Why this environment matters
A transfer station between differently trusted networks must decide more than whether a file is malware-free. It must know which direction is permitted, which content may cross and who approved this particular release. This concept considers a controlled file-transfer workflow; it does not present NØNOS as an accredited cross-domain solution.
The security challenge
Incoming media would first enter a quarantine workspace with no authority to write to the destination network. Format-specific parsing and, where appropriate, transformation would produce a candidate output. A separate reviewer or policy process would decide whether that output is permitted to cross, using its own authenticated context.
How the capsule model could help
A prototype could use NØNOS capsules to limit each parser to a single input and a constrained output channel. The exporter would receive the exact approved derivative, its destination and a one-use release permit. It would not accept an arbitrary path supplied by the parser, because that could turn file handling into a general data-extraction mechanism. Content can be disallowed without being executable. Images, embedded metadata, document layers or apparently ordinary text may carry information that the receiving side must not obtain. The transfer policy therefore requires a defined content model and appropriate human or technical review beyond memory-safe decoding. The evaluation would retain a durable record of input identity, transformation, approval and output identity. A station restart should not cause an approved transfer to run twice or convert a partly reviewed file into a released one. Temporary sessions and lasting accountability need deliberately different storage paths.
Deployment requirements
A deployment would need the relevant cross-domain policy, approved components and independent evaluation. This concept does not establish classification correctness, sanitisation completeness, physical separation or permission to handle classified data. Evaluation requirements: Change a derivative after review and verify that its existing release permit no longer matches. Present an otherwise valid permit for the opposite transfer direction and confirm refusal. Restart between approval and delivery, then demonstrate that the transfer record distinguishes pending, completed and uncertain outcomes.
Current public-beta limitations, hardware support and application availability must be assessed before any pilot. Neither this use case nor an industry source establishes NONOS certification or a current customer deployment.
Parsing and release authority belong to separate components
Incoming media would first enter a quarantine workspace with no authority to write to the destination network. Format-specific parsing and, where appropriate, transformation would produce a candidate output. A separate reviewer or policy process would decide whether that output is permitted to cross, using its own authenticated context.
A prototype could use NØNOS capsules to limit each parser to a single input and a constrained output channel. The exporter would receive the exact approved derivative, its destination and a one-use release permit. It would not accept an arbitrary path supplied by the parser, because that could turn file handling into a general data-extraction mechanism.
A clean parser cannot classify information reliably by itself
Content can be disallowed without being executable. Images, embedded metadata, document layers or apparently ordinary text may carry information that the receiving side must not obtain. The transfer policy therefore requires a defined content model and appropriate human or technical review beyond memory-safe decoding.
The evaluation would retain a durable record of input identity, transformation, approval and output identity. A station restart should not cause an approved transfer to run twice or convert a partly reviewed file into a released one. Temporary sessions and lasting accountability need deliberately different storage paths.
Who could buy or integrate it?
- Defence and intelligence organisations procuring controlled transfer workflows
- Cross-domain solution vendors integrating content handling and release components
- Government security integrators building approved transfer-station environments
Industry examples: BAE Systems, Everfox. These are research prospects, not represented as NONOS customers, partners or endorsers.
