Capability Brief // Human-AI Teaming Lab Aug 2026
Capability Brief  //  Space Systems Command

AI That Survives (And Thrives) During

Scenarios: a total comms blackout, GPS jamming and spoofing, a nation-state cyber attack, contested, denied spectrum, a coronal mass ejection, an orbital debris cascade, electronic warfare, a poisoned-data attack, a severed uplink, a geomagnetic storm, and a supernova.

A working platform with a swappable brain. It runs on your hardware, inside your perimeter, with nothing leaving the building. Hardened for jamming, intrusion, blackout, and whatever the sun decides to do next.

Prepared for MD S. "Doc" Rana  ·  Director, Human-AI Teaming Lab
Space Systems Command  ·  Introduced by Tony Swantek
Scroll
01  //  Posture

Three properties, decided before the first line of code.

Every choice in this architecture traces back to one of these. They are not features that got added. They are the reason the thing is shaped the way it is.

Resilient

Degraded, denied, disconnected. The system assumes all three are the normal case, not the exception. No external dependency sits in the critical path.

Private

Data stays inside the perimeter. No identifiers in the payload, no telemetry leaving, no third party holding a copy of what your people asked.

Intelligent across systems

The value is not one answer. It is one grounded picture, assembled from sources that never talked to each other, cited back to what your unit already wrote.

Speed only counts if the call is right, and only if the tool is still standing at the moment it is needed. Everything here is built to that second half.

02  //  What exists today

A live platform, in production, with real users on it.

Not a prototype, and not a pitch to buy a subscription. What matters is how it is built, because that is what makes it portable into your environment.

Interface

Chat assistant

A conversational surface operators already understand, grounded in the organization's own material rather than the open internet.

Ground truth

Knowledge base

A curated, permissioned source of truth. Answers come from it, and the answer shows what it came from.

Ingestion

Document search

Bulk processing and retrieval across large document sets, so a question about policy returns the policy, with the citation attached.

Control

Permissions & admin

Role-based access, user management, and an administrative layer built for a real organization rather than a demo account.

Unattended

Workflow automation

Scheduled and triggered jobs running against the same AI layer without a human in the loop, on the same permissions model.

Architecture

One AI adapter

Every model call routes through a single integration point. The model is an address the system points at, not a dependency baked through the code.

03  //  The swap

The brain is an endpoint, so it comes out.

Every provider runs through one adapter. Pointing the platform at a model on your hardware is a small, checkable change, not a rebuild. Model selection stays a deployment decision, which means we build to your approved list instead of arriving with a favorite.

PLATFORM Chat assistant Knowledge base Document search Workflows & admin Automations ONE ADAPTER single integration point Cloud API how it runs commercially today Local model, your hardware your environment, your approved list nothing leaves the building

If provenance matters, and we assume it does, there are options that publish training data and not just weights. That is your call to make, and the architecture is built so it stays your call.

04  //  Resilience

Hardened for cyber attacks, supernovas, and everything in between.

The threat list looks wildly different top to bottom. The engineering answer is the same every time: nothing outside the room is allowed to be load-bearing.

PROMPT INJECTIONPoisoned documents, adversarial input
Isolated at the adapterRetrieval is limited to a permissioned corpus. Untrusted content is data to report on, never instruction to follow.
TAMPERING & EXFILWeight substitution, spoofed feeds, someone inside the wire
Known weights, no outbound pathYour models, on your storage, behind an authentication layer. No third-party call to intercept and no vendor account to compromise.
JAMMING & DENIALContested spectrum, degraded link
Inference is already localThe console never phones out for an answer. A tool that lives in a data center fails exactly when the fight starts.
FULL BLACKOUTCable cut, uplink gone
Runs on the box in the roomIndefinitely, and without degradation. Reconnection is for updates, not a condition of operating.
SPACE WEATHERSolar events, debris cascade, orbital loss
Nothing assumes an uplink survivesWhen the constellation is the system under stress, decision support cannot be one more thing waiting on it.

Give us a week and we will show it answering from its knowledge base with the network physically disconnected. Live app, cable pulled, still working.

05  //  Privacy

Private by construction, not by policy.

A privacy promise you have to trust is worth less than an architecture where the data physically has nowhere else to go. We build the second kind.

Inference stays on your metal

Models are served from hardware in your environment. There is no request that crosses a boundary, which means there is no request anyone else can log, retain, or subpoena.

Anonymous in the payload

In the platform running today, model calls carry no IP address and no user identifiers. The only user data present is the context deliberately injected to answer the question. Verified against the code, not assumed.

Transcription never leaves either

Speech-to-text runs on the same local hardware. Audio from a briefing, a call, or a console session is processed in the building and stays there.

The commercial exhaust comes out

Billing, marketing integrations, analytics, external email. None of it belongs in a government build. Removing it shrinks the attack surface and the data-handling story at the same time.

