Portable, compartmentalized, policy-enforced data objects.
Generalize the secure-document model into compartmentalized zero-trust data capsules. A protected object can be copied, cached, or archived anywhere while staying tamper-evident, policy-bound, independently verifiable, and decryptable only through an authorized access decision.
- Data-centric zero trust (NIST SP 800-207)
- Compartment-level micro-segmentation
- Connected, degraded & disconnected modes
- Enforce policy that travels with the data object
- Operate in contested, comms-denied environments
- Keep cryptographic roots customer-controlled
- Maintain tamper-evident accountability without a blockchain
Why government & defense teams need data-centric trust
Data leaves the perimeter
Network controls can't protect a file once it's copied out.
Compartmentalization
Users need only the sections their role and mission require.
Degraded operation
Connectivity loss must not halt operations or accountability.
OSDF solution architecture
Purpose-built capabilities layered on the open OSDF core and verification engine.
Compartment encryption
Per-compartment DEKs and policies enforce data-layer segmentation.
Identity & device
PIV/CAC, Entra, Login.gov, OIDC/SAML, plus enrolled device keys.
Short-lived leases
Near-real-time authorization with bounded offline grants.
Append-only audit
Signed event queues, witnesses, and reconciliation on reconnect.
What you gain
- Enforce policy that travels with the data object
- Operate in contested, comms-denied environments
- Keep cryptographic roots customer-controlled
- Maintain tamper-evident accountability without a blockchain
Designed for assessment
OSDF supports controls and evidence - a compliant deployment also depends on your environment, policies, and operations.
NIST SP 800-207
Maps to Policy Engine, Policy Administrator, and Enforcement Point roles.
Zero-trust alignment
Designed around user, device, data, and visibility pillars.
Bring verifiable trust to government & defense
Generalize the secure-document model into compartmentalized zero-trust data capsules. A protected object can be copied, cached, or archived anywhere while staying tamper-evident, policy-bound, independently verifiable, and decryptable only through an authorized access decision.