Products

Five layers.
One sovereign stack.

Sites, modules, sovereign cloud, cybersecurity, applications — each layer is a distinct product. Pick what solves your problem. Own more as your demand grows.

The Navon stack

Five layers. One owner. Yours.

5 layers · 1 control plane
Hover or click any band to dive in
05 / APPLICATIONS & AGENTS

Sovereign AI, agents, skills.

Domain agents, vertical apps, and MCP-style skills running on your infrastructure — citizen services, CBDC, defence copilots, finance assistants, healthcare AI.

/ Agents · skills · apps
  • Sovereign LLM
  • RAG
  • MCP skills
  • CBDC
  • Citizen ID
  • Vertical apps
Explore utility
04 / CYBERSECURITY

Quantum-safe by default.

PQC + QKD defence-in-depth, sovereign HSMs, and crypto-agility — protecting workloads with sensitivity lifecycles measured in decades.

/ Sovereign trust
  • PQC
  • QKD
  • HSM
  • QRNG
  • Vaults
Explore security
03 / SOVEREIGN CLOUD

CPU, GPU, QPU. One API.

Bare-metal, VMs, GPU pools, QPU queues, object/block/file storage — all in-country, addressable from a single white-label control plane.

/ Compute · GPU · QPU
  • IaaS
  • GPU
  • QPU
  • Storage
  • White-label
Explore cloud
02 / MODULAR DATA CENTRES

Tier III, factory-built.

Three steel modules, twenty 20 kW racks, dual UPS, in-row DX cooling — witness-tested before shipping. Capacity lands when the trailer arrives.

/ Tier III modules
  • 400 kW
  • 20 kW racks
  • Tier III
  • EI60
  • ~6 mo
Explore modules
01 / SITES · POWER · LAND

The base everything stands on.

SEZ land tenure, geothermal and hybrid renewables, fibre, water — the physical conditions that make sovereign compute possible at all.

/ Foundation
  • Land
  • Solar
  • Geothermal
  • Wind
  • Fibre
  • SEZ
The foundation
01 / Modular data centres

Tier III, built in a factory.

A complete 400 kW Tier III data centre packaged into three insulated steel modules. Twenty 20 kW racks, dual UPS, eighteen in-row cooling units, hot-aisle containment, integrated fire detection and suppression — all assembled, witness-tested, and commissioned at the factory before being trucked to site. Civil works run in parallel; capacity lands when the trailer arrives.

01 / THE MODULE

The 400 kW MDC.

Three insulated steel enclosures combine into one Tier III data centre: two IT rooms hosting twenty 20 kW racks plus a dedicated power-and-cooling room. Witness-tested at the factory before shipping.

  • FORM3 × steel modules
  • CAPACITY400 kW · N+N
  • RACKS20 × 42U @ 20 kW
  • LEAD TIME~6 mo
Tier III EI60 · 80 mm Hot-aisle contained
02 / THE RACK

20 kW, 42U.

An EIA-310-D cabinet with 70% perforated front and split rear doors that open 130° for service. Tool-less doors, removable power trough, and a removable bottom cover for raised-floor cabling. Frame rated to 1,420 kg, IP20.

  • FORM42U · 600 × 1100 × 2000 mm
  • POWER20 kW · A+B feeds
  • STANDARDEIA-310-D · IP20
  • LOAD1,420 kg max
70% perforation Tool-less doors Raised floor ready
03 / THE DCIM

One pane of glass.

A real-time platform spanning every rack and site: live PUE and energy analytics, rack-level asset and capacity views, ITIL-aligned incident and work-order flow, plus a mobile inspection app with QR-coded assets.

  • VIEWSingle pane · multi-site
  • METRICSLive + historical PUE
  • MODULESAsset · Capacity · Work order
  • ACCESSWeb + mobile app
Live PUE Asset graph ITIL incident flow
01 / N+N POWER

Dual-fed by default.

Two 1,600 A main distribution boards with automatic transfer, two 500 kVA UPS systems, and vertical PDUs giving every rack independent A and B feeds. No single point of failure.

02 / N+1 COOLING

PUE 1.29 verified.

Eighteen in-row DX cooling units with paired outdoor condensers, hot-aisle containment throughout, and a dedicated split system for the electrical room — independently validated against Nairobi's 20-year ASHRAE profile at 400 kW IT load.

03 / CARRIER-NEUTRAL

Dual fibre entry.

Multiple terrestrial and submarine carriers terminating into a meet-me room. Customer cross-connects on request, no lock-in.

04 / FACTORY-BUILT

Witness-tested before shipping.

Modules are wired, plumbed, and commissioned off-site, then put through a factory witness test. Civil works run in parallel; capacity lands when the trailer arrives.

05 / FIRE & SAFETY

EI60 throughout.

Insulated 80 mm steel panels with 60-minute fire rating, EI60-rated entrance and internal doors, integrated detection and clean-agent suppression. Optional aspirating smoke detection for early warning.

06 / SECURITY-READY

Access & surveillance built in.

