CONTEXT A
Strategic
Headquarters analysis across the full historical picture — trend, readiness, capability and resource judgements built on years of data, not last week's spreadsheet.
Full corpus · Petabyte scale
Actionable intelligence data
Plintir connects classified, legacy, sensor and open sources into one governed mission model — then gives analysts, watch floors and commanders the tools to interrogate it, decide from it, and account for every decision afterwards.
The difference that matters
Most platforms give you more data. Plintir gives you the next decision — and the evidence to stand behind it.
Raw collection is abundant. What is scarce is a picture that is current, sourced, releasable and specific enough to act on. Everything Plintir builds is measured against one question: did this shorten the distance between an observation and a decision someone can defend?
Where Plintir operates
Platforms built for one operating context leave everyone else with a read-only view of someone else's work. Plintir assumes all four contexts run at once, on one ontology, one policy engine and one audit trail — including when the network is gone.
CONTEXT A
Headquarters analysis across the full historical picture — trend, readiness, capability and resource judgements built on years of data, not last week's spreadsheet.
Full corpus · Petabyte scale
CONTEXT B
Command and intelligence fusion on the watch floor. Live alerting, common intelligence picture, collection management and planning in one place.
Watch floor · Seconds to update
CONTEXT C
Execution where connectivity fails. Local inference, pre-positioned mission packages and deferred synchronisation that never overwrites what it cannot see.
Disconnected · Days of autonomy
CONTEXT D
Partner and inter-agency work where every object carries its own handling, releasability and need-to-know — enforced, not trusted.
Per-object releasability
The product suite
Each product solves a distinct problem and shares the same mission model, security policy and audit trail. Adopt one, or adopt the suite — nothing has to be re-modelled to add the next.
PLINTIR NEXUS
Intelligence Data Fabric & Mission Ontology
Connects classified, legacy, streaming and geospatial sources into one governed mission model, so analysts stop reconciling spreadsheets and start answering questions.
Explore Nexus
PLINTIR CITADEL
All-Source Intelligence & Mission Operations
The analyst workbench and common intelligence picture: search, link analysis, geospatial and temporal fusion, alerting and finished intelligence production in one place.
Explore Citadel
PLINTIR AUGUR
AI Decision Intelligence
Retrieval, copilots and agents operating on classified networks — with authorisation applied before retrieval, citations on every claim, and a human approval gate on every consequential action.
Explore Augur
PLINTIR SENTINEL
ISR Fusion & Sensor-to-Decision
Correlates sensor observations into tracks, fuses multi-source returns against the mission picture, and carries governed decision-support dossiers through review and approval.
Explore Sentinel
PLINTIR CONSTELLATION
Space & Multi-Sensor Collection Orchestration
Matches collection requirements to satellite and airborne opportunities, submits and tracks requests, and routes returned products straight back to the analyst who raised the gap.
Explore Constellation
PLINTIR OUTPOST
Tactical Edge Intelligence
Runs the mission picture, local search and on-device inference on a disconnected field node for days, then synchronises safely — surfacing conflicts instead of silently overwriting them.
Explore Outpost
PLINTIR VANGUARD
Expeditionary Ground Station & Deployable Node
Ruggedised, rapidly emplaced hardware and software that gives a deployed headquarters direct sensor access and full local analytic capability within hours of arrival.
Explore Vanguard
PLINTIR ENCLAVE
Coalition & Cross-Domain Collaboration
Publishes a releasable subset of the mission picture to partners and other agencies under per-object handling rules, with complete dissemination audit and controlled cross-domain transfer.
Explore Enclave
PLINTIR BASTION
Accredited Sovereign & High-Side Hosting
Runs the suite in sovereign cloud, on-premises, high-side and air-gapped environments with separate key hierarchies, zero-trust controls and an accreditation path already walked.
Explore Bastion
PLINTIR CONDUIT
Continuous Delivery & Fleet Assurance
Delivers signed, policy-gated software updates across cloud, classified and disconnected estates, with staged rollout, verified provenance and one-step rollback.
Explore Conduit
Core capabilities
Twelve capabilities that show up in every deployment, whatever the mission and whatever the classification environment.
