OCTAAR

// ARCHITECTURE

Engineered as readiness infrastructure.

One data model. One audit substrate. Four deployment topologies — managed cloud, customer cloud, on-premise, fully air-gapped — chosen per customer environment, not imposed by the platform.

// REFERENCE DIAGRAM

Edge → Sync → Core → Delivery.

The full data path. On-site capture at the edge, signed transport over the sync bus, calibration and audit at the core, decision-grade delivery upward and outward.

// REFERENCE DIAGRAM · TLS 1.3 · KMS-ISOLATED · CONFLICT-AWARE SYNC · APPEND-ONLY AUDIT

// REFERENCE STACK

An evaluation pipeline, not a software stack.

Mobile collection, secure synchronization, centralized analytics, leadership reporting, and improvement closure — engineered as one mission system, governed by one audit trail.

// 01 · CAPTURE

Mobile field collection

Tablet- and phone-grade observer surface. Offline-tolerant. Conflict-aware sync. Optional device attestation under MDM profiles.

// 02 · SYNC

Secure synchronization

TLS 1.3 transport. Signed payloads. Configurable residency and KMS isolation. Cross-task-force read enforcement at the data layer.

// 03 · CALIBRATE

Calibration pipeline

Rubric-anchored scoring. Inter-observer variance detection. Evaluator-level drift surfaced to the calibration lead.

// 04 · DECIDE

Leadership reporting

Posture, trend, drift. Audit-defensible exports for higher headquarters and inspectors-general.

// 05 · CLOSE

Improvement closure

AAR + assigned action plan. Owners, dates, and re-observation hooks. Findings persist across personnel rotation.

// DEPLOYMENT TOPOLOGIES

Four topologies. One data model.

Same rubric library, same audit substrate, same methodology across deployment options. Customers pick the topology their environment requires; the platform does not impose a choice.

// MANAGEDT+0 days

Managed cloud

OCTAAR-operated SaaS. Customer-isolated tenancy. Fastest time-to-value. ITAR-aware variants on request.

Data KMSAir-gap
// CUSTOMER CLOUDT+14 days

Customer cloud

Deployed into the customer's existing cloud account (AWS GovCloud, Azure Gov, etc.). Customer-owned data and key material.

Data KMSAir-gap
// ON-PREMT+30 days

On-premise

Hardened container deployment behind the customer's network boundary. Customer-controlled upgrade cadence.

Data KMSAir-gap
// AIR-GAPPEDT+45 days

Fully air-gapped

No outbound dependencies. Signed, versioned offline upgrades. Designed for classified-adjacent and SCIF environments.

Data KMSAir-gap

// COMPARISON

What changes across topologies. What does not.

The data model, rubric library, audit substrate, and methodology are identical. Trust boundary, residency, and operations responsibility shift to meet the environment.

CapabilityManagedCustomer cloudOn-premAir-gapped
Data residency controlRegion selectFullFullFull
KMS / key controlOCTAAR-mgmtCustomerCustomerCustomer
Outbound dependenciesOCTAAR-mgmtCustomer auditCustomer auditNone
Upgrade cadenceContinuousContinuousCustomerSigned offline
Time-to-deployT+0T+14dT+30dT+45d
Audit substrateShared schemaShared schemaShared schemaShared schema
Methodology / rubric libIdenticalIdenticalIdenticalIdentical

// PRINCIPLES

The non-negotiables.

Architectural decisions that are the same on day one and on day one thousand — whether the deployment is in cloud, on-prem, or fully air-gapped.

  • One data model.

    Same schema for cloud, on-prem, and air-gapped. Same rubric library. Same audit substrate. No fork.

  • One audit substrate.

    Every score, edit, and closure attributed and timestamped — across topology. Tamper-evident by design.

  • Customer-owned data.

    Data residency, retention, and legal hold are customer choices. The platform follows the policy.

  • Documented continuity.

    99.9% availability target on managed deployments. Published RTO/RPO. Horizontal scaling. Signed, versioned upgrades.

// REQUEST OPERATIONAL READINESS DEMO

Bring us your environment. We will walk the architecture.