UNCLASSIFIED // MARKETING — REPRESENTATIVE DATA
NNEXUS

Standards · Security

Inside the Crown perimeter. By design.

Built for the frameworks Canadian agencies operate under — not a foreign-prime checklist with a Canadian decal. Architectural postures below are auditable today; the regulatory work (CGP, Vendor of Record) is the deployment path, not done yet. We will not claim what we have not earned.

Sovereign by design

NEXUS is architected so that classified data does not leave the Crown perimeter. Operator workstations, appliances, and the inference plane sit inside the agency boundary — no foreign-cloud round-trip, no third-party telemetry. Canadian-incorporated, pre-procurement.

Regulatory posture · CGP registration to be completed pre-deployment

Open-source models, license-enumerated

Every ML model used inside NEXUS is open-source with a permissive license — every weight, every license, every training data lineage publicly auditable. Nothing in production is trained on data we cannot disclose to your CIO. No ITAR-controlled model weights in the registry.

Model registry available under NDA · open-source by choice

ATIP-ready disclosure

Every operator action and every model call is recorded with timestamp, classification, and provenance. ATIP exports bundle the request, the operator session, the model call trace, and the reasoning citations as a tamper-evident PDF.

30-day reasoning-trace retention by default · configurable

Stinchcombe disclosure

Investigation workspaces flag every privileged, s.8, or third-party-source record at ingest. Disclosure rollup tiles update live. Stinchcombe-ready export is a one-click PDF with provenance chain attached.

RCMP IPOC + DOJ guidance · external review on request

PKI · TLS · zero standing access

Operator authentication is via CAF PKI or RCMP CPIC integration. Workstation ↔ appliance communication is mTLS 1.3 on an inside-boundary network. No standing access; every privileged action is consent-prompted and logged.

Operator-level break-glass procedures documented in deployment kit

Crown perimeter sovereignty

NEXUS Edge runs entirely inside the agency network boundary. No telemetry, no model calls, no metadata leaves the perimeter. Federation across agencies is opt-in by signed instrument, partner by partner.

Air-gapped operation supported · disclosure exports work disconnected
Compliance alignment

Procurement-clean across the five frameworks that actually gate a Crown deployment.

FrameworkNEXUS coverage
TBS Directive on Service & DigitalOperator workstation pattern · digital service standard alignment
GC Cyber Security Event Management PlanLogging, monitoring, and incident reporting hooks designed in
ITSG-33 · CSESecurity control catalogue alignment per workstation + appliance roles
Five Eyes operator clearance compatibilityCAF PKI · UK MoD · US DoD CAC interoperability architecture
Disclosure boundary

What we publish · what we will not.

We publish
  • · Model registry under NDA
  • · Architecture diagrams under NDA
  • · Operator-action audit-log schema
  • · ATIP export format + sample bundle
  • · Stinchcombe export format + sample bundle
  • · Architectural posture diagrams for Crown procurement review
We will not publish
  • · Customer agency names · until disclosure is authorised by the agency
  • · Classified operator workflows · ever
  • · Detection model weights · under license
  • · Pricing on classified-tier deployments · per Crown procurement instrument
Next

The deployment-kit binder for your CIO.

UNCLASSIFIED // MARKETING — REPRESENTATIVE DATA