Solutions — sector
Airgapped is a control, not a deployment note.
The sector that asks the outbound question first and does not accept a policy statement as the answer. Airgapped mode refuses to start if any setting selects a service outside your network — checked at startup, not at first use.
What airgapped actually forbids
- Every outbound path, enumerated
- The connections a deployment could make are listed and probed rather than described. A module that opens a network connection without appearing in that inventory fails the build.
- Refusal at startup
- With airgapped mode set, the deployment refuses to start if any setting selects a service outside your network. Configuration that appears to take effect and does not is the most dangerous state a control can be in.
- And what you give up, stated
- External anchoring is an outbound path, so airgapped mode forbids it — which means integrity rests on trusting the operator. The platform says that rather than quietly dropping the property and leaving the claim standing.
No model is called on any code path, airgapped or otherwise. That is asserted by a test which fails the build if a model provider appears in the dependency graph, and it is a stronger claim than having an AI feature.
Equity, and the vocabulary problem
Which attributes may lawfully be used for bias testing is set by the jurisdiction, not by us, and the categories differ between them — caste is a recognised ground of discrimination in some jurisdictions and is neither protected nor lawfully collectable in the EU. A profile carries the attributes, the legal basis for each and the conditions attached, and the platform distinguishes conditions it enforces from ones it can only record.