Cybersecurity
Once the operating system is compromised, you cannot rely on it to prove its own integrity.
Endpoint security inside the operating system stops a great deal, and we are not pretending otherwise. The problem is what happens after that boundary falls. A tool that depends on the same trust boundary as the attacker can be blinded, bypassed or subverted, and it cannot be the final authority on whether the machine it runs on is trustworthy. Something outside that boundary has to make that call, and prove afterwards what actually happened rather than logging it somewhere an attacker or an insider can edit.
The principle
Enforce the outcome, then evidence it
That is not a new idea for us. It is exactly how the erasure engine works, and it is why the certificate it issues means something that other certificates do not.
A destruction certificate that records a process ran is worthless if the data survived. The engine only certifies where the outcome is proven at the device, and where it cannot be proven it fails closed and issues nothing. Applied to security, the same reasoning says a device should not be trusted because it passed a check somewhere, it should be prevented from running until trust is established, and every action afterwards should be recorded in a form nobody can alter, including us.
01 / Today
What you can buy and test now
The Smart Wipe Engine
The destruction side of that principle already exists. Independently certified under ADISA Product Assurance against NIST SP 800-88 Rev 1, the subject of published patent applications in the UK and the United States, and carrying a warranted outcome with £10 million of professional indemnity insurance behind it.
It is the part of this you can put under contract today, and the part you can hold us to.
How it works → Read the assurance register → Read the licence →
02 / In development
What we are building
The DSS Security Endpoint
We are building the wider endpoint system around that engine, extending the same standard from destruction to the whole life of the device. Trust decided before boot rather than after. Behaviour assessed continuously rather than matched against a list of things already known to be bad. Every action recorded in a form that nobody, including us, can alter after the event.
The architecture is ours. The reasoning and semantic layer is being developed with Almato, whose platform we also deliver.
This is in development. It is not available to buy today and we are not taking orders for it.
We are publishing the direction because it is where the erasure work leads, not because it is finished. We will not describe the architecture publicly while it is in development, and we will not put a date on it that we cannot stand behind. When there is something certified and warranted, it will be published here the same way the erasure engine was, with the references and the licence attached.
If you run an estate where this matters, particularly in government, defence or healthcare, we are willing to talk about it under NDA. That is the only way the detail gets discussed.
The common thread
The same test applies across everything we do
A certificate telling you a process ran is not evidence the data is gone. An AI answer you cannot interrogate is not evidence either. And security that depends on the operating system cannot be the final authority on whether that system is trusted. The same reasoning runs through the destruction engine, the data platform and this.
If you want to test how we treat evidence, the destruction side is where we have published all of it, including the research, the certifications and the licence wording.