Platform Vision

Infrastructure for the post-static-surface world

Every industry that relies on digital infrastructure — defence, finance, cloud, critical infrastructure — is built on a flawed assumption: that surfaces stay static long enough to protect. ACSE eliminates that assumption. One platform. Six domains. A trillion-dollar opportunity.

$10.5T
Annual cybercrime cost by 2025
$350B
Global cybersecurity spend
71%
YoY rise in credential attacks
1
Patent Published · IN202641070690
Why Now

The threat landscape has fundamentally shifted

Static surfaces have always been a liability. What changed is the speed, scale, and automation of the attacks exploiting them — and the regulatory cost of getting it wrong.

Minutes
AI Reconnaissance Time

AI-Assisted Attackers

WormGPT, FraudGPT, and AutoGPT-based attack frameworks cut reconnaissance from days to minutes. AI maps surfaces, correlates fingerprints, and drafts exploit chains faster than any human analyst can respond. ACSE's answer: the surface expires before any AI model can act on what it observed.

6 hrs
Internet Rescan Frequency

Automated Continuous Scanning

Shodan and Censys re-index the entire internet every few hours. Every static API endpoint, every TLS certificate is catalogued before you've noticed the scan. ACSE: what they index is cryptographically stale by the time they serve the result.

71%
YoY Increase in Credential Attacks

Identity is the Primary Attack Vector

IBM X-Force 2024: credential-based attacks rose 71% year-over-year. Valid accounts were used in 30% of all incidents. The root cause isn't weak passwords — it's that stolen credentials remain valid. ACSE closes this at the root: credentials expire at mutation cycle boundaries.

1,000+
Cloud Services Per Enterprise (Gartner 2024)

Cloud Sprawl Explodes the Attack Surface

The average enterprise uses over 1,000 cloud services. Each service is an API. Each API is a static fingerprint accumulating in attacker databases. ACSE: every API surface rotates on every access event.

10 days
Median Attacker Dwell Time (Mandiant 2024)

Dwell Time Remains Catastrophic

Change Healthcare: 9 days and $2.457B in damage. SolarWinds: 14 months. These attacks succeed because surfaces stay static long enough to stage. ACSE's staging window is measured in microseconds.

4 days
SEC Breach Disclosure Deadline

Regulatory Liability is Now Personal

SEC rules, EU NIS2 (2024), India DPDP Act, CERT-In mandatory reporting. Board directors are personally liable. The cost of a static surface failure is now measured in fines, criminal liability, and stock price.

"

An attacker can't exploit a surface they mapped yesterday
if that surface no longer exists today.

The Kali Invariant  ·  ACSE Core Principle  ·  Published Patent IN202641070690
Applications

Six domains. One platform. Trillion-dollar opportunity.

ACSE is infrastructure — like TLS, it sits beneath everything else and makes everything else more effective. Every industry built on digital surfaces is a potential deployment.

Sector 01 · Priority

National Defence & Intelligence

Command, control, intelligence, and surveillance surfaces are the most targeted in the world. Nation-state adversaries rely on long-duration reconnaissance — the exact capability ACSE eliminates. A surface that expires in 10 microseconds cannot be mapped in 14 months.

ScaleNational defence agencies · DoD (USA) · NATO · Five Eyes · national military networks
ProfilesKrakenNet (AD/credential), LeviathanGrid (network topology), KaliCoreTarget (estate-wide)
Sector 02

Critical Infrastructure

16 CISA-designated sectors — power grids, water systems, hospitals, transportation networks — run on legacy OT/IT systems with static surfaces. Colonial Pipeline was stopped by one leaked VPN password. Change Healthcare cost $2.457B.

Scale$27.5T GDP dependent on protected infrastructure across 195 countries
ProfilesJellyNet (elastic), MantisNet (intrusion response), AnglerShield (API surface)
Sector 03

Financial Systems & Payments

SWIFT, central banks, payment processors, and trading platforms handle $120T+ in annual global flows. SquidShield delivers 100% fingerprint uniqueness at 76.1k transactions per second with full PCI-DSS audit trail. Credential replay and session hijacking are structurally impossible.

