Secure LLM Deployment for Federal and Government Programs
A secure LLM for federal government use runs open-weight models air-gapped on your own controlled infrastructure, under four controls an agency can verify on government hardware — not four claims to take on a vendor's word. Those controls are byte-identical weight provenance, dormant-capacity enumeration, no egress, and a post-quantum (ML-DSA) signed audit chain. The model runs where the data already sits under agency control, and every one of the four controls resolves to a check the agency runs on its own machine.
Most "secure AI for government" offers are a governance layer bolted onto a commercial API: the data still leaves the boundary, the model can still change without notice, and the audit trail is an export you cannot independently check. For a federal program that is trust, not security. Hyfstele inverts it. The weights execute inside the enclave with no path out, and the security properties are things an evaluator reproduces on the target hardware — the output of those checks is the assurance, not our attestation of it.
The federal requirement: air-gapped, no-egress AI on controlled infrastructure
Federal and government AI programs frequently sit on data whose sensitivity forbids it leaving an accredited boundary — CUI, program-of-record data, source-selection material, PII, and mission data that must remain on agency-controlled or agency-accredited infrastructure. A model that reaches a commercial endpoint moves that data outside the boundary and outside the agency's control, which is a non-starter regardless of the vendor's marketing.
The requirement is therefore concrete: the model must run inside the accredited enclave, on infrastructure the agency controls; it must have no route to egress data; and its behavior in production must be auditable and provenanced for the life of the records it touches. Hyfstele is built to meet exactly that shape — open-weight models, air-gapped, with the four controls below carrying the diligence.
The four controls, in federal diligence terms
Each control is independent, and each is verifiable on the customer's own hardware inside the boundary. Together they are the evidence package an evaluator, ISSO, or auditor can actually work from.
-
Byte-identical weight provenance
The weights loaded into memory are proven byte-for-byte identical to the published public artifact the agency approved. This is the AI equivalent of a known-good baseline: it lets an evaluator confirm exactly what is running and detect any swap, dark fine-tune, or silent update between approval and inference.
VERIFY: hash the loaded weights, compare to the published artifact hash. -
Dormant / latent capacity enumerated
The capabilities present in the model — including capacity dormant until triggered — are enumerated and disclosed, so what the model could do is a documented known quantity for the risk assessment rather than a surprise discovered in production.
VERIFY: review the capacity enumeration against the model in the enclave. -
No egress
There is no route to the internet and no name to resolve. Things go in; nothing comes out. Controlled data cannot leave the enclave and the model cannot phone home, because there is nowhere for a packet to go. This is a boundary property an evaluator checks directly, not a policy promise.
VERIFY: inspect network policy and DNS resolution on the host — no route, no name. -
Post-quantum signed audit chain
Every inference call is anchored to a linked, tamper-evident audit chain signed with post-quantum cryptography (ML-DSA / FIPS 204). Any alteration to the record of what ran breaks the signature and is detectable — producing an attributable, verifiable record of every AI action for the accreditation package and for audit.
VERIFY: check the ML-DSA signatures over the linked inference records.
Post-quantum signatures for long-lived record integrity
Federal records outlive the cryptography that protected them at creation. A signature that is sound today can be forgeable in the retention window of a decades-long record once a cryptanalytically relevant quantum computer exists — the "harvest now, forge later" problem applied to record integrity rather than confidentiality.
Hyfstele signs the audit chain with ML-DSA, the module-lattice digital-signature standard published by NIST as FIPS 204. Choosing a post-quantum scheme means the integrity of the inference record stays verifiable across the full retention life of the record, not only for as long as classical signatures hold. For an agency whose obligation is to be able to prove what an AI system did years after it did it, that is the difference between an audit trail and an audit trail that still means something later.
We do not claim the model is clean, safe, or backdoor-free. We do not claim to have scanned the model. No one can honestly certify that a large open-weight model is free of hidden behavior. What we make verifiable on your own hardware is different and stronger for federal diligence: the exact weights you approved cannot silently change, latent capacity is enumerated, nothing can leave the enclave, and every call is signed and tamper-evident. Evidence an evaluator reproduces on government hardware — not our word.
Where this maps to existing regulatory language
The four controls speak directly to obligations government and regulated buyers already carry:
- 21 CFR Part 11 — electronic records and signatures must be attributable, tamper-evident, and auditable. The post-quantum signed audit chain produces exactly that record for every inference.
- GxP — good-practice process control requires the exact validated model version to be pinned and provable. Byte-identical provenance makes the version a fact, not an assumption.
- Data residency — regulated and controlled data must not leave the boundary. No egress means there is no path for it to.
- Model provenance — auditors and inspectors ask which model produced a result and whether it could have changed. Provenance plus a signed chain answers both, reproducibly.
The live proof point: MLR assist
The approach is not a whitepaper. The Hyfstele MLR assist is a working deployment for pharmaceutical MLR (Medical, Legal, Regulatory) promotional review, with a live demo at mlr.hyfstele.com. Pharma and federal share the same shape of obligation — controlled data, provenanced models, auditable actions — so the MLR assist doubles as a demonstrable reference for the four-control model. Its operating doctrine is deliberate:
The system flags potential issues; a qualified human judges; and every step is proven on the signed audit chain. Critically, there is no LLM inside the flag decision plane — the model surfaces candidates, but the decision logic that determines what counts as a flag is deterministic and reviewable. The doctrine is short: "It flags. You decide." The accountable official stays in control, and the record of every call is captured for audit.
Frequently asked questions
What is a secure LLM for federal or government use?
Open-weight models running air-gapped inside government-controlled infrastructure, under four controls the agency verifies on its own hardware: byte-identical weight provenance, dormant-capacity enumeration, no egress, and a post-quantum (ML-DSA) signed audit chain. The model runs where the data already sits under agency control.
Does it mean the model is certified clean or backdoor-free?
No. We do not claim the model is clean, safe, or backdoor-free, and we do not claim to have scanned it. What a secure deployment makes verifiable on government hardware is a boundary and an evidence trail — it constrains what the model can do and proves what it did, without certifying the model's internals.
How does a signed audit chain support long-lived federal records?
Every inference is anchored to a tamper-evident chain signed with post-quantum cryptography (ML-DSA / FIPS 204). Any alteration breaks the signature and is detectable, and because the scheme is post-quantum, the integrity of the record stays verifiable across the decades-long retention life of federal records — not just today.
How does an agency confirm exactly what model is running?
By hashing the weights loaded into memory and comparing them byte-for-byte against the published public artifact. Matching hashes prove the running model is the exact version approved — nothing swapped or silently updated. Provenance becomes a fact the agency reproduces on its own hardware, not an assumption.
Who builds Hyfstele, and is it a small business?
Hyfstele is built by Hibiscus Consulting LLC (Blake Burnette, Raleigh / Cary NC), an SBIR-eligible small business. The live proof point is the MLR assist at mlr.hyfstele.com, following "It flags. You decide." Contact blake@hibiscus.buzz.
Bring a program; we will show the evidence trail
Walk the MLR assist, or bring your controlled use case and we will show the four controls verified on your own hardware.
Talk to Hibiscus Consulting See the live MLR demo