Defence & intelligence

Defence

Coalition analytics, signals processing, and secure inference without declassification: computation that never opens the data.

The decryption gap is the moment data must be decrypted to be used. Institutional and government buyers.

Is this you?

Operations environment for classified encrypted analytics

What this looks like in practice

Situation, how Umbra runs it, and what changes for the team that owns the risk.

01

Coalition analytics without declassification

Two or more nations need joint correlation on holdings that cannot leave national key domains. Release authorities govern every output; source material must never resolve on a shared fabric in the clear. Prior programmes stalled on declassification timelines measured in months.

How it runs

Each partner contributes ciphertext under national keys. Encrypted search, graph correlation, and pattern joins run on Umbra N8 nodes inside accredited facility power and airflow. Queries and intermediate tensors stay encrypted; only policy-governed aggregates exit under bilateral release rules.

What changes

Mission analytics proceed without a prior declassification campaign or a shared plaintext lake. Coalition staff work from encrypted correlation results that survive releasability review because the underlying collections never opened.

02

Encrypted signals processing

RF, COMINT, or sensor streams must be inspected at line rate without staging plaintext on analyst workstations or vendor analytics tiers. Throughput requirements exceed what lattice FHE prototypes can sustain; accreditation rejects any pipeline that decrypts at the accelerator.

How it runs

Feature extraction, dwell detection, and cross-channel matching run on Umbra against encrypted streams ingested at the collection boundary. A single U100 characterises the workload; production scales to N4 or N8 nodes sized to the mission envelope: 160M to 320M encrypted ops/s estimated at the node class from published specs.

What changes

Line-of-mission inspection stays inside cryptographic and accreditation controls already familiar to the programme. Analysts receive actionable indicators without a plaintext staging tier between collection and compute.

03

Multi-level secure inference

Classification-aware models must answer prompts that span levels the host environment cannot hold in the clear. Commercial AI stacks assume a single trust domain at the GPU; MLS policy blocks them from production networks.

How it runs

Prompts, context windows, and model weights traverse the stack as ciphertext. Inference executes on Umbra; results are labelled and routed by policy without a trusted enclave holding every level as plaintext simultaneously.

What changes

Inference becomes available where MLS policy previously blocked commercial AI stacks. Programmes gain model-assisted analysis without collapsing compartment boundaries at the compute tier.

04

Cross-domain fusion without a plaintext merge

All-source fusion requires correlates from HUMINT, GEOINT, and SIGINT programmes that cannot be co-located in one database. Manual fusion does not scale; automated fusion on plaintext violates every compartment rule.

How it runs

Programmes export encrypted feature vectors and entity graphs to a fusion node. Correlation models run in ciphertext; only matched entity handles and confidence scores release under dual-key governance.

What changes

Fusion timelines compress from analyst-weeks to machine-hours without a super-database of raw holdings. Accreditation reviewers see a smaller plaintext scope because fusion never required decryption at the compute boundary.

Constraint

Why plaintext fails here

Classification, national caveats, and releasability rules forbid moving sensitive holdings to lower trust domains. Coalition partners cannot share raw collections. Any path that decrypts to analyse fails review before it reaches a rack. Air-gapped enclaves block commercial cloud tools; compartmented programmes cannot merge datasets at machine speed. The constraint is not policy alone: it is architectural: plaintext at the point of use is a standing breach window.

Approach

Ciphertext through the stack

Traditional analytics assume plaintext at the point of use. In defence that assumption breaks at every boundary: declassification is slow, shared lakes violate compartment rules, and GPU farms that decrypt for inference cannot pass accreditation. Lattice FHE stacks run at roughly 1000× below rack requirements; they are useful in the lab, not on mission timelines. Umbra U100 cards deliver 40M encrypted logic operations per second per card; N4 and N8 nodes scale that into production envelopes. Umbra runtime runs deterministically on ciphertext throughout: no bootstrapping, no trusted-enclave plaintext boundary. RainDB, encrypted inference, and the SDK carry forward as workloads move from evaluation card to deployed node.

Why Umbra

Production FHE at rack scale

Umbra is a production path to full FHE that software lattices do not offer at rack scale. Trusted execution and plaintext GPU paths still decrypt: they shrink the attack surface, they do not remove it. Umbra hardware and Umbra runtime together are what institutional buyers need to advance confidently into workloads: coalition correlation, signals feature extraction, MLS inference: that conventional FHE cannot run in a rack and that plaintext stacks cannot accredit. Nodes are the commercial unit: configured, burned in, and acceptance-tested systems, not a research toolchain stapled to commodity GPUs.

How you buy cards

Sized from one card to multi-card packs

Workload → one evaluation card → multi-card pack → N4/N8 when the programme wants ZipLogic to own thermals and acceptance.

Start

1 × U100 in an accredited host: RainDB smoke queries or ZChat inference against a classified feature set on their own chassis.

Scale pack

Multi-card pack for mission concurrency: RainDB query fan-out across cards, or ZChat reference scale (6 × U100 + 2 × NVIDIA GPUs) for encrypted inference beside existing GPUs.

Institution path

N4 / N8 when the programme wants ZipLogic thermals, burn-in, and acceptance: not a parts list in a classified rack.

Workflow

Partners encrypt at national key domains → Umbra runs correlation / RainDB / ZChat on ciphertext → only policy-governed aggregates decrypt under release authority.

Deployment

How it lands

Programmes typically characterise workloads on a single U100 in an accredited host, then scale to engineer-installed N4 or N8 nodes. N8 nodes operate at roughly 1.4 kW wall power under dual-socket load, with standard server airflow and no rack redesign. Survey, rack integration, burn-in, and acceptance ship as a certified deployment. Runtime and firmware follow the same change-control path as other cryptographic equipment.

Regulatory

What buyers ask next

Export control, national cryptographic accreditation, and programme authority to operate apply to every deployment. ZipLogic supplies technical packs for accreditation. No FHE evaluation regime currently exists that can assess the scheme; formal certification is available customer-funded. Customers retain sovereignty over keys, placement, and release decisions.

Request a briefing

Bring the sector constraint. We respond within two business days.

Request a briefing Read the methodology

Integrate · Security

Also