Internal · Working Session · August 2026 · Revision 2
The Sovereign Factory, asked and answered.
Seven questions that define what we build. Each schematic is a proposed answer — the "open for debate" line under each is where the conversation continues. Direction locked: Apolo doesn't build the org's apps; Apolo is the sovereign factory where the org — its people plus AI agents — builds its own. And Apolo is not a service the org reaches out to. Apolo is installed inside the organization.
Companion to Apolo_Repositioning_Sovereign_Sandbox.key · incorporates the DRR model (H.M., board) · demo assets referenced from the AI Launchpad kit
What changed in this revision
Rev. 1 drew Apolo as an outside party with a pipe reaching into the customer. Wrong model. We install inside the org and connect the org's resources over secure VPN so that leased racks, cloud capacity and remote sites all fall inside one cohesive internal perimeter. The VPN doesn't punch a hole in the wall — it extends the wall around more ground.
Consequence for the data story: there is no vendor telemetry pipe. What exists is an insight module in a hardened enclave inside the org. It reads full-fidelity data locally, publishes only anonymized distributions outward, and reads fleet-level reference data back in so the org never has to leave its own perimeter to get an answer. Q4 is rebuilt entirely around this; Q2 is new.
Q1 · The Product
What are we actually selling now?
Three layers, one story, all of them installed on the customer's side of the wall. The Ground is the deck's sovereign contour — paid infrastructure, the Series A line. The Factory is the new middle: auto-provisioned sandboxes for the whole org, and the org's own catalog where finished apps land. Apps themselves cost nothing — they're the exhaust, not the product. The Intelligence layer is the data story, and it runs in-perimeter too: the portal is a tenant of the org's contour, not a cloud they log into.
Open for debate — do we name the middle layer "Factory" externally, or keep "Sovereign Contour" as the umbrella and let the factory be its verb? Naming decides the deck's spine.
Q2 · The Deployment
Where does Apolo actually live?
Inside. Apolo is software the organization installs, on the organization's Kubernetes, under the organization's identity provider, on the organization's keys. Compute that isn't physically in the building — leased GPU racks in a partner DC, private cloud capacity, a plant on the other side of the country — is joined by secure VPN into one cohesive internal perimeter. That is the whole trick: the tunnel extends the wall rather than piercing it, so the CISO reviews one perimeter instead of five vendor integrations. Apolo-the-company sits outside it with no data plane and no standing access; what flows in is signed release bundles, pulled on the org's schedule through the org's own gate.
Open for debate — do we ship our own overlay mesh (WireGuard-class, keys handed to the customer) as part of the install, or ride whatever SD-WAN/MPLS the org already runs? That choice decides who our buyer is inside IT — the platform team or the network team — and how long the install actually takes.
Q3 · The Factory
How does an app get born?
Two lanes into one machine, and every step of it inside the contour. The guided lane is the Crimson CFO: describe the tool in plain language, the scaffolder does the heavy lifting inside a sandbox already wired to org models, org data and org policy. The power lane is the org's engineer with full harness choice. Everything exits through one promotion gate — SSO wrap, audit, security scan, owner sign-off — and lands on the org's shelf. Because every attached resource is inside the same perimeter, where a sandbox runs is a capacity decision, not a security decision.
Open for debate — the promotion gate is where enterprises will judge us: how heavy is v1 governance (full approval workflow vs. sign-off checkbox)? And do we show both builder lanes in the mockup, or lead guided-only for emotional punch?
Q4 · The Perimeter
What does Apolo actually see?
Nothing. Apolo-the-company has no view into the org's systems, because there is no pipe from their systems to ours. What exists instead is an insight module in a hardened enclave inside the org, operated by the org. It reads full-fidelity telemetry locally and publishes only anonymized distributions — rates, ratios, binned shapes, threshold-gated — through a release gate the org's own admin signs. The same module reads fleet-level reference data back in, so the org gets comparative answers without anyone leaving the perimeter to ask. This is what makes Herb's data agreement signable: not a promise about restraint, an architecture where the raw material physically has nowhere to go.
