Skip to content
Use case 095

Classified Data Transfer Stations

A deployment concept for Defence and intelligence organisations procuring controlled transfer workflows; Cross-domain solution vendors integrating content handling and release components; Government security integrators building approved transfer-station environments.

Proposed deployment · Compatibility assessment required
Government, Public Safety and Defence

Why this environment matters

A transfer station between differently trusted networks must decide more than whether a file is malware-free. It must know which direction is permitted, which content may cross and who approved this particular release. This concept considers a controlled file-transfer workflow; it does not present NØNOS as an accredited cross-domain solution.

The security challenge

Incoming media would first enter a quarantine workspace with no authority to write to the destination network. Format-specific parsing and, where appropriate, transformation would produce a candidate output. A separate reviewer or policy process would decide whether that output is permitted to cross, using its own authenticated context.

How the capsule model could help

A prototype could use NØNOS capsules to limit each parser to a single input and a constrained output channel. The exporter would receive the exact approved derivative, its destination and a one-use release permit. It would not accept an arbitrary path supplied by the parser, because that could turn file handling into a general data-extraction mechanism. Content can be disallowed without being executable. Images, embedded metadata, document layers or apparently ordinary text may carry information that the receiving side must not obtain. The transfer policy therefore requires a defined content model and appropriate human or technical review beyond memory-safe decoding. The evaluation would retain a durable record of input identity, transformation, approval and output identity. A station restart should not cause an approved transfer to run twice or convert a partly reviewed file into a released one. Temporary sessions and lasting accountability need deliberately different storage paths.

Separate address spaces and capability checks can limit cross-process reach. They cannot stop harmful use of legitimate permissions, prove AI decisions correct or substitute for domain-specific safety controls.

Deployment requirements

A deployment would need the relevant cross-domain policy, approved components and independent evaluation. This concept does not establish classification correctness, sanitisation completeness, physical separation or permission to handle classified data. Evaluation requirements: Change a derivative after review and verify that its existing release permit no longer matches. Present an otherwise valid permit for the opposite transfer direction and confirm refusal. Restart between approval and delivery, then demonstrate that the transfer record distinguishes pending, completed and uncertain outcomes.

Current public-beta limitations, hardware support and application availability must be assessed before any pilot. Neither this use case nor an industry source establishes NONOS certification or a current customer deployment.

Parsing and release authority belong to separate components

Incoming media would first enter a quarantine workspace with no authority to write to the destination network. Format-specific parsing and, where appropriate, transformation would produce a candidate output. A separate reviewer or policy process would decide whether that output is permitted to cross, using its own authenticated context.

A prototype could use NØNOS capsules to limit each parser to a single input and a constrained output channel. The exporter would receive the exact approved derivative, its destination and a one-use release permit. It would not accept an arbitrary path supplied by the parser, because that could turn file handling into a general data-extraction mechanism.

A clean parser cannot classify information reliably by itself

Content can be disallowed without being executable. Images, embedded metadata, document layers or apparently ordinary text may carry information that the receiving side must not obtain. The transfer policy therefore requires a defined content model and appropriate human or technical review beyond memory-safe decoding.

The evaluation would retain a durable record of input identity, transformation, approval and output identity. A station restart should not cause an approved transfer to run twice or convert a partly reviewed file into a released one. Temporary sessions and lasting accountability need deliberately different storage paths.

Who could buy or integrate it?

  • Defence and intelligence organisations procuring controlled transfer workflows
  • Cross-domain solution vendors integrating content handling and release components
  • Government security integrators building approved transfer-station environments

Industry examples: BAE Systems, Everfox. Organisations shown illustrate the industry. No NONOS customer, partner or endorsement relationship is implied.

Market opportunity

Market benchmarks and device scenarios.

Published industry benchmark
US$37.2 billion

Endpoint security

Global · 2025 · annual market estimate

Solutions and services protecting endpoints across industries; includes application control and managed security, not a government workstation subtotal.

Modelled global devices
4K–150K

Candidate OS endpoints

Hypothetical planning range · 2025

Low confidence: planning assumptions. Hardware compatibility, procurement and adoption have not been validated.

Illustrative annual licensing
$1M–$150M

USD / year at full model coverage

Device scenario × assumed US$250–$1000 per device / year.

Not a revenue forecast, announced price or measured serviceable market.

Device calculation

Hypothetical global planning range, 2025 scenario: assume 2,000–15,000 government and defence classified transfer facilities × 2–10 candidate OS endpoints per site/asset = 4,000–150,000 endpoints. Counting unit: cross-domain review and transfer workstations. Site and asset counts, and devices per site, are planning assumptions. The installed base has not been measured. Coverage is limited to the defined equipped subset; includes all candidate endpoints within that assumed subset. Hardware eligibility, certification, adoption and achievable NØNOS share are unverified; overlaps other cases.

Endpoint security market report ↗

Market context only; separate from device and site population estimates. Original monetary-market scope and geography are preserved in benchmark. This source does not establish the assumed worldwide site count or endpoint density.

How to interpret the figures

Adjacent or broader commercial market benchmark; not the NØNOS OS market, licensable-device count or revenue forecast.

Modelled candidate endpoints multiplied by an assumed annual USD price per endpoint. Pricing is a planning assumption, not a vendor quote. This illustrates the full scenario range, not revenue or total addressable market. It excludes adoption timing, procurement, certification, support costs, channel economics and achievable market share. Use cases can overlap, so their totals do not represent unique devices.

Research from 2026. Publisher estimates have not been independently audited.

Read the full methodology

Explore NONOS

Choose your
NONOS experience.

Discover the platform for your organisation or explore the software.

You can reopen this chooser from the footer at any time.