A model reasons. An agentic platform operates.
Monarch's intelligence layer is a frontier cybersecurity LLM. But a model that can reason about an exploit is not a security programme — it forgets what it learned yesterday, it has no authority to act, and it can't prove who did what.
Monarch is the whole stack: the model, the orchestration that puts it to work, the memory that makes it improve, the governance that keeps it inside the rules, and the identity layer that makes every action attributable. Sovereign, on your infrastructure, end to end.
01 · Intelligence — the cybersecurity LLM
An on-premise security LLM — a sovereign LLM purpose-built to reason about offence and defence — exploit development to automated patching, red-teaming to threat hunting. Where general-purpose frontier models refuse authorized security work, Monarch's model performs it under governance — inside an authorization and audit framework, which the layers below provide.
- •#1 on Cybench versus every frontier model
- •~0 refusals on authorized security tasks
- •No token caps — unlimited use across the team
- •Sovereign — built in Europe, tuned in Singapore. PDPA · GDPR · NIS2 · EU AI Act
Fully on-prem, full capability
The compact sovereign model runs inside controlled infrastructure on a single machine, data never leaving your environment. On Cybench (of 33, pass@3) it solves 25 — against Claude Code at 15, Codex at 15, Mistral at 10. Air-gapped is not the weaker edition.
Foundation model via Alias Robotics; integrated, tuned and operated by UD Works.
02 · Orchestration — agents that do the work
Intelligence becomes action through an orchestration engine that composes specialised agents from one command line and runs them in parallel under shared context.
- •Multi-platform — workstations, data centres, edge, robots. On-prem and air-gapped.
- •Multi-model — 300+ models including the sovereign model: OpenAI, Anthropic, DeepSeek, Ollama, or fully local.
- •Agent-based — modular, MCP and Burp Suite compatible.
- •Day-zero UX — automatic agent selection and guided workflows.
Each agent maps to a real security role — composed per scenario, run in parallel, end to end across offence, defence and monitoring:
03 · Memory — the platform that gets better with use
A model with no memory starts every engagement from zero. Monarch's memory layer gives the agents persistent, sovereign recall and a reusable skill library — so the platform compounds instead of repeating itself.
- •Engagement memory — findings, asset context and prior results persist across sessions. A re-test knows what the last test found; an investigation builds on the last one.
- •Skill library — proven procedures captured once and reused: a validated attack path, a detection-tuning routine, a remediation playbook becomes a repeatable skill any agent can invoke.
- •Organisational knowledge — your environment's topology, exceptions and history stay with the platform, not in an analyst's head.
- •Sovereign by construction — memory lives on your infrastructure. Nothing about your environment is retained off-site. Behind the air-gap, recall is complete and local.
This is what separates a platform from a chatbot: it accumulates. The tenth engagement is sharper than the first because Monarch remembers the nine before it.
04 · Governance — every action inside the rules
An AI that can write an exploit needs a runtime that decides what it is allowed to do — enforced on every call, local models included.
- •Runtime guard, <2ms — policy evaluated on every tool call: dangerous commands, protected paths, secret and network safety.
- •Policy DSL — YAML rules, 26 built in, evaluated in under 2ms.
- •AI governance gateway — PII detection across 8 entity types with redaction before and after the model; prompt-injection blocking across 20+ patterns; token, model and rate limits.
- •No exceptions — governance applies identically to sovereign local models. There is no ungoverned path.
This layer is why an offensive capability is safe to run continuously: nothing executes outside policy, and every decision is logged.
05 · Identity — every action attributable
Autonomous agents acting on live infrastructure raise the hardest question in security: who did this? Monarch answers it with an identity layer that binds every action to an accountable actor.
- •Actor identity for agents and humans — every agent operates under a verifiable identity, scoped to what it is authorized to do.
- •Non-repudiable audit trail — an unbroken chain from the human who set intent, through the model, to the action taken. Nothing is anonymous.
- •Least-privilege by default — an agent gets only the authority its task requires, and identity governs credential revocation on response.
- •Sovereign trust — identity is issued and verified inside your environment, not delegated to an external provider.
For a regulated buyer this is the difference between an audit that passes and one that doesn't: not "the AI did it," but exactly which authorized identity did what, when, under whose intent.
Why five layers, not one model
Every competitor selling "AI security" is selling a model with an API. Monarch is the layers that make a model operational and safe:
Intelligence reasons. Orchestration acts. Memory compounds. Governance constrains. Identity accounts.
Remove any one and it isn't an enterprise platform. A model with no memory can't improve. Orchestration with no governance can't be trusted on live systems. Action with no identity can't be audited. Monarch is sovereign in all five — built where IT, OT, robotics and AI converge, and where none of it is allowed to leave the network.
The trajectory
On a fixed benchmark, successive sovereign models keep raising the solve rate while spending an order of magnitude fewer tokens than general-purpose agents — from 13/33 to 28/33 Cybench solved across the model line, 80%+ of the benchmark saturated, leading pass@3 against every frontier model from Anthropic, OpenAI, Google and Mistral in early 2026.
Sources: arXiv:2512.02654; arXiv:2601.14614.
One sovereign agentic stack — intelligence, orchestration, memory, governance, identity.
