Cybairsecurity
Technology

Aviation domain knowledge meets frontier AI.

Generic cybersecurity AI is not equipped for aviation. Our stack was designed from first principles — with deep understanding of how avionics systems work, how they fail, and what regulators actually require.

Local LLM

Ollama — Llama3 / Qwen3, runs on your hardware

RAG over Standards

DO-326A, DO-356A, ED-202A, MITRE ICS

Zero egress

No telemetry, no callbacks, no cloud

Architecture

How the analysis pipeline works.

Every stage runs inside your network perimeter. Nothing crosses the boundary.

// System boundary — your network perimeter

Input

System Architecture Docs
ICD Specifications
Safety Assessments (FHA/SSA)
Design Artefacts

CompliAir Engine

Aviation-tuned LLM

Ollama local

RAG — DO-326A / ED-203A

ChromaDB vectors

Compliance Reasoner

Structured chains

Audit Trail

SQLite local

Output

Security Objectives List
Threat Condition Mapping
DO-356A Method References
EASA / FAA DER Evidence Pkg
Zero external network calls at any stage of the pipeline
Stack

What makes it different.

Aviation-tuned LLM core

Fine-tuned on DO-326A, DO-356A, ED-202A, and a curated corpus of aviation system documentation. Understands the semantics of airworthiness security natively.

Structured compliance reasoning

CompliAir applies structured reasoning chains aligned with the DO-326A process model. Every output is traceable to a specific regulatory requirement, method, or threat category.

Zero-egress architecture

Both products run in closed networks. No telemetry, no licensing callbacks, no external connections. Certification artefacts stay under your control — always.

Protocol-level threat modelling

VulnAirabilityDb's threat taxonomy is built at the protocol layer. ARINC 429 word-level anomalies, AFDX VL spoofing, and MIL-STD-1553 bus monitoring attacks modelled with protocol-aware precision.

Regulatory traceability engine

Every Security Objective, threat condition, and mitigation recommendation is tagged with explicit references to the originating DO-326A section, ED-203A clause, or DO-356A method.

Air-gap update protocol

VulnAirabilityDb uses a signed, verified offline package format compatible with USB, optical media, or data diode transfer — cryptographic integrity at every step.

Deployment

Two deployment models.

Both products support on-premise and full air-gap deployment out of the box. The choice depends on your network security posture — not our architecture.

On-Premise

Standard Deployment

Runs entirely within your corporate network. Ollama manages the local LLM, ChromaDB stores aviation ontology vectors, SQLite handles audit trails. No internet connection required at runtime.

  • Deployed on your own hardware or private cloud
  • No outbound connections — ever
  • Intelligence updates via signed packages
  • Full audit trail stored locally

Air-Gapped

Classified / SCIF

For environments where no external network is permissible. Intelligence update packages are delivered via cryptographically signed USB or optical media and verified before ingestion.

  • No network interface required
  • Signed offline update packages (USB / optical)
  • Compatible with data diode environments
  • Suitable for classified and SCIF deployments
Standards coverage:DO-326AED-203ADO-356AED-204AED-202AARINC 429ARINC 664 / AFDXMIL-STD-1553ARINC 825
Contact

Built for the people who cannot afford to get it wrong.

CompliAir and VulnAirabilityDb are available for NDA-protected evaluation. Deployments are scoped, on-premise, and covered by NDA from day one.