Sovereign by architecture

Architecture you can verify.
Data that never leaves.

Five human approval gates. Bicep-first IaC. Azure AI Foundry Local enclaves. Every deployment auditable from locked specification to compliance runbook.

Powered by Azure AI Foundry Local Models execute inside your enclave. Nothing leaves your network perimeter.

  • ISO 27001 aligned
  • Cyber Essentials
  • UK South · sovereign
  • Air-gap ready
topology / sovereign-boundary
Talastron No operational access
Your Azure tenant UK South
Managed resource group · isolated
enclave Azure AI Foundry Local models + inference
Orchestrator five-gate pipeline
OneLake corporate knowledge base
Deployed applications your IP
Zero egressCustomer-managed keysPrivate endpoints only
Dark-Silicon Guardrail

If the subscription lapses, the orchestrator shuts itself down. Your data, your IP, and your deployed applications stay in your tenant. No extraction, no exit fee.

The other half of the architecture

What we refuse to build.

Sovereignty is not a setting you toggle. It is the absence of the things that would compromise it. Three we designed out entirely.

Data

No shared datastore

Your data lives only in your tenant. There is nothing on our side to subpoena, breach, or leak, because there is nothing on our side at all.

Access

No vendor backdoor

Management access is just-in-time and revocable by you at any moment. No standing connection, no privileged account waiting in the background.

Network

No path off the tenant

Private endpoints only, zero egress. Models, orchestration, and telemetry never traverse the public internet. Air-gap compatible for SECRET enclaves.

How an output is produced

Five human gates plus a documented hand-off.

Every output, from a single requirement to a deployed Azure resource group, travels the same line. No phase advances until your nominated reviewer signs off.

01 Human sign-off

Requirements

Natural-language intent → locked specification.

02 Human sign-off

Architecture

Solution design, AVM-first. Azure Verified Modules — Microsoft-hardened, CAF-aligned.

03 Human sign-off

Governance

WAF scoring, RBAC, policy.

04 Human sign-off

IaC Generation

Bicep (AVM-first) or Terraform, reviewed.

05 Human sign-off

Deployment

Into your own Azure tenant.

The documented hand-off

As-Built Docs

Shipped at Gate 5 as the procurement-ready evidence package. Yours permanently.

  • runbook.md
  • compliance-report.pdf
  • deployment-lineage.json
  • audit-trail.log

Each gate is run by one of eight specialist agents — Minerva, Vitruvius, Nemesis, Fabricius, Vulcan, and Themis (primary), plus Plutus and Cassandra (specialist sub-agents) — and adversarially challenged by Themis's Dual-Judge at every step before sign-off. Every deployment is WAF-scored across all five pillars: floor 6, target 8. How it works → WAF methodology →

Platform Architecture

Three layers. One managed platform.

The Talastron platform is three distinct layers — each independently valuable, each accelerating the next. The Talastron Spec-Driven Engineering Platform builds and maintains the Tier 2 and Tier 3 layers.

Tier 3 · Surface layer

Where users meet AI

Microsoft Teams, Copilot Studio, M365 Copilot, and autonomous agents — the interfaces through which business users interact with the governed AI estate.

MS Teams Copilot Studio M365 Copilot Autonomous agents
Tier 2 + 3 · Middle trusted layer

Deterministic neural-symbolic engine

The trust layer between surface tools and backend models. Semantic mapping, deterministic guardrails, knowledge graph grounding, and audit trails — applied at every gate. A hallucination cannot pass this layer.

Semantic ontology · Fabric IQ Deterministic guardrails Knowledge graph · LLM grounding Audit trails at every gate
Tier 2 · Infrastructure layer

Sovereign & secure AI landing zone

The foundational Azure infrastructure layer — sovereign, evergreen, and managed. Three compliance variations. Annual platform rent replaces the £100k–£120k/year cost of building and maintaining this in-house.

Standard Enterprise · £24,000/yr Regulated ISO 27001 · £36,000/yr Sovereign / Defence · £66,000/yr
The Talastron Spec-Driven Engineering Platform builds and maintains the Tier 2 and Tier 3 layers. Tier 1 is pre-built and self-serve — no delivery engagement. Tier 2's fixed-price diagnostic establishes the infrastructure layer. Tier 3 adds the middle trust layer and surface agents — then the Platform stays to manage both through evergreen operations.

The technology beneath the gates

Two views of the same architecture.

The first shows where Talastron sits within the broader Microsoft agentic ecosystem — from M365 front office through to Azure Cloud Services. The second shows the internal technology stack layer by layer, from foundation models to sovereign output. Together they give a complete picture of what runs, where it runs, and what owns it when we disconnect.

01
Microsoft Agentic Ecosystem Where Talastron sits in the stack you already own

Five layers: M365 front office · Orchestration (Copilot Studio, Logic Apps, Service Bus) · Talastron Agentic Factory (eight agents, five human gates) · Identity & Governance (Entra ID, Azure Policy, ISO 27001/42001) · Azure Cloud Services (UK South sovereign).

02
The Complete Microsoft AI Stack Seven layers from foundation models to sovereign output

Seven layers: Foundation models · AI Infrastructure · Data + Memory (Obsidian Knowledge Vault) · Agentic Platform (Minerva → Vitruvius → Nemesis → Fabricius → Vulcan → Themis) · Governance (APEX, Five Gates, ISO 27001/42001) · Delivery Surface · Sovereign output.

The eight-agent pipeline

Primary agents — user-invocable

01 Minerva
Discovery & Requirements · four Logic Gates · Gate 1 owner
02 Vitruvius
Architecture & Blueprint · WAF scoring · Sovereign Gate · Gate 2 owner
1c, 2c, 4c Themis
Dual-Judge Challenger · adversarial review at every gate · Final handover
04a Nemesis
Governance Discovery · live Azure Policy · Deny/Modify as hard constraints
04b Fabricius
IaC Planning · AVM-pinned build contract · Gate 3 owner
05 Vulcan
IaC Build (Bicep) · AVM-first · zero hardcoded secrets · Gate 4 owner

Specialist sub-agents — auto-called

03 Plutus
Cost Estimation & SKU Manifest · live Azure pricing · called by Vitruvius
06 Cassandra
Deployment Preview · az deployment what-if · Gate 4 blocker · called by Vulcan
Full agent roster — roles, output contracts, and gate ownership →
Procurement-friendly. Audit-ready. UK-sovereign.

See the architecture evidence.
Then bring a real requirement.

Request the architecture assurance pack, including the compliance evidence, WAF scoring methodology, and Bicep IaC output samples. Or book the 1-hour live demonstration and we build a working architecture together. You leave with a locked specification and a fixed-price commitment.

Or book the 1-hour Executive demonstration →

Defence and sovereign procurement enquiries: see the Defence page →