Open tactical node platform
- [ TESTS ]
- ~930 GREEN //
- [ CI ]
- 9 PIPELINES · BIT-FOR-BIT REPRODUCIBLE BUILD //
- [ CRYPTO ]
- ML-DSA-65 (FIPS 204) · X25519MLKEM768 //
- [ LICENSE ]
- APACHE-2.0 //
- [ STATUS ]
- X86-64 + ARM64 EMULATION · JETSON TOOLING //
OC2-Edge turns any embedded computer into a hardened C2 node: an immutable OS with verified boot, signed and isolated modules, a resilient multi-bearer mesh, and a tactical picture in a plain browser. Released under the Apache-2.0 license: auditable, deployable and federable by any defense-industry actor.
Instantiate, audit, federate — without vendor lock-in
Immutable OS with verified boot, signed and sandboxed modules, chained audit log: every node stays operable, observable and revocable — even offline. The foundation is public; your program keeps control.
[ SOURCE ] PUBLIC REPOSITORY //
~930
automated tests green on the public repository
9
CI pipelines — bit-for-bit reproducible build
Standards
Your standards, already on board.
NATO, NIST, ANSSI, OGC, IETF: OC2-Edge speaks the language of your theaters, your allies and your auditors. 70 standards covered across 13 domains, each with an owned, acceptance-verified status — no brochure compliance.
[ 01 ] Geodesy & mapping 9 standards
-
WGS-84 (STANAG 2211)
reference datum for all positions (EPSG:4326), Web Mercator for tiling
Compliant
-
MGRS · UTM · GEOREF
military grids, multi-format conversion and input (DMS, decimal, Maidenhead)
Compliant
-
STANAG 3809 (DTED) · MIL-PRF-89020
elevation levels 0/1/2 and SRTM, line of sight, viewshed, terrain navigation
Compliant
-
OGC WMTS (WebMercatorQuad)
tile service consumable by any third-party OGC client
Compliant
-
OGC API Features · WMS 1.3.0 · WFS 2.0.0
served and tested; arbitrary-extent resampling deferred
Partial
-
GeoPackage (OGC 12-128r)
read at ingestion
Partial
-
OGC 3D Tiles · Cesium quantized-mesh 1.0
3D tiled terrain served from the DEM layer
Compliant
-
STAC 1.0.0
spatiotemporal catalog served, IDs carried by map packages
Compliant
-
PMTiles v3 · MBTiles · MVT
offline formats: read, write, serve and render
Compliant
[ 02 ] Cryptography 10 standards
-
FIPS 204 (ML-DSA-65)
post-quantum signature, NIST level 3, KAT/POST self-tests
Aligned
-
FIPS 203 (ML-KEM) · X25519MLKEM768
hybrid key exchange on the mesh, hardened require_pqc mode
Aligned
-
NSA CNSA 2.0
ML-DSA / ML-KEM choices and hybrid agility consistent with the roadmap
Aligned
-
FIPS 186-5 · RFC 8032 (Ed25519)
classical signature and branch of the hybrid mode
Compliant
-
FIPS 140-3 · CMVP
frozen crypto module and self-tests shipped; external lab validation not engaged
Partial
-
FIPS 180-4 · FIPS 197 · FIPS 202
SHA-256 for standardized integrity, XTS-AES for encryption at rest (LUKS2)
Compliant
-
BLAKE3
high-performance internal hashing, outside the FIPS catalog: accepted choice
Accepted deviation
-
TLS 1.3 (RFC 8446)
mTLS anchored on the fleet CA, hybrid post-quantum handshake
Compliant
-
RFC 9106 (Argon2)
argon2id in PHC format for local passwords
Compliant
-
RFC 6238 (TOTP)
optional second factor
Planned
[ 03 ] System security & evaluation 8 standards
-
UEFI Secure Boot · TPM 2.0 (ISO/IEC 11889)
verified and measured boot, PCR sealing; without TPM, explicit degraded posture
Compliant
-
fs-verity · IMA · dm-verity
