Security & Sovereignty

Sovereignty is architectural,
not contractual

Six-layer, brain-inspired defense in depth. Air-gap mode. Zero-trust mesh. Tamper-evident memory integrity. Your data never leaves your hardware.

0
Security Layers
0
Provider Modes
Security framework
Threat Framework
Tamper-Evident
Memory Integrity

Defense-in-Depth

Six-layer security mesh

Inspired by the three protective layers that surround the human brain. We doubled them.

Layer 1

Perimeter Gate

Perimeter gate. Air-gap toggle. All outbound traffic blocked in sovereign mode.

Layer 2

Policy Router

Policy routing. Provider mode enforcement. Request classification and rate limiting.

Layer 3

Inference Shield

Inference contact layer. Local-first execution. Model inputs never serialized to external APIs.

Layer 4

Approval Gate

Human-in-the-loop for high-stakes actions. Configurable thresholds per domain and risk level.

Layer 5

Secret Management

Token rotation. Gitleaks CI scanning. Vault integration. Zero secrets in source or logs.

Layer 6

Security Validation Suite

Automated penetration validation against Spoofing, Tampering, Repudiation, Info Disclosure, DoS, Elevation.

Air-Gap Sovereignty

Four provider modes

ModeBehaviorNetworkUse Case
localAll inference on-deviceZero outboundSovereign edge, classified environments
mixedLocal-first with explicit cloud fallbackSelective outboundEnterprise hybrid deployment
cloudOpt-in to external providersStandard HTTPSDevelopment, non-sensitive workloads
air-gapFully disconnectedNo interfaceSCIF, submarine, forward operating base

Tamper-Evident Memory

Every new memory is added to a tamper-evident audit trail. Every recall is scored for confidence. Leakage between memory compartments is a testable threat — expect zero. Memory integrity is cryptographic, not assumed.

Every recall
cryptographically verified

Zero-Trust Mesh Authentication

Every message between nodes is cryptographically authenticated. Peers verify each other’s memory integrity before they exchange data. No implicit trust — every packet proves its origin and integrity.

Every packet
authenticated at origin

Security is a property of the substrate, not just the weights.

View Architecture Use Cases Technical White Paper →