Scale$120T+ annual global payment flows · 2B+ card holders · 10,000+ financial institutions
ProfilesSquidShield (payments), NautilusVault (data vault), GlassFrog (compliance/audit)
Sector 04

Cloud Platforms & SaaS

AWS, Azure, and GCP integration at the platform layer means one deployment protects every tenant workload. ACSE becomes a cloud-native security primitive — deployed once by the hyperscaler, enforced everywhere. One hyperscaler partnership scales to billions of endpoints.

Scale$650B+ global cloud services market · 1,000+ cloud services per enterprise
ProfilesChameleonNet (cooperative enclaves), JellyNet (elastic), KaliCoreTarget
Sector 05

Data Centres & COLO

ElectricEelGrid is the only available solution defending the power side-channel in COLO environments — where physical co-location allows observable electromagnetic and thermal side channels that no other product addresses. Red team power correlation: 0.03%.

Scale10,000+ commercial data centres globally · $200B+ data centre market
ProfilesElectricEelGrid (COLO/side-channel), MantisNet (intrusion response)
Sector 06

National Cyber Defence

Government CERTs, national SOCs, election infrastructure, and classified national systems face nation-state adversaries with unlimited resources. LeviathanGrid provides 16-node simultaneous rotation for nation-scale topology — the capability that would have stopped SolarWinds at all 18,000+ victim organisations simultaneously.

Scale195 countries × national cyber defence budgets · government frameworks
ProfilesLeviathanGrid (nation-scale), KrakenNet (AD), KaliCoreTarget (estate-wide)
The ACSE Advantage

Infrastructure, not a point product

ACSE doesn't replace your SIEM, your EDR, or your Zero Trust architecture. It changes the surface all of those tools protect. Like TLS — infrastructure that makes your entire stack more effective.

Zero Rip-and-Replace

Three lines of code. ACSE deploys alongside your existing stack — firewalls, SIEM, EDR, Zero Trust all remain in place and become more effective because they now protect surfaces that change rather than surfaces that don't.

Signature-Free Zero-Day Defence

ACSE doesn't need to know about a vulnerability to defend against it. The Kali Invariant holds against zero-day exploits, supply-chain implants, and credential theft equally — because the protection is at the surface identity layer, not the exploit signature layer.

Formally Verified Security Properties

Three ProVerif models. ZK authentication: TRUE. Cascade authentication: TRUE. TEE-bound management: CORRECT across all queries. Mathematical proofs, not performance claims. No other defensive architecture in production has this level of formal rigour.

Domain-Adaptive — 11 Profiles

Finance, healthcare, defence, cloud, COLO, and nation-scale — each domain has a tuned mutation profile. Swap profiles with one configuration line. No architectural changes required.

Hyperscale-Ready

Sub-millisecond mutation cycles. 1,045 tests, zero failures. All cycles complete in 10–144 microseconds depending on profile. Estate-wide rotation in under 200 microseconds via KaliCoreTarget.

IP-Protected & Patent Published

Patent IN202641070690 — Published 19/06/2026, Journal No. 25/2026, Indian Patent Office. Expedited examination in progress. The Kali Invariant, PME architecture, ASMP/1.0, and all 11 profiles are covered.

Management Layer

ACSE Control Plane

v0.4.0 Released

One dashboard. Every estate. Real-time Kali Invariant status across every protected node — with SIEM dispatch, firewall orchestration, and TEE-attested policy management built in from day one.

🛡

TEE-Attested Authentication

Every API call validated inside a Trusted Execution Environment — SGX, Nitro, SEV-SNP, or ARM CCA. Admin / Operator / ReadOnly RBAC enforced per endpoint.

📊

Estate-Wide Dashboard

Live organ-state view across every registered estate. EWMA anomaly score, torpedo count, channel fingerprint, JA3 hash, p0f signature — updating every 5 seconds.

🔗

SIEM Integration

Every mutation event and Torpedo firing dispatches to your SIEM automatically. Splunk HEC, IBM QRadar, RFC 5424 Syslog, and stdout — all supported out of the box.

🔥

Firewall Orchestration

When a surface mutates, the connected firewall updates automatically. Palo Alto Networks XML API (Dynamic Address Groups), Cisco ASA REST, and Fortinet FortiOS — all three integrated.

📋

Policy Management

Define mutation schedules, EWMA thresholds, and active profiles per estate from a single API. Assign policies across hundreds of nodes with one call.