Optional PoE-managed access control with card-and-keypad readers on EI60 doors, full IP CCTV with NVR, and a managed PoE switch — all wired, mounted, and configured at the factory.

07 / SOVEREIGN

Built where you operate.

Sites placed where the energy, fibre, and regulatory clarity converge. Operated by local teams under local jurisdiction, monitored from the DCIM platform you control.

08 / ALTITUDE READY

1,624 m · 6–34 °C.

Performance verified at Nairobi altitude across the full annual temperature band — efficiency holds where most reference designs degrade.

09 / ECONOMICS

~$7M / MW · ~6 months.

Factory-assembled modules deliver a complete Tier III megawatt at a fraction of a ground-up build's cost, and compress time-to-deploy from 18–36 months down to about six. Every infrastructure decision sized to maximise compute per watt and compute per dollar.

02 / Turnkey hardware systems

Pre-configured racks, right-fit by workload.

Each rack is engineered backwards from the workload — every watt of the 20 kW envelope spent on compute, or every rack unit spent on capacity, sized to what the customer actually runs. Five reference configurations cover the most common sovereign-compute use cases — four compute-led, one storage-led — and everything ships pre-integrated, cabled, and commissioned.

01 / RESEARCH RACK

One rack. Mixed workloads.

A single 20 kW rack pre-built for university, lab and research workloads — three CPU nodes for general compute, two 8-GPU training nodes, and a half-petabyte NAS, on a redundant 25 / 100 G fabric. Fourteen rack units left free for the team to grow into.

  • FORM1 × 42U @ 20 kW
  • COMPUTE3 CPU + 2 × 8-GPU
  • STORAGE~576 TB NAS
  • LEAD TIME14–16 wk
Academic Research labs Mixed AI / HPC
02 / TRAINING CLUSTER

Frontier GPU. Five racks.

Five 20 kW racks built around 8-GPU training systems, each paired with a Blackwell-class PCIe accelerator node to fully utilise the 20 kW envelope. Engineered for large-model training and high-throughput inference, with a flat 400 G fabric across the cluster. Ships pre-integrated with vLLM, Ollama, and an OpenAI-compatible endpoint — the same serving stack as the sovereign cloud, on dedicated silicon. Two tiers: latest-generation or prior-generation HGX.

  • FORM5 × 20 kW racks
  • COMPUTE5 × 8-GPU + PCIe nodes
  • FABRIC400 G end-to-end
  • LEAD TIME14–16 wk · or 30–32 wk
Large-model training Frontier silicon 100 kW
03 / INFERENCE CLUSTER

Lowest cost per token.

Five 20 kW racks built around dense PCIe inference nodes — tuned for serving traffic, not training runs. Memory-bandwidth-rich silicon, packed as tightly as the 20 kW envelope allows, behind a vLLM-class serving stack with continuous batching and paged-KV-cache. Optimised for the metric that actually shows up on the bill: cost per million tokens out, not peak FP16 TFLOPS.

  • FORM5 × 20 kW racks
  • COMPUTEDense PCIe inference nodes
  • FABRIC100 G (400 G optional)
  • METRICTuned for $ / token
Production inference Low $ / token High concurrency
04 / OPEN ACCELERATOR

An alternative to GPU lock-in.

Five 20 kW racks built around a non-mainstream AI accelerator paired with general-purpose PCIe compute. For customers who want serious training and inference capacity without committing the entire stack to a single silicon supplier — sovereignty and supply-chain diversity, by design.

  • FORM5 × 20 kW racks
  • COMPUTEAlt-AI + PCIe nodes
  • FABRIC400 G end-to-end
  • POSTUREVendor-diverse
Sovereignty Supply-chain hedge Open silicon
05 / COLD STORAGE

Petabyte-scale, sized to your data.

Storage-led racks shaped to whatever the customer actually holds — from a few hundred terabytes for a research lab to multiple petabytes per rack for sovereign archives, scientific data lakes, and long-tail data residency. Mostly disk shelves, a slim controller, and the same dual-corded power and 25 / 100 G fabric the compute racks ride on. Configurations span all-flash for low-latency archive, hybrid NVMe + HDD, and pure HDD for true cold tiers.

  • FORM1 × 42U · ≤ 20 kW
  • CAPACITY~0.5 PB → 2 PB+ raw
  • TIERSAll-flash · hybrid · cold HDD
  • USEArchive · data lake · sovereign residency
Sovereign archive Scientific data lake Compliance retention Backup & DR target
Design principles

Right-fit means more than spec-matching.

We engineer infrastructure backwards from the application — not from the catalogue — to match each workload and its environment. Optimal performance, cost-efficiency, and seamless integration with the modular Tier III data centre that hosts it.

01 / APPLICATION ALIGNMENT

Workload first, hardware second.

Configurations selected by end-use case — AI inference, HPC analytics, training, storage. The most suitable hardware system is determined by the use case's performance requirements and cost constraints, not by what's on a SKU sheet.

02 / PERFORMANCE & SCALABILITY

Headroom by design.

Vertical and horizontal scaling paths to track software evolution, with margins of safety so customers never top off on compute. Cooling, IT-load and space envelopes are sized after the application is locked, not before.

