Northwind is a software-defined fusion-and-compliance fabric that runs on commercial off-the-shelf edge compute and rides existing CAF bearers. Four tiers scale from a soldier-carried node, through combat-team and battle-group hubs, to a Forward Operating Base Intelligence Fusion Centre beside the Task-Force HQ.
Every datum traverses a nine-stage ingestion pipeline. Each input is authenticated and content-inspected, then normalized into the Northwind Observation — a tagged object carrying source sensor, time and location, classification with caveats and a Protected B flag, reliability, and a pointer into a signed, hash-linked custody chain. Policy comes from two live frameworks in Tangram — zone policy set at deployment, mission-continuum policy bound at instantiation — and the Origi trust harness resolves them per action, deterministically.
Downgrade is a transformation, not a veto: the pipeline emits a releasable derivative — masked imagery, extracted structured text in the recipient’s format, re-marked classification — recorded as a child of the unreleased parent, so lineage survives release. Under any load, nothing moves untagged, unauthenticated or unrecorded.
The enforcement vocabulary
Permit
Restrict
Downgrade
Segregate
Each disposition executes programmatically for predefined conditions, and is recorded with the exact policy version that produced it.
Validation without government data
DND/CAF supplies no data, and the plan assumes none. A five-layer simulation environment — emulated fabric, synthetic sensors with versioned ground truth, and an independent compliance oracle that checks every enforcement decision — becomes the standing verification harness carried into the build phase.