🔍

Cryptographic Audit Chain

Every mutation event from every node aggregated into a tamper-evident PostgreSQL audit chain. Paginated API for compliance review, forensics, and regulatory reporting.

📊

Compliance Reports

Four report types — Summary, EWMA Anomaly History, Attack & Defence Log, Audit Extract — generated in the background and downloaded as CSV or JSON.

Probe & Discover

Enter a CIDR range and click TCP Probe — every live host appears, classified by port signature, with a suggested mutation profile. SSH Scan for Linux estates. Scan All Sources for LDAP/Azure AD/Cloud.

🔱

KaliCore System Tray

The KaliCore Mandala icon sits in the system notification area (Windows + Linux). One click opens the dashboard. Live health polling. Installed automatically by the MSI or DEB.

🔐

mTLS Production Transport

The ACSE CA issues a unique X.509 client certificate to every registered agent. Mutual TLS verifies both sides at the TLS handshake layer. Required by government security evaluations and banking sector pilots.

🔑

HSM Adapter — PKCS#11

All HSM-resident key operations via the PKCS#11 standard. Dynamic library loading — no compile-time vendor dependency. Compatible with Thales Luna, SafeNet, Entrust nCipher, Utimaco, and SoftHSM2.

🧙

First-Run Setup Wizard

On first boot with no database configured, the Control Plane launches a browser-based wizard on port 9000. Three screens: PostgreSQL connection → admin account creation → API key reveal. Zero manual configuration required.

📄

Licensing Enforcement

SHA3-signed license tokens enforce estate limits per tier — trial (3 estates), professional (configurable), enterprise (unlimited). HTTP 402 on limit breach.

🔄

Auto-Update

Version manifest hosted on Cloudflare CDN. On startup: applies staged .next binary and re-execs. Background check every 24 hours. SHA3-256 hash verification before staging. ACSE_AUTO_UPDATE=true to enable.

🤖

Client Endpoint Agent

The acse-agent binary runs on every protected node. First boot: self-registers with the CP, writes api_key + estate_id to .env. PME engine runs in a dedicated thread. Push loop sends live state to CP every 30 seconds.

🏢

Multi-Tenant + Row Level Security

Every estate, user, API key, policy, SIEM sink, and firewall device belongs to an organisation. Two isolation layers: application-level org_id filtering + PostgreSQL Row Level Security on every table.

🧠

AI/ML Hybrid — Foundation-A

Every mutation cycle feeds a 16-dimensional feature vector into a local anomaly classifier — Normal, Suspicious, or Critical. Stub classifier ships in the default binary. Custom trained ONNX model slots in via ACSE_ML_MODEL_PATH without recompiling. Air-gap safe, no cloud API calls.

● LIVE — v0.4.0 Available Now
  • ✅ PostgreSQL persistence
  • ✅ TEE-attested auth & RBAC
  • ✅ Estate management REST API
  • ✅ SIEM dispatch (Splunk / QRadar / Syslog)
  • ✅ Palo Alto · Cisco ASA · Fortinet adapters
  • ✅ Live estate dashboard
  • ✅ Kali Invariant global monitor
  • ✅ Windows MSI (Endpoint Agent + System Tray) + Linux DEB (full platform including Control Plane)
  • ✅ Auto-Discovery engine — 22 source types
  • ✅ Agent zero-config self-registration
  • ✅ HCI & Storage fabric connectors
  • ✅ Compliance Reports — 4 types, CSV/JSON
  • ✅ Probe & Discover — TCP Probe · SSH Scan · Scan All
  • ✅ KaliCore Mandala system tray (Windows + Linux)
  • ✅ mTLS production transport — CA + agent certificates
  • ✅ HSM Adapter — PKCS#11 (SoftHSM2 · Thales Luna · Entrust nCipher)
  • ✅ First-run browser setup wizard
  • ✅ Licensing enforcement — trial · professional · enterprise tiers
  • ✅ Auto-update — manifest-driven, SHA3-verified, atomic re-exec
  • ✅ Client endpoint agent (acse-agent) — self-registers, runs PME, pushes live state
  • ✅ Multi-tenant + Row-Level Security
  • ✅ macOS support — acse-agent + acse-tray on macos-latest (Control Plane is Linux-only by design — see note below)
  • ✅ AI/ML Hybrid — Foundation-A local ONNX inference, air-gap safe
○ ROADMAP — v2 Coming Next
  • ○ ONNX model training pipeline — real anomaly data from estate telemetry
  • ○ Reporting module v2 + dashboards
  • ○ HA Control Plane (PostgreSQL streaming replication)
  • ○ macOS system tray (KaliCore Mandala on macOS)
  • ○ ASRK-ODS — second system (defence organisations)
🔒