measured integrity of images and Driver Store, SHA-256 Merkle root
Compliant
-
NIST SP 800-207 (Zero Trust)
deny-by-default on the bus, declarative capabilities, RBAC, audited gating
Aligned
-
NIST SP 800-88 rev.1
crypto-erase by key destruction, graded scope, erasure certificate
Aligned
-
Common Criteria (ISO/IEC 15408)
security target written (TOE, SFRs, target EAL); external lab evaluation
Partial
-
CSPN (ANSSI)
CSPN target and evaluator test plan written; external evaluation
Partial
-
RGS (ANSSI)
qualification dossier and tested compliance guard; external qualification
Partial
-
RFC 8785 (JSON Canonicalization)
canonical form for audit chaining and profile fingerprints
Aligned
[ 04 ] Fleet PKI & software supply chain 5 standards
-
X.509 (RFC 5280)
fleet CA, chain validation, CRL, mDNS and IP SANs
Compliant
-
The Update Framework (TUF)
four roles and delegations, key rotation, anti-rollback, root keys in HSM
Compliant
-
SPDX (ISO/IEC 5962) · CycloneDX
per-package SBOM, signed build provenance with CVEs and licenses
Compliant
-
SLSA · NIST SSDF (SP 800-218)
bit-for-bit reproducible build, signed provenance; formal SLSA attestation not produced
Aligned
-
NIST NVD / CVE
cve-check at build, CVEs recorded in image provenance
Aligned
[ 05 ] Tactical tracks & ISR 5 standards
-
STANAG 4676 (NATO ISR Tracking)
track model, lifecycle, affiliation; advanced estimators pluggable as option
Aligned
-
STANAG 4607 (GMTI)
dwell and target-report parsing into tracks, fed to the bus pivot
Partial
-
STANAG 4545 (NSIF)
secondary imagery, ICORDS/IGEOLO georeferencing
Partial
-
STANAG 7023 (imagerie primaire)
ingestion into objects; pixel decoding deferred
Partial
-
STANAG 4559 (NSILI)
query client for third-party ISR libraries, BQS queries
Partial
[ 06 ] Video & media 6 standards
-
UIT-T H.264 · H.265 + RFC 6184 · RFC 7798
real codecs and compliant RTP packetization
Compliant
-
H.266/VVC (RFC 9328)
RTP packetization and NAL parsing shipped; pixel decoding deferred, clean fallback
Partial
-
STANAG 4609 · MISB ST 0601/0102 (KLV)
georeferenced video metadata; media chain in place, KLV muxing to be wired
Planned
-
UIT-R BT.601/709/2020/2100 · SMPTE P010/V210
SDR/HDR colorimetry, 10/12/16-bit paths
Compliant
-
GigE Vision · GenICam · PFNC
industrial camera acquisition GVCP/GVSP, source to encoding
Compliant
-
OpenTelemetry · W3C Trace Context · Parquet
OTLP observability, columnar export with bounded retention
Compliant
[ 07 ] Symbology & tactical graphics 3 standards
-
APP-6(D/E) (STANAG 2019)
frames, affiliation, dimension, echelon; full SIDC decoding, fine iconography out of scope
Aligned
-
MIL-STD-2525C/D
letter and numeric SIDC forms, pivot referenced on 2525D
Aligned
-
NVG (NATO Vector Graphics)
tactical overlay import/export (points, lines, polygons), advanced styling out of scope
Partial
[ 08 ] C2 interoperability & messaging 4 standards
-
Cursor-on-Target · TAK Protocol v1
bidirectional CoT XML and protobuf, TAK bridge with fail-closed mTLS, out of the box
Compliant
-
STANAG 5525 (JC3IEDM / MIP)
replication gateway from pivot to JC3IEDM, serializable DEM batch
Partial
-
ADatP-3 · APP-11 (FORMETS)
POSREP and SITREP encoded and decoded; full catalog out of scope
Partial
-
FMN · NATO NISP
building blocks of a coalition profile; spiral enrollment not engaged
Aligned
[ 09 ] Classification & coalition 4 standards
