Security

Security posture by subtraction.

The most reliable way to reduce attack surface is to have less to attack. Unimatrix0 removes the database, removes the management services, removes the writable operating system, and keeps every heavyweight component in an isolated guest.

Trust zones

Four concentric boundaries. Traffic flows one way, and only between neighbours.

───────────────────────────────────────────────────────────────────
ZONE 4  UNTRUSTED            external networks · third-party agents · vendor SaaS
───────────────────────────────────────────────────────────────────
                │  only via the hardened gateway appliance
───────────────────────────────────────────────────────────────────
ZONE 3  BOUNDARY           network appliance · agent gateway
                              TLS termination · rate limits · tenant policy
                              passthrough NICs · schema validation at the edge
───────────────────────────────────────────────────────────────────
                │  virtual interfaces only
───────────────────────────────────────────────────────────────────
ZONE 2  TENANT             customer VMs · AI appliances · third-party protocol servers
                              mutually isolated · own PCI devices · no route to Dom0
───────────────────────────────────────────────────────────────────
                │
───────────────────────────────────────────────────────────────────
ZONE 1  CONTROL            Dom0 · hypervisor · one daemon · immutable
                              no public interface · no unauthenticated socket
                              read-only root · cannot be modified at runtime
───────────────────────────────────────────────────────────────────

KEY PROPERTY: a compromise in zone 3 or 2 cannot reach zone 1.
                The hypervisor is not a service on the network.
Controls

Seven properties, and why each one holds.

1. The hypervisor is not on the network

No public interface, no unauthenticated API socket. Every request enters a guest that exists to be the entry point. There is no privileged service to attack directly — you must first own a workload.

2. Runtime changes cannot persist

The control plane runs from a read-only filesystem in RAM. An attacker who modifies the running system gains nothing across a reboot, because the next boot restores the exact signed image. There is no "re-image the host" playbook because there is no install.

3. Heavy stacks are guests, not the host

Model runtimes, CUDA drivers, language servers, protocol parsers, routing daemons and backup agents all run in isolated appliances. Each one is a containment boundary with its own PCI devices and its own failure domain.

4. Safety is enforced on the storage layer

Mutual exclusion is an atomic claim on shared storage, not a timeout. Two hosts cannot both own a disk, regardless of what the network did. The watchdog is bound to lease renewal, so a hung host is reset before it can appear dead-but-alive.

5. Agents get least privilege, and a brake

Role-scoped tokens, per-tool visibility, schema validation at the boundary, and a mandatory human approval on destructive operations. An agent cannot discover a tool it is not permitted to call.

6. Supply chain is signed and pinned

Appliance manifests and console bundles are signed. Nodes report their exact release and the platform flags mixed or outdated images. Roll forward or back by changing which image the fleet boots — an auditable, reversible act.

7. Full attribution for every action

Every operation — from the console, the CLI, the API or an agent — records the identity, the surface it arrived on, the operation, an argument digest and the outcome. When an agent drains a node at 03:00, the audit trail names the agent, its token, its role and the approval that authorised it. This is the single most-requested control in the evaluations we run, and the hardest to retrofit onto an existing platform.

Threat model

What we defend against, and where we stop.

Any security claim without a stated boundary is marketing. Here is ours.

In scope

  • External network access to the control surface — blocked by design, no exposed privileged service
  • Agent or credential compromise attempting privilege escalation — scoped tokens, approval gates, non-discoverable tools
  • Exploitation of a model runtime or protocol parser — contained in an appliance guest
  • Network partition or hostile node — disk leases prevent dual ownership
  • Physical tampering with a running node — eradicated at next boot by immutability
  • Unauthorised or unsigned extension loading — rejected unless explicitly trusted
  • Silent data egress via telemetry — none exists; no external calls, no licence server

Out of scope — and your responsibility

  • A compromised host kernel or a malicious hypervisor binary before it is verified against the signed image
  • A storage array that lies about durability or silently loses acknowledged writes
  • Host BIOS or boot-order tampering without hardware control of the boot process
  • Application-layer vulnerabilities in the workloads you run — those are yours
  • Model weights or datasets that arrive already compromised
  • Physical access to the array, the network fabric or the management endpoints
  • Credential hygiene: a leaked admin token is still a leaked admin token

We do not claim certification we do not hold. Ask us which control frameworks we have been assessed against, which we are actively working toward, and which we are not. Where you have a compliance obligation that requires attestation we do not yet provide, we will say so in the first conversation rather than the fourth.

Compliance posture

The properties auditors actually ask about.

Data residency

Everything stays on infrastructure you specify. No telemetry, no usage reporting, no external dependency in the operation path.

Access control

Role-based permissions, scoped tokens, human approval for destructive operations, and per-call audit records across all surfaces.

Change control

Immutable, versioned images with signed extensions. An upgrade is a deliberate, reversible act with a visible fleet state.

State & records

Configuration and workload definitions are plain files on your array in documented formats — auditable, diffable, and exportable without our software.

Segmentation

VLAN-aware cluster networks, per-domain placement, drain by fault domain, and no management path from the workload zone to the hypervisor.

Agent accountability

Autonomous actions are attributed to a named identity and scoped token, with the approving human recorded — the control most agentic platforms lack.

Deployment guidance

How we recommend you deploy it.

  • Dedicated management VLAN. Keep node traffic off user networks entirely.
  • Trunk only the VLANs you use. Each cluster network is a tagged VLAN on the uplink.
  • Private control endpoints. The agent gateway is optional and should stay inside your perimeter.
  • Hardware watchdog enabled. Fencing depends on it; the platform falls back and reports if absent.
  • Fixed addresses via DHCP reservation. Nodes are diskless, so identity should come from the network.
  • Isolate the array. Storage safety is only as good as the array's durability semantics.
  • Encrypt at rest and in transit. We leave this to your array and fabric policies — and say so plainly.
  RECOMMENDED TOPOLOGY                                        
  user / tenant VLANs ──────┐                                 
                            │ trunk                           
  agent gateway VLAN ───────┐                     (optional)  
                            │                                 
  management VLAN ──────────┴────────nodes────┤               
                            │                                 
                            │ NFS · bus · API                 
                            │                                 
  storage VLAN ───────────────────────────────┘               
                              iSCSI · FC · NVMe-oF            
  CONTROL POINTS                                              
  ✓ hardware watchdog      ! fixed management IPs
  ✓ mgmt VLAN isolation    ! NTP time source
  ✓ array isolated         ! lease clock consistency
  ✓ no telemetry egress

Bring your questionnaire.

If you have a security review process, send us the questions in advance. We will answer them in writing, flag anything we cannot yet evidence, and tell you what we are working on.