06  //  Applied intelligence

One picture, pulled across systems that never talked.

The hard part was never generating text. It is getting the right material in front of the model, with the right permissions attached, and delivering the result where the work already happens.

Not a chatbot bolted onto a wiki. One brain reading everything the organization already wrote, and answering from it.

07  //  Design rules

Anything we build follows three rules.

Human-AI teaming, not human replacement. The AI eats the firehose. The human makes the call.

RULE 01

Less on the operator's plate

If a tool adds a screen someone has to read, it made the job worse. Output arrives inside the workflow that already exists, or it does not ship.

RULE 02

Honest confidence

The system states how sure it is, and that number has to be true. A tool that says ninety-five percent and is wrong a third of the time is worse than no tool, because now the human trusts it.

RULE 03

The model is a target

Poisoned data, spoofed feeds, prompt injection. We design assuming someone is attacking the AI itself, because eventually someone will be.

08  //  The work

What we could build for the lab.

Custom builds inside your environment, in the family of tools Space Systems Command has already funded and already said it needs.

Onboarding

Knowledge assistants for units without one

Policy, training, benefits, and jargon answered from your own documents, with the source shown every time.

Throughput

Admin & documentation automation

Built to the standard that actually matters: the person does not have to go back and double-check the output.

Acquisition

Contract & proposal analysis

Digging through large paperwork sets and surfacing what matters, with stated confidence, for a contracting staff stretched thin.

Decision support

Interfaces that show their certainty

Screens that carry an honest confidence signal, not just an answer, so the operator trusts the tool the right amount in both directions.

NOT OUR LANE  //  orbital tracking, sensor fusion, or anything requiring a cleared facility.

09  //  Straight talk

What stands between today and a government deployment.

Three pieces of real work. Naming them here is the point, because a vendor who only lists upsides is a vendor you have already met.

KNOWN WORK · ~1 WEEK

Document search needs a local model

That piece currently calls a cloud service. Swapping in a local one is solved work, but it means re-processing the documents. A week, not a footnote.

BIGGEST SINGLE PIECE

The database layer must be self-hosted

Built on an open-source stack that supports exactly this, so it is a supported path rather than a science project. Still real work, and the largest item on the list.

MAKES IT SIMPLER

Everything commercial comes out

Billing, marketing integrations, external email. Stripping it reduces the attack surface and shortens the accreditation story.

Two more we will say before you have to ask. It runs in your cloud or on your hardware, never ours. And we would not be the prime. Realistically that is a prototype agreement or a build under someone already on contract, and pretending otherwise would be the fastest way to waste your time.

10  //  Engagement

How we would work with you.

01

Your environment, your rules

Your cloud or your hardware, your approved model list, your provenance bar. Because model selection is a deployment decision in this architecture, we build to your constraints instead of arriving with a favorite.

02

A written spec, tested against

Custom means a requirements document the build gets verified against. We do not agree to scope on a call. We agree to write one, and then we get held to it.

03

Through the right vehicle

An existing contract vehicle, a prototype agreement, or building under a prime already on contract. Whichever one you tell us is real.

The short version: a small team that already ships production AI, already runs its own models on its own hardware, and already has most of the thing built.

11  //  Who we are

Two people. Production AI, already in the field.

We build robust, cutting-edge AI systems that have to survive contact with a real environment, not a demo. The model layer is the last decision, not the first.

Operator

Kim Garst

Builds and runs production AI products with real users on them. Owns the relationship, the requirements, and the question that actually matters: does the operator use it, or does it sit on a slide.

Builder

Matt Johnston

Ships the systems end to end, no agency overhead. Already running local inference and transcription on his own hardware, daily, which is why disconnected is a working posture instead of a future promise.

01

Ship the hard part first

Interface, knowledge, permissions, workflows. A year of production work, already done, already used. The AI brain is an endpoint we point at whatever you approve.

02

Build as if it will be attacked

Poisoned data, severed uplink, jammed spectrum. Nothing outside the room is load-bearing, and commercial exhaust never enters the government build.

03

Stay small on purpose

No agency layers, no account team between you and the people writing the code. A written spec, then we get held to it.

Introduced by Tony Swantek. If this leaves the room, those are the two names attached to it.

The ask

Twenty minutes on the workflow eating the most Guardian hours.

We are not here to demo a product. We are here to find out what is actually broken, and whether it is the kind of thing we can build.

Q1What workflow is eating the most Guardian hours right now?
Q2When the lab evaluates a tool, what does intake look like, and who has to sponsor it?
Q3If you wanted to move on something this fiscal year, is there a vehicle already in use?
Q4What environment would it have to live in, and what are the rules on where models come from?
Q5How much of what you are looking at has to run disconnected, versus assuming a network?
Next step  //  a second conversation with a specific problem attached
Capability Brief  ·  Prepared for the Human-AI Teaming Lab  ·  August 2026