-
STANAG 4774 / ADatP-4774
confidentiality labels, releasability, caveats, fail-safe composition, XML profile shipped
Aligned
-
STANAG 4778 / ADatP-4778
cryptographic label-to-data binding, XML binding with tamper detection
Aligned
-
IGI 1300 (SGDSN)
mapping to national levels, permanent banner, single-level partitioning per node
Aligned
-
II 901 (SGDSN)
encryption at rest, mTLS, tamper-evident audit: properties of a restricted-level system
Aligned
[ 10 ] Drones & effectors 3 standards
-
MAVLink
v1/v2 frames, CRC-16/X.25, PX4 and ArduPilot, standard integration path
Compliant
-
STANAG 4586
DLI driver (codec, LOI grading, safety envelope); socket egress at the daemon
Partial
-
ONVIF (Profile S/T)
PTZ camera and gimbal control
Aligned
[ 11 ] Links & timing 4 standards
-
STANAG 5066 (HF)
SIS/ALE connector for third-party HF interop; transport-agnostic oc2-wire point to point
Partial
-
UIT-R P.525 · P.526 · P.833
first-order link budget: FSPL, diffraction, refraction, vegetation
Aligned
-
Longley-Rice / ITM · deux-rayons
advanced band-calibratable models, tested against numeric oracles
Partial
-
NTP (RFC 5905) · NTS (RFC 8915) · PTP (IEEE 1588)
disciplined time sources, GNSS included
Aligned
[ 12 ] Mission AI 3 standards
-
Principes OTAN d’IA responsable (2021)
strict human-in-the-loop, marked provenance and confidence, no automatic kinetic chain
Aligned
-
Règlement (UE) 2024/1689 (AI Act)
military use out of scope; transparency, human control and traceability applied by choice
Aligned
-
ISO/IEC 42001 · 23894 · TR 24028
AI management system formalized, tested model-admission guard; external certification audit
Partial
[ 13 ] Interface, accessibility & engineering 6 standards
-
W3C WCAG 2.2 (niveau AA)
AA contrast on four themes, field-grade touch targets, prefers-reduced-motion
Compliant
-
W3C CSP Level 3
default-src self, module widgets in null-origin iframes
Compliant
-
WebAssembly · WASI
portable isolation floor, wasm32-wasip2 targets
Compliant
-
BCP-47 · Unicode CLDR
locale resolution, plurals, right-to-left writing
Compliant
-
RG Aéro 000 40/42 · AQAP 2110/2210
codified specification, requirement-to-test traceability, proof by automated test
Aligned
-
ISO/IEC/IEEE 12207 · 15288 · ISO/IEC 25010
lifecycle and quality characteristics treated as verifiable requirements
Aligned
Open source
Open, auditable, federable.
The foundation ships under the Apache-2.0 license. Clone the repository, replay the demo in the emulator (x86-64 + ARM64), verify the reproducible build — no NDA, no meeting.
Ecosystem — six modules on one foundation
-
[ 01 ]
Immutable OS
Minimal base with verified boot and signed A/B images. A node’s state is exactly what you audited.
-
[ 02 ]
Signed & isolated modules
Every capability is a signed, sandboxed, revocable module — yours, ours, or a third party’s.
-
[ 03 ]
Cryptography
ML-DSA-65 (FIPS 204), X25519MLKEM768, offline key management. Post-quantum now, not on a roadmap.
-
[ 04 ]
Multi-bearer mesh
Radio, SATCOM, tactical LTE/5G: seamless failover and controlled link degradation.
-
[ 05 ]
Tactical standards
Interoperable with current tactical standards and allied architectures — no proprietary gateway.
-
[ 06 ]
Tactical picture
The common operational picture in a plain browser: offline tiles, fused geodata, explicit LIVE / MOCK modes.