Joint Reference Architecture · Wand AI x Protopia AI

Maximizing Sovereign AI ROI through confidential inference.

Wand AI runs the sovereign agentic stack and attaches it to sovereign compute. Protopia AI keeps the data sovereign across every layer, so every ministry, agency, and business in the nation can run its most sensitive workloads on one shared sovereign backend, at full utilization, with plaintext never leaving the trust boundary.

01 / The Problem

Real sovereignty needs the whole stack on sovereign soil.

The agentic layers can be sovereign, but the moment an agent sends sensitive data to a model, that plaintext is exposed across the serving environment, in logs, caches, GPU memory, and traces. So to keep each data owner’s secrets apart, nations fragment the backend into a stack per ministry, leaving the national compute investment idle.

The choice becomes an isolation tax on the build, or data that is sovereign in name, not in fact.

02 / The Solution

One sovereign backend. Every data owner. No plaintext at the host.

Wand AIsovereign agentic stack
Adaptive RouterWand · picks the model
Protopia SGTinference privacy
Any modelone sovereign backend

SGT transforms at the dispatch seam, so the host only ever sees protected representations.

Leg 1 · Inference Privacy

Stained Glass Transform™ alone, across the sovereign backend. Lights up every model immediately, no enclave required.

Leg 2 · Confidential Inference

SGT with Confidential Computing for a sovereign model on the compute base. Together they form the zero-trust AI factory.

Stained Glass Transform can be complemented with Confidential Computing, but does not depend on it.

03 / The Impact

The whole stack on sovereign soil, data plaintext-free across every layer.

End to end

the whole stack on sovereign soil, data plaintext-free across every layer

80%+

GPU utilization on shared sovereign capacity, up from roughly 25%

80–90%

lower infrastructure cost, because models served on protected representations share one backend instead of carving it into coarse-grained per-owner silos

Every workload

every ministry’s most sensitive workloads on one sovereign backend, at the lowest cost per outcome

Better Together

Wand turns the stack into sovereign labor. Protopia keeps the data sovereign across every layer.

Wand AI brings

Country-level governance, the hybrid human-AI OS, certified AI labor, and autonomous agents, attached to the sovereign compute base. Leadership across every agentic layer of the stack.

Protopia AI brings

The inference privacy layer across the data path, the SafeCLAW subagent in the agent layer, and the two-leg deployment that lets every ministry share one high-utilization sovereign backend, plaintext-free.

Protopia AI

Part of the NVIDIA AI Factory for Government reference design · native to NVIDIA NIM and Nemotron · deployed with the U.S. Army and U.S. Air Force.

Wand AI

Production deployments with Global 500 enterprises and government institutions · 40+ foundational patents on the agentic workforce.

Drill-Down / Where SGT Plugs In

One seam. Every model private.

Wand’s Adaptive Router already reduces every call to a single dispatch seam. That seam is where Protopia SGT plugs in, so every model in the Open Model Registry becomes usable on sensitive data, full fidelity, with no plaintext at the host.

Wand agent harnessOS, AI labor, agents, the executor loop
SafeCLAWProtopia · private tool-use
Adaptive Router + dispatchcapability floor, then quality / cost
Protopia SGT transformprotected representation
Sovereign backendmodels never see plaintext

Two Protopia technologies, in blue: SafeCLAW inside Wand’s agent harness for private tool-use, and SGT at the dispatch seam for every model call.

The Open Model Registry, made private

The Open Model Registry holds the sovereign models on the backend, all self-hosted on sovereign soil. SGT makes privacy a capability flag on each row, so one shared backend can serve every data owner:

model_idRuntimePrivate (no plaintext at host)
nemotron-3-superNVIDIA NIMvia SGT · available today
llama-3-70bself-hosted vLLMvia SGT · available today
mistral-largeself-hosted vLLMvia SGT · on request
gemma-2-27bself-hosted vLLMvia SGT · on request

Illustrative rows. A transform is trained once per model; the Nemotron and Llama families are available today; transforms for other models are created on request.

Why it matters: even a self-hosted sovereign model exposes plaintext in the serving environment, to the backend operator, and to the other tenants sharing the capacity. SGT transforms each data owner’s calls before they reach the shared backend, so every model stays private to its owner. The router still picks on quality and cost, and SGT lowers the cost side too: models served on protected representations share one backend without coarse-grained per-owner isolation, so privacy and economics point the same way.

Three integration points

Capability flag

Privacy becomes a stage-one hard requirement, like supports_tools. A sensitive call is filtered to privacy-capable models before cost is considered.

Dispatch transform

Every provider funnels through one shared seam, so a single wrap covers the whole model zoo. Plaintext is replaced before any bytes leave the platform.

No plaintext downstream

The registry keeps API keys out of the database and payloads. SGT extends the same discipline, from no key in the table to no plaintext in the logs.

From a model market to a private model market

The router competes models on measured quality and cost. SGT adds the data dimension: a model served through its transform stays private and consolidates on one backend at lower cost, full fidelity, with no plaintext at the host. Any model joins the private market once its transform exists.