Learn

TORCH.AI REASONING INFRASTRUCTURE

What Is Cross-Domain Data Integration (Across Classification Levels)?

Written by

Ben Brown

Mission Engagement Engineer

Cross-domain data integration is the practice of combining intelligence and mission data that lives in separate, isolated security domains, unclassified or CUI, SECRET, and top secret/SCI, into a coherent picture while enforcing the classification controls and accredited cross-domain solutions that govern what may move between them.

Also called cross-classification data integration or data integration across classification levels.

The tension is built into the problem. The whole point of classified networks is that they are isolated: data at one classification is kept off networks at another, enforced by hardware, policy, and accreditation. But a complete intelligence picture usually needs data from more than one of them. Integrating across domains therefore cannot mean copying everything into one place; it means combining what the rules allow to be combined, moving data between domains only through accredited mechanisms, and keeping classification intact the whole way.

That makes cross-domain integration a classification-governed layer on top of the rest of this hub: you cannot combine across domains data you have not made AI-ready, resolved, and marked for classification. It is also the vertical, by-classification counterpart to the horizontal, by-partner sharing of coalition interoperability.

Key takeaways

  • What it is: combining mission data across isolated security domains (CUI, SECRET, TS/SCI) into one picture while enforcing the classification controls and accredited cross-domain solutions that govern transfer.
  • Why it is hard: classified networks are isolated by design, so integration means reasoning across a divide that policy and accreditation deliberately enforce, not pooling everything.
  • The pattern: build authoritative knowledge at a lower classification, and as data moves up through an accredited cross-domain solution, higher-classification reporting enriches the shared picture.
  • What to require: classification enforced at the data level, transfer only through accredited cross-domain solutions, provenance preserved, and human and accreditation authority over what moves.
  • The payoff: a force reasons across classification tiers at machine speed, with the shared picture current and every transfer controlled and traceable.

Why Classified Networks Are Islands by Design

Cross-domain integration exists because separation is a feature, not a bug, and yet the mission needs to see across it. Networks are segregated by classification precisely to protect the most sensitive data, and moving information between security domains is governed, not free: Department of Defense policy requires that any transfer between domains go through an accredited cross-domain solution under defined controls (DoD, DoD Instruction 8540.01, Cross Domain (CD) Policy, 2017). Integration across classification levels is not a networking convenience; it is a governed, accredited activity.

The classification tiers map to specific networks, and only some of those tiers correspond to official cloud accreditation levels. The authoritative framework is DISA's Cloud Computing Security Requirements Guide, which defines impact levels IL2, IL4, IL5, and IL6, with IL6 covering classified information up to SECRET (DISA, DoD Cloud Computing Security Requirements Guide, via the DoD Cyber Exchange). Above SECRET, top secret and SCI data lives on the separate JWICS environment; that top-secret tier is not an official cloud impact level, so it should be described as the TS/SCI tier rather than given an impact-level number.

The reason manual approaches fail is that reconciling across these islands by hand is slow and unaccountable. Point-to-point data agreements, manual transfers, and stovepiped holdings at each level leave no common picture and no automated record of what moved where, under what authority. The demand is for integration that is both automated and governed: a shared picture that respects classification at the data level and moves data between domains only through the accredited paths policy requires.

For the mission the payoff is reasoning that spans the classification divide without weakening it: a picture that draws on what each tier is allowed to contribute, assembled at machine speed, with every cross-domain transfer controlled, logged, and defensible.

The Classification Tiers: CUI, SECRET, and TS/SCI

Bottom line: mission data lives in tiers that map to separate networks, and integrating across them is governed by classification. The official DoD cloud impact levels are IL2, IL4, IL5, and IL6 (up to SECRET); the top-secret tier (JWICS) sits above them and is not an official impact level.

TierNetworkClassificationOfficial cloud impact level
Unclassified / CUINIPRNet-tierUnclassified, including higher-sensitivity CUIIL4 (CUI), IL5 (higher-sensitivity CUI and national security systems)
SecretSIPRNetSECRETIL6
Top secret / SCIJWICSTS / SCINot an official cloud impact level; the TS/SCI tier

The takeaway for an evaluator is that the tiers are real networks with real separation, and that precision matters: IL5 and IL6 are official accreditation levels, while the TS/SCI tier is a classification environment, not an impact-level number. A capability that claims an "IL7" accreditation is misusing the terminology, and that is a useful tell.

