Sovereignintelligence.

Prompt
› Summarise the board paper.
3 risks flagged · indemnity first.
no external inference endpoint
Tool output
04:14:07 PERMIT retrieval · 12 chunks
04:14:09 DENY web fetch · default deny
04:14:12 SEAL output · in perimeter
Context
board-pack-q3.pdf48 pages
contract_v3.docxclause 12.4
6 sourcessealed

Put frontier-class AI to work across your organisation while your data, prompts and models stay inside an environment you control.

Talk to sales Read the docs →

Built in Britain by former

  • Ministry of Defence
  • Darktrace
  • British Army
  • Royal Arms
  • Digital Trust
  • US Special Forces

Encryption ends where inference begins.Inference and output inside your perimeter.

The prompt leaves your VPC encrypted. The model reads it in English, outside your environment.There is no external inference endpoint. You own the gateway, the compute, and the policy.

Your VPC

Applications / agents

S3 / data stores

PrivateLinkYour account

The wire

Encrypted · TLS

Managed inferenceDedicated GPUs

AWSBedrock

Microsoft AzureAI Foundry

Google CloudVertex AI

Welcome to the frontier of enterprise AI.

ACRA makes it possible to scale frontier intelligence inside an environment you control, without an external inference endpoint.

01

Run on dedicated GPUs.

LLMs don’t work with encrypted prompts. If your model is served outside your environment, your model provider can see your unencrypted data.

ACRA enables you to route and schedule your workloads across NVIDIA, Cerebras, and more — all inside your environment.

See what it can run on

02

Choose your model.

Download any open-weight model on Hugging Face and start running it inside your environment. Pick models suited for your work, fine-tune them inside your boundary, and swap between them freely without losing context.

You can still use frontier models like Fable and Astra inside ACRA if you choose. They serve outside your environment, but you control what they have access to, every call is recorded, and you can cut the route at any time.

See which models are available

03

Connect your tools.

Turn intelligence into outcomes. Bring the harness you already use, with its loop, tools, skills, memory, and prompts, and connect it to your context: MCP servers, APIs, data stores, other agents. Declare each connection for that workload alone; ACRA grants it, and you can revoke it in one step.

See the harnesses it supports

04

Scale on Kubernetes.

ACRA extends the Kubernetes you already run, and lets you have hundreds of concurrent users, several models, GPU fleets scheduled and shared, failover and audit, and the same experience for everyone. As the number of workloads grows, the control architecture does not.

See where it can deploy

Deployed where control
is non‑negotiable.

Deployed for

Government

Privileged government and defence workloads run air‑gapped, with keys held in‑country.

For government →

Deployed for

Enterprise

Regulated enterprises run trading, communications and AI workloads with every access auditable end to end.

For enterprise →

Deployment ledger · live

live · sovereign
live · sovereign
live · sovereign
live · sovereign
live · sovereign
live · sovereign
access · valarianDENY
Valarian HQ · London

Due diligence.

What platform teams and CISOs ask before ACRA runs in production.

Kubernetes solved orchestration; ACRA solves governance. It extends the cluster with workload-level control: inherited policy, default-deny boundaries, containment, telemetry and audit. The environment itself enforces posture, rather than tooling bolted around it. Kubernetes is the primitive; ACRA is the posture.

The per-workload policy stack comprises seven layers: cryptographic workload identity (SPIFFE/SPIRE), user identity (your internal IdP), default-deny network isolation (Cilium + Istio), admission and workload policy enforcement (Kyverno and gateways), short-lived scoped secrets (Vault), per-workload messaging permissions (NATS), and audit and evidence (platform audit logs). OpenTelemetry provides observability across every layer.

You do. Each deployment is cryptographically unique and the customer holds the keys. Even Valarian cannot access systems after launch. Governance emerges from enforced boundaries, not privileged access; securing the environment should not require admitting a new privileged actor into it.

Yes. ACRA is a cloud-agnostic control architecture: the same governance, containment and audit posture across clouds, on-prem and air-gapped estates, deployed where you need it to run and able to keep operating if connectivity drops. The cloud remains the substrate; the trust boundary belongs to you.

It gets contained. Specific workloads or whole environments can be isolated, sealed or revoked at runtime without destroying the system around them — a non-destructive kill switch, enforced at the infrastructure layer. Every powerful machine eventually gets a circuit breaker; AI will not be the exception.

No. ACRA extends Kubernetes — it does not replace it. Applications, workloads, teams and AI inherit the environment's posture by default; the number of applications grows, the control architecture does not. Every application should not become a new security project.

From the frontier.

View all

Deploy infrastructure
you control.

Company

About Careers

Resources

Blog Contact

Compliance

Privacy
Established 2020 · London

Control infrastructure for high-consequence systems.
© 2026 Valarian · London

Made in the UK