Open for debate — two knobs, and both are the DSSA conversation. First, governance: does the admin sign every release, or set a standing policy with periodic review? Second, the anonymization parameters — k-threshold, bin widths, noise — do we publish them openly as a trust move: "here is everything that can ever be computed, and here is the floor it is blurred to"?
Q5 · The Data Asset
Where does the compounding data story come from?
Two flywheels, both spinning inside the customer. The ops flywheel turns runtime telemetry into sold recommendations — redeploy resources, fix pricing, harden security. The build flywheel turns build traces into a smarter scaffolder. Both feed the org's own full-fidelity corpus, which never moves. The fleet corpus is a second, thinner thing: assembled purely from the distributions orgs publish, one signed release at a time. It grows more slowly than a telemetry pipe would — and it is the only version of this asset an enterprise will ever agree to. Nobody else has it: the labs see API calls, Copilot and Cursor see editors; nobody sees whole-org build-and-run inside enterprise perimeters.
Open for debate — synthetic data's third act: distilled synthetic app-templates and workload traces sold to hardware partners and DC operators for capacity planning. In or out of the story for the raise? And the harder one: with publication org-gated, our corpus growth rate is a function of how many admins press the button — do we underwrite that with a pricing incentive, or leave it to the benchmark give-to-get?
Q6 · The Money
Who pays for what — and what does the raise lead with?
Herb's mechanics, mapped honestly onto the factory. Apps go to zero forever — radical, and nobody can undercut it, because the org builds them itself. The ground stays paid: that's the infrastructure ARR the deck already claims. The DRR line is the raise headline — recurring answers from OpEx, delivered by a portal that runs on their own metal.
Open for debate — does the 2026 money slide move the $1M+ target to install + platform + DRR with the agent line at zero? And do we show Herb illustrative DRR math (20 orgs × $3–5k/mo portal) or let him do that arithmetic himself in the room?
Q7 · The Mockup & The Demo
What do we mock this week, and what do we demo live?
One continuous HTML walkthrough, three scenes, all of it framed by a visible perimeter — the chrome itself is the argument. And one live demo that weaponizes the concession: rebuild MTR CrossCheck inside the factory, in twenty minutes, from the same Artrom PDFs in the sales demo kit. Slide 03's threat becomes the product demo.
Open for debate — skin the mock as a DC-builder org (Aligned-ready) or vertical-neutral with a toggle? And does the live-demo promise (20 minutes, real build) go into the mock as a claim, or stay verbal until we've timed it on the real stack?
The Q&A Queue
Open questions, in decision order
Each of these changes what gets mocked or what gets said to Herb, Bill, or Aligned. Answer in any order — the mock starts moving on #6 and #7 immediately.
Naming — "Sovereign Factory" as the layer name, or keep "Sovereign Contour" as umbrella with the factory as capability? (decides deck spine + mock header)
VPN posture — ship our own overlay mesh with the install, or ride the org's existing SD-WAN/MPLS? (decides the install playbook, the buyer inside IT, and time-to-first-sandbox)
Insight-module governance — admin signs every published release, or standing policy with periodic review? (decides the DSSA text and scene 3 of the mock)
Anonymization parameters — publish the k-threshold, bin widths and noise settings openly as a trust move? (decides the lineage badge's claim and how fast a CISO clears us)
Air-gap variant — with zero outbound, does the insight module publish by offline media, or does that site simply never contribute? (decides the government / defence / regulated pitch)
Promotion gate weight — v1 governance: approval workflow, or checkbox sign-off? (decides CISO story vs. speed story)
Mock skin + builder lanes — DC-builder org (Aligned-ready) or neutral with toggle; guided-only for punch, or both lanes? (decides scene art, sample apps, portal queries, scene 1 script)
Money slide — move the $1M+ 2026 target to install + platform + DRR, agent line to zero? Show Herb the DRR math or let him do it? (decides the board conversation)
Synthetic resale — templates/traces to hardware + DC partners: in the raise story or held back? (decides slide 09/10 edits)