Technical review
The document a security reviewer actually asks for.
Not a deck. A written review of how the kernel is built, what it cannot do by construction, where each guard lives in the code, what we attacked and what broke, and where the design stops scaling. Shared under NDA with design partners.
What it contains
Six sections, each with pointers into the tree.
Every claim in the review names the file and the test that pins it. If you have the repository, you can check each one in a few minutes.
Architecture
Invariants and the tests that pin them
Threat model
Red-team history
Performance wall
Benchmark methodology
Reading it
Written to be read in an afternoon, with the tree open beside it.
The review is a document. It is pinned to a commit hash so the pointers stay true, and it is reissued when the hash moves. Questions are answered by the person who wrote the code.
Pinned to a commit
The version you receive names the commit it describes. File and line references resolve against that tree even after later commits ship.
Red-team findings are not summarised away
Where an attack succeeded before the fix, the review says so, with the severity we assigned and the commit that closed it.
Roadmap is labelled roadmap
Hosted sign-up, hosted Observe, and hosted instances for Solo and Starter are in the launch plan. The review keeps them in a separate section from what is enforced today.
- 0
Scope and commit hash
what this version describes
- 1
Architecture
package map · ingest to learned fire · outbox · SQLite per tenant
- 2Pinned
Invariants
predicate · file · pinning test, one row each
- 3
Threat model
assets · boundaries · controls · residual risk
- 4Pinned
Red-team history
class · verdict · severity · fixing commit
- 5
Performance wall
measured limits · authority caches · where it stops
- 6Seeded
Benchmark methodology
GovBench generation, drift, scoring, publication gate
- ARoadmap
Launch plan
hosted sign-up · hosted Observe · hosted instances · independent audit
Who it is for
Two readers, two different questions.
Security reviewers
Platform leads
If you are filling in a procurement checklist rather than reviewing the design, start with the security page. It answers the standard questions without an NDA.
How it is shared
Under NDA, to design partners.
The repository is private. The review is how a team reads the design before it commits an engineer and real traffic.
A mutual NDA
Before you install anything
With the engineering team on the call
What it is not
Without an NDA
Most of the mechanism is already public.
Security
Request the technical review.
One email with your name, your organisation, and what you are evaluating it for. We reply within two business days with the NDA and a time.