Security-First Architecture

Security Posture

Data custody stays with the Client. Offline verification is first class. No telemetry by default. Built for paranoid operators.

Telemetry
Zero
BY DEFAULT
Key Custody
Client
OWNED
Network
Air-Gap
CAPABLE
Verification
Offline
FIRST CLASS

Design Posture

๐Ÿ“ก

01 Air-Gapped Capable

No outbound internet required for runtime operation. Deploy in classified or isolated environments without modification.

Tested on fully disconnected networks
๐Ÿ”‡

02 Zero Telemetry

No phone-home behavior. No usage metrics. No license servers. The binary runs without external communication.

Verified by network traffic analysis
๐Ÿ”‘

03 Client-Owned Keys

Private keys are injected at runtime via environment or HSM. No keys stored, transmitted, or escrowed.

HSM integration available for Enterprise
โœ…

04 Verification Purity

Verification is a pure function. Same inputs always produce same outputs. No hidden state.

Mathematically deterministic verification

Threat Model

In Scope

  • Tamper detection after seal creation
  • Non-repudiation of sealed events
  • Offline verification without vendor
  • Cryptographic binding of metadata

Out of Scope

  • Prevention of event fabrication before sealing
  • Key compromise at the client
  • Physical security of deployment
  • Application-layer vulnerabilities

Breach Simulation

DEFCON MODE

Try to tamper with a sealed record. Click any field to modify it. Watch the cryptographic verification fail in real-time.

SEALED RECORD
entity_id TXN_SAMPLE_001
amount 50000.00
timestamp 2026-02-02T15:39:35Z
status completed
data_hash c8b3e2f9...d1e
signature aca9f872...180e
โœ“
SEAL VALID
All verification checks passed
โœ“ Data Hash MATCH
โœ“ Binding Root VALID
โœ“ Signature VERIFIED
โœ“ Canonicalization COMPLIANT
Quick Attacks:

See It In Your Environment

The Proof Sprint puts 0REI's security model to the test with your real data, your infrastructure, your threat model.

Start Proof Sprint โ†’ $9,500 Read Security Posture

Security Documentation

Full Security Posture Document

Complete threat model, design constraints, custody boundaries, and operational security guidelines.

Genesis Pricing Active โ€” Founding rates lock in before General Availability.
Start Sprint โ†’ $9,500