# Starlight > The private AI and infrastructure platform for enterprise, government, and defense. Run virtual machines, Kubernetes, and private AI on a single hardware-isolated platform with one operational model from data center to tactical edge. Starlight is built by Mainsail Industries Inc. for organizations operating infrastructure where resilience, operational clarity, sovereignty, and reliability matter most. Customers include the U.S. Department of Defense, Intelligence Community, defense industrial base, critical infrastructure operators, and enterprises running sensitive workloads. Mainsail is a C corporation and an independent software vendor: Starlight is software customers install and run on their own infrastructure. Mainsail does not provide infrastructure, billing, capacity, or hosted services. ## Products - [AI inference](https://www.mainsailindustries.com/starlight/ai-inference): Private, OpenAI-compatible LLM inference on infrastructure you control. Models delivered as immutable OCI containers, pulled from public or private registries or on-premises mirrors for air-gapped sites. vLLM for production GPU serving, llama.cpp for CPU and mixed CPU+GPU hosts with quantization. One model artifact resolves to the right runtime per host. Confidential computing for data-in-use protection. Declarative network intent for endpoints. Runs connected, degraded, or fully disconnected. AI security posture management (AI-SPM) available. - [Agent microVMs](https://www.mainsailindustries.com/starlight/agent-microvms) (early access): Hardware-isolated execution sandboxes for AI agents. Each session runs commands, code, and tools inside its own microVM with host-enforced resource budgets and network allowlists. Credentials stay on the host and never enter the guest. Results return as content-addressed artifacts with a tamper-evident audit record. Framework-neutral API; works with LangChain and LangGraph, CrewAI, OpenAI Agents SDK, and Vercel AI SDK. - [Kubernetes microVMs](https://www.mainsailindustries.com/starlight/kubernetes-microvms): Complete Kubernetes clusters on lightweight microVMs. Every controller and worker runs in its own machine with its own kernel and hardware boundary; clusters isolate at node level. Real Kubernetes distributions (k0s and k3s profiles), so kubectl, Helm, operators, CRDs, and kubeconfigs work unchanged. Nodes boot from immutable, digest-addressed OCI images with signed, reviewable inputs. - [Virtual machines](https://www.mainsailindustries.com/starlight/virtual-machines): Replace enterprise virtualization without refactoring a single VM. Existing Windows and Linux guests run unchanged. No per-core or per-socket licensing. Confidential computing with AMD SEV / SEV-ES / SEV-SNP and Intel TDX. UEFI and Secure Boot, snapshots, clones, resize, and live migration. Connects to existing block, file, and object storage and directly to existing networks and VLANs. Operates with the observability, SIEM, and IaC tooling teams already run. - [Containers](https://www.mainsailindustries.com/starlight/containers): Run any OCI-compliant container image, pulled from existing registries, on-premises mirrors, or airgapped sites. Peer-mesh control plane: every node runs its full control plane locally and operates independently when partitioned. Two-node high availability without quorum, witness, or third-node tax. Modern service-mesh networking with declarative intent compiled to firewall rules and an L7 gateway, no sidecar required. ## Architecture - MicroVM isolation: workloads run behind hardware virtualization boundaries that are lightweight enough to wrap a single AI agent, with density far above conventional VMs. - Peer-mesh control plane, not hub-and-spoke. Every node is independently operational; peers coordinate as a mesh when reachable and operate independently when partitioned. There is no central control plane to lose. - One operational model from data center to tactical edge. Same control plane, same policy, same audit, everywhere. - Hardware-rooted security. Hardened, immutable host with STIG and FIPS alignment. Confidential computing for data encrypted while in-use. Hardware attestation for trusted launches. Quantum random number generation from Qrypt and post-quantum cryptographic algorithms built into the platform. - Runtime protection inside the workload. Process-level monitoring, file system access controls, network policy enforcement, capability and syscall controls. Preconfigured agents from first boot. - AI security posture management (AI-SPM) with AccuKnox for prompt firewall, model red-teaming, supply-chain controls, and governance mapped to NIST AI RMF, MITRE AI, EU AI Act, ISO 42001, and OWASP. - Governance for MCP and agentic clients: human operators, automation, and AI agents drive the platform through the same API surface with one identity, policy, and audit model. ## Pricing - Simple node-based pricing: one node equals one subscription. - No per-core or per-socket licensing. - No quotas on the number or type of VMs or containers you can run. - No bundled SKUs forcing customers to buy what they do not use. - Compute, networking, storage, security, lifecycle management, and operations console are all included. ## Resources - [Whitepapers](https://www.mainsailindustries.com/resources/whitepapers): Architecture deep-dives, deployment patterns, comparative analysis. - [One-pager](https://www.mainsailindustries.com/resources/one-pager): Single-page summary briefs you can hand off to a colleague or evaluator. - [Blog](https://www.mainsailindustries.com/resources/blog): Notes on what Mainsail is building and how to operate Starlight. ## Key articles - [Introducing Starlight](https://www.mainsailindustries.com/resources/blog/introducing-starlight) - [Peer mesh vs hub and spoke](https://www.mainsailindustries.com/resources/blog/peer-mesh-vs-hub-spoke) - [Why AI needs a new isolation boundary](https://www.mainsailindustries.com/resources/blog/why-ai-needs-a-new-isolation-boundary) - [Governed AI infrastructure](https://www.mainsailindustries.com/resources/blog/governed-ai-infrastructure) - [Starlight and air gap](https://www.mainsailindustries.com/resources/blog/starlight-and-air-gap) - [Confidential compute made simple](https://www.mainsailindustries.com/resources/blog/confidential-compute-made-simple) - [RSS feed](https://www.mainsailindustries.com/rss.xml): all posts ## Optional - [Industries](https://www.mainsailindustries.com/industries): Defense, intelligence community, and critical infrastructure deployments. - [Use cases](https://www.mainsailindustries.com/use-cases): How teams deploy and operate Starlight. - [Contact](https://www.mainsailindustries.com/contact): Talk to us about a deployment review or migration assessment. ## Company Mainsail Industries Inc. 100 S. Ashley Drive, Suite 600 Tampa, FL 33602 info@mainsailindustries.com