Security & Sovereignty
Six-layer, brain-inspired defense in depth. Air-gap mode. Zero-trust mesh. Tamper-evident memory integrity. Your data never leaves your hardware.
Defense-in-Depth
Inspired by the three protective layers that surround the human brain. We doubled them.
Perimeter gate. Air-gap toggle. All outbound traffic blocked in sovereign mode.
Policy routing. Provider mode enforcement. Request classification and rate limiting.
Inference contact layer. Local-first execution. Model inputs never serialized to external APIs.
Human-in-the-loop for high-stakes actions. Configurable thresholds per domain and risk level.
Token rotation. Gitleaks CI scanning. Vault integration. Zero secrets in source or logs.
Automated penetration validation against Spoofing, Tampering, Repudiation, Info Disclosure, DoS, Elevation.
Air-Gap Sovereignty
| Mode | Behavior | Network | Use Case |
|---|---|---|---|
| local | All inference on-device | Zero outbound | Sovereign edge, classified environments |
| mixed | Local-first with explicit cloud fallback | Selective outbound | Enterprise hybrid deployment |
| cloud | Opt-in to external providers | Standard HTTPS | Development, non-sensitive workloads |
| air-gap | Fully disconnected | No interface | SCIF, submarine, forward operating base |
Every new memory is added to a tamper-evident audit trail. Every recall is scored for confidence. Leakage between memory compartments is a testable threat — expect zero. Memory integrity is cryptographic, not assumed.
Every message between nodes is cryptographically authenticated. Peers verify each other’s memory integrity before they exchange data. No implicit trust — every packet proves its origin and integrity.