Air-gapped and sovereign deployments can't reach public Sigstore. AIR runs a private Rekor v2 / Tessera transparency log inside your boundary, signed with FIPS-validated cryptography, so agent accountability clears IL5 / IL6 with no network path out.
What the impact-level ladder and the crypto floor require.
IL5 requires FedRAMP High plus a DISA Provisional Authorization, FIPS-validated cryptographic modules for all encryption, US-person administrative access, and physical separation from non-DoD tenants. IL6, for data classified up to Secret, can run only in an air-gapped government community cloud.
FIPS 140-3 replaces 140-2 by 2026. NIST stopped accepting new 140-2 submissions in April 2022, and existing 140-2 validations sunset in 2026.
An air-gapped deployment cannot anchor to public Sigstore. AIR runs a private Rekor v2 / Tessera transparency log inside the enclave, so inclusion proofs exist without a packet leaving.
The record is signed in-process with FIPS-validated cryptography and anchored to a transparency log that lives inside the enclave. Your own people verify inclusion, offline, with no call to Vindicara and no call to the public internet.
See the evidence model →Sovereignty is the lever: you don't pay us to reach your network, you pay us to prove your agents inside it, with the trust root never leaving your hands.
A sovereign briefing for your security and accreditation teams. We walk the IL5 / IL6 path, the FIPS posture, and the in-enclave transparency log, on your terms.
Request a sovereign briefing →