Skip to content
Back to Research & Innovation

// Research project · Reference Node R1

Status: target architecture · 180-day research pilot · partners sought

Sovereign AI Security Node R1

On-premises sovereign AI infrastructure for secure code analysis, agentic-AI evaluation and private cybersecurity workflows.

SKOPION Sovereign AI Security Node is a planned, controlled research and development programme. Reference Node R1 defines a professional workstation target architecture for reproducible local AI, software-security and assurance workloads with human validation.

Reference Node R1 is a target architecture, not a system currently owned. SKOPION does not claim ownership of the named components or a partnership with or endorsement by their manufacturers. Equivalent professional platforms remain explicitly in scope.

Who the pilot is for

  • Technology partners evaluating workstations, GPUs, CPUs or platforms
  • SMEs and public organisations with tightly bounded, authorised AI-security use cases
  • Research and engineering partners interested in defensive, reproducible validation

The problem

Sensitive source code, incident data and evidence do not always belong in external AI services. Large local models, long contexts, deterministic security tools and agentic test environments also need a robust, isolatable platform. R1 measures where local processing creates genuine value without replacing evidence with model opinion.

Reference Node R1 — target architecture

The configuration is a measurable starting point for the pilot, not a purchase or ownership claim. Equivalent professional components can be compared against the same gates.

  1. R1 · 01

    CPU

    AMD Ryzen Threadripper PRO 9985WX, 64-core class, or an equivalent professional workstation platform for compilation, parallel analysis and CPU fuzzing.

  2. R1 · 02

    GPU

    1 × NVIDIA RTX PRO 6000 Blackwell with 96 GB ECC VRAM as the reference target for local inference and model adaptation; 96 GB Max-Q as a power-efficient alternative.

  3. R1 · 03

    System memory

    256 GB DDR5 ECC RDIMM as the target for long contexts, parallel tools, vector data and reproducible test runs.

  4. R1 · 04

    Storage

    2 TB NVMe for system and toolchain plus 8 TB NVMe for models, datasets and evidence — or an equivalent securely segmented high-speed layout.

  5. R1 · 05

    Network

    10 GbE target for controlled data movement, backup and lab integration; no uncontrolled remote access.

  6. R1 · 06

    Operating systems

    Ubuntu 24.04 LTS as the primary research base; Windows 11 Pro / WSL2 only where tooling or compatibility requires it.

Real R1 workloads

Every workload remains defensive, authorised in writing and measurable. GPU support does not replace CPU fuzzing, deterministic tooling or human review.

A · Local AI

Local LLM inference, 70B-class models where architecture and quantisation permit, long-context evaluation, embeddings, reranking and private RAG.

B · Secure Software Analysis

Source-code analysis, deterministic-tool correlation, automated triage and controlled software quality and security research.

C · Fuzzing Support

CPU performs compilation and parallel test runs; AI assists crash clustering, harness analysis, triage and prioritisation. No published exploit-development workflow.

D · Agentic AI Assurance

Authorised evaluation of tool-use safety, prompt-injection resistance, excessive agency, RAG safety and human-in-the-loop controls.

E · OSINT / EASM / Incident Analysis

Public-source correlation, document classification, evidence structuring and defensive incident-support workflows.

F · Specialised Model Adaptation

LoRA and QLoRA experiments where technically appropriate, plus domain embeddings, rerankers and classifiers.

Sovereign-by-design principles

Data minimisation

Only data required for the approved assessment or benchmark purpose.

Controllable processing

Documented storage, provider dependencies, network paths and deletion rules.

Portability

Evidence, configuration and results should be available in open, exportable formats.

No hidden reuse

No unagreed training on partner data and no cross-client data mixing.

Human in the loop

Model output is a signal, not proof. Relevant findings require deterministic correlation, reproduction and negative controls.

180-day pilot

  1. Phase 1 · Baseline & Hardening

    Deployment, isolation, documented configuration, reproducibility and baseline measurements.

  2. Phase 2 · Local AI

    LLM/VLM inference, context, memory behaviour, data locality and controlled quality measurement.

  3. Phase 3 · Software Security

    Secure code analysis, deterministic-tool correlation and triage workloads.

  4. Phase 4 · Agentic AI

    Authorised multi-agent and tool-use assurance with stop rules and human approval.

  5. Phase 5 · Optimisation

    Performance, power, stability, thermals and reproducibility.

  6. Phase 6 · Report

    Benchmark report, architecture conclusions, safe demonstrator and — only if jointly approved — an anonymised case study.

Measurable R1 gates

A demonstration is not a success criterion. Measurement plans, datasets and boundaries are defined in advance; results include uncertainty and negative controls.

  • Reproducibility of configuration, test data and results
  • Latency, throughput and resource use per defined workload
  • Stability, power draw and thermal behaviour over sustained runs
  • Demonstrable data locality and controlled network paths
  • False-positive rate and cycle-time gain from AI-assisted triage
  • Compatibility and architecture feedback backed by traceable evidence

Technology partnership

We are seeking partners for a professional, time-bounded evaluation framework. Purpose, loan or contribution model, ownership, permitted testing, data, publication and return terms are agreed in writing before technical work.

Possible models

  • Evaluation workstation
  • Evaluation GPU, CPU or platform
  • 180-day loan
  • Component contribution
  • Project pricing
  • Technical validation
  • Jointly approved case study

What SKOPION can deliver

  • Reproducible benchmark results
  • Compatibility, stability and architecture feedback
  • An anonymised case study after joint approval
  • A safe technical demonstrator
  • Public acknowledgement only after written approval

Requirements

  • Named business and technical contacts
  • A clear evaluation scope with ownership, duration and return terms
  • Willingness to review evidence, provide feedback and support controlled re-tests

Explicit boundaries

  • No unauthorised or production-disrupting testing
  • No autonomous blocking, changes or enforcement in partner systems
  • No customer data, credentials or unpublished vulnerabilities as partner deliverables
  • No uncontrolled remote access and no exclusivity without a separate contract
  • No promises of zero-days, finding counts or payouts
  • No funding, programme, ownership or partnership claim without published confirmation