Classified reporting, legacy systems, streaming sensors, imagery, documents and open sources arrive with their markings, reliability and lineage intact.
Entities, observations, tracks, events, relationships and assessments modelled once and used by every analyst, application and model.
Eight records about one vessel become one vessel with eight sources — scored, reviewable and reversible.
Map, track, replay, geofence and correlate across space and time, with freshness and confidence visible on every symbol.
Observations correlate into tracks, tracks into assessments, assessments into governed decision support with a full evidence chain.
Intelligence gaps become collection requirements, matched to real sensor opportunities and tracked until the answer comes back.
Authorised retrieval, cited output, visible confidence and a human approval gate on every consequential action.
Correlation rules over live streams produce priority alerts in seconds, with assignment, escalation and incident workflow attached.
Publish releasable slices to partners under per-object policy, with a dissemination record an inspector can query.
Days of autonomous capability at the edge, honest degradation and conflict-safe synchronisation on reconnection.
Supply, maintenance and movement constraints traced directly to the missions and plans they threaten.
Every derived value traces to its source and every action to a named person, months after the fact.
See it working
Three screens from across the suite, running in your browser on fabricated data. Full detail for each product sits on its own page.
Tracks · 3 active
Signals + imagery correlate
Entity: ENT-8890 · 4 s ago
Transponder + imagery
Entity: VES-4471 · 11 s ago
Edge sensor NODE-11
Entity: unresolved · 2 s ago
Geofence alerts
Unresolved stays unresolved. TK-7730 has no confident entity association, so it is shown that way rather than attached to the nearest plausible candidate to make the picture look tidier.
Advisory output · retrieval scoped to caller
Three material changes in the last 12 hours.
1 · Track TK-4471 was associated to ENT-8890 at 0912Z on correlated signals and imagery, confidence 0.87 OBS-2291.
2 · Vehicle count at FAC-0093 rose from 4 to 11 IMG-7714.
3 · CONTRADICTION — the 0400 assessment ASM-0088 placed the same entity 240 km south, citing one report whose source reliability was downgraded at 1120Z. Both cannot hold. I have not resolved this; an analyst should adjudicate.
▲ Proposed action · requires human authorisation
Create collection request CR-2291 against gap G-14 and route to the collection manager.
Policy check · PASSED at execution time
Authority required · Collection manager or above
Audit trail · this session
Query received · caller a.reyes · clearance attributes evaluated
Scoped to caller — 2,104 of 8,880 candidates authorised
Routed to private on-premise model, domain-authorised
7 citations attached · sensitivity inherited from sources
Action proposed — awaiting human authorisation
The gate is architectural. The copilot can propose a collection request; it cannot create one. Authorisation is checked when the action executes, never inherited from the model's earlier reasoning.
| Requirement | Intelligence gap | Priority | Eligible sensors | Coverage | Status |
|---|---|---|---|---|---|
| CR-2291 | Pattern of life, NAI-07 north approach | P1 | SAT-A2 · UAS-114 | TASKED | |
| CR-2287 | Vessel association, TK-2019 | P1 | SAT-C1 · AIS | PARTIAL | |
| CR-2280 | Facility status change, FAC-0093 | P2 | SAT-A2 | RETURNED | |
| CR-2276 | Ground movement corridor, grid 44S | P2 | UAS-114 · NODE-11 | PARTIAL | |
| CR-2270 | Infrastructure survey, ORG-2205 | P2 | Withheld — compartment | NO ACCESS | |
| CR-2264 | Throughput assessment, FAC-0121 | P3 | SAT-C1 | TASKED |
Compartmentation without blind spots. CR-2270's sensor list is withheld from this caller, but the requirement stays visible — so the collection manager still knows the gap exists and can escalate it.
Mission outcomes
Not features. The work itself — each of these is a thread we will run end to end against your own data during evaluation.
Reports, events, tracks and imagery-derived products resolve into entity dossiers with contradictions surfaced rather than averaged away, and an assessment that cites its evidence.
A live geospatial and temporal view where freshness, confidence and source status are visible on every symbol, so nobody briefs stale data as current.
