Security
Our posture, stated without the usual reassurance vocabulary — including the parts that are still ahead of us, and how to tell us when we have got something wrong.
Zero trust, applied to ourselves
ZTAL™ — the Zero Trust Algorithm Layer — is designed to verify identity, consent and behavioural risk continuously rather than at a session boundary. That verification applies to our own services and internal callers on the same terms as anyone else's.
Never trust, always verify, continuously validate is a design constraint here, not a slogan attached to a network diagram.
Minimizing what is worth stealing
The strongest security property in this architecture is not a control. It is the absence of a central store of raw emotional and behavioral data to compromise.
Local processing, encryption under the person's own key, and proof-based consumption are all aimed at the same outcome: reducing the value of a successful breach to close to nothing.
Security as a product capability
From Phase 05, behavioral analysis, anomaly detection and emotional risk analysis feed a security layer that can act — holding a transaction, requiring step-up verification, or resisting an account takeover.
A stolen session does not behave like the person who owns it. The layer that notices that is the same one that makes recommendations useful.
Where we are today
Phase 01 is a website and an access list. The security surface is correspondingly small, and we are not going to describe it as though it were larger.
Independent review, formal audit and a published disclosure programme belong to the phases in which there is something substantial to review.
Reporting a vulnerability
If you find a weakness in this site, in the published architecture, or in the reasoning behind either, tell us through the access form and mark it clearly.
We will acknowledge it, tell you what we did about it, and credit you if you would like to be credited. We will not respond to a good-faith report with a legal threat.
Architectural weaknesses count
A flaw in the design is more valuable to us than a flaw in an implementation, because it is far cheaper to fix now than after Phase 04.
If you believe a claim on this site is not achievable as described, that is a report we want to receive.