03 / COST-EFFICIENCY

Pay-as-you-scale.

Competitive CapEx operationalised through energy-aware configurations and PUE-tuned designs. A modular growth model — capacity follows demand, not the other way around — keeps every euro and every watt working.

04 / SECURITY & RELIABILITY

Hardened, warranted.

Encrypted storage, tamper-evident racks, in-jurisdiction compute. High availability and extended warranties are included by default — never retrofitted at the contract stage.

01 / RIGHT-FIT

Engineered to the watt — or to the petabyte.

Compute racks are sized so steady-state load lands ≈95% of the 20 kW envelope; storage racks are sized to whatever capacity the customer actually holds. Every dollar of CapEx spent on what gets used, not stranded.

02 / DUAL-FED

Active/active across A+B.

Every node is dual-corded across A and B PDUs and sized so that on single-feed failover, the surviving feed carries the full ≈19 kW load within budget.

03 / FLAT FABRIC

25 G to 400 G, dual-switch HA.

Cluster-wide Ethernet — 25 / 100 G for the research rack and the inference cluster, full 400 G for training and open-accelerator clusters — built around a vendor-open switch stack rather than a closed network silo.

04 / LANDED

Installed and commissioned.

Crating, freight, on-site rack-and-stack, network and software bring-up — handled by a specialist field team. Customer takes delivery of a working cluster, not a parts list.

05 / FITS THE MODULE

Drops into a Navon MDC.

Every configuration — research rack, training cluster, inference cluster, open accelerator, cold-storage rack — is sized to the same 20 kW rack envelope used in the 400 kW MDC, so compute and storage live side-by-side under the same facility, DCIM, and cooling budget.

06 / VENDOR-AWARE

Choose your stack.

Where the workload demands the latest GPU silicon, we ship it. Where customers want to hedge supply-chain or sovereignty risk, we offer a fully-credible non-mainstream accelerator path — same rack, same fabric, same operating model.

Anatomy of a rack

One 20 kW rack, most workloads.

The research-rack reference design — three CPU nodes, two 8-GPU training nodes, half-petabyte NAS, dual leaf fabric, dual-corded power. Click any unit to inspect its hardware, networking, and load.

  • Form1 × 42U
  • Steady-state load19.05 kW · 95% util
  • Lead time14–16 wk
Rack elevation · 42U Est. load
  1. 381U cable mgmt
  2. 311U gap · airflow
  3. 261U gap · airflow
  4. 211U gap · airflow
  5. 16–3 Reserved · 14U expansion capacity
  • GPU node
  • CPU node
  • NAS
  • Network
  • PDU
Logical topology

Two GPU nodes for training and high-throughput inference. Three CPU nodes for general compute and orchestration. One NAS for shared training data and checkpoints. Two leaf switches and two PDUs in active/active redundancy. Hover any rack unit to highlight its connection.

  • GPU compute13.0 kW
  • CPU compute4.5 kW
  • Storage1.0 kW
  • Network0.55 kW
Per-node IT loadSteady-state · TDP-derived
  • GPU Node 16.50 kW
  • GPU Node 26.50 kW
  • CPU Node 11.50 kW
  • CPU Node 21.50 kW
  • CPU Node 31.50 kW
  • NAS1.00 kW
  • Asterfusion fabric0.55 kW
Budget summary
Rack budget20.0kW
Est. IT load19.05kW
Headroom0.95kW
Utilisation95%
0 kW20 kW
Dual-feed (A/B) PDU allocationBalanced for redundancy
DevicePSU configFeed A drawFeed B drawTotalNotes
GPU Node 12× 3 kW redundant3.25 kW3.25 kW6.50 kWActive/active across A+B
GPU Node 22× 3 kW redundant3.25 kW3.25 kW6.50 kWActive/active across A+B
CPU Node 12× 1.6 kW redundant0.75 kW0.75 kW1.50 kWActive/active across A+B
CPU Node 22× 1.6 kW redundant0.75 kW0.75 kW1.50 kWActive/active across A+B
CPU Node 32× 1.6 kW redundant0.75 kW0.75 kW1.50 kWActive/active across A+B
NAS2× 1.6 kW redundant0.50 kW0.50 kW1.00 kWActive/active across A+B
Asterfusion leaves2× PSU per switch0.28 kW0.27 kW0.55 kWPrimary on A, redundant on B
Feed totals9.53 kW9.52 kW19.05 kWFailover load per feed: ≈ 19 kW (within 20 kW budget)

Load figures are steady-state estimates derived from component TDPs (EPYC 9965 ≈ 500 W; RTX 5090 ≈ 575 W TGP) plus platform overhead. Peak training bursts can push GPU nodes ≈ 10–15% higher — size PDUs and breakers for peak, not average. On single-feed failover the surviving feed carries the full ≈19 kW, so both PDUs are sized to 20 kW.

03 / Sovereign cloud

CPU, GPU, QPU, storage —
one control plane.

