Joint Reference Architecture · Wand AI x Protopia AI
Wand AI runs the sovereign agentic stack and attaches it to sovereign compute. Protopia AI keeps the data sovereign across every layer, so every ministry, agency, and business in the nation can run its most sensitive workloads on one shared sovereign backend, at full utilization, with plaintext never leaving the trust boundary.
01 / The Problem
The agentic layers can be sovereign, but the moment an agent sends sensitive data to a model, that plaintext is exposed across the serving environment, in logs, caches, GPU memory, and traces. So to keep each data owner’s secrets apart, nations fragment the backend into a stack per ministry, leaving the national compute investment idle.
The choice becomes an isolation tax on the build, or data that is sovereign in name, not in fact.
02 / The Solution
SGT transforms at the dispatch seam, so the host only ever sees protected representations.
Stained Glass Transform™ alone, across the sovereign backend. Lights up every model immediately, no enclave required.
SGT with Confidential Computing for a sovereign model on the compute base. Together they form the zero-trust AI factory.
Stained Glass Transform can be complemented with Confidential Computing, but does not depend on it.
03 / The Impact
the whole stack on sovereign soil, data plaintext-free across every layer
GPU utilization on shared sovereign capacity, up from roughly 25%
lower infrastructure cost, because models served on protected representations share one backend instead of carving it into coarse-grained per-owner silos
every ministry’s most sensitive workloads on one sovereign backend, at the lowest cost per outcome
Better Together
Wand turns the stack into sovereign labor. Protopia keeps the data sovereign across every layer.
Country-level governance, the hybrid human-AI OS, certified AI labor, and autonomous agents, attached to the sovereign compute base. Leadership across every agentic layer of the stack.
The inference privacy layer across the data path, the SafeCLAW subagent in the agent layer, and the two-leg deployment that lets every ministry share one high-utilization sovereign backend, plaintext-free.
Part of the NVIDIA AI Factory for Government reference design · native to NVIDIA NIM and Nemotron · deployed with the U.S. Army and U.S. Air Force.
Production deployments with Global 500 enterprises and government institutions · 40+ foundational patents on the agentic workforce.
Drill-Down / Where SGT Plugs In
Wand’s Adaptive Router already reduces every call to a single dispatch seam. That seam is where Protopia SGT plugs in, so every model in the Open Model Registry becomes usable on sensitive data, full fidelity, with no plaintext at the host.
Two Protopia technologies, in blue: SafeCLAW inside Wand’s agent harness for private tool-use, and SGT at the dispatch seam for every model call.
The Open Model Registry holds the sovereign models on the backend, all self-hosted on sovereign soil. SGT makes privacy a capability flag on each row, so one shared backend can serve every data owner:
| model_id | Runtime | Private (no plaintext at host) |
|---|---|---|
nemotron-3-super | NVIDIA NIM | via SGT · available today |
llama-3-70b | self-hosted vLLM | via SGT · available today |
mistral-large | self-hosted vLLM | via SGT · on request |
gemma-2-27b | self-hosted vLLM | via SGT · on request |
Illustrative rows. A transform is trained once per model; the Nemotron and Llama families are available today; transforms for other models are created on request.
Why it matters: even a self-hosted sovereign model exposes plaintext in the serving environment, to the backend operator, and to the other tenants sharing the capacity. SGT transforms each data owner’s calls before they reach the shared backend, so every model stays private to its owner. The router still picks on quality and cost, and SGT lowers the cost side too: models served on protected representations share one backend without coarse-grained per-owner isolation, so privacy and economics point the same way.
Privacy becomes a stage-one hard requirement, like supports_tools. A sensitive call is filtered to privacy-capable models before cost is considered.
Every provider funnels through one shared seam, so a single wrap covers the whole model zoo. Plaintext is replaced before any bytes leave the platform.
The registry keeps API keys out of the database and payloads. SGT extends the same discipline, from no key in the table to no plaintext in the logs.
The router competes models on measured quality and cost. SGT adds the data dimension: a model served through its transform stays private and consolidates on one backend at lower cost, full fidelity, with no plaintext at the host. Any model joins the private market once its transform exists.