Gaps become collection requirements, matched to real sensor opportunities, tracked to completion and linked back to the assessment that needed them.
Expand relationships from any seed, identify key nodes and communities, and show the observation behind each connection under scrutiny.
Resource, risk, timeline and intelligence confidence scored side by side, with assumptions recorded and decision authority tracked.
Correlation rules and confidence thresholds turn a flood of events into a short list a watch officer can actually work.
Publish a releasable subset of the picture under per-object policy, with dissemination recorded for later account.
Deployed teams run the mission picture, local search and inference for days, then rejoin without corrupting the enterprise record.
Direct downlink and local processing at a deployed node, with products routed straight to the requirement that justified them.
Shortages and maintenance constraints traced downstream to the tasks, plans and timelines that depend on them.
A copilot that retrieves only what the caller is cleared for, cites every claim, names the gaps and proposes rather than acts.
Controlled cases with evidence chain, timeline correlation, review workflow and managed release.
Built for the whole floor
Each role gets a working surface built for its job and an authorisation profile that matches its clearance — including oversight, which can query the record without touching operations.
Intelligence analyst
Search and fuse sources, build dossiers, test hypotheses, publish finished intelligence.
All-source fusion analyst
Correlate multi-source reporting, tracks and incidents against source reliability.
Collection manager
Turn gaps into requirements, match sensors, track requests and returns.
Watch officer
Hold the picture, triage alerts, coordinate operational response.
Commander
Consume decision-ready views, compare options, review risk and assumptions.
Mission planner
Build plans, synchronise resources, map dependencies and contingencies.
Geospatial analyst
Analyse terrain, imagery-derived products, tracks, routes and time-series.
Counterintelligence analyst
Resolve entities, analyse networks, manage cases and controlled release.
Logistics analyst
Assess readiness, supply, maintenance, movement and mission dependencies.
Cyber analyst
Correlate indicators, infrastructure, identities and operational impact.
Data engineer
Connect sources, build pipelines, certify data products, own quality and markings.
Ontology engineer
Define mission objects, relationships, actions and policy-aware operations.
AI engineer
Register models, build retrieval and agents, evaluate performance, monitor drift.
Security administrator
Own identity, classification, compartments, transfer policy and audit.
Platform operator
Operate environments, deploy releases, manage deployed nodes and recovery.
Oversight and inspection
Query audit and dissemination records independently of operational systems.
Eight stages, and the one that gets skipped is always the last. Plintir treats consumer feedback as a first-class object, so collection priorities improve instead of drifting.
STAGE 1
Requirements, priorities, authorities, constraints and deadlines captured as objects, not email.
STAGE 2
Sources and sensors identified, coverage gaps quantified, opportunities matched.
STAGE 3
Authorised reporting, sensor returns, documents, media and feeds arrive with provenance.
STAGE 4
Parsed, normalised, geolocated, entity-extracted and enriched, with markings preserved.
STAGE 5
Sources correlated, entities resolved, hypotheses tested, confidence scored, gaps named.
STAGE 6
Assessments, dossiers, maps and briefs generated with citations and handling controls.
STAGE 7
Released under per-object policy to approved consumers, with a complete record kept.
STAGE 8
Consumer response captured, requirements updated, collection re-prioritised. The loop closes.
Responsible AI in the mission
AI output is advisory until an authorised person accepts it. Plintir may correlate, summarise, forecast and recommend — consequential action requires a human.
This is an architectural constraint rather than a policy note. The authorisation gate sits in the action layer beneath every application and every agent, so there is no route to a consequential action that goes around it.
Authorisation is applied before any document reaches a model. Nothing is retrieved and then hidden — it is never retrieved at all.
Classified prompts never route to an endpoint that is not authorised for the same handling level, regardless of how well that model performs.
Actions are checked when they execute. An agent's earlier reasoning is never treated as permission to act.
Generated text inherits the sensitivity of what it retrieved, and derivative review runs before anything is released.
Retrieved documents, uploaded files and external content are treated as data, never as instructions to the agent.
Effects workflows are decision support with human approval throughout. The platform does not select, authorise or execute.
Engineered against known failure modes
Published because they are predictable, and because any vendor who cannot name them has not delivered one. Each answer is an engineering commitment, not an operating procedure written after go-live.
