An AI defender caught the east-west techniques a deterministic perimeter is structurally blind to — an audited +58.3-point gap closed.
Watch the loop run. Breach a twin, prove you closed it — signed, with no LLM in the decision.
This is a real run, not a diagram. One engine picks a genuinely reachable exposure; an AI red model breaches a twin of the environment — never production; two independent witnesses prove the breach; an AI blue model detects it; a deterministic gate that contains no model decides the fix; a re-exploit proves it now fails; and every step is sealed into a signed, tamper-evident record.
Real evidence, streamed from the signed ledger — the hashes on screen are the record. Captured from the product; interactive walkthrough on request.
A pentest tells you a door was open. We hand you signed proof you closed it. — Proven, not recommended.
What you're watching
Eight stages, one incident. The colour tells you who is acting — the attacker, the defender, or the deterministic gate that no model can talk its way past.
- 01
Cairn
Selects a genuinely reachable exposure — the feed that decides what red even attempts.
- 02
Red model
Plans and fires the attack against a twin — a copy, never your live network.
- 03
Digital twin
Real vendor-OS fabric. The exploit transits the in-path firewall and lands.
- 04
Two-witness oracle
Breach proven only when two independent witnesses fire — a firewall counter and an in-target marker.
- 05
Blue model
Detects the technique from telemetry and recommends containment.
- 06
DVL · no LLM
A deterministic gate decides and enforces the fix. No model sits in the decision path.
- 07
Re-exploit
The same attack is re-fired. It now fails — closure, not opinion.
- 08
Signed proof
Every step sealed into an append-only, hash-chained, signed Proof-of-Resilience.
The proof, measured
Not adjectives — numbers, taken from real runs.
Injection resistance of the deployed model, guard off vs on, over an identical 256-attack probe. +55 points; attack success cut ~11×.
Models propose; deterministic policy decides, predicts blast radius, and a human approves anything real. The answer to “AI tools are themselves attack surface.”
It runs where your data already lives
The entire loop — models, twin, gate, signed ledger — runs inside your walls. No outbound path. The run above was booted from a single command against a real backend.
$ make demo — boots the stack, seeds a real run, opens the live loop.