12 sovereign AI credential entry points · 8 credential priorities · 6 DEFONEOS MCPs · 33-agent BFT council attestation backbone
The DEFONEOS-SEAL is the cryptographic credential issued by the 33-agent Byzantine Fault Tolerant (BFT) defence council to certify that an AI system, model, or decision chain meets the DEFONEOS sovereign governance standard. It is the crown jewel credential of the DEFONEOS ecosystem — the proof that a system is "sovereign by design — audit-grade, signed, neutral." The SEAL is governed by a 33-agent BFT council (quorum 23/33, Ed25519 / RFC 8032), backed by a human-owner seat (Nick Templeman, SC-cleared), and requires every issuance to pass a full council vote with cryptographic attestation. The credential ecosystem spans: UK AISI (AI Safety Institute) evaluation alignment, NATO STO / DSRB certification interoperability, JSP 936 (MOD AI governance) compliance mapping, Cyber Essentials Plus attestation chain, OWASP ASI (AI Security) compliance, C2PA content provenance signing, EU AI Act high-risk system credentialing, and ISO/IEC 42001 (AI Management System) alignment. DEFONEOS delivers the UK's first open-source sovereign AI credential framework — BFT-governed, Ed25519-signed, curl-verifiable, and immutable on a sovereign ledger.
All SEALs are BFT-signed (Ed25519 / RFC 8032 / 2026-Q3 rotation) and curl-verifiable. Per-entry contacts sourced from CSOAI.org governance registry (2026-Q1).
| # | Entry point | Location | Function | DEFONEOS fit |
|---|---|---|---|---|
| C1 | UK AI Safety Institute (AISI) | London | Frontier model evaluation · safety testing · red-teaming | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — evaluation attestation + safety evidence chain |
| C2 | NATO STO (Science & Technology Organization) | Neuilly-sur-Seine, FR | Allied AI standards · interoperability · dual-use certification | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — allied certification attestation + interoperability evidence |
| C3 | NATO DIANA (Defence Innovation Accelerator) | London / Halifax | Dual-use AI challenge acceleration · start-up pipeline | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — accelerator credential attestation + innovation evidence chain |
| C4 | MOD DSA (Defence Science Advisor) | London / Porton Down | MIL-AI governance · JSP 936 oversight · operational safety | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — JSP 936 compliance chain + operational safety attestation |
| C5 | NCSC (National Cyber Security Centre) | London / Cheltenham | Cyber Essentials Plus · AI security guidance · CNI protection | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — security attestation + CE+ evidence chain |
| C6 | IARPA / Five Eyes AI Security Liaison | Langley / London Liaison | Five Eyes AI threat intelligence · allied red-teaming | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — allied threat intelligence attestation + joint assessment chain |
| C7 | IASME Consortium (Cyber Essentials Delivery) | Rugby | Cyber Essentials / CE Plus assessment · certification delivery | DEFONEOS MCPs: sovereign-keystore · data-gov-uk-mcp — CE assessment evidence + certification provenance chain |
| C8 | Information Commissioner's Office (ICO) | Wilmslow / London | UK GDPR · data protection · AI fairness oversight | DEFONEOS MCPs: bft-council-probe · data-gov-uk-mcp — GDPR compliance attestation + DPIA evidence chain |
| C9 | Centre for Data Ethics & Innovation (CDEI / DSTA) | London | AI ethics framework · algorithmic transparency standard | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — ethics attestation + transparency evidence chain |
| C10 | BSI / CEN-CENELEC (AI Standards) | London / Brussels | ISO/IEC 42001 · EU AI Act standards harmonisation | DEFONEOS MCPs: sovereign-keystore · bft-council-probe — standards compliance attestation + harmonisation evidence chain |
| C11 | DASA (Defence & Security Accelerator) | London / Harwell | Defence innovation funding · dual-use technology pipeline | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — innovation grant attestation + project evidence chain |
| C12 | CSOAI Governance Registry (Internal) | csoai.org | 33-agent BFT council · SEAL issuance · credential lifecycle | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — SEAL issuance + lifecycle attestation + revocation chain |
| # | Priority | Owning body | DEFONEOS MCP coverage | Alignment cross-walk |
