1. The hypervisor is not on the network
No public interface, no unauthenticated API socket. Every request enters a guest that exists to be the entry point. There is no privileged service to attack directly — you must first own a workload.
The most reliable way to reduce attack surface is to have less to attack. Unimatrix0 removes the database, removes the management services, removes the writable operating system, and keeps every heavyweight component in an isolated guest.
─────────────────────────────────────────────────────────────────── ZONE 4 UNTRUSTED external networks · third-party agents · vendor SaaS ─────────────────────────────────────────────────────────────────── │ only via the hardened gateway appliance ─────────────────────────────────────────────────────────────────── ZONE 3 BOUNDARY network appliance · agent gateway TLS termination · rate limits · tenant policy passthrough NICs · schema validation at the edge ─────────────────────────────────────────────────────────────────── │ virtual interfaces only ─────────────────────────────────────────────────────────────────── ZONE 2 TENANT customer VMs · AI appliances · third-party protocol servers mutually isolated · own PCI devices · no route to Dom0 ─────────────────────────────────────────────────────────────────── │ ─────────────────────────────────────────────────────────────────── ZONE 1 CONTROL Dom0 · hypervisor · one daemon · immutable no public interface · no unauthenticated socket read-only root · cannot be modified at runtime ─────────────────────────────────────────────────────────────────── KEY PROPERTY: a compromise in zone 3 or 2 cannot reach zone 1. The hypervisor is not a service on the network.
No public interface, no unauthenticated API socket. Every request enters a guest that exists to be the entry point. There is no privileged service to attack directly — you must first own a workload.
The control plane runs from a read-only filesystem in RAM. An attacker who modifies the running system gains nothing across a reboot, because the next boot restores the exact signed image. There is no "re-image the host" playbook because there is no install.
Model runtimes, CUDA drivers, language servers, protocol parsers, routing daemons and backup agents all run in isolated appliances. Each one is a containment boundary with its own PCI devices and its own failure domain.
Mutual exclusion is an atomic claim on shared storage, not a timeout. Two hosts cannot both own a disk, regardless of what the network did. The watchdog is bound to lease renewal, so a hung host is reset before it can appear dead-but-alive.
Role-scoped tokens, per-tool visibility, schema validation at the boundary, and a mandatory human approval on destructive operations. An agent cannot discover a tool it is not permitted to call.
Appliance manifests and console bundles are signed. Nodes report their exact release and the platform flags mixed or outdated images. Roll forward or back by changing which image the fleet boots — an auditable, reversible act.
Every operation — from the console, the CLI, the API or an agent — records the identity, the surface it arrived on, the operation, an argument digest and the outcome. When an agent drains a node at 03:00, the audit trail names the agent, its token, its role and the approval that authorised it. This is the single most-requested control in the evaluations we run, and the hardest to retrofit onto an existing platform.
Any security claim without a stated boundary is marketing. Here is ours.
We do not claim certification we do not hold. Ask us which control frameworks we have been assessed against, which we are actively working toward, and which we are not. Where you have a compliance obligation that requires attestation we do not yet provide, we will say so in the first conversation rather than the fourth.
Everything stays on infrastructure you specify. No telemetry, no usage reporting, no external dependency in the operation path.
Role-based permissions, scoped tokens, human approval for destructive operations, and per-call audit records across all surfaces.
Immutable, versioned images with signed extensions. An upgrade is a deliberate, reversible act with a visible fleet state.
Configuration and workload definitions are plain files on your array in documented formats — auditable, diffable, and exportable without our software.
VLAN-aware cluster networks, per-domain placement, drain by fault domain, and no management path from the workload zone to the hypervisor.
Autonomous actions are attributed to a named identity and scoped token, with the approving human recorded — the control most agentic platforms lack.
RECOMMENDED TOPOLOGY user / tenant VLANs ─────┐ trunk │ agent gateway VLAN ──┐ (optional, │ internal │ private) │ management VLAN ────┴──┴──── nodes ────┤ NFS · bus · API │ │ │ storage VLAN ────────────────────────────┘ iSCSI · FC · NVMe-oF CONTROL POINTS ✓ hardware watchdog ! fixed management IPs ✓ management VLAN isolation ! NTP time source ✓ array isolated ! time sync for lease correctness ✓ no telemetry egress
If you have a security review process, send us the questions in advance. We will answer them in writing, flag anything we cannot yet evidence, and tell you what we are working on.