DEFONEOS-SEAL CREDENTIAL GOVERNANCE PACK

12 sovereign AI credential entry points · 8 credential priorities · 6 DEFONEOS MCPs · 33-agent BFT council attestation backbone

12Credential entry points
8Credential priorities
33BFT council agents
23/33BFT quorum threshold
£3,20030-day credential pilot

1. WHY THE DEFONEOS-SEAL GETS A DEDICATED PACK

The DEFONEOS-SEAL is the cryptographic credential issued by the 33-agent Byzantine Fault Tolerant (BFT) defence council to certify that an AI system, model, or decision chain meets the DEFONEOS sovereign governance standard. It is the crown jewel credential of the DEFONEOS ecosystem — the proof that a system is "sovereign by design — audit-grade, signed, neutral." The SEAL is governed by a 33-agent BFT council (quorum 23/33, Ed25519 / RFC 8032), backed by a human-owner seat (Nick Templeman, SC-cleared), and requires every issuance to pass a full council vote with cryptographic attestation. The credential ecosystem spans: UK AISI (AI Safety Institute) evaluation alignment, NATO STO / DSRB certification interoperability, JSP 936 (MOD AI governance) compliance mapping, Cyber Essentials Plus attestation chain, OWASP ASI (AI Security) compliance, C2PA content provenance signing, EU AI Act high-risk system credentialing, and ISO/IEC 42001 (AI Management System) alignment. DEFONEOS delivers the UK's first open-source sovereign AI credential framework — BFT-governed, Ed25519-signed, curl-verifiable, and immutable on a sovereign ledger.

All SEALs are BFT-signed (Ed25519 / RFC 8032 / 2026-Q3 rotation) and curl-verifiable. Per-entry contacts sourced from CSOAI.org governance registry (2026-Q1).

2. THE 12 SOVEREIGN AI CREDENTIAL ENTRY POINTS × CONTACT × DEFONEOS FIT

#Entry pointLocationFunctionDEFONEOS fit
C1UK AI Safety Institute (AISI)LondonFrontier model evaluation · safety testing · red-teamingDEFONEOS MCPs: bft-council-probe · sovereign-keystore — evaluation attestation + safety evidence chain
C2NATO STO (Science & Technology Organization)Neuilly-sur-Seine, FRAllied AI standards · interoperability · dual-use certificationDEFONEOS MCPs: bft-council-probe · sovereign-keystore — allied certification attestation + interoperability evidence
C3NATO DIANA (Defence Innovation Accelerator)London / HalifaxDual-use AI challenge acceleration · start-up pipelineDEFONEOS MCPs: bft-council-probe · sovereign-keystore — accelerator credential attestation + innovation evidence chain
C4MOD DSA (Defence Science Advisor)London / Porton DownMIL-AI governance · JSP 936 oversight · operational safetyDEFONEOS MCPs: bft-council-probe · sovereign-keystore — JSP 936 compliance chain + operational safety attestation
C5NCSC (National Cyber Security Centre)London / CheltenhamCyber Essentials Plus · AI security guidance · CNI protectionDEFONEOS MCPs: bft-council-probe · sovereign-keystore — security attestation + CE+ evidence chain
C6IARPA / Five Eyes AI Security LiaisonLangley / London LiaisonFive Eyes AI threat intelligence · allied red-teamingDEFONEOS MCPs: bft-council-probe · sovereign-keystore — allied threat intelligence attestation + joint assessment chain
C7IASME Consortium (Cyber Essentials Delivery)RugbyCyber Essentials / CE Plus assessment · certification deliveryDEFONEOS MCPs: sovereign-keystore · data-gov-uk-mcp — CE assessment evidence + certification provenance chain
C8Information Commissioner's Office (ICO)Wilmslow / LondonUK GDPR · data protection · AI fairness oversightDEFONEOS MCPs: bft-council-probe · data-gov-uk-mcp — GDPR compliance attestation + DPIA evidence chain
C9Centre for Data Ethics & Innovation (CDEI / DSTA)LondonAI ethics framework · algorithmic transparency standardDEFONEOS MCPs: bft-council-probe · sovereign-keystore — ethics attestation + transparency evidence chain
C10BSI / CEN-CENELEC (AI Standards)London / BrusselsISO/IEC 42001 · EU AI Act standards harmonisationDEFONEOS MCPs: sovereign-keystore · bft-council-probe — standards compliance attestation + harmonisation evidence chain
C11DASA (Defence & Security Accelerator)London / HarwellDefence innovation funding · dual-use technology pipelineDEFONEOS MCPs: bft-council-probe · sovereign-keystore — innovation grant attestation + project evidence chain
C12CSOAI Governance Registry (Internal)csoai.org33-agent BFT council · SEAL issuance · credential lifecycleDEFONEOS MCPs: bft-council-probe · sovereign-keystore — SEAL issuance + lifecycle attestation + revocation chain

