Sovereign edge · Advanced materials and process manufacturing
The AI layer over your process line should not live in someone else's cloud.
A manufacturing scale-up runs on data it cannot publish: the recipe, the accepted parameter window, the inspection imagery, the yield history. Each one is a trade secret, and together they are the process know-how that makes the product hard to copy. NGARi runs the agent and evidence layer that keeps that thread linked — on hardware you own, with no outbound calls.
What actually crosses the wire
An orchestration layer that reads across a production line has to read the line. When that layer is a hosted service, the recipe, the parameter window, the inspection imagery and the yield history all travel to somebody else's infrastructure and sit under somebody else's terms. For most industries that is a policy question. For advanced materials it is the asset.
The recipe and the window
The process parameters that produce the material, and the range each one is allowed to sit inside. This is the part of the company that is not written down anywhere public.
The inspection record
What each unit looked like when it came off the line — the imagery and the measurements taken from it — and which units failed and why.
The run history
Every run, its parameters and its yield. Individually it is a log; together it is the correlation the process team has been carrying in their heads.
If your AI layer reads it, your AI layer holds it. The only version of this that a security review can approve without an argument is the one that never leaves the building.
Where the layer sits
NGARi does not replace a single tool on your line. It is the layer above them: agents that call tools you authorize, on a machine you own, and a record of everything they did.
| Stage of the thread | What you already run | What NGARi adds |
|---|---|---|
| Process run | Your furnace, sensors and run log | Reads telemetry through a tool you authorize, and records the read |
| Inspection | Your camera or microscope and your QC technicians | A written inspection policy applied consistently, with the result pinned to the image record |
| Correlation | Your run history in spreadsheets and notebooks | A ranked account of which parameters move with yield, and how strongly |
| Drift | Baselines your process engineers hold in their heads | Every run checked against the accepted window, with the distance from it stated |
| Evidence | Tickets, mail threads and shift notes | One hash-chained ledger: run to inspection to parameter to conclusion |
The thread is the product. A tool can pass its own checks while the line still carries risk that no single tool was asked to look for.
What runs today, and what a pilot adds
This is the honest split, because a production line cannot afford to discover it during an evaluation.
| Capability | Where it stands |
|---|---|
| On-premises inference and agent runtime, Apache 2.0 | Runs today |
| Sandboxed tool execution against an allow-list | Runs today |
| Hash-chained audit of every agent action | Runs today |
| Deterministic parameter-to-yield ranking and window drift checks | Runs today |
| A written inspection policy applied to image measurements | Runs today |
| A trained vision model tuned on your own inspection imagery | Pilot scope — built on your data, with you |
| Read connectors into a named plant system | Pilot scope — scoped and tested with you |
| Driving a named furnace or imaging tool end to end | Pilot scope — your process team stays in charge |
| Measured defect-detection accuracy against your experts | Not claimed — no measurement exists yet |
| Yield improvement on your line | Not claimed — we hold no baseline |
We would rather show you this table than a logo wall. The left column is what we can demonstrate this week; the pilot column is what we build with you against your own line.
The evidence chain is the product
A run that cannot be reconstructed a year later is a run nobody can defend — to a customer, an auditor or a grant program. Every action the layer takes is written to a hash-chained ledger that stays on your premises, so the answer to "what happened to this batch, and why?" is a query, not a meeting.
- Runthe parameters that were actually used, read from the source rather than retyped
- Inspectthe policy version applied, the measurements it saw, and the class it returned
- Correlatewhich parameters ranked against yield, with the strength and the sample count
- Driftwhich runs fell outside the accepted window, by how far, and on which parameter
- Closethe change that was made and the run that carries it
- Riskthe things the layer could not settle, stated as open items rather than buried
Each run is pinned by a run index as well as a chain, so a record cannot be quietly rewritten after the fact: editing an entry breaks the chain at that point, and rewriting the whole chain breaks the index that recorded its fingerprint. The ledger is a property of the deployment, not a promise from a vendor — it survives the people who were in the room.
How it runs
Free kernel, or a flashed appliance
The NS-BOS Kernel is Apache 2.0 and free: it orchestrates inference, runs the agent lifecycle, encrypts data at rest, keeps the hash-chained audit trail, and sandboxes agent actions. It is Linux, Python 3.10+, and you supply the model. If you would rather not run a Python environment, NGARi+ is the same stack pre-flashed and verified on NVIDIA Jetson.
Power, not connectivity
The appliance is designed to run with no path to the internet, and the kernel sends no telemetry and makes no outbound calls. That is what makes it usable next to a furnace: it can sit in the plant, on the bench the process team already uses.
| NGARi+ Nano | $999 · Jetson Orin Nano Super, 8 GB |
| NGARi+ Orin | $4,999 · AGX Orin 64 GB, 275 TOPS |
| NGARi+ Thor | $8,999 · AGX Thor 128 GB, 2,070 TFLOPS |
What we will not claim
- We have not deployed this on a live production line. The engines run against a plant model; a line deployment is pilot work, done on your premises.
- We do not quote an accuracy number we have not measured. A defect-detection figure means nothing until it is scored against your own experts on your own imagery.
- We do not claim a yield improvement. Correlation is not causation, and a yield lift is a customer result, not a vendor slide.
- The inspection engine we ship is a reference policy, not a trained model. It is a written set of thresholds a person can read and argue with; the trained model is built during a pilot, on your data.
- We do not connect to a system we have not scoped and tested. If a connector does not exist yet, we say so and it becomes pilot work.
- We do not hold certifications we have not stated. SOC 2 Type I readiness is in progress; we show the current state rather than a report we do not have.
- We do not ask you to send us your process data to evaluate this. The evaluation happens on your premises, or it does not happen.
Questions from the plant floor
Is this a trained AI model that inspects our units?
No. The inspection engine that ships is a reference policy: a versioned, human-readable set of thresholds applied to measurements taken from the image, and it records that it is a policy rather than a model. A trained model on your imagery is real pilot work, and we will tell you when it exists and what it scored — not before.
Do you connect to our historian, MES or LIMS today?
Not out of the box, and we will not pretend otherwise. The kernel supports sandboxed tool execution and agent workflows today; a named connector into your historian, MES or LIMS is scoped, built and tested with you as part of a pilot.
Can a local model do useful work here?
For reading run logs, applying a written inspection policy, ranking parameters against yield and keeping the evidence linked: yes, and it runs today. For open-ended process judgement in place of your engineers: no, and we will say so in the room. The point of sovereignty is that the trade is yours to make, not that it does not exist.
Does anything leave the machine?
No outbound calls, no telemetry, no licence check. You can verify that by reading the kernel or by running it with the network down. There is no account to create.
What does a pilot look like?
Four to six weeks, one line, one process question that matters, on your premises or a machine we leave with you. You get the working loop, the ledger for it, and a written account of what the layer did and did not catch — including the parts it could not settle.
Why not just use a cloud service with a data agreement?
Because the agreement protects the data contractually, and the architecture protects it physically. If the recipe and the yield history are the moat, the version that never leaves the building is the one that does not need to be defended after the fact.
Start with one run you have already inspected by hand.
Bring us a run your team has already assessed. We will take it through the sovereign layer, on your premises, and show you the ledger — or tell you plainly that it is not a fit yet.