Over-centralisation
One global system becomes a bottleneck, or an unacceptable concentration of risk.
Federated domains, data products, explicit replication decisions, independent capability at the edge.
Classification leakage
Derived analytics or AI output combines sources and exposes what should have stayed closed.
Per-object labels, derivative policy, output checks, releasability review and negative testing.
Over-trust in AI
Model output is read as fact rather than as an advisory judgement to be checked.
Citations, confidence bands, visible source-versus-inference distinction, human approval, continuous evaluation.
Wrong entity merge
Two distinct entities are fused and quietly contaminate every product built on them.
Scored matching, evidence per merge, analyst review, reversible merges, source records preserved.
Stale picture
A pipeline or link failure creates confident-looking awareness that is hours out of date.
Freshness indicators, feed health, degraded-mode interface, alerting on stale critical sources.
Deployed node compromise
A captured or lost node exposes mission data or trust credentials.
Encryption at rest, device identity, short-lived credentials, remote revocation and bounded local caches.
Vendor lock-in
Mission capability becomes dependent on one model or one proprietary data engine.
Ontology and API abstraction, open storage formats, a model gateway and exportable data products.
Supply-chain compromise
A malicious or vulnerable update reaches classified or deployed estates.
Signed artifacts, bill of materials, staged rollout, offline verification and vulnerability gates.
Cross-domain bypass
Unofficial export becomes easier than the approved release route, so people use it.
Uncontrolled egress disabled, transfer service integration, approval workflow, inspection and audit.
Deployment and scale
Ingest volume, retention, relationship cardinality, streaming rate, concurrency, inference strategy, deployed fleet size and cross-domain replication — not user count alone. Figures below are planning envelopes, confirmed against your real source throughput during design.
| Scale | Named users | Concurrent | Ingest | Primary data | Objects + links | Streaming |
|---|---|---|---|---|---|---|
| Mission cellSingle team or pilot | 100–300 | 25–75 | 0.1–0.5 TB/day | 20–100 TB | 10–100 M | 5k–20k /s |
| EnterpriseJoint headquarters | 1,000–3,000 | 150–500 | 1–5 TB/day | 0.2–1 PB | 0.5–5 B | 50k–200k /s |
| Multi-domainNational or alliance scale | 10,000–25,000 | 1,000–5,000 | 5–25 TB/day | 2–10 PB | 5–50 B | 250k–1M /s |
<2s
Entity search response, typical indexed query in authorised scope
<3s
Relationship expansion for a bounded network query
2–10s
Priority feed from platform receipt to map display
<5s
Priority alert generated from a qualifying event
3–8s
AI response begins streaming for common requests
99.95%
Core mission service availability target, monthly
24–72h
Deployed node autonomy without core connectivity
30 / 5 min
Recovery time and recovery point, critical operational state
Security markings, provenance, audit and attribute-based authorisation are built in the first step. Retrofitting them once mission applications exist is the most expensive mistake available on a programme like this.
STEP 1
4–8 weeks
Mission threads, data classification, security domains, authority model, core ontology and target service levels agreed before a line of integration work starts.
STEP 2
8–16 weeks
Priority sources connected, catalogue and lineage established, core mission objects modelled, search live, attribute-based access in force.
STEP 3
8–12 weeks
Workbench, mapping and common intelligence picture, entity resolution, timeline, alerting and reporting delivered to real users.
STEP 4
8–12 weeks
Model gateway, authorised retrieval, citations, evaluations, safe tool use, approval gates and red-team testing.
STEP 5
12–24 weeks
Collection management, planning, readiness, investigations, coalition sharing and role-specific views.
STEP 6
12–24 weeks
Deployed nodes, disconnected operation, signed updates, domain replication and cross-domain workflow.
STEP 7
Continuous
Load and failure testing, disaster recovery, accreditation, model assurance and operational exercises.
Start small, prove it fast
Our first engagement is deliberately narrow: three to five critical sources, a compact mission ontology, analyst search and link analysis, geospatial and timeline, one operational workflow and one governed copilot. If it does not shorten a real decision, it does not scale.