Data Sovereignty & Privacy
Complete data retention, local AI inference on your own servers, and zero reliance on black-box third-party dependencies.
Independent Systems & AI Lab
We build sovereign products and take on the engineering problems most companies delegate: bare-metal Kubernetes, carrier-grade networks, on-premise AI.
Three rules that decide every architecture we ship, and every product we run.
Complete data retention, local AI inference on your own servers, and zero reliance on black-box third-party dependencies.
End-to-end Zero Trust security, applied from BGP network routing down to LLM token-stream filtering.
Pragmatic engineering focused on eliminating cloud waste, reducing operational overhead, and delivering high ROI.
Every brand is built, hosted and operated by us: sovereign by design, from scheduling to security.
Sovereign meeting scheduling for teams: no trackers, no third-party cookies, your calendar stays yours.
Get early accessSecurity suite: external attack surface monitoring, LLM privacy gateway and security drills, built for MSPs.
range-zero.comHigh-integrity surveys and structured feedback collection, designed for analysis without surveillance.
Follow the buildOne suite for external attack surface monitoring, LLM privacy and security training, built for MSPs, enterprise teams and infrastructure managers. Below: the product, in action.
Continuous monitoring of external digital assets. Atlas ingests domains or IP ranges and automatically discovers subdomains, open ports, SSL health and configuration drift in real time.
A continuous training platform: short modules adapted to each role, covering phishing, passwords, data handling and physical security, with harmless drills that measure what sticks. Compliance-ready reporting for auditors.
Team path - Finance
Week 4 of 12After 90 days with Paladin
A high-performance proxy that redacts confidential credentials, API keys, e-mails and personal identifiers before prompt dispatch, then seamlessly restores them into the model's response stream.
Vanguard in detailDeliver turnkey security visibility and LLM privacy control to your entire client portfolio through a unified MSP control plane, with tiered volume discounts, automated API provisioning and dedicated onboarding.
Ready to expand your managed services?
Get in early, help shape the suite: direct line to the team building it.
Explore the programEarly accessrange-zero.comHands-on architectural advisory, cost optimization and crisis engineering for high-assurance systems.
Step 1 / 3
Carrier-grade routing, air-gapped AI, sovereign Kubernetes: real infrastructure work, anonymized by design.
Engineered a redundant BGP peering topology across two distinct datacenters with /32 RIPE LIR prefix management, maintaining uninterrupted 99.95% service continuity through major transit outages.
Deployed a fully air-gapped local LLM stack with Qdrant vector storage and automated PII redaction for confidential document processing, resulting in zero external data exposure.
Migrated cloud workloads to sovereign bare-metal Kubernetes (Talos OS, ArgoCD, StackGres) with an encrypted Zero Trust SD-WAN mesh, cutting operational cloud costs by 32%.
Engineered a high-throughput, private document parsing engine using PaddleOCR and vector embeddings for multi-language invoice and contract classification.
The questions we get asked most often, answered with the depth we'd want to find elsewhere. Missing yours? Ask it directly.
Ask us directlyCardinal Codes is an independent systems and AI lab. We design sovereign infrastructure and carrier-grade engineering: bare-metal Kubernetes clusters, BGP/IPv6 networking, on-premise AI inference, and LLM privacy protection. Our product suite, Range Zero, covers external attack surface management (Atlas), security drills (Paladin), and LLM privacy gateway (Vanguard).
Sovereign AI infrastructure means running large language models entirely on your own hardware, with zero data leaving your network. This involves on-premise inference engines like vLLM, vector databases like Qdrant for retrieval-augmented generation, and open-weight models such as Llama or Mistral. No API keys sent to third parties, no usage telemetry, full control over your data pipeline.
Vanguard is a real-time LLM proxy that intercepts outbound prompts before they reach external AI models. It redacts API keys, email addresses, internal IP addresses, and personal identifiers (SSN, financial data) in under 1 millisecond. After the model responds, Vanguard restores the redacted values in-flight so the user sees their original data. Zero configuration changes needed on the AI provider side.
Atlas performs continuous external attack surface management (EASM). It discovers unauthorized subdomains, detects expired or misconfigured SSL certificates, monitors open ports and configuration drift, and alerts on DNS changes in real time. Deployment is zero-agent: provide your domains or IP ranges, and Atlas begins scanning immediately with no software to install on your infrastructure.
Paladin is a continuous cybersecurity training platform with short modules adapted to each role: phishing awareness, password hygiene, data handling, and physical security. It runs harmless simulated phishing drills to measure what sticks, then adapts content accordingly. Compliance-ready reporting for auditors, with a team resilience index that tracks improvement over time.
Bare-metal Kubernetes means running container orchestration directly on physical servers instead of cloud VMs. This eliminates cloud markup (typically 3-5x over hardware cost), removes vendor lock-in, and provides deterministic performance. We deploy it with Talos OS for immutable infrastructure, ArgoCD for GitOps, Cilium for networking, and StackGres for distributed PostgreSQL.
Describe the stack and the constraint. We answer within 48 hours with a scoped proposal.
Work with us