Doctrine · security · standards

Trust is a property of the architecture.

BlackTimber systems keep the human in command, stay air-gapped by architecture, and record every decision to a verifiable log. Nothing acts on its own, and nothing you feed the system leaves the box. This page states the posture; the evidence page shows it under test.

Discipline floors

Four floors, held on every route.

Human-in-command

A human operator authorizes every effect. There is no autonomous engagement path. Software ranks options and recommends; the operator makes the call. Engineered to DoDD 3000.09.

Air-gapped by architecture

The air gap is a property of the design, not a setting you can forget. Sensing is passive-by-default, and there are zero external network calls. Nothing you feed the system leaves the box.

You own the data

The whole decision loop runs on your hardware, at the edge or at a fixed site. No cloud dependency, no back-haul, no third-party account. Your operational data stays yours.

Every decision is recorded

Each authorization is written to a tamper-evident, SHA-256-chained decision record. You can verify the chain in your own browser, with no server round-trip.

  • Air-gapped by architecture, not a setting
  • Passive-by-default sensing
  • Zero external network calls
  • Human-in-command per DoDD 3000.09 — no autonomous engagement path
  • Tamper-evident, SHA-256-chained decision record, verifiable in-browser

Responsible-AI doctrine

The Human Gate is the whole point.

Software reasons and recommends. It never arms, fires, or acts on its own. A kinetic effect or an active emission is released only after a human operator authorizes it — one gate, stated once, that holds everywhere.

Security posture

Aligned to the frameworks that govern federal systems.

Posture is stated as alignment, never as a certification we do not hold. Security is assessed per program under the appropriate authorization process.

Risk management

Aligned to NIST RMF 800-37 and the NIST 800-53 control families, and to DoDI 8530.01 for cyber defense of the platform.

Cryptographic integrity

Decision records are chained with SHA-256. Engineered to FIPS 180-4 and 186-5 for hashing and signatures.

Attack modeling

Threats are reasoned against MITRE ATT&CK, and the platform is aligned to CMMC 2.0 practices for handling controlled unclassified information.

Standards-alignment matrix

Export control

Stated at outcome level.

This public site is Unclassified // Public Release and describes what the systems achieve, never how. It contains no controlled technical data.

ITAR / EAR posture

Technical data is handled as potentially controlled under the ITAR (22 CFR) and the EAR (15 CFR). Export classification and any authorization are determined per transaction and per recipient, in writing, before controlled data changes hands.

What that means for you

Evaluations happen under an agreement. Access to controlled material follows the appropriate license or exemption for your organization and jurisdiction — never by default, and never through this site.

Standards register

Aligned to, and engineered to.

The full set of standards the platform is aligned or engineered to. Alignment language is deliberate: it states intent and design, not a certification.

  • DoDD 3000.09
  • NIST RMF 800-37
  • NIST 800-53
  • MITRE ATT&CK
  • DoDI 8530.01
  • FIPS 180-4 / 186-5
  • NATO SAPIENT
  • STANAG 4609 / 4607
  • ASTERIX
  • ASTM F3411 (Remote ID)
  • ATP-45
  • WCAG 2.2
  • MIL-STD-1472
  • FAR / DFARS
  • CMMC 2.0

Reporting & statements

Where to point security and accessibility.

Coordinated disclosure

Report a security concern through our security policy at /.well-known/security.txt, or write to EBlack@blacktimberdefense.com.

Accessibility statement

The site targets WCAG 2.2 AA and MIL-STD-1472 human-factors principles. Read the full accessibility statement.