QUANTOM DOM markQUANTOM DOM

Security · QUANTOM DOM · AEGIS-Q architecture

Assume a patient operator.

AEGIS-Q is designed for people who will try to turn the agent off, forge its updates, isolate the plant, replay an activation, or rewrite the incident story later. Dual-control, air-gap autonomy, accountless one-time TRELYAN activation, and Algorand nullifier + QRL Merkle evidence are the answers we are willing to defend. A glossy 'zero breach' badge is not.

Adversaries

Who we design against.

The insider

A local admin who wants the kill-switch quiet, an exclude that never expires, or a quarantine emptied before the IR call. Dual-control and evidence events are the friction.

The forger

Someone who can break or steal classical vendor keys after Q-Day — or who can already phish a code-signing token today. Packs and evidence are aimed at post-quantum binding.

The isolator

Ransomware that kills the network first. A Faraday cage that is policy, not accident. The agent must finish the protection loop without us.

Dual-control

One person is not a process.

In managed fleets, the following require a second authorized operator: uninstall, tamper-protect disable, global excludes, quarantine restore of a high-severity object, and policy rollback to a weaker pack. Break-glass exists for named incidents and is itself an evidence event on both rails when a rail is reachable.

Air-gap

Dark is a mode.

Connected update is convenience. Signed pack ferry is the guarantee. Isolated hosts keep protecting on the last valid pack, refuse rollback to older vulnerable packs (anti-rollback), and queue evidence. We do not market a cloud region as a control.

Disclosure

How to tell us we are wrong.

Write security@quantom.trelyan.ch. There is no paid bug bounty on a public schedule today, and no claim of an audited safe harbor program. If you have a finding against this site or a design partner agent, say so plainly. We prefer a boring email to a theatre of hall-of-fame names we have not earned.

ClaimStatus
Public bug-bounty cash programNot offered
Independent agent pentest reportNot yet
This marketing site's security headersShipped (nosniff, frame deny, referrer)
Foundation protocol adversarial notesSee trelyan.foundation/verify