Perimeter · Northstar DC Group | |egress · deny by default |models · in-perimeter |published artifacts · 0
MOCKUP · SYNTHETIC DATA
Northstar Sovereign Factory
AR
Scene 1 · The Factory

Describe the tool you need.

Anyone at Northstar can. The sandbox spawns on whichever attached resource has capacity — HQ rack, colo GPU, edge node — and it is wired to the org's own models, the org's own documents and the org's own policy before the first token is generated.

Guided lane · A. Ruiz, Procurement
Sources · Deliveries share Sources · Steel spec library Model · GLM-5.2 (in-perimeter) Harness · org default
Promotion gate
◇SSO wrap
◇Audit hooks
◇Security scan
◇Resource caps
◇Owner sign-off
Auto-sandbox · one-click spawn
  • Sandbox sbx-7d41 provisioned on colo-gpu-04 — VPN-attached, inside the contour
  • Model endpoints mounted: GLM-5.2 (big) · VibeThinker-3B (small) — both in-perimeter
  • Org context attached: 14,208 delivery documents · 312 steel specs
  • Secrets brokered — never rendered into a prompt
  • Egress policy applied: deny by default — 0 outbound connections permitted
  • Telemetry sink: local — the insight module reads it, nothing else does
Build log
Scene 2 · The Org's Shelf

Northstar's catalog.

Not our shelf — theirs. Every tile was built by Northstar, inside Northstar, and passed the same promotion gate. Apolo supplies the factory and the golden templates; the org supplies the apps, and there is no per-app licence to negotiate because there is no per-app licence.

9 apps 6 built this quarter avg. 24 min to live 0 apps ever left the perimeter
Scene 3 · The Insights

Northstar's AI P&L — computed inside.

The portal is a tenant of Northstar's contour, not a cloud they log into. It reads full-fidelity telemetry locally, which is why it can answer at this resolution. The only thing that ever crosses the wall is the artifact at the bottom of this page — and only when Northstar signs it.

Hours returned this quarter
3,180
Measured as task-completions × the pre-AI baseline time for each workflow, both recorded in-perimeter. Nothing here is modelled from an industry average.
Apps in catalog
9
+6 this quarter
Avg. time to live
24 min
−71% vs Q1
Compute cost / task
$0.14
−38% vs Q1
Sandbox utilisation
61%
HQ 44% · colo 88%
Policy events
0
egress denials: 214
Apps promoted to the catalog
per month, since the factory went live
Compute cost per completed task
US dollars, all workloads, in-perimeter metering
Move 3 idle serving replicas from HQ to colo-gpu-04
HQ serving has sat under 44% for 21 days while colo runs at 88% and queues. Rebalancing holds p95 latency and drops monthly spend by an estimated $2,140. Both sites are inside the contour, so this is a scheduling change, not a security review.
The insight module · segregated enclave
Publish this month's distributions?
This is the entire artifact. Read it, then decide. Apolo cannot pull it — Northstar pushes it, or it never moves.
# northstar · 2026-08 · derived metrics, k≥12, laplace noise ε=1.0 apps_promoted_bin "3–5" time_to_live_p50_bin "20–30min" cost_per_task_bin "0.10–0.20usd" harness_mix {claude:.52, codex:.19, open:.29} model_mix_big_small {big:.34, small:.66} gate_pass_rate 0.87 egress_denial_rate 0.031 sandbox_util_bin "60–70pct" # withheld: app names, prompts, code, documents, users, sites
Computed inside your perimeter · only anonymized distributions can be published
Fleet benchmarks are locked
They light up once Northstar publishes its first distribution. Give to get — the fleet is built from what orgs choose to send, one signed artifact at a time.
Fleet benchmarks · 34 orgs
Northstar vs the fleet
percentile within the published fleet — higher is better
Northstar    fleet median
Scene 4 · The Contour  ·  Admin only

The perimeter, drawn and editable.

Four sites, one policy domain. Click any node for its configuration. The contour is not a diagram someone drew once — it is the live object the scheduler reads, and it is edited here, in plain language, by an agent running on Apolo itself.

