QBO CLOUD/TechNet Augusta 2026/17–20 Aug/Augusta Marriott/Booth T25

Fitted to this year’s theme — C2 / Counter C2 in Support of Army and Joint Warfighting.

qbo · chat · ratio 1 uplink up

  • +Encrypted overlay across every hostup
  • +Virtual IP, DNS records, TLS certificatesup
  • +Private container registry, images localup
  • uplink severed
  • +Storage volumes, scoped per userno reachback
  • Kubernetes answering your kubectlunder 3 min
  • Ratio 1 reasoning, inside the enclavewe are the api

From an idea to a deployment at scale — in a sentence.
Code to combat, accelerated.

One binary runs it all — Kubernetes, MC2 containers, Plasma GPU and Windows workstations — and is itself their network, storage, identity, security, observability and AI. Under your control, on your own metal.

Stood up from one sentence of plain English, at bare-metal speed. Counter-C2 begins by severing your link. QBO does not have one to sever.

Come watch us cut the network cable mid-build. Nothing stops.

What you will watch happen

0:00

From an idea to a deployment, in a sentence

You choose the shape. We type it in English — no YAML, no Terraform, no hypervisor. Overlay, virtual IP, DNS, TLS, registry and storage come up around a CNCF-conformant cluster answering your own kubectl in under three minutes, all out of one binary already on the box — at bare-metal speed, with no virtualization tax between the workload and the hardware.

0:08

We cut the uplink. Mid-build.

Nothing stops — because there was never anything out there to depend on. QBO carries its own identity and its own authority: its users, its service accounts, the certificates it issues itself, single sign-on across the whole fleet. No external directory, no federation, nothing to stand up alongside it. The cluster keeps scheduling and the AI keeps answering, because the model is Ratio 1 — our own engine, running inside the enclave. There is no cloud API to call: we are the API. No keys, no reachback. Denied comms is not denied AI.

0:16

And it sees — today, not on a roadmap

Visio 1 is running now, and its viewer does three things on one page while the box stays disconnected:

  • Detection on live video, with the frame count and frame rate ticking on the page — pointed at the bundled feed, or at your own RTSP camera.
  • The same inference, moved from CPU to GPU with one click, so the frame-rate change is something you watch rather than something we claim. That is the no-hypervisor argument, measured.
  • Teaching it a new class, live — we train “wheel” from scratch on an anchor-free YOLOv8-class model (decoupled head, DFL, TAL assignment) in front of you, then watch it find wheels. Training, not just inference, runs in the same C engine on the same box.

On a second page it streams the same detection over H.264/WebRTC with NVENC hardware encoding, side by side against a plain JPEG/WebSocket path — encoder, resolution, frame rate, kilobytes per frame, bandwidth and loss counted for both, so you can see what it costs the link before you put it on one.

0:20

Your turn

Bring the DDIL scenario you think breaks it. We would rather run yours than ours.

Performance, observability and security are the platform

Performance

nothing between the workload and the hardware
  • Containers on the host kernel — CPU, memory and I/O are not virtualized. No hypervisor, no guest OS, no nested scheduling
  • GPUs passed straight through. CUDA, Vulkan and NVENC run against the physical driver stack at full hardware speed, with no emulation layer
  • The dataplane is eBPF executing in the kernel, not a userspace proxy — no packet copies, no context switches to move traffic

Observability

the box tells you what it is doing, as it does it
  • Per-core CPU, memory, per-disk usage, per-NIC throughput and per-GPU utilization and VRAM, streamed live over a persistent connection — pushed as they change, never polled
  • Kernel flow events, per packet — direction, flow hash, domain and drop reason, straight off the BPF event map
  • Bytes and packets counted per firewall rule, and structured logs stamped to the microsecond and the source line that emitted them

Security

enforced in the kernel, not in a sidecar
  • Deny-by-default ingress, with micro-segmentation held per identity in a BPF map and enforced at the kernel level
  • Every instance in its own network namespace — lateral movement is blocked by default, not by policy you have to remember to write
  • Ownership is checked before a single byte is forwarded; certificates are issued and rotated by the platform; RMF and SCAP evidence is queryable on demand with no agent installed

And all three answer to the same natural-language surface. You ask the platform what it is doing, and it tells you — the AI reads the telemetry, writes the policy and provisions the resource, on the box, disconnected.

Why it matters at the tactical edge

Sovereign identity
Its own users, service accounts, certificates and fleet-wide SSO. No external directory or IdP required.
Bare metal, cloud flexibility
Containers on the host kernel — no hypervisor, no guest OS, no virtualization tax between workload and hardware.
AI is the control surface
Provision, inspect and enforce in natural language; Ratio 1 and Visio 1 answer on your own hardware — QBO is the API.
One platform, one binary
Network, registry, DNS, TLS, storage, security and observability — not a stack of products to integrate.
Airgap-native
Nothing to reach out to at runtime. The demo is run disconnected on purpose.
Standard Kubernetes
CNCF-conformant. Your kubectl and your unmodified manifests, unchanged.
RMF evidence, no agent
Policy, certificate, user and network state queryable on a schedule by any SCAP/SIEM/RMF tool.
Less SWaP-C
One binary displaces a rack of appliances and licences — size, weight, power and cost all come down.
Rack to vehicle
The same binary, with identical behaviour, on amd64 and arm64.

One binary. Your whole universe.

Compute, Kubernetes, networking, storage, the container registry, DNS, TLS, identity, security and observability all ship inside the same binary — and all of it is driven in natural language by the AI running on that same box. Security policy, network state, telemetry and provisioning are not bolted-on products with their own consoles. They are the platform, and the AI operates them.

You can run the mission on QBO and nothing else.

That collapse is a SWaP-C argument before it is an architectural one. No hypervisor layer, no separate directory, registry, monitoring or security appliances to power and carry — the boxes, the watts, the weight and the licences all come out of the footprint. What is left fits the platform you actually have to move.

And it is why code reaches combat faster: a capability goes from an idea to a deployment at scale in a sentence, on the operator’s own hardware, without a cloud region, a change board or a provisioning queue in between.

Live demo

What
A live, unscripted demo, run on bare metal we bring with us
Where
Booth T25, Augusta Marriott at the Convention Center — or a closed session in RAM Room, 100 Grace Hopper Lane, Augusta, GA 30901
When
August 18, 2026, 3:00–4:00 PM ET Register →
Bring
Nothing. No install, no cloud account, no cluster, no network.

Sovereign. Airgapped.
Nothing else required.

Come with the hardest question you have. We would rather run your scenario than ours.

Register
QBO Cloud Inc./qbo.io/Sovereign, self-contained, authoritative