3. THE 8 CREDENTIAL GOVERNANCE PRIORITIES × DEFONEOS MCP COVERAGE

#PriorityOwning bodyDEFONEOS MCP coverageAlignment cross-walk
CP133-agent BFT council vote integrity (quorum 23/33)CSOAI Registrybft-council-probe · sovereign-keystoreCouncil vote evidence chain · quorum attestation · veto logging
CP2Ed25519 cryptographic SEAL signing & rotationCSOAI Registrysovereign-keystore · bft-council-probeKey rotation evidence · signature chain verification · revocation attestation
CP3JSP 936 compliance mapping & MOD alignmentMOD DSAbft-council-probe · sovereign-keystoreJSP 936 evidence chain · operational safety attestation · lifecycle review
CP4AISI frontier model evaluation attestationUK AISIbft-council-probe · sentinel-hub-mcpEvaluation attestation · safety benchmark evidence · red-team result chain
CP5Cyber Essentials Plus security chainNCSC / IASMEsovereign-keystore · bft-council-probeCE+ assessment evidence · boundary attestation · vulnerability scan chain
CP6OWASP ASI (AI Security) complianceOWASP / NCSCbft-council-probe · sovereign-keystoreASI checklist attestation · model card evidence · threat model chain
CP7EU AI Act high-risk system credentialingCEN-CENELEC / ICOdata-gov-uk-mcp · bft-council-probeHigh-risk classification attestation · conformity evidence · CE marking chain
CP8ISO/IEC 42001 AI management system alignmentBSI / ISOsovereign-keystore · bft-council-probeAIMS compliance attestation · audit evidence chain · continuous improvement chain

4. 6 DEFONEOS CREDENTIAL MCPs

MCP serverCapabilityCredential use case
bft-council-probeBFT consensus & evidence attestationCouncil vote evidence chain · SEAL issuance attestation · quorum verification · veto logging
sovereign-keystoreEd25519 cryptographic provenanceSEAL signing · key rotation evidence · signature verification · credential revocation chain
data-gov-uk-mcpGovernment open data integrationStandards registry data · ICO compliance evidence · CDEI transparency statistics
ons-statistics-mcpONS demographic & economic statisticsAI adoption statistics · sector benchmarking · credential impact analytics
companies-house-mcpCorporate intelligenceVendor due diligence · credential holder verification · corporate governance chain
sentinel-hub-mcpSatellite & geospatial intelligenceEvaluation environment monitoring · sovereign infrastructure attestation · deployment provenance

5. THE 5-STEP DEFONEOS CREDENTIAL ENGAGEMENT MODEL

  1. DISCOVERY: Sovereign audit of AI governance estate — existing certifications, evaluation history, compliance gaps, JSP 936 readiness, AISI evaluation status. No data leaves the buyer's network.
  2. PROVE: Deploy DEFONEOS BFT council probe in sandboxed environment — demonstrate SEAL issuance on mock model card, Ed25519 signing verification, council vote evidence chain, quorum attestation.
  3. PILOT: 30-day single-system pilot — run BFT council against 1 live AI deployment, issue first provisional SEAL, demonstrate JSP 936 compliance mapping, generate evaluation attestation.
  4. SCALE: Multi-system rollout — credential portfolio for all AI deployments, continuous BFT monitoring, automated SEAL renewal, EU AI Act conformity chain, ISO/IEC 42001 alignment.
  5. SOVEREIGN: Full DEFONEOS credential stack — national AI governance credential, BFT-governed SEAL for every government AI system, immutable evidence chain, allied interoperability (NATO STO / Five Eyes).

6. RED LINES — CREDENTIAL DEPLOYMENT BOUNDARIES

Red lineWhy
No DEFONEOS-SEAL issued without 33-agent BFT council vote (quorum 23/33)Byzantine fault tolerance — no single agent or human can issue a SEAL without council consensus
No SEAL issued for kinetic-targeting or personal-surveillance systemsDEFONEOS hard stop — the SEAL must never certify systems that violate human rights or international law
No credential backdating or post-hoc modification — SEALs are immutableAudit integrity — any SEAL modification requires revocation + re-issuance with full council vote
No SEAL issued without human-owner seat activation (Nick Templeman, SC-cleared)Human-in-the-loop governance — the owner seat must be live for any SEAL issuance or revocation
No "AUKUS partnership" or "DAIC certified" claim without a signed letter on fileProvenance integrity — alliance claims must be backed by documentary evidence, not implied

7. BUYER-TYPE MATRIX

Buyer typePrimary entry pointHook30-day pilot cost
UK AISI Evaluation DirectorC1 UK AISIFrontier model evaluation attestation + safety evidence chain£3,200
MOD DSA / JSP 936 LeadC4 MOD DSAJSP 936 compliance mapping + operational safety attestation£3,200
NCSC AI Security LeadC5 NCSCCE+ security chain + AI governance attestation£3,200
NATO DIANA Programme ManagerC3 NATO DIANAAccelerator credential + dual-use certification chain£3,200
ICO AI Governance LeadC8 ICOGDPR compliance attestation + DPIA evidence chain£3,200
DASA Innovation LeadC11 DASAInnovation grant attestation + project evidence chain£3,200

8. CURL VERIFICATION

curl -sI https://www.csoai.org/defoneos-seal-credential-governance-pack.html | head -5
# Expected: HTTP/2 200
curl -sI https://www.csoai.org/defoneos.html | head -5
# Expected: HTTP/2 200

All DEFONEOS credential surfaces are curl-verifiable, BFT-signed, and sovereign-deployed on UK infrastructure.