ARTIFACT GATE · INBOUND NORTHSTAR CONTOUR · 4 SITES · ONE POLICY DOMAIN HQ · PRIMARY DC Ashburn, VA APOLO — INSTALLED HERE · control plane + scheduler · model registry + serving · catalog + policy engine · audit log · insight module 12 nodes · 4× H200 · 44% used VPN · ORG KEYS · mTLS colo-gpu-04 · partner DC Reno NV · 8× H200 · burst train + serve · 88% used cloud VPC · private link us-east-1 · 0–24 nodes · no public endpoint Sterling campus · edge 2× L40S · inference next to the data · 31% used Regulated enclave · SEALED zero outbound — the broker refuses these projects LLM EGRESS BROKER the only component with a route out redact · log · hash · meter 18% of tokens today EXTERNAL FAUCETS Anthropic OpenAI Google brokered-open every call logged OUTSIDE THE CONTOUR SANDBOXES HAVE NO ROUTE OUT — NOT A POLICY, A ROUTING TABLE A sandbox that wants an external model asks the broker over the internal network. It opens no socket to the internet and never sees the provider credential — the broker holds it. Delete the broker and every harness falls back to in-perimeter models. Nothing breaks open.
Contour configurator · runs on Apolo
Change the perimeter in a sentence.
The agent writes the declarative change, applies it, and keeps a revert point. It runs in a sandbox like everything else — it just has the policy scope to edit the contour.
awaiting instruction …
Guardrails · enforced by the policy engine
Not the agent's good behaviour — the agent has no scope for these, so a prompt injection cannot reach them either.
  • disable or truncate the audit log
  • remove, bypass or re-point the egress broker
  • widen a sealed enclave or unseal one
  • delete or reconfigure the insight module
  • grant itself scopes it was not given
Change history
  • 08-04 09:12Raised cloud VPC ceiling 16 → 24 nodes
  • 07-28 16:40Sealed the regulated enclave — outbound removed
  • 07-19 11:03Attached Sterling campus over WireGuard
Sovereignty ratio — tokens served in-perimeter
82%
Up 24 points since March. Not a target imposed by us — the number Northstar drives up as the scaffolder learns which work the small in-perimeter model can already do.
Sovereignty ratio
share of all tokens served by in-perimeter models, by month
Where this month's tokens were served
18% crossed the wall — every one of them through the broker, logged
In-perimeter · 82% · 41.2B tokens External faucets · 18% · 9.0B tokens
By harness — the same split, per tool
Models in service
What actually answered, and from where
this month, all projects
ModelServed fromRoleTokensShareCost
GLM-5.2HQ + colo-gpu-04big brain — reasoning, long context18.4B36.6%$14,200
VibeThinker-3Bevery site, incl. edgesmall brain — classify, extract, route19.1B38.0%$2,910
bge-m3 (embeddings)HQretrieval over org context3.7B7.4%$480
Claude (Anthropic)external faucetagentic coding in Claude Code6.1B12.1%$31,700
GPT (OpenAI)external faucetagentic coding in Codex CLI2.6B5.2%$13,400
Gemini (Google)external faucetoccasional long-context review0.3B0.7%$1,850
17.9% of tokens carry 74% of the model bill. That gap is the scaffolder's backlog, not a moral failing.
Faucet discipline
How a harness is allowed to reach an external model
Brokered-open: teams do not file a ticket to use Claude Code. They also cannot make a call nobody can see.
1 · No direct routeThe sandbox has no egress. Its resolver returns the broker for every model provider hostname; the credential lives in the broker.
2 · Redaction passSecrets, customer identifiers and files from tagged stores are stripped before the request leaves. What was removed is recorded.
3 · Full capturePrompt, response, model, harness, project and a content hash are written to the in-perimeter log. Replayable later, in full.
4 · Meter and ceilingPer-project spend and token ceilings. Cross one and the broker degrades to the in-perimeter model rather than failing the job.
FaucetModelsStatusCalls todayRedactionsSpend / ceiling
Anthropicclaude-opus-5, claude-sonnet-5open14,208311$31.7k / $40k
OpenAIgpt-5.x-codexat 88% of ceiling6,940180$13.4k / $15k
Googlegemini-3-proopen4026$1.9k / $10k
All faucets — regulated enclave—refused at the scheduler0—n/a
One captured call, as stored
# broker log · in-perimeter · retained 400d · replayable ts 2026-08-06T09:41:22Z project "mtr-crosscheck" sealed: false harness "claude-code" sandbox "sbx-7d41" faucet "anthropic" model "claude-opus-5" tokens {in: 18402, out: 2911} redacted {secrets: 2, customer_ids: 0, tagged_files: 1} prompt_sha256 "9f2c…a41e" full text stored locally decision "allowed" under ceiling, project not sealed
Mockup · synthetic data · no real customer figures Design language: Apolo Launchpad Companion to the Q&A schematics ← back to Apolo