SECURITY NOTE — Control Plane is Linux-only by design

This is a deliberate architectural decision, taken out of security requirements. The Control Plane is the only ACSE-PME component that faces the outside world: it terminates public HTTP endpoints, brokers SSO/SAML/OIDC identity federation, and performs PKI/CA private-key operations. Concentrating this attack surface on a single, well-understood, deeply auditable platform — rather than distributing it across three separate OS-specific build and dependency chains — is a deliberate security-first choice, not a platform limitation.

The Endpoint Agent and System Tray, which run on protected infrastructure rather than facing the public internet, remain fully cross-platform: Linux, Windows, and macOS.

SAML/OIDC federation capability is unaffected — the IdP may run on any operating system; only the Control Plane's SSO endpoint, which IdPs talk to over standard network protocols, is Linux-hosted.

Auto-Discovery — Zero Manual Inventory

Before you can protect a node, you need to know it exists. The ACSE Control Plane discovers every server, VM, HCI node, and storage controller in your estate automatically — across 22 source types — then suggests the right mutation profile for each one.

🔍
Configure Source
LDAP · SSH · Cloud · HCI · Storage · CSV
📋
Catalog Populated
Auto-classified · Profile suggested
Admin Approves
Click Protect — estate + api_key created
🤖
Agent Deploys
Key installed · Kali Invariant active
🔱
Protected
Mutation active · Surface non-existent
Identity & Directory
Active Directory · LDAP
Azure AD / Entra ID
Active Scan (No Agent)
SSH Linux Discovery
TCP Port Probe
Cloud
AWS EC2 · Azure VMs
GCP Compute Engine
HCI Management Planes
Nutanix Prism · Cisco UCS
VMware vCenter · Azure Stack HCI
Storage Fabric
Pure Storage · NetApp ONTAP
Dell PowerStore · Brocade FC
Cisco MDS · Ceph
Network & Import
Palo Alto Panorama
Fortinet FortiManager · SNMP
CSV · Agent Self-Register

Zero-Config Agent Deployment

Set ACSE_REGISTRATION_TOKEN on the Control Plane and on each agent node. On first boot, the agent calls POST /v1/discovery/self-register, receives its api_key, and starts pushing immediately — no admin catalog step required. Ideal for Ansible/SCCM rollouts and cloud auto-scaling groups.

The Opportunity

Not a feature. Not a product. Infrastructure.

$350B
Global cybersecurity market
100%
Built on static surface assumption
ACSE
Changes the assumption, not the mitigation
1
Patent Published · IN202641070690
"If I have a firewall, locked-down ports, and a hardened server — what is the use of TLS?"
When HTTPS was introduced, that question was asked. The answer was simple.
TLS

Hardening protects the network. TLS protects the data independently of the network. Your firewall, your locked ports, your patched OS — TLS adds a layer that operates regardless of all of them.

ACSE

ACSE protects the surface identity independently of everything else. Your firewall, your patched OS, your Zero Trust policy — ACSE adds a layer that operates regardless of all of them.

In concrete terms — three scenarios every security team will recognise:

1
The OS has an unpatched CVE

The surfaces the attacker needs to exploit are rotating every few microseconds. The fingerprint they mapped to reach the vulnerability is stale before they can act on it.

2
A credential was phished

The session token that credential produces expires at the next mutation cycle. The attacker cannot replay it. The stolen credential is correct — but the surface it opens no longer exists.

3
A firewall rule was misconfigured

The endpoint fingerprint the attacker mapped through that open rule is stale. The path they found leads nowhere — not because the firewall was fixed, but because the destination no longer looks the same.

The point is the same as it was with TLS:

TLS is not a replacement for your firewall. ACSE is not a replacement for your EDR, your SIEM, or your Zero Trust architecture. It is an additional layer that operates independently of all of them — and makes all of them more effective, because the surfaces they protect are no longer static.

