P-00 · Sovereign infrastructure
WHALE
- / Challenge
- Defence and government programmes deploy mission applications without a consistent sovereign layer — deployment, runtime control, data egress, and audit are fragmented or dependent on external platforms.
- / Objective
- Provide a permanent control plane for packaging, deploying, running, and governing any mission application in secure or air-gapped environments — with enforced data boundaries, tamper-evident audit, and doctrine-based decision support.
- / Technologies
- Offline sovereign bundlesRuntime posture governanceData boundary enforcementHash-chained audit ledgerDoctrine engine
- / Intended outcome
- Mission applications run under a single sovereign layer with verifiable audit trails, blocked egress, and one-click rollback — without cloud or external dependencies.
/ Product tiers
WHALE ships as two product tiers. CORE lands the platform on a single site. POD adds fleet scale, observability, hardened supply chain, and commercial support.
WhaleOS CORE
The sovereign operating system for one classified or air-gapped site — deploy mission applications, enforce data-boundary posture, and maintain a tamper-evident audit chain without a platform license fee.
WhaleOS POD
For organisations operating multiple sovereign sites or requiring fleet-scale trust — central package distribution, cross-site observability, hardened supply chain, accreditation evidence, and commercial SLA.
| / Area | WhaleOS CORE | WhaleOS POD |
|---|---|---|
| Scope | One sovereign site — offline or air-gapped | Multi-site fleet with central governance |
| Platform license | No platform license fee | Platform license with commercial SLA |
| Command Center | Deploy, run, govern, and audit from a single surface | Everything in CORE, plus fleet-wide visibility |
| Sovereign bundles | Offline packages with manifest, checksum, and rollback | Central package catalog across sites via Whale Registry |
| Data boundary | Enforced egress policy and routing rules per site | Fleet-wide mesh visibility and enhanced boundary control |
| Audit & governance | Hash-chained ledger, verify, export — single site | Fleet aggregation and accreditation-grade evidence export |
| Doctrine engine | Written doctrine → governed recommendations, human approval | Included — decision replay across fleet audit trails |
| Observability | Runtime health and posture for one cluster | Whale Observatory — fleet metrics, logs, and alerts |
| Supply chain | Signed bundles with SBOM verification | Hardened, near-zero-CVE, and FIPS-validated images |
| Accreditation | Audit evidence export for local assessors | ATO artifact pack — SCTM, SSP, diagrams, evidence bundle |
| Support | Community and best-effort Core updates | 24/7 named support with response SLAs |