Infrastructure, built to perform.
A modular family of infrastructure products — hypervisor, operations, security, storage, and compute — hardware-attested from boot to runtime.
The product family.
Each one stands alone. Pair them when it makes sense.
Secured Hypervisor
A hypervisor that audits itself.
Infrastructure Automation
Fleet operations on autopilot.
Adaptive Security Guard
Continuous security, around the clock.
Secure Remote Access
Browser-native access to your fleet, with full audit.
WebAuthn Authentication
Passwordless sign-in and task approval — no OTPs, no shared secrets.
Zero-Knowledge Storage
Encrypted backups we cannot read.
Application Marketplace
Extensions and verified third-party apps.
Environment Preparation and Execution Rig
Compliance you can run on demand.
Local Trust Agent
A goal-directed agent that acts across the stack, attested at every step.
Lightweight Application Server
A lightweight application server with two compute modes and a signed receipt per call.
The runtime, in numbers.
Same workload. Two execution modes. Signed results you can verify independently.
KVM-isolated execution
Each actor boots directly as a KVM guest — a flat binary with no operating system inside, isolated at the hardware level. The result is Ed25519-signed before it leaves the host. You can verify the receipt offline.
- 200 µs warm dispatch (reference voting workload)
- Hardware-attested receipt per call
- Snapshot hot-pool — no cold start penalty
Distributed microservice mesh
The same actor source deployed as a supervised cluster on Firecracker microVMs. Scales horizontally across hosts. HATP receipts on every call — same attestation model, different execution target.
- 78 ms sandbox spawn
- Horizontal scale, same code
- Strong-consistency replication available
Environment validation rig
DE:EPER runs the full validation pyramid — from install checks to whole-stack scenarios — on every release. The output is signed evidence the auditor can verify byte-for-byte against the recipe. Compliance becomes something the pipeline produces.
- Automated test pyramid, install to whole-stack
- Signed evidence per run
- Auditor-verifiable, offline
The exact same source code. Different deployment target. You choose which fits your workload. Read the DE:LIGHT docs → See the benchmarks →
DE:PLOY and DE:FENDER work together — operations and security in one loop. Incidents are contained and remediated by the platform, and every action lands in the audit trail.
You're informed. You're not paged.
Security, without the theatre.
Quick to deploy, and built so that even we cannot access your systems without your approval.