Security & Sovereignty

Sovereignty is architectural,
not contractual

Six-layer defense-in-depth modeled on biological meninges. Air-gap mode. Zero-trust mesh. Merkle-verified memory integrity. Your data never leaves your hardware.

0
Security Layers
0
Provider Modes
STRIDE
Threat Framework
BLAKE3
Merkle Hash

Defense-in-Depth

Six-layer meninges security model

Inspired by the three biological meninges that protect the brain. We doubled them.

Layer 1

Dura Mater

Perimeter gate. Air-gap toggle. All outbound traffic blocked in sovereign mode.

Layer 2

Arachnoid Router

Policy routing. Provider mode enforcement. Request classification and rate limiting.

Layer 3

Pia Mater Neural

Inference contact layer. Local-first execution. Model inputs never serialized to external APIs.

Layer 4

Approval Gate

Human-in-the-loop for high-stakes actions. Configurable thresholds per domain and risk level.

Layer 5

Secret Management

Token rotation. Gitleaks CI scanning. Vault integration. Zero secrets in source or logs.

Layer 6

STRIDE Test Suite

Automated penetration validation against Spoofing, Tampering, Repudiation, Info Disclosure, DoS, Elevation.

Air-Gap Sovereignty

Four provider modes

ModeBehaviorNetworkUse Case
localAll inference on-deviceZero outboundSovereign edge, classified environments
mixedLocal-first with explicit cloud fallbackSelective outboundEnterprise hybrid deployment
cloudOpt-in to external providersStandard HTTPSDevelopment, non-sensitive workloads
air-gapSPORE_GERMINATING=1 — fully disconnectedNo interfaceSCIF, submarine, forward operating base

Merkle Integrity Verification

Every FHRR bind appends a BLAKE3 Merkle leaf. Every recall computes a coherence score. Cross-room leakage is a testable threat — expect zero. Memory integrity is cryptographic, not assumed.

BLAKE3
per-recall integrity hash

Zero-Trust Mesh Authentication

Every mesh envelope is HMAC-SHA256 authenticated. E8-routed peers validate holographic Merkle state. No implicit trust — every packet proves its origin and integrity.

HMAC-SHA256
per-envelope authentication

Security is a property of the substrate, not just the weights.

View Architecture Use Cases Request Deck →