Sovereign edition

Your data never
leaves your network.

Air-gapped, on-premises SDCStudio for organizations that require complete data sovereignty. Local inference, local cryptographic signing, no cloud dependencies.

Requesting an evaluation means agreeing to the Evaluation License Agreement.

sdcvalidator on PyPI SDCRM specification Air-gap capable ECDSA P-256, local keys BFO · ISO/IEC 21838-2

Built for sovereignty

Every component runs inside your network

No telemetry, no cloud calls, and no data-exfiltration vector. The evaluation is designed so your security team can confirm that rather than take our word for it.

Isolation

Air-gapped deployment

Delivered as a self-contained package with no outbound connections required at any point. Operate on classified networks, in SCIFs, or anywhere data must never cross the perimeter.

Inference

The local LLM of your choice

Semantic modeling runs against a local model, open or private, on your preferred runtime such as vLLM or Ollama. All inference stays on your hardware. No prompt and no data reaches an external API.

Signing

Local ECDSA P-256

Sign and verify data models with keys that never leave your infrastructure. No cloud HSM in the path, and no dependency on us being reachable.

Reasoning

GraphDB with OWL 2 RL

Graphwise GraphDB as the enterprise triplestore, with OWL 2 RL reasoning, SPARQL 1.1 and automatic inference over your knowledge graph.

Identity

LDAP authentication

Authenticate against the Active Directory or OpenLDAP you already run. No external identity provider is required.

Operations

Docker Compose, not Kubernetes

Single-command deployment. Reproducible, auditable, and simple enough for any infrastructure team to operate.

What it learns

An assistant you can read, edit and audit

The sovereign assistant accumulates knowledge about your data architecture, components, workflows and conventions over time, in human-readable files on your hardware.

No model retraining. Nothing leaves the building. And because what it has learned is a set of files rather than weights, you can open them, correct them, and remove anything that should not be there.

The stack

Ten services, declared in one place

Seven core services in a single Docker Compose file, plus three XMI2SDC conversion services. No Kubernetes. Everything is declared where an auditor can read it rather than discover it.

web

Django on Daphne. ASGI application server with WebSocket support.

celery

Async processing for data parsing and agentic model generation.

celery-beat

Periodic scheduler for maintenance and background operations.

db

PostgreSQL with pgvector, for embeddings alongside the primary store.

redis

Broker and result backend for the task queue.

graphdb

Graphwise GraphDB with OWL 2 RL reasoning and SPARQL 1.1.

nginx

Reverse proxy and static serving at the network edge.

XMI2SDC · three services

Convert UML models exported as XMI, from Sparx Enterprise Architect, MagicDraw and others, into SDC4 models. Five agents run across them: parser, analyzer, mapper, reviewer and assembler. Parsing and mapping run offline; only the assembler calls the Assembly API. Delivered as a separate package on request.

Have your security team try to break it.

The evaluation runs on your hardware, on your network, with the perimeter closed. That is the only test that settles the question.