Built On

Technology Foundation

Every component of ACSE — engine, server, agent, tray, dashboard — is built on proven technology with no framework bloat and no AI-generated code. 36,424 lines of hand-written Rust. 1,045 tests. Zero warnings.

100% of the implementation — engine, server, agent, and tray
36,424 lines  ·  105 files  ·  1,045 tests  ·  0 failures  ·  0 warnings  ·  16 database migrations  ·  Operator Console: 2,852 lines, 11 complete views  ·  Memory-safe, zero garbage collection, sub-microsecond mutation cycles
GitHub →
Async Runtime & Web
Tokio — async runtime
Axum — REST API web framework
Tower HTTP — middleware (CORS, tracing)
Note: Axum (Tokio project), not Actix Web — ACSE uses Axum
Database
PostgreSQL v14+ — estates, audit chain, reports
SQLx — async DB driver, SQLX_OFFLINE compatible
SQL migrations — idempotent, embedded in binary
Cryptography & Verification
SHA3-256 — audit chain integrity
HMAC-SHA3 — frame & message authentication
rcgen + rustls — mTLS · X.509 CA · agent cert signing
cryptoki (PKCS#11) — HSM dynamic loading
ProVerif — formal verification, Dolev-Yao model
TEE adapters — SGX · Nitro · SEV-SNP · ARM CCA
Frontend & Dashboard
HTML5 · CSS3 · Vanilla JS — zero framework dependency
Serde / serde_json — JSON serialization
csv crate — compliance report generation
System Integration & Protocols
ASMP/1.0 — custom session protocol, formally verified
CEF — SIEM event format (Splunk / QRadar / Syslog)
tray-icon — system tray (Win32 · GTK3 · macOS)
axum-server + RustTLS — HTTPS / mTLS server
SHA3-keyed license tokens — trial · professional · enterprise
Packaging & Distribution
WiX Toolset — Windows MSI installer
DEB packaging — Linux installer (Ubuntu · Debian · Kali)
GitHub Actions — CI/CD · Linux DEB · Windows MSI · Release
Development Environment
Kali Linux — primary development OS
VS Code — IDE with rust-analyzer
GitHub Projects — project tracking & sprint management
tokei — code line counting & analysis
Infrastructure & Hosting
AWS EC2 — live deployment · ACSE Public Challenge instance
Cloudflare Pages — website hosting (acse-pme.in)
Cloudflare Web Analytics — privacy-first traffic analytics
GitHub — version control (private repository)
Quality Assurance & Security Testing
cargo clippy — lint-level code quality enforcement
cargo audit — continuous dependency CVE scanning
cargo-tarpaulin + cargo-llvm-cov — test coverage measurement
cargo-fuzz (libFuzzer) — coverage-guided fuzzing of the ASMP wire protocol against malformed/adversarial network input
cargo-bolero — structured property-based testing of the PME mutation engine's state machine invariants
Miri — MIR-level interpreter for undefined behavior and memory-safety verification (zero unsafe blocks, zero defects found across 843 interpreted tests)
dhat — heap allocation profiling for memory-growth analysis
Combined with 1,045 automated tests and multiple independent AI-assisted architecture and security audits, this pipeline represents a defense-in-depth approach to code quality suitable for defence-sector and critical-infrastructure deployment.
What Was Not Used
No AI code generation  ·  No cloud build services  ·  No frontend framework (React/Vue/Angular)  ·  No managed database  ·  No third-party authentication  ·  No infrastructure-as-code  ·  No external security scanning tools
Every line written by a single inventor.
Coming Soon

The ACSE Public Challenge

A live ACSE endpoint — deployed on AWS, open to the world. No registration. No rules to fill out. Just a running instance of the Kali Invariant, and a question the mathematics already answers.

What It Is

A fully operational ACSE instance running on AWS — the same engine, the same Kali Invariant, the same 10–143 microsecond mutation cycles that power the production platform. Open to any security researcher, red team, or penetration tester in the world.

The Question

Can you exploit a service whose cryptographic surface identity changes faster than you can act on what you observed? The Kali Invariant says no. The mathematics say no. The Public Challenge will say no in real time.

Ready to evaluate?

For pilot deployments, investment discussions, or to review the full technical evidence base — reach out directly.