A complete sovereign cloud stack: bare metal and virtual machines for general-purpose CPU workloads, multi-tenant GPU pooling for AI training and inference, sandboxed access to partner quantum hardware, and object, block and filesystem storage — all under one API, all in your jurisdiction. Built on best-of-breed open source where it adds leverage, white-labelled where it pays.

01 / CPU & VMs

General-purpose, in your jurisdiction.

Bare metal servers, virtual machines, managed Kubernetes, and managed databases for everything that isn't AI training. Provision in minutes through a single API; private VPCs, firewalls, and cross-cloud gateways for hybrid workloads. The right answer for web services, data platforms, internal tooling, and the long tail of compute that doesn't need a GPU.

  • FORMBare metal · VMs · K8s
  • PROVISIONMinutes via API
  • MANAGEDPostgres · K8s · Object
  • NETWORKINGVPC · firewall · gateway
General-purpose Web & data Hybrid cloud
02 / GPU CLOUD

Multi-tenant AI compute.

Software-defined GPU pooling layered on Navon's bare metal — overcommit-aware scheduling pushes utilisation toward 100%, with VRAM and TFLOPS provisioned in real time. Rebrandable self-service portal, consumption billing per tenant, and a one-click model library. White-labelled on the hosted·ai GPU cloud platform.

  • FORMMulti-tenant GPU pool
  • WORKLOADSTrain · infer · fine-tune
  • PORTALRebrandable self-service
  • BILLINGVRAM-h · TFLOPS · b/w
30+ GPU SKUs BYO model No lock-in
03 / INFERENCE

Native, not a routing layer.

Production model serving on owned GPU pools — vLLM, TGI, and TensorRT-LLM for high-throughput workloads, Ollama-ready for self-hosted open weights. An OpenAI-compatible endpoint sits in front, so SDKs and tools you've already integrated — LangChain, LiteLLM, OpenRouter, LlamaIndex, Cursor — work without code changes. Bring your stack; we provide what's underneath.

  • APIOpenAI-compatible
  • RUNTIMESvLLM · Ollama · TGI · TRT-LLM
  • WEIGHTSIn-country · never egress
  • FORMNative serving on Navon silicon
Open weights Drop-in SDKs Zero egress
04 / QPU ACCESS

Sovereign quantum sandbox.

Sandboxed access to curated partner quantum hardware via a queue API — algorithm development, benchmarking, and hybrid HPC + QPU pipelines, all under Navon's sovereignty posture. For research teams, defence labs, and government programmes building toward post-classical workloads alongside their classical compute.

  • ACCESSQueue API · sandbox
  • PARTNERSCurated QPU hardware
  • WORKLOADSAlgorithm dev · bench
  • HYBRIDHPC + QPU pipelines
Research Algorithm dev Early access
05 / STORAGE

Object, block, file — local-first.

NVMe-backed object, block, and filesystem storage tiered to match the workload — fast media for live data, hybrid for working sets, cold HDD for archive and compliance retention. S3-compatible API for object, POSIX for filesystem, iSCSI for block. All in the customer's jurisdiction by default; cross-region replication only on explicit request.

  • TIERSObject · block · file
  • MEDIANVMe · hybrid · cold HDD
  • PROTOCOLSS3 · iSCSI · NFS · SMB
  • RESIDENCYIn-country, by default
Data lake Backup & DR Sovereign archive
Committed Capacity

Pre-commit. Pay less. Stay sovereign.

Cloud customers who can size their floor — production inference, recurring training jobs, working-set storage — pre-commit a 1-year or 3-year horizon and land closer to colocation economics than to public cloud, without leaving the jurisdiction.

SKU
On-demand
1Y commit
3Y commit
3Y discount
GPU computeH100 · A100 · MI300X
$1,000
$680
$450
−55%
vCPU computegeneral-purpose VMs
$1,000
$720
$520
−48%
StorageNVMe block · object
$1,000
$770
$600
−40%

Indicative anchors · normalised to a $1,000/mo baseline · final pricing confirmed at contract

See the full pricing model on the Cloud page
Open source, end-to-end

An open-source hyperscaler — seven layers, production-proven.

The big three (AWS, Azure, GCP) run proprietary stacks top-to-bottom. There's a parallel universe of open-source projects that, composed correctly, replicate most of what a hyperscaler does — already in production at OVHcloud, CERN, Walmart and dozens of telcos. We've assembled the full stack, layer by layer, and engineered around the gaps the open ecosystem leaves behind.

07 / TENANT Tenant-facing services Billing · DNS · Load balancing · CDN
06 / SECURITY Security & identity Auth · Secrets · Policy · Scanning
05 / OBSERVE Observability Metrics · Logs · Traces · Alerts
04 / ORCHESTRATE Orchestration & automation Containers · GitOps · IaC · CI/CD
03 / STORAGE Unified storage plane Block · Object · File · NVMe
02 / NETWORK Networking SDN · Routing · Overlay · Physical NOS
01 / FOUNDATION Compute foundation Bare metal · Hypervisor · Cloud platform (IaaS)
We did the hard parts

Pure open source has known gaps — billing & invoicing, marketplace & service catalogue, global traffic management, managed-database wrappers, SLA & support tooling. These are where most open-stack projects die. Our white-label control plane closes them — so customers get the cost-curve and sovereignty of open source and the polish of a commercial cloud.

