Engineering & Manufacturing

Deployment Blueprint: A Precision Manufacturer Air-Gaps Its Institutional Knowledge

This blueprint is a representative reference architecture — anonymized and generalized from the industrial deployment patterns we design. No company is named, and no outcome figures are invented.

The situation

A precision manufacturer — aerospace-adjacent, a few hundred engineers, decades old — holds its real competitive advantage in an archive nobody can read end to end: CAD models and drawing notes, engineering change orders, tolerance stack-ups, failure analyses, first-article reports, and supplier terms accumulated over thirty years. That knowledge lives partly in the PLM system and substantially in the heads of senior engineers approaching retirement. It is also exactly the material the company can never paste into a public chatbot: trade secrets whose value depends on secrecy, and — for the defence lines — ITAR-controlled technical data that may not touch unauthorized systems at all.

The constraint

  • ITAR (22 CFR 120–130): controlled technical data restricted to authorized persons and systems; a public AI API is an unauthorized export path.
  • CMMC 2.0 Level 2: the 110 NIST SP 800-171 controls for CUI, including boundary protection (3.13.1) and information-flow control (3.1.3) — the assessed boundary must demonstrably contain the data.
  • DFARS 252.204-7012: safeguarding covered defence information, with incident-reporting duties the company cannot delegate to an AI vendor's terms of service.
  • Trade-secret law: protection requires "reasonable measures" to preserve secrecy; process knowledge flowing through a third-party AI service undermines the claim itself.

The requirement was absolute rather than contractual: the knowledge system must have no path to any external network.

The architecture

Component Choice
Reasoning model GLM-5.2 (744B MoE, 40B active, MIT license), fine-tuned via LoRA on company terminology, part-numbering, and tolerancing conventions
Vision & documents Qwen3-VL over the PLM/CAD archive — drawings, scans, handwritten shop-floor notes, inspection photos
Heavy batch Kimi K3-class capability reserved for a managed cluster tier for large historical-analysis runs, where program requirements permit
Isolation Fully air-gapped enclave: internal mirrors for all packages and weights, checksummed sneakernet updates, deny-all egress with alarmed violations
Access control Per-project and per-program authorization; ITAR data segmented to authorized persons; append-only audit logging
Update cadence Staged transfer process with documented provenance for monthly open-weight releases — a designed process with named owners, not a USB stick

Weights, serving stack, and every dependency were verified and carried across the boundary on approved media; the hardening phase specifically hunted the classic air-gap breakers — model-hub SDK update pings, framework telemetry, license phone-homes — and proved isolation with a flat egress graph at the boundary, not an assurance.

What it unlocks

Institutional knowledge that stops walking out the door. Any authorized engineer can now interrogate thirty years of the company's own record: has this alloy shown this failure mode before; what did we change after the 2014 field returns; which supplier lots drove that tolerance excursion. The answers cite the underlying documents. Retirement stops being an unrecoverable data loss.

Frontier assistance inside the ITAR boundary. Engineers on controlled programs get the same class of AI help as anyone in an unregulated industry — drafting, analysis, design-review preparation — without controlled technical data ever leaving authorized systems. The compliance story for the assessor is one sentence: nothing egresses, because the intelligence came inside.

Overnight archive analysis at zero marginal cost. Digitizing and indexing the scanned backlog, cross-referencing failure analyses against change orders, summarizing supplier histories — batch queues that run on idle hardware for the cost of electricity, continuously deepening the retrieval corpus.

An asset no policy change can revoke. The June 11, 2026 export order that cut foreign access to top US models, vendor deprecations, API repricing — all of it stops at a rack with no network path. The validated model the company owns keeps working until the company itself decides to upgrade it.

The isolation techniques — and the telemetry and license-check gotchas that silently break lesser builds — are detailed in our air-gapped LLM deployment guide; sizing for the reasoning tier is in the Kimi K3 hardware requirements guide. See our engineering and manufacturing practice and air-gapped AI service for the engagement model.

Deployment blueprints are representative reference architectures — anonymized and generalized from the deployment patterns we design. They are not client testimonials.

Questions we get

Frequently asked questions

Can a manufacturer use AI on ITAR-controlled technical data?

Only inside the authorization boundary. ITAR (22 CFR 120–130) restricts controlled technical data to authorized persons and systems, which rules out public AI APIs. An air-gapped open-weight deployment keeps drawings, specs, and process data on authorized systems while still giving engineers frontier-class assistance.

How does AI capture institutional knowledge before engineers retire?

By making the archive conversational. Retrieval over decades of CAD notes, engineering change orders, failure analyses, and supplier documents — with a fine-tuned model that speaks the company's part numbers and tolerancing conventions — lets any engineer interrogate the collective record: what failed, why, and what the fix was. The knowledge stops living exclusively in a few veterans' heads.

Why must this be air-gapped rather than just on-premise?

For ITAR and CMMC Level 2+ environments, the assessed boundary is the control: NIST SP 800-171's boundary-protection and flow-control requirements make 'no path out' the cleanest evidence. Air-gapping also protects trade secrets absolutely — a system that cannot transmit cannot leak — and open weights make it practical, since the models run fully offline.

Is this a real manufacturer case study?

It is a representative deployment blueprint — anonymized and generalized from the industrial deployment patterns we design. No company is named and no productivity statistics are invented; quantitative claims are structural properties, such as overnight batch analysis at zero marginal cost.

Want this architecture, sized to your workloads?

The sovereignty assessment maps your obligations and concurrency, then hands you a written architecture and cost model.

Book a sovereignty assessment Explore industries

New blueprints and briefings, monthly

Deployment patterns, model releases, and regulatory shifts — no hype.

Sovereign-AI briefings, roughly monthly. No spam, one-click unsubscribe.