Animus AI LLC — DoD / Federal

Daidalos cATO Platform

The first compliance-native, air-gapped MLOps CI/CD platform built for CMMC 2.0, DFARS, and RMF environments. Deploy, train, scan, and document AI pipelines — fully offline, fully auditable.

16
Integrated Services
91
Tests Passing
0
External Dependencies
cATO
Ready Architecture
Compliance
CMMC 2.0 DFARS 252.204-7012 NIST SP 800-171 RMF / cATO Air-Gapped FIPS 204 · ML-DSA-65 SBOM Tracking
Cryptography — ML-DSA-65 post-quantum digital signatures (FIPS 204) for ML-artifact integrity, validated air-gapped · Argon2id password hashing · hardened JWT / CSRF session security · SHA-256 tamper-evident audit chain · data at rest via host full-disk encryption (FDE)
Capabilities

Built for the cleared world.

Every feature was designed around one constraint: no internet, no cloud, no exceptions. Daidalos brings enterprise MLOps to environments where it has never existed before.

Compliance-Native POAMs
Auto-generate POAM entries from STIG/SCAP findings. AI-assisted risk narratives, target dates, and NIST control recommendations — no manual documentation required.
POAMForge AI
Air-Gap Native Deployment
Ships as a single self-contained bundle. Double-click install on Windows or Linux. All 16 services, local LLM inference included — zero internet required from first boot through operation. Air-gap net-cut proven.
Offline-First
5-Phase ML Pipeline
INGEST → TRAIN → VALIDATE → SCAN → DEPLOY. Full state machine with audit trail on every phase transition. Gitea webhooks trigger pipeline runs on push to main.
CI/CD
PandorasBaux Security Runtime
AI-powered threat assessment, container analysis, and dependency auditing — all running offline via the bundled Bonsai-LLM. Embedded pandorasbaux-runtime v1.1.13. Full compliance gap analysis on demand.
PandorasBaux
SBOM Tracking & Audit Log
Full Software Bill of Materials tracking per pipeline run. Tamper-evident audit log on every user action. Paginated, filterable, admin-only — built for accreditation reviews.
RMF Ready
RBAC & User Management
Role-based access control with admin and analyst tiers. User provisioning, deactivation, and audit within the platform. JWT auth with token refresh — no external identity provider needed.
Zero-Trust Ready

Sixteen services. One network. No cloud.

Daidalos orchestrates proven open-source components into a compliance-ready substrate — eight core services plus an eight-service monitoring & security tier. Every service runs on an isolated Docker bridge network — fully auditable, fully replaceable. Air-gap net-cut proven.

Daidalos v1.1.3 — Service Architecture — daidalosnet Bridge Network
Daidalos API
FastAPI — 27 endpoints — Auth, Pipelines, POAMs, Models, Artifacts, SBOM, Audit, Webhooks
:8000
Daidalos UI
React — 10 routes — Dashboard, Pipelines, POAMs, Security, Audit, Compliance
:3002
↕                                             ↕
POAMForge AI
POAM generation, risk scoring, NIST control recommendations via LLM
internal module
PandorasBaux Runtime
Embedded v1.1.13 — threat analysis, container audit, compliance gap detection
:8001
Bonsai-LLM
Local LLM inference — bundled model — no internet required
internal
↕                                             ↕
PostgreSQL
Primary datastore — 6 tables — pipelines, POAMs, SBOM, audit
:5432 internal
MinIO
S3-compatible artifact object store — model weights, evidence files
:9000 / :9001
MLflow
ML experiment tracking — run history, metrics, model registry
:5000
Gitea
Air-gapped source control — webhook triggers pipeline on push to main
:3003 / :2222
↕                                             ↕
Prometheus
Metrics collection & alerting across all services
:9090
Loki
Centralized log aggregation — audit-ready retention
:3100
Promtail
Log shipping agent — feeds Loki from every container
internal
cAdvisor
Per-container resource & performance metrics
:8080
Falco
Runtime security — syscall-level threat detection
internal
Node-Exporter
Host-level metrics for the deployment node
:9100
MLflow-Exporter
Bridges MLflow run metrics into Prometheus
internal
OpenSCAP
STIG / SCAP compliance scanning & evidence
internal
Orchestration Layer
AI / Compliance Modules
Infrastructure & Monitoring / Security
Pipeline

From commit to deployment — fully documented.

Every pipeline run moves through five mandatory phases. Each phase transition is logged, timestamped, and audit-ready. No phase can be skipped.

Phase 01
Ingest
Data intake, source validation, SBOM generation
Phase 02
Train
Model training, MLflow experiment tracking
Phase 03
Validate
Performance benchmarking, metric thresholds
Phase 04
Scan
STIG/SCAP scanning, CVE audit, POAM generation
Phase 05
Deploy
Artifact packaging, MinIO storage, audit seal

Ready to deploy AI in your accredited environment?

Daidalos is available for DoD contractors, federal agencies, and cleared facilities. Request a demo or reach out to discuss your environment.

Request Received
We'll be in touch within 2 business days. For urgent inquiries, contact us directly at animusai.devops@gmail.com

Animus AI LLC · Nebraska · CAGE pending · animusai.devops@gmail.com