Live run · captured on real hardware · zero egress

Watch the loop run. Breach a twin, prove you closed it — signed, with no LLM in the decision.

This is a real run, not a diagram. One engine picks a genuinely reachable exposure; an AI red model breaches a twin of the environment — never production; two independent witnesses prove the breach; an AI blue model detects it; a deterministic gate that contains no model decides the fix; a re-exploit proves it now fails; and every step is sealed into a signed, tamper-evident record.

net/red · live loop replay · Cairn → attack → prove → close → re-prove ◈ ZERO EGRESS
Live replay of one run: Cairn selects a reachable exposure, the red model exploits a twin, two witnesses (a firewall counter and an in-target marker) prove the breach, the blue model detects the technique, the deterministic DVL gate with no LLM contains it, a re-exploit proves closure, and a signed Proof-of-Resilience is sealed. An injection-resistance panel shows the agent guard raising resistance from 39.5% to 94.5%.

Real evidence, streamed from the signed ledger — the hashes on screen are the record. Captured from the product; interactive walkthrough on request.

A pentest tells you a door was open. We hand you signed proof you closed it. — Proven, not recommended.

What you're watching

Eight stages, one incident. The colour tells you who is acting — the attacker, the defender, or the deterministic gate that no model can talk its way past.

  1. 01

    Cairn

    Selects a genuinely reachable exposure — the feed that decides what red even attempts.

  2. 02

    Red model

    Plans and fires the attack against a twin — a copy, never your live network.

  3. 03

    Digital twin

    Real vendor-OS fabric. The exploit transits the in-path firewall and lands.

  4. 04

    Two-witness oracle

    Breach proven only when two independent witnesses fire — a firewall counter and an in-target marker.

  5. 05

    Blue model

    Detects the technique from telemetry and recommends containment.

  6. 06

    DVL · no LLM

    A deterministic gate decides and enforces the fix. No model sits in the decision path.

  7. 07

    Re-exploit

    The same attack is re-fired. It now fails — closure, not opinion.

  8. 08

    Signed proof

    Every step sealed into an append-only, hash-chained, signed Proof-of-Resilience.

The proof, measured

Not adjectives — numbers, taken from real runs.

Detection
100%vs 41.7%

An AI defender caught the east-west techniques a deterministic perimeter is structurally blind to — an audited +58.3-point gap closed.

The AI itself is attack surface
guard off · model exposed39.5%
guard on · scanner in path94.5%

Injection resistance of the deployed model, guard off vs on, over an identical 256-attack probe. +55 points; attack success cut ~11×.

The gate
0LLMs in the decision path

Models propose; deterministic policy decides, predicts blast radius, and a human approves anything real. The answer to “AI tools are themselves attack surface.”

It runs where your data already lives

The entire loop — models, twin, gate, signed ledger — runs inside your walls. No outbound path. The run above was booted from a single command against a real backend.

✔ 100% on your hardware · air-gap-ready ✔ Source-available core · BYO-GPU or sovereign appliance ✔ Every action signed & replayable

$ make demo — boots the stack, seeds a real run, opens the live loop.