How Cross-Domain Integration Works: Build Low, Enrich Up

The pattern that respects both the mission and the controls is to build authoritative knowledge at a lower classification and enrich it as it moves up. The stages are:

  • Establish authoritative knowledge at the lower tier. Build the shared, reusable picture, for example an enterprise or CUI-level foundation, where the broadest set of data can be combined.
  • Mark classification at the data level. Ensure every entity, record, and relationship carries its classification, so the picture always knows what belongs where.
  • Transfer only through an accredited cross-domain solution. Move data between domains exclusively through the accredited guard that policy requires, never by copying across the boundary.
  • Enrich at each higher tier. At SECRET and at the TS/SCI tier, higher-classification reporting adds to the shared picture, deepening it without pushing restricted data down to where it does not belong.
  • Preserve provenance across the boundary. Keep every element traceable to its source and its classification through the transfer, so the integrated picture can be inspected and defended.
  • Log every transfer. Record what moved between domains, in which direction, and under what authority, for audit and accreditation.

The load-bearing idea is build low, enrich up: a shared foundation at a lower classification that each higher tier adds to through accredited transfer, rather than many disconnected pictures or a reckless pooling of everything into one. Done right, the lower tiers are never starved of what they are cleared to see, and the higher tiers are never leaked downward.

Cross-Domain Integration vs. Related Terms

These terms cluster around classified data movement and are easy to blur. The table separates them.

TermWhat it isRelationship to cross-domain data integration
Cross domain solution (CDS)An accredited guard that moves data between security domains under controlsThe accredited mechanism integration uses to transfer data across classification boundaries
Multi-level security (MLS)A system that handles multiple classifications with built-in separationA design approach to the same problem; cross-domain integration focuses on combining the data across domains
CJADC2Integrating data and decisions across warfighting domains and partnersRelated but different: see CJADC2. There "domain" means a warfighting domain; here it means a classification domain
Classification-aware integrationHandling data with its classification enforced throughoutThe property cross-domain integration depends on, applied across tiers

What Makes Cross-Domain Integration Hard

  • Isolation by design. The networks are deliberately separated, so integration can never mean simply pooling the data.
  • Accredited transfer only. Data may cross a boundary only through an accredited cross-domain solution, under policy, not by ad hoc copying.
  • Record-level classification. The control over what may move lives on each record, so enforcement has to be just as granular.
  • Directionality. Enriching upward is safe; pushing higher-classification data down is a spillage, so the flow has to be controlled by direction.
  • Provenance across boundaries. Keeping every element traceable through an accredited transfer is harder than within one domain, but it is required.
  • Terminology precision. Misusing accreditation terms, such as claiming an official "IL7," signals a capability that does not understand the controls.

Why Cross-Domain Integration Has to Be Government-Owned and Accredited

Cross-domain integration touches the most sensitive data a force holds and the controls that protect it. If the logic that marks classification, drives transfers, and reconciles across tiers lives in a vendor's proprietary environment, the government has put the enforcement of its own classification controls somewhere it cannot fully inspect or accredit. The table contrasts the models against what cross-domain integration requires.

ConsiderationTypical commercial platformGovernment-owned reasoning infrastructure
Control of classification enforcementHeld in the vendor's environmentCustomer controls how classification is enforced across tiers
Relationship to accredited transferVariesWorks with the accredited cross-domain solution, does not bypass it
Sensitivity of the dataMost-sensitive holdings externally heldKept under government control
Provenance across boundariesOften limitedPreserved and logged through every transfer
Directional controlGenericEnriches up without pushing restricted data down
Where it can runFrequently cloud-onlyAcross CUI, SECRET, and TS/SCI environments

Government-owned does not mean the government builds everything itself or owns a vendor's underlying intellectual property. It means the classification enforcement, the integration logic, and the transfer log stay under the customer's control and accreditation rather than inside a proprietary model. Whether a specific deployment is government-owned (GOTS) or commercial (COTS) depends on the system the customer installs and purchases; for the integration of a force's own classified data, the government-owned model is the one to evaluate.

Keeping the Guard and the Human in the Loop

Moving data across a classification boundary is an accredited, policy-governed act, so the controls and a human stay in command. The accredited cross-domain solution is the guard that enforces what may transfer; the integration capability works with it, never around it. The machine does the scale: marking classification, reconciling the picture across tiers, and preparing data for accredited transfer, faster than any manual process. But the authority to accredit a transfer path and to approve what moves rests with the security and accreditation authorities, not an automated default, and the system withholds rather than guesses when classification is unclear. This is the same auditable discipline the rest of this hub requires, applied where a wrong transfer is a spillage: the AI integrates and prepares; the accredited guard and the human authority control what crosses.

What to Require for Cross-Domain Integration AI

The sections above explain why classification enforcement and accredited transfer matter; the checklist is what to require in an evaluation.

