GOLD DAWN · SOVEREIGN RUNTIME · TOKYO

Frontier intelligence,
inside your own walls.

Gold Dawn runs open-weight frontier models on processors an institution already owns — with no accelerator, no vendor endpoint, and nothing transmitted for processing.

The data does not leave. The dependency does not exist.

THE QUESTION BEHIND IT

The usual question is how to fit a model into an accelerator.

Frontier models have grown faster than accelerator memory, and the gap is widening. The industry answer has been to buy more accelerators, which places the largest models out of reach of the institutions with the strictest obligations — hospitals, ministries, regulated industry — precisely the places where the data cannot travel.

Gold Dawn asks a different question: which parameters need to be close to the processor right now? For a sparse frontier model the honest answer is: a small minority of them. The rest can wait on disk until they are selected.

Most of the model is never in memory at once.Always-active coreresident in memorySelected per tokenstreamed on demandDormanton storage, untouchedWidths are proportional. The dormant majority never enters memory — which is why the floor is a workstation, not a cluster.

WHAT IT GIVES THE INSTITUTION

Sovereignty as a property, not a promise.

Open weights

The model is a file you hold, not a service you rent. It cannot be deprecated, rate-limited or withdrawn on someone else's schedule.

Ordinary processors

Sparse frontier models activate a small fraction of their parameters per token. Gold Dawn keeps the always-active core resident and streams the rest from storage, so the memory ceiling stops being the accelerator's.

Inside the perimeter

Inference happens on hardware the institution already owns and already audits. Nothing is transmitted for processing, because nothing needs to be.

No revocable dependency

There is no upstream account, contract or endpoint whose withdrawal stops the system. That is a property of the architecture, not a clause in an agreement.

HOW IT IS ASSEMBLED

Five layers. The body is replaceable; the identity is not.

05 · Governance

Access, evidence, model eligibility, human approval, audit, rollback.

04 · Operating identity

Constitutional anchors, memory, relationships — persistent across restarts and across substrates.

03 · Memory orchestration

Which parameters must be close to the processor right now: pin, cache, prefetch, evict, stream.

02 · Execution

Direct low-precision arithmetic on packed weights. No dequantisation step, no accelerator requirement.

01 · Body

An open-weight sparse frontier model, held as a file on the institution's own storage.

The memory-orchestration layer is ours and is model-independent: it schedules residency across cache, memory and storage without knowing which model it is serving. That is what allows the body to be exchanged — for a newer model, a smaller one, or one a jurisdiction requires — without disturbing the identity above it.

WHERE GOLD DAWN DOES NOT APPLY

The constraint is also the explanation.

We state the boundary on the page rather than in a footnote. An institution that discovers a limit after signing stops believing everything it was told before it.

Sparse models, not dense ones

A sparse mixture-of-experts model activates a few percent of its parameters per token, so most of it can stay on disk. A dense model needs every parameter for every token — there is nothing to page, and no engineering removes that. Gold Dawn addresses the sparse frontier class.

Capacity, not throughput

This is not the fastest way to serve a model, and it is not intended to be. It is the way to run one where an accelerator cannot go: inside a hospital network, behind an air gap, under a data-residency rule.

Governed, not autonomous

Gold Dawn is the substrate layer. Identity, memory, evidence and human authority remain governed by KoLo above it. Sovereignty of hardware without governance of behaviour would be the wrong kind of independence.

WHO IT IS FOR

Institutions whose obligations arrive before their preferences.

A hospital that cannot send patient records outside its network does not choose a model by tokens per second. It chooses one that runs at all, on hardware inside the building, under an audit it controls. The same is true of a ministry with a residency rule, a bank under supervisory obligation, and an industrial site with no reliable connection.

For those institutions the accelerator question was never the real one. The real one was whether frontier capability could exist inside the perimeter at all.