AI-specific upstream

Three projects we ship into the AI tier.

On top of the seven-layer base, three upstream OSS projects sit inside the GPU layer where they matter most — distributed inference, memory optimisation, and AMD-tuned kernels. Credit and links to upstream below.

01 / SOVEREIGN BY DEFAULT

Keys, logs, tenants stay in-country.

Every workload — CPU, GPU, QPU job, storage object — lands and lives within the customer's jurisdiction. Cross-border replication only on explicit contract, never by default.

02 / SINGLE CONTROL PLANE

One API, every kind of compute.

Bare metal, VMs, GPU pools, QPU queues, and storage tiers all addressable through the same REST API and the same self-service portal. Customers don't switch consoles to switch silicon.

03 / WHITE-LABEL READY

Operate as Navon, or run your own.

Take the platform under your brand — telcos, ministries, and DFIs run a sovereign cloud with their colours, their pricing, their tenants. The hosted·ai layer rebrands end-to-end; the rest of the stack follows.

04 / PROGRAMMABLE

API · Terraform · Ansible.

Every operator action exposed through REST, with Terraform providers and Ansible playbooks for repeatable deployment and Day-2 ops. Automation-first, console-second.

05 / METERING & BILLING

Consumption-based, by line item.

VRAM-hours, TFLOPS, CPU cores, storage GB-month, bandwidth, QPU shots — all metered and billed per tenant, with regional pricing across multi-DC and built-in WHMCS hooks.

06 / HARDWARE-AGNOSTIC

NVIDIA, AMD, partner QPUs, mixed.

30+ GPU SKUs across both major vendors, alternative non-mainstream accelerators, and curated partner QPU hardware — all addressable from the same control plane. No silicon lock-in.

Built with ↓ hosted·ai NVIDIA AMD Asterfusion Kinesis Enterprise AI Kenya Alliance for AI
04 / Cybersecurity

Sovereign infrastructure.
Quantum-ready protection.

Security without sovereignty is rented trust. Sovereignty without quantum protection has an expiration date. Navon collapses the two into a single deployable platform — the modular shell, the power, and the cryptographic layer, all under the customer's flag, all engineered to outlast the post-quantum transition.

/ The clock has already started

Encrypted traffic is being harvested today and stored for the day a quantum machine can break it. Every secret with a shelf-life past a decade is already exposed.

Today · 2026
Harvest now.

State-level adversaries intercept and archive ciphertext at scale, betting on future decryption capability.

Mid-term · 5–7 yrs
Cryptographic obsolescence.

National agencies have set full PQC migration deadlines inside the decade; classical RSA and ECC fall first.

Long-tail · 10–30 yrs
Decrypt later.

Citizen registries, health records, financial archives, defence intelligence — sensitivity outlives the encryption.

The three-pillar model

Three reinforcing pillars. One compounding defence.

Data security gives the cryptographic foundation. Data sovereignty gives the physical and legal control. Quantum protection makes both durable across the post-quantum transition.

PILLAR 01 · DATA SECURITY

Cryptographic foundation.

Hardware-native protection, not a software overlay. Tamper-resistant key vaults, physics-based entropy, and an agility engine that re-encrypts the estate as standards move.

  • HSM root of trust · keys non-exportable
  • QRNG entropy · physics-based randomness
  • Hybrid classical + PQC · NIST-aligned
  • Crypto-agility engine · auto re-encrypt
  • Discovery + CBOM inventory · 5 domains
  • Evidence-based SOAR · TTP coverage
PILLAR 02 · DATA SOVEREIGNTY

Physical control.

Sovereignty is a physical condition, not a contractual assurance. Customers own the shell, the power, the network perimeter, and the keys — across National Vaults, cross-border Data Embassies, and air-gapped pods.

  • Sovereign Vaults · in-territory custody
  • Data Embassies · neutral jurisdiction
  • Jurisdiction-aware compliance profiles
  • Compute-to-data · no transit exposure
  • Sovereign AI on locally held data
  • Data gravity moat · compounds over time
PILLAR 03 · QUANTUM PROTECTION

Durable across the transition.

Quantum protection is not a 2030 retrofit — it is built in. Classical and PQC algorithms run in parallel today, with QKD reserved for the highest-assurance links between sovereign nodes.

  • Hybrid cryptography · safety-net on both sides
  • Crypto-agility orchestration · debt eliminated
  • PQC-ready HSM extensions · in-boundary ops
  • Quantum Key Distribution · physics-secured
  • Three-phase migration · assess → prioritise → full
  • Aligned to NIST · CNSA 2.0 · BSI · ANSSI
/ Thesis

Physical infrastructure controls digital sovereignty. The organisations that own the shell, the power, and the cryptographic layer own the trust.

Defence in depth

QKD secures the channel. PQC secures everything else.

