approves in eMASS. ARES polls STIG Manager and updates the ticket when approved.
Request a Risk Acceptance (SAR). ISSM reviews in eMASS. ARES auto-resolves the ticket when STIG Manager shows acceptance.
Tell us your classification level and enclave size. We'll set up a classified sandbox that matches.