
DAF: Defense Agent Framework
Governed agent workflows for defense and national-security missions.
DAF gives defense and intelligence teams a governed way to deploy multi-agent AI beside existing systems, combining mission workflows, human approval gates, classification-aware controls, model routing, tool permissions, and replayable audit records. It is the clearest expression of the Trunnion control plane applied to sensitive environments.
DAF (Defense Agent Framework) is a governed multi-agent AI framework for defense and national-security missions, built and operated by Trunnion AI.
It is designed for policy-based authorization, layered tool controls, reviewable execution records, and human-in-the-loop approval gates, with implementation and tests verified for the exact release, deployed to cloud, on-premise, or fully air-gapped environments (security boundaries). Trunnion AI is aDuskbridge company, built by the team behind Viceroy NM.
Feature highlights.
The capabilities that carry the defense & national security workflow in DAF, on the governed Trunnion control plane: agents draft and route the work while a human operator stays in command.

Representative feature highlights. Actual screens vary by deployment and configuration.

Defense, intelligence, and regulated enterprise teams: mission owners, AI program leads, security teams, acquisition teams, and regulated operators.
What DAF does.
A library of pre-built agent patterns, shipped with the platform
CAC and PIV identity traceability for DoD environments
Classification-aware workflow controls up to TS/SCI
Human approval gates on high-consequence actions
Mission workflow designer with adapters and operator handoff
Trace, replay, and review of every policy path and tool call
Cloud, VPC, on-premise, or air-gap deployment; LLM-agnostic execution
Inside DAF, capability by capability.
Built for the classified boundary
DAF runs the same control plane inside the strictest deployment boundaries, from VPC to full air gap.
Air gap as configuration
The same stack ships cloud, VPC, on-premise, and air gap; a government boundary deployment is a configuration change, not a rewrite.
Classification ceilings enforced
Data above a boundary's classification level never imports; over-ceiling records are dropped and logged, never silently downgraded.
Models inside the fence
Calls carrying classified or CUI-tagged context route only to models inside the boundary, including local runtimes.
CAC/PIV identity
The architecture is designed to bind actions to the acting user's identity and evaluate permissions per action. Privilege-escalation resistance must be verified for the exact release and environment.
Autonomy you can defend in an audit
Agents earn autonomy on evidence, and the highest-risk actions never leave human hands.
Humans commit federal actions
No federal representation by AI is a hard guardrail in code; federal artifacts always require a draft plus a human commit at any trust level.
Earned, quantified autonomy
Each skill carries a trust score from acceptance, calibration, and blast radius, and widening any gate requires human ratification plus security sign-off.
Reviewable audit design
Committed actions are designed to record the policy path, model decision, and approver. Hash linkage, coverage, and replay are confirmed from release evidence rather than assumed from this page.
Federal alignment posture
Architecture may be mapped to the FedRAMP Moderate baseline derived from NIST SP 800-53 Rev. 5 for a scoped deployment. No FedRAMP authorization is held, Trunnion AI is not represented here as listed on the FedRAMP Marketplace, and CMMC or ITAR suitability is determined for the deployed system.
Operations inside the fence
A disconnected DAF deployment is a full citizen of the platform, with its own learning loop inside the boundary.
Signed release bundles
Disconnected systems update through signed, versioned bundles that are checksummed, signature-verified, and recorded in the local audit chain.
Telemetry never leaves
Metrics, scorecards, and training labels accumulate locally, and model training for air-gapped tenants runs on in-boundary compute.
Hostile input containment
Inbound documents and messages are intended to be treated as untrusted data and constrained by tool authorization and human gates. Prompt-injection resistance is a design objective pending release-specific adversarial test evidence.
What DAF is for, and what it is not.
Designed for defense and national-security program operations: mission intake, document assembly, compliance checks, and status reporting under classification-aware policy. It prepares and routes work for human decision and is not designed to make targeting, personnel, or benefit decisions.
Like every Trunnion product, DAF is designed to propose, draft, and prepare work for human decision, with consequential actions pausing at a human approval gate. AI outputs may be inaccurate, incomplete, or unsuitable and should not be the sole basis for a consequential decision affecting a person. Expected inputs, model providers, known failure modes, and the exact human review points for a deployment are documented in the release documentation and written agreement. See theAI transparency notice and theAI acceptable use policy.
DAF: key facts.
| Product | DAF: Defense Agent Framework |
|---|---|
| Category | Defense & National Security |
| Status | Live |
| Platform | Trunnion control plane: governed multi-agent orchestration |
| Governance | Designed for policy-based authorization and layered tool controls; verified per release |
| Audit | Reviewable execution records; integrity and replay verified per release |
| Human oversight | Human-in-the-loop approval gates on consequential actions, by design |
| Model posture | LLM-agnostic model routing, hosted or on-premise |
| Deployment | Cloud, on-premise, or fully air-gapped |
| Classification | Designed for classification-aware workflows up to TS/SCI; accreditation determined per environment |
| Security alignment | Engineered to align with NIST SP 800-53 control families; alignment by design, ahead of formal certification. |
| Developer | Trunnion AI, LLC, a Duskbridge company |
Governed by design, like every Trunnion product.
DAF inherits the platform's governance, audit, and deployment patterns instead of rebuilding them: policy on every action, a human operator in command, and a record you can hand to an auditor.
Policy-aware governance
Attribute-based access control (ABAC) is designed to decide what every agent may see and do, per tenant, role, and classification.
Human-in-the-loop gates
Consequential actions are designed to pause for a named operator to approve, edit, or reject before anything executes.
Reviewable execution records
The architecture is designed to record actions, approvals, and supporting traces for review. Cryptographic implementation is verified per release.
Common questions about DAF.
Does DAF work fully disconnected?
Yes. Air gap deployment is a supported configuration of the same stack. Updates arrive as signed, verified bundles, and all telemetry, labels, and model training stay inside the boundary.
Can an agent submit or represent anything to the government?
No. Federal representation by AI is prohibited in code, and federal artifacts sit in the highest blast-radius class, which always requires a human commit regardless of trust score.
How is classified data kept inside the boundary?
Five classification levels tag every record. Calls carrying classified or CUI context route only to in-boundary models, and imports above a system's classification ceiling are dropped and logged.
Next step
See DAF against your workflow.
Request a demo and see the governed control plane run in your environment, from cloud to air-gap.