Quantum security is not one technology — it is a layered defence. Physics-based key exchange and software-defined post-quantum cryptography address different threat vectors at different points in the stack. Together they cover both current and future quantum threats.

QKD · Hardware layer

Quantum Key Distribution.

Powered by ID Quantique
  • Physics-based key exchange — not maths
  • Provably secure against any computational attack
  • Eavesdropping is physically detectable
  • Ideal for high-value point-to-point links
  • Inter-vault and cross-border sovereign fibre
Defence in depth
PQC · Software layer

Post-Quantum Cryptography.

Powered by ExeQuantum
  • NIST-standardised algorithms — deployable anywhere
  • Software-defined — no special hardware
  • Scales across cloud, edge, IoT, and APIs
  • Cryptographic discovery + CBOM reporting
  • Protects data at rest, in transit, and in use
Two-layer defence: QKD secures the channel; PQC secures everything else. Where the threat model warrants physics-based assurance — sovereign communications, cross-border financial corridors, defence — both layers operate together.
The Navon Cyber Security Test Bed

Africa's first operational quantum-secure platform.

Live at Hell's Gate Deep Tech Park. Hardware-level QKD and software-defined PQC running side by side in a single, integrated environment — open to governments, telcos, banks, and research partners for evaluation, validation, and deployment of quantum-secure systems on commercially proven gear.

/ Live · operational · open for partners

Two world-class partners. One integrated platform.

Built with ID Quantique (Geneva — global leader in QKD, deployed in Korea, Singapore, EU) and ExeQuantum (ISO 27001 certified PQC stack — discovery, encryption, sovereign architecture).

Africa's 1st Operational QKD + PQC test bed
2 layers Hardware photons · software algorithms
5 sectors Gov · finance · telco · CI · academia
Sandbox For regulators, universities, partners
Cryptographic discovery CBOM reporting Vendor-agnostic QKD Loaner demo systems Joint engineering Talent development
Deployment models

Three shapes for three threat profiles.

Each model ships the full Navon security stack — HSMs, QRNGs, hybrid PQC, the crypto-agility engine. The differentiation is the sovereignty model, the connectivity posture, and the physical context.

Model ANational Vault Model BData Embassy Model COffline Quantum Pod
Location On-prem, within national territory Geopolitically neutral third jurisdiction Mobile or fixed · air-gapped
Sovereignty Full sovereign control by host nation Extraterritorial sovereignty via legal framework Complete physical and network isolation
Connectivity Connected · QKD-secured inter-site links Connected · encrypted cross-border links Air-gapped · no external network access
Primary use National registries · CBDC · defence systems Disaster recovery · cross-border resilience Elections · currency issuance · classified research
Assurance level Highest High Maximum (isolation)
Where it lands

Built for the workloads with the longest shelf-life.

Citizen registries, treaty archives, and central-bank infrastructure carry sensitivity lifecycles measured in decades. They are the first to demand quantum-resilient sovereignty — and the largest beneficiaries of getting it right early.

01 · Government & defence
Sovereign data, diplomatic comms.

Quantum-resilient citizen registries, digital embassies, classified research, and national cryptographic inventories ahead of mandate.

02 · Financial services
CBDC, banking, payments.

Encryption upgrades for core banking, quantum-secure transaction APIs, and PQC-mandate readiness ahead of global regulation.

03 · Telecoms
Cross-border QKD corridors.

Quantum-secure managed services for enterprise, inter-city QKD links, and backend protection against harvest-now-decrypt-later.

04 · Critical infrastructure
SCADA, ICS, IoT.

Hardware-rooted resilience for industrial control, IoT communications secured with pre-shared quantum keys, sector-specific compliance.

05 · Healthcare & identity
Records that outlive the keys.

Lifelong patient records, biometric registries, and identity systems whose sensitivity windows exceed any classical cipher's lifetime.

06 · Research & academia
Continental innovation hub.

University collaboration, applied quantum-security research, and a continental sandbox for cybersecurity startups building on real infrastructure.

Built with ↓ ID Quantique ExeQuantum QCentroid Hoptroff
05 / Utility

What you actually
ship.

The top of the Navon stack — sovereign AI applications running on your data, in your jurisdiction, on your hardware. Three composable layers: applications solve sector problems, agents orchestrate the work, and skills are the atomic primitives both depend on. Operable through low-code workflows for business and operations teams, full SDKs for engineering groups — same platform, same data, different entry points.

Layer 03 · Applications

Sector products.

Citizen ID CBDC Gov copilot Fin agent Health AI Defence Energy ops Edu copilot
Outcome layerWhat the user touches
Layer 02 · Agents

Orchestration layer.

Document intel Compliance Research copilot Decision support Translation Workflow
Reasoning & toolsHow work gets done
Layer 01 · Skills

Atomic primitives.

RAG OCR ASR TTS Translation Tool use Code exec Embeddings Vector search Forecast + 30 more
ComposableReusable across sectors
Layer 03 · Applications

Built where the data lives.

Vertical applications shaped to the workflows of each sector — running on Navon's sovereign cloud, encrypted at rest with PQC, and trained on locally held corpora. Each is a packaged, low-code outcome — configurable by domain teams without an engineering rebuild.

