Product line
Products
The catalog. One page per product — the problem, what it does, and who it is for. For hands-on experiments, use the studio.
Tier 1 — Pilot-capable · 16 modules
Tier 1 — Pilot-capable (16): live demo + guided private pilot under NDA (/v1, durable). All other live modules below are evaluation / experimental — live demo on /demo (ephemeral) only, not in pilot boundary and not compliance-certified. Request a pilot →
Two guided suites are also available under the same framework — Portable Sovereign Credentials and the Sovereign Emergency Continuity Package — as compositions of existing modules (not separate products), run under NDA on private infrastructure.
Prove where a sensitive image came from with a classic 1-bit LSB mark — evaluation-only; extraction can fail after re-encode or crop.
Give every AI decision a reviewable record — inputs, context, and rationale — for governance and compliance.
Collect audit events from many sources into one immutable, queryable history with integrity checks.
Store and retrieve regulatory evidence with an immutable seal, chain of custody, and NDA-controlled review.
Manage contractual agreements with an immutable seal, version history, and chain-of-custody review.
Give teams encrypted communication channels with optional sealed payloads and provenance.
Define who owns and controls data across organizational boundaries, with governance and audit.
Record production and transit events on an immutable trail with integrity verification.
Anchor a content hash to an immutable registry and produce receipts that anyone can verify.
Let autonomous agents act only within allow / deny / escalate policy, with a full audit trail.
Move sealed payloads across air-gapped boundaries inside image carriers, with integrity verification.
Prove what was redacted and that it stayed redacted, with verifiable receipts.
Keep emergency access sealed by default and release it only with a recorded reason.
Build policy once, sign it, and distribute verified cartridges that agents can trust and you can revoke.
Issue portable credentials once, let them be verified anywhere, and revoke them on demand.
Experimental — evaluation only · not in pilot / compliance boundary
Produce redacted versions with a verifiable chain, legal-hold, and export — without destroying evidence.
Share a payload once, prove it was claimed or destroyed, with optional time-bound expiry.
Register replicas by contentHash + locationRef and burn them with a verifiable receipt — registered copies only.
Distribute registered variants and triage a recovered mark to the originating variant.
Embed multiple plausible payloads under different keys; extraction returns the layer for that key or fail-closed.
Draft, dispatch, accept/reject, and verify agent handoffs across domains.
Grant and check purpose-bound consent with expiry and revocation.
Register nodes and edges, then verify derivation paths.
Govern sends over channels you operate with policy and a complete audit trail.
Build and list custody export bundles with contentHash.
Publish a policy package (name, version, content) and list all packages with content hashes and published timestamps. Content is hashed for integrity but not distributed.
Register a model (modelId, version, weightsHash, architecture, publisher) and list all registrations with status and timestamps. weightsHash must be a 64-char SHA-256 hex.
Record a risk observation (source, decision, riskNote, optional riskId/severity/status) and list all entries newest-first with content hashes.
Fetch a curated policy entry by entryId (or cartridgeId) and list all catalog entries. Entries are pre-seeded — this is a read-side discovery tool, not a policy engine.
Bind an audit event stream to a carrier image so provenance survives off-platform copies and extracts fail-closed under a wrong key.
Prove that a recovered output was produced under a registered intent by binding the two into a carrier image extractable only under the correct key.
Prove what was removed from a text by sealing the original→scrubbed residual with pre/post hashes, extractable only under the correct key.
Bind a registration to canary tokens woven into an agent output so downstream detection can confirm the output originated from your registered agent.
Submit a primary trajectory, submit a shadow under the same run ID, then diff — step-by-step action and hash comparison with aligned flag and delta report.
Append tool-call receipts (tool, argsHash, resultHash, agentId, meta) to a hash-linked chain. Each receipt links to the previous via prevHash, enabling tamper-evident audit.
Create a notarized escape-hatch exception (reason, policy, actor, scope, expiration) with a content hash, then optionally seal it into a carrier image with key-bound steganography.
Issue a consent receipt (purpose, scope, subjectRefHash, issuer, expiresAt, meta), verify its validity on the registry, and optionally seal it into a carrier image with key-bound steganography.
Set a policy of allow/deny/escalate rules keyed on jurisdiction arrays. Tag a resource with jurisdictions and payloadRefHash. Resolve an effect via route. Query full policy and inspect a tagged record.
Create an approval request (actionLabel, requesterId, requiredApprovals, unlockAfter, meta), then collect approvals up to the threshold. Status transitions pending → armed → unlocked.
Define an allowed-purposes policy with a default effect (deny or escalate). Evaluate a purpose against the policy, optionally tied to an actionType, resourceId, and consentReceiptId, to determine whether an action is permitted.
Schedule a resource for expiry by retainUntil or ttlSeconds. List due schedules for a point in time. Dispose a single schedule one-shot with a note. Get full record by ID.
Place a hold flag on a resource (with reason, caseId, actor, meta). Check whether a resource is held. Release one-shot with an audit note. List and inspect all holds.
Open a SAR by subjectRef with optional scope/requesterId/dueBy/meta. Complete with an exportManifest or manifest text, returning a receiptId, contentHash, artifactHash, and status. Optionally seal the receipt into a carrier PNG. Fetch full record by request ID and list all.
Request an erasure attestation by subjectRef with optional scope/reason/requesterId/meta. Attest with method, systemsTouched, completedAt, note, and attestorId — returns an attestationId, contentHash, and status (attested). Optionally seal into a carrier PNG. Fetch by request ID and list all.
Research
Independent security analysis, hardening guidance, and evidence-based reporting, delivered under NDA.
Retail
A free interactive comic studio where every creation carries a permanent, hidden voice in the pixels.
