Skip to content
EMBIby Móholt

Locally sovereign. Under your authority.

Your records.
Your authority.
Every environment.

Electronic records and case management for public authorities and defence cooperation. Preserve decisions, protect national and allied records, and govern their lifecycle under your authority.

Explore the five pillars
Illustrative HNS workflow · Fictional NG26 data

Five pillars / one records platform

From official record to accountable history.

EMBI is an electronic Records and Case Management System (RMS) for public authorities and defence cooperation. These five pillars guide its development: a working records foundation, demonstrated security controls and a planned ingestion engine.

01 /

Capture the authoritative record

Preserve issued reports, agreements and decisions with their originals, source and time of receipt. Capture during the work as well as at closeout; an approved records policy determines what is retained.

02 /

Connect through controlled boundaries

Receive national and allied records through approved transfers and interfaces. Keep the originator’s markings, caveats and provenance intact as information enters the recipient’s environment.

03 /

Normalize into a case

Turn supported formats into structured metadata linked to the institution’s file plan. Profile-based ADatP-3 parsing and automated case registration are planned for the Validation & Normalization Engine.

04 /

Bind security to the record

Carry source restrictions alongside the recipient’s national obligations. The design combines metadata binding, clearance, need-to-know and compartments, with mapping approved for each policy and deployment.

05 /

Govern the full lifecycle

Protect declared versions, retain traceable changes and apply authorised retention and disposal rules. Manage disclosure and archival transfer as accountable decisions, with evidence of what was sent and accepted.

ISO 15489 informs the records model. National mandates are configured for the receiving institution; Iceland is our first context, with other jurisdictions part of the design. Classified use requires the relevant authority’s approval.

EMBISEC-L / Continuity • Evidence • Control

Records continuity.

Prepared records work can continue through a link interruption.

A fictional host-nation support handover brings together a rotation SITREP, a signed handover package and an after-action draft. The prepared workspace keeps local work during a link interruption and queues changes for reconciliation. Local save, server registration and recipient acceptance are distinct steps.

For operations teams

Display mode

Built-in evidence.

Provenance and recorded checks support assessment.

Release manifests, a bill of materials (SBOM), content digests, signed EMBI metadata and audit-chain checks provide evidence to inspect. The console shows an illustrative evidence pack; each assessment must use results from the actual release and deployment.

For records & security assessors

Illustrative results · conformance and deployment assurance assessed separately.

Inspectable sovereignty.

Buyers can examine hosting, custodians and outbound controls.

A sovereignty manifest records components, hosting jurisdiction, custodians and permitted connections. Compare declared configuration with observed behaviour, then verify the deployment’s enforcement. Hosting location alone does not establish control or authorisation to handle classified records.

For IT & procurement owners

Sanitised console · fictional HNS exercise data (NG26) · illustrative workflow

Anatomy of a sovereign record

One record. Seven layers you can inspect.

Explore the record model: original content, its case, security metadata, binding, access, audit evidence and deployment boundary. The diagram explains how these responsibilities fit together. Each layer describes its current foundation and the controls still needed for the intended deployment.

L4 BINDINGSigned EMBI metadata · content digest

Signed EMBI exports bind content digests and metadata for verification. The planned engine must preserve source evidence, record the trust decision and bind recipient obligations without replacing source markings. Full STANAG 4778 conformance requires defined profiles and independent test vectors.

Provided by EMBISEC
  1. Registerreceived · digest
  2. Classifylabel · binding
  3. Workcase · versions
  4. Declareversion protected · per plan
  5. Retainschedule · review
  6. Transferarchives · per policy

The product family

One foundation. Progressive capability.

01 / Civil foundation

EMBI

Open. Sovereign. Trial-ready.

The open-core (AGPL) records and case management foundation: registration, declared versions, retention, holds and archive workflows. Designed around ISO 15489 records practices and institution-specific mandates.

TRL 6 · Trial-readyExplore EMBI →

02 / Security classification

EMBISEC

Access follows clearance.

The commercial security layer for sensitive national and allied records. Classification, clearance and case-level need-to-know controls exist; the planned Validation & Normalization Engine will bind source requirements to recipient policy.

TRL 5 · DemonstratedExplore EMBISEC →

03 / Local records continuity

EMBISEC-L

Local first. Network optional.

A local-first configuration for interrupted communications. Lab workflows demonstrate prepared local work and queued synchronization; secure offline deployment and complete receipt handling remain development and assurance work.

TRL 4 · Lab-validatedExplore EMBISEC-L →

Readiness, stated plainly

A working foundation. A measured path forward.

EMBITRL 6 / 9
EMBITrial-readyTRL 6 / 9
EMBISECTRL 5 / 9
EMBISECDemonstratedTRL 5 / 9
EMBISEC-LTRL 4 / 9
EMBISEC-LLab-validatedTRL 4 / 9

TRL = Technology Readiness Level, self-assessed. Readiness does not imply formal accreditation.

What we don’t claim

  • Not accredited. Readiness levels are self-assessed and stated per tier.
  • Not a cross-domain guard, and not transmission cryptography — those are bought, not built.
  • No customer deployments yet. Trials are how impact gets established.
  • Standards guide the design; full profile conformance and accreditation remain separate work.
  • Product views show sanitised, fictional exercise data (NG26) — never a real bundle, record or unit.
  • Alliance work follows applicable export-control and clearance rules; it implies no endorsement.

Show the impact in trials.

Screenshots demonstrate the interface. A four-week evaluation on your site, with your data and agreed exit criteria, establishes the impact — with a written report either way.

Track A · EMBI

Records

One unit, 30 days of real-shaped work on your infrastructure.

Measure: Registration completeness · access-request turnaround · retention findings

Track B · EMBISEC

Classification

A set of labelled documents moves through ingestion, handling and declaration.

Measure: Binding checks · mis-handling caught · review time per record

Track C · EMBISEC-L

Field trial

Two prepared workspaces and a planned link interruption using synthetic records.

Measure: Reconciliation accuracy · conflicts · offline chain verification

Agree a baseline, run the scenario, and review the results together.

Request an evaluation plan

Who we work with

Public responsibility. Different operating realities.

EMBI

Public administration

Ministries, municipalities and public bodies managing government records under national records law and local authority.

EMBISEC

Sensitive & dual-use work

Agencies and companies handling classified or dual-use material, where handling must follow the information rather than the network.

EMBISEC-L

Field & security services

Civil protection, search and rescue, police, border and coast-guard services — and defence partners — working where connectivity is not guaranteed.

We work with dual-use parties and follow applicable export-control and clearance rules.

A deliberate boundary

Records and case management.
For accountable public authority.

EMBI preserves official records of decisions and activity. It is not a live command-and-control system. Approved transmission cryptography and cross-domain guards belong to specialist infrastructure; their integration and authorisation are separate from the RMS.

Let’s start with your requirements.

Discuss your records, security and operational environment.

Request a briefing