01 / GOVERNMENT
Citizen services · public records

Sovereign citizen platform.

Identity, registries, document workflows, and government copilots that keep every byte under national control. Designed for ministries that cannot send citizen data to a foreign cloud.

  • Digital citizen ID & biometrics
  • Tax, customs & benefits agents
  • Multilingual gov copilots
  • Records digitisation pipelines
02 / FINANCIAL SERVICES
CBDC · banking · capital markets

Risk and ops AI.

CBDC issuance, real-time fraud and AML, lending models, and quantum-secure transaction processing — built for central banks, commercial banks, and exchanges with sub-second SLAs.

  • CBDC platforms & wallets
  • Fraud, AML & KYC agents
  • Credit scoring on alt-data
  • Compliance & audit automation
03 / HEALTHCARE
Records · imaging · trials

Records that outlive the keys.

Patient-record platforms, medical-imaging AI, and clinical-trial assistants — running on data whose sensitivity windows exceed any classical cipher's lifetime.

  • Lifelong electronic health records
  • Imaging triage & reporting AI
  • Clinical-trial copilots
  • Outbreak surveillance models
04 / DEFENCE & INTELLIGENCE
Comms · ISR · decision support

Air-gapped intelligence.

Sovereign LLMs on classified corpora, encrypted comms, and ISR analytics — deployable in offline quantum pods where no byte ever crosses an external boundary.

  • Classified-corpus RAG & search
  • ISR fusion & geospatial agents
  • Sovereign messaging & voice
  • Cyber-defence copilots
05 / ENERGY & UTILITIES
Grid · assets · forecasting

Grid & asset intelligence.

Demand and load forecasting, predictive maintenance for turbines and substations, and operations copilots — running close to the SCADA layer for low-latency decisions.

  • Demand & load forecasting
  • Predictive maintenance agents
  • Geothermal & renewables ops
  • Grid-stability decision support
06 / TELECOMS
Network · customer · revenue

Network and customer copilots.

Network-optimisation agents, customer-service automation in local languages, and revenue-assurance models — for operators ready to embed AI in the OSS/BSS stack without offshoring data.

  • RAN & transport optimisation
  • Multilingual support agents
  • Fraud & revenue assurance
  • Churn & lifetime-value models
07 / EDUCATION & RESEARCH
Tutors · research · talent

National research grid.

Personalised tutors in local languages, sovereign research compute for universities, and a continental innovation hub — built with academic partners and on-site internship programmes.

  • Curriculum-aligned AI tutors
  • Research RAG over local corpora
  • JupyterHub & shared GPU pools
  • University internship pipeline
08 / CRITICAL INFRASTRUCTURE
SCADA · IoT · safety

Edge intelligence.

Industrial control monitoring, IoT fleet management, and safety-critical anomaly detection — at the edge, on-prem, with quantum-resilient device identity.

  • SCADA anomaly detection
  • Fleet IoT analytics
  • Safety & compliance agents
  • Edge-side inference pipelines
09 / TRADE & LOGISTICS
Customs · supply chain · ports

Sovereign trade backbone.

Customs and border copilots, supply-chain agents, and port operations AI — designed for the cross-border data flows of regional trade blocs and the harmonisation of customs regimes.

  • Customs declarations & risk
  • Multimodal logistics agents
  • Port & terminal ops AI
  • Cross-border data corridors
Layer 02 · Agents

The orchestration layer.

Agents are the workers — long-running, tool-using, multi-step reasoners that combine skills to deliver outcomes. They are the substrate every application above this layer is built on.

AGENT 01 / DOCUMENT INTELLIGENCE

From PDF to structured outcome.

Parses, classifies, extracts, and reasons over unstructured documents at scale — passports, contracts, medical scans, legal filings, customs declarations. Outputs JSON, decisions, or downstream actions.

  • OCR
  • Layout parsing
  • RAG
  • Tool use
  • Schema extraction
AGENT 02 / COMPLIANCE & AUDIT

Continuous regulatory readiness.

Maps the regulatory landscape, scans transactions and configurations against policy, generates audit-ready reports, and flags violations the moment they appear. Ready for NIST, NDPA, GDPR, and emerging PQC mandates.

  • Policy graph
  • Rule engine
  • Anomaly detection
  • Reporting
  • Tool use
AGENT 03 / RESEARCH COPILOT

RAG over your private corpus.

Retrieval-augmented research across closed-domain document stores — internal reports, citizen records, legislation, scientific literature. Cites sources, supports follow-up reasoning, and never leaks the corpus to a foreign endpoint.

  • Embeddings
  • Vector search
  • RAG
  • Citation
  • Multi-hop
AGENT 04 / DECISION SUPPORT

Numbers, with reasoning.

Forecasts, scenario simulation, and structured trade-off analysis on operational data — for executive dashboards, central-bank monetary committees, energy operators, and ministers running national programmes.

  • Time-series
  • Forecast
  • Tool use
  • Code exec
  • Reasoning
AGENT 05 / TRANSLATION & VOICE

Reach citizens in their language.