|---|---|---|---|---|
| CP1 | 33-agent BFT council vote integrity (quorum 23/33) | CSOAI Registry | bft-council-probe · sovereign-keystore | Council vote evidence chain · quorum attestation · veto logging |
| CP2 | Ed25519 cryptographic SEAL signing & rotation | CSOAI Registry | sovereign-keystore · bft-council-probe | Key rotation evidence · signature chain verification · revocation attestation |
| CP3 | JSP 936 compliance mapping & MOD alignment | MOD DSA | bft-council-probe · sovereign-keystore | JSP 936 evidence chain · operational safety attestation · lifecycle review |
| CP4 | AISI frontier model evaluation attestation | UK AISI | bft-council-probe · sentinel-hub-mcp | Evaluation attestation · safety benchmark evidence · red-team result chain |
| CP5 | Cyber Essentials Plus security chain | NCSC / IASME | sovereign-keystore · bft-council-probe | CE+ assessment evidence · boundary attestation · vulnerability scan chain |
| CP6 | OWASP ASI (AI Security) compliance | OWASP / NCSC | bft-council-probe · sovereign-keystore | ASI checklist attestation · model card evidence · threat model chain |
| CP7 | EU AI Act high-risk system credentialing | CEN-CENELEC / ICO | data-gov-uk-mcp · bft-council-probe | High-risk classification attestation · conformity evidence · CE marking chain |
| CP8 | ISO/IEC 42001 AI management system alignment | BSI / ISO | sovereign-keystore · bft-council-probe | AIMS compliance attestation · audit evidence chain · continuous improvement chain |
| MCP server | Capability | Credential use case |
|---|---|---|
| bft-council-probe | BFT consensus & evidence attestation | Council vote evidence chain · SEAL issuance attestation · quorum verification · veto logging |
| sovereign-keystore | Ed25519 cryptographic provenance | SEAL signing · key rotation evidence · signature verification · credential revocation chain |
| data-gov-uk-mcp | Government open data integration | Standards registry data · ICO compliance evidence · CDEI transparency statistics |
| ons-statistics-mcp | ONS demographic & economic statistics | AI adoption statistics · sector benchmarking · credential impact analytics |
| companies-house-mcp | Corporate intelligence | Vendor due diligence · credential holder verification · corporate governance chain |
| sentinel-hub-mcp | Satellite & geospatial intelligence | Evaluation environment monitoring · sovereign infrastructure attestation · deployment provenance |
| Red line | Why |
|---|---|
| No DEFONEOS-SEAL issued without 33-agent BFT council vote (quorum 23/33) | Byzantine fault tolerance — no single agent or human can issue a SEAL without council consensus |
| No SEAL issued for kinetic-targeting or personal-surveillance systems | DEFONEOS hard stop — the SEAL must never certify systems that violate human rights or international law |
| No credential backdating or post-hoc modification — SEALs are immutable | Audit integrity — any SEAL modification requires revocation + re-issuance with full council vote |
| No SEAL issued without human-owner seat activation (Nick Templeman, SC-cleared) | Human-in-the-loop governance — the owner seat must be live for any SEAL issuance or revocation |
| No "AUKUS partnership" or "DAIC certified" claim without a signed letter on file | Provenance integrity — alliance claims must be backed by documentary evidence, not implied |
| Buyer type | Primary entry point | Hook | 30-day pilot cost |
|---|---|---|---|
| UK AISI Evaluation Director | C1 UK AISI | Frontier model evaluation attestation + safety evidence chain | £3,200 |
| MOD DSA / JSP 936 Lead | C4 MOD DSA | JSP 936 compliance mapping + operational safety attestation | £3,200 |
| NCSC AI Security Lead | C5 NCSC | CE+ security chain + AI governance attestation | £3,200 |
| NATO DIANA Programme Manager | C3 NATO DIANA | Accelerator credential + dual-use certification chain | £3,200 |
| ICO AI Governance Lead | C8 ICO | GDPR compliance attestation + DPIA evidence chain | £3,200 |
| DASA Innovation Lead | C11 DASA | Innovation grant attestation + project evidence chain | £3,200 |
curl -sI https://www.csoai.org/defoneos-seal-credential-governance-pack.html | head -5
# Expected: HTTP/2 200
curl -sI https://www.csoai.org/defoneos.html | head -5
# Expected: HTTP/2 200
All DEFONEOS credential surfaces are curl-verifiable, BFT-signed, and sovereign-deployed on UK infrastructure.