  1. Enforces classification at the record level. Marks and applies classification on each entity and record, not just at the network boundary.
  2. Works with accredited cross-domain solutions. Transfers across boundaries only through the accredited guard, never by bypassing it.
  3. Controls direction. Enriches upward without pushing higher-classification data to a lower tier.
  4. Preserves provenance across boundaries. Every element stays traceable to its source and classification through a transfer.
  5. Logs every transfer. Records what moved, in which direction, and under what authority, for audit and accreditation.
  6. Human and guard in command. Security and accreditation authorities approve transfer paths; the capability does not self-authorize movement.
  7. Government-owned and accreditable. The customer controls classification enforcement and its data across CUI, SECRET, and TS/SCI environments.

Evaluating a capability? The seven requirements above are the backbone of a cross-domain data-integration evaluation you can score vendors against. Bring them to a scoping call and we will walk each one against your environment: request a technical walkthrough.

How Torch.AI Supports Cross-Domain Integration

Torch.AI builds reasoning infrastructure the customer can own and govern, offered as a government-owned (GOTS) deployment when a mission requires it, designed to operate across classification tiers. ORCUS ingests and normalizes data with classification preserved at the record level; NEXUS reads unstructured reporting and applies classification and releasability labels at scale; and HALO resolves and fuses the data into a shared picture in which every entity and relationship carries its classification, so the picture can be built at a lower tier and enriched as higher-classification reporting is added. The capability works with the accredited cross-domain solution that governs transfer rather than around it, and every element stays traced to its source and classification through the boundary. You can see how this is packaged as a capability on the Torch.AI software page.

Because classification is enforced at the data level with provenance preserved, the integrated picture is defensible across tiers: a security authority can see why a record carries the classification it does and govern what moves, while the accredited guard enforces the transfer. This is the systems of record versus systems of reason distinction at the center of Torch.AI's approach, carried across the classification divide: the reasoning layer builds the shared picture on top of the authoritative sources at each tier, which stay intact, so a force reasons across classifications without weakening the separation that protects them.

Torch.AI's approach is built for the conditions this page describes: classification enforced at the record level; a shared picture built low and enriched up; accredited cross-domain transfer respected, not bypassed; provenance preserved across boundaries; and government-owned operation across CUI, SECRET, and TS/SCI environments.

For evaluators scoping a capability, see how Torch.AI integrates data across classification tiers while respecting cross-domain controls on the software page, or request a technical walkthrough and we will run it against a representative cross-domain scenario, with provenance traced end to end.

Sources

  • U.S. Department of Defense, DoD Instruction 8540.01, Cross Domain (CD) Policy (2017), esd.whs.mil - establishes that transfer of data between security domains must use an accredited cross-domain solution under defined controls.
  • Defense Information Systems Agency, DoD Cloud Computing Security Requirements Guide (CC SRG), via the DoD Cyber Exchange, public.cyber.mil - defines the official cloud impact levels (IL2, IL4, IL5, IL6), with IL6 covering classified information up to SECRET.

Frequently Asked Questions

What is cross-domain data integration in simple terms? It is combining mission data that lives on separate, isolated networks at different classifications, unclassified or CUI, SECRET, and top secret/SCI, into one coherent picture, while enforcing the classification controls and accredited cross-domain solutions that govern what may move between them. Here "domain" means a classification domain, not a warfighting domain.

What is a cross domain solution (CDS)? A cross domain solution is an accredited guard that moves data between security domains under defined controls. Cross-domain integration uses an accredited CDS to transfer data across classification boundaries; it never copies data across a boundary without one.

Is there an IL7 classification level? No. The official DoD cloud impact levels are IL2, IL4, IL5, and IL6, with IL6 covering classified data up to SECRET. Top secret and SCI data lives on the JWICS environment, which is the TS/SCI tier, not an official cloud impact level. A capability claiming "IL7 accreditation" is misusing the term.

How do you integrate data across classification levels without a spillage? By enforcing classification at the record level, transferring only through an accredited cross-domain solution, and controlling direction, enriching a lower-tier picture with higher-classification data as it moves up, never pushing restricted data down. Provenance and a transfer log keep every movement accountable.

How is this different from CJADC2? CJADC2 integrates data and decisions across warfighting domains and partners; cross-domain data integration here is about combining data across classification domains (CUI, SECRET, TS/SCI). The word "domain" means different things in the two: warfighting domain versus classification domain.

Why does cross-domain integration need to be government-owned? Because it touches the most sensitive data and the controls that protect it. A government-owned (GOTS) deployment keeps classification enforcement, integration logic, and the transfer log under the customer's control and accreditation. The same capability can also be delivered commercially (COTS); which applies depends on the system the customer installs and purchases.

Talk to our team