Real-time translation and speech across English, French, Arabic, Swahili, Amharic, Yoruba, Hausa and more — text, voice, and call-centre integration. Tuned for the languages global LLMs underserve.

  • ASR
  • TTS
  • Translation
  • Diarization
  • Voice cloning
AGENT 06 / WORKFLOW AUTOMATION

Glue between systems.

Long-running, stateful workflows that wire AI into existing systems — approvals, escalations, notifications, ticket routing, downstream API calls. Replaces glue code, RPA, and the spreadsheet-and-email layer.

  • Tool use
  • API calls
  • Forms
  • State machines
  • Approvals
Layer 01 · Skills

Atomic, reusable, composable.

Skills are the Lego bricks. Every agent is composed of skills; every application is composed of agents. Build once, reuse across sectors — and swap implementations as the underlying models improve.

SKILLS · 01

Language & reasoning.

  • RAG
  • Summarization
  • Q&A
  • Classification
  • Extraction
  • Translation
  • Multi-hop
  • Citation
  • Reasoning
  • Planning
SKILLS · 02

Vision & documents.

  • OCR
  • Layout parsing
  • Image classification
  • Object detection
  • Captioning
  • Diagrams
  • Schema extraction
  • Geospatial
SKILLS · 03

Audio & voice.

  • ASR
  • TTS
  • Diarization
  • Voice cloning
  • Speaker ID
  • Sentiment
  • Real-time
SKILLS · 04

Tools & execution.

  • Tool use
  • Code exec
  • API calls
  • SQL
  • Browser
  • Forms
  • State machines
  • Approvals
SKILLS · 05

Knowledge & memory.

  • Embeddings
  • Vector search
  • Graph
  • Long context
  • Episodic memory
  • Schema
  • Provenance
SKILLS · 06

Numerical & analytics.

  • Time-series
  • Forecast
  • Anomaly detection
  • Optimisation
  • Simulation
  • Statistics
  • Decision trees
Quantum AI · runtime

A quantum-classical hybrid environment.

For workloads where classical compute is hitting its ceiling — combinatorial optimisation, drug discovery, financial risk, post-quantum cryptography — Navon ships a quantum-AI development environment alongside the classical stack. Build, benchmark, and deploy hybrid algorithms on the same infrastructure your AI already runs on. No bespoke research project. No vendor lock-in. No second pipeline.

/ Workflow · classical ↔ quantum ↔ classical Sandbox → Queue → Real QPU or simulator
Stage 01 · Classical

AI inference & pre-processing.

Your existing models do feature engineering and shortlist candidate inputs. No code rewrite — drop a quantum subroutine where it pays off.

Stage 02 · Quantum subroutine

The hard kernel runs on a QPU.

Optimisation, sampling, or quantum-enhanced learning runs on a real QPU or simulator — selected automatically by the queue based on availability and cost.

Stage 03 · Classical

Post-process & deploy.

Multishot results aggregate into a final answer; the artefact is shipped through the same control plane your classical workloads already use.

// LIVE · One artefact, two runtimes — classical + quantum Same SDK · Same control plane · Same security
CAPABILITY · 01

Quantum access.

Simulators plus real quantum hardware. Build, test, and benchmark on the same machines the next decade of AI will run on.

CAPABILITY · 02

Hybrid workflows.

Seamless quantum-classical orchestration. Mix classical AI inference with quantum subroutines without rewriting your pipeline.

CAPABILITY · 03

Pre-built templates.

Quantum machine learning, optimisation, and post-quantum cryptography — production-grade starting points, not from-scratch research projects.

CAPABILITY · 04

One-click deployment.

Sandbox to production on Navon Sovereign Cloud — same artefact you trained, same security posture, no rewrite at the line.

CAPABILITY · 05

Algorithm benchmarking.

No-code execution and side-by-side benchmarking across solvers. Multishot aggregation, full result histories, and audit-ready reports.

CAPABILITY · 06

Qubit-agnostic.

Simulators, quantum-inspired, ion-trap, superconducting, neutral-atom, photonic — all addressable through one API. No vendor lock-in, ever.

CAPABILITY · 07

Security by default.

An encrypted SDK that keeps your data yours. In-country keys, sovereign HSMs, and security baked into the protocol — not bolted on at the perimeter.

CAPABILITY · 08

API & smart-contract oracle.

Simple integration via RESTful API plus a built-in Web3 oracle. Wire quantum results into existing IT systems and on-chain workflows.

/ Runs on
Simulators Quantum-inspired Ion-trap Superconducting Neutral-atom Photonic
/ Compose, don't rebuild

Skills compose into agents. Agents compose into applications. Build a skill once — every sector benefits.

Built & deployed with ↓ Hugging Face AI Kenya Alliance for AI Strathmore University UCL ETH Zurich
Not sure which?

Most customers start
with one and grow into the rest.

We'll walk you through the workload, the constraint, and the right starting layer — usually a 30-minute conversation, not a sales process. Or browse the docs first if you'd rather.