Infrastructure for the post-static-surface world
Every industry that relies on digital infrastructure — defence, finance, cloud, critical infrastructure — is built on a flawed assumption: that surfaces stay static long enough to protect. ACSE eliminates that assumption. One platform. Six domains. A trillion-dollar opportunity.
The threat landscape has fundamentally shifted
Static surfaces have always been a liability. What changed is the speed, scale, and automation of the attacks exploiting them — and the regulatory cost of getting it wrong. The timing for ACSE has never been more critical.
AI-Assisted Attackers
WormGPT, FraudGPT, and AutoGPT-based attack frameworks cut reconnaissance from days to minutes. AI now maps surfaces, correlates fingerprints, and drafts exploit chains faster than any human analyst can respond. ACSE's answer: the surface expires before any AI model can act on what it observed.
Automated Continuous Scanning
Shodan and Censys re-index the entire internet every few hours. Every static API endpoint, every service fingerprint, every TLS certificate is catalogued before you've noticed the scan. ACSE: what they index is cryptographically stale by the time they serve the result.
Identity is the Primary Attack Vector
IBM X-Force 2024: credential-based attacks rose 71% year-over-year. Valid accounts were used in 30% of all incidents. The root cause isn't weak passwords — it's that stolen credentials remain valid after theft. ACSE closes this at the root: credentials expire at mutation cycle boundaries.
Cloud Sprawl Explodes the Attack Surface
The average enterprise now uses over 1,000 cloud services. Each service is an API. Each API is an endpoint. Each endpoint is a static fingerprint accumulating in attacker databases. ACSE: every API surface rotates on every access event — the sprawl stops being a liability.
Dwell Time Remains Catastrophic
Mandiant M-Trends 2024: median attacker dwell time is 10 days. Change Healthcare: 9 days and $2.457B in damage. SolarWinds: 14 months. These attacks don't succeed instantly — they succeed because surfaces stay static long enough to stage. ACSE's staging window is measured in microseconds.
Regulatory Liability is Now Personal
SEC cybersecurity disclosure rules (December 2023) require material incident disclosure within 4 business days. EU NIS2 Directive (2024) imposes personal liability on board directors. India DPDP Act (2023) and CERT-In mandatory reporting. The cost of a static surface failure is now measured in fines, criminal liability, and stock price.
An attacker can't exploit a surface they mapped yesterday
if that surface no longer exists today.
Six domains. One platform. Trillion-dollar opportunity.
ACSE is infrastructure — like TLS, it sits beneath everything else and makes everything else more effective. Every industry built on digital surfaces is a potential deployment. These six represent the highest-value, highest-urgency applications of the first generation.
National Defence & Intelligence
Command, control, intelligence, and surveillance surfaces are the most targeted in the world. Nation-state adversaries with unlimited time and resources rely on long-duration reconnaissance — the exact capability ACSE eliminates. A surface that expires in 10 microseconds cannot be mapped in 14 months.
Critical Infrastructure
16 CISA-designated sectors — power grids, water systems, hospitals, transportation networks — run on legacy OT/IT systems with static surfaces. Colonial Pipeline was stopped by one leaked VPN password. Change Healthcare cost $2.457B. New mandatory resilience requirements are incoming globally.
Financial Systems & Payments
SWIFT, central banks, payment processors, and trading platforms handle $120T+ in annual global flows. SquidShield delivers 100% fingerprint uniqueness at 76.1k transactions per second with full PCI-DSS audit trail. Credential replay and session hijacking are structurally impossible — not just mitigated.
Cloud Platforms & SaaS
AWS, Azure, and GCP integration at the platform layer means one deployment protects every tenant workload. ACSE becomes a cloud-native security primitive — deployed once by the hyperscaler, enforced everywhere. The distribution model: one hyperscaler partnership scales to billions of endpoints with zero additional sales.
Data Centres & COLO
Equinix, Digital Realty, and hyperscale operators host the internet's infrastructure. ElectricEelGrid is the only available solution defending the power side-channel in COLO environments — where physical co-location allows observable electromagnetic and thermal side channels that no other product addresses. Red team correlation: 0.03%.
National Cyber Defence
Government CERTs, national SOCs, election infrastructure, and classified national systems face nation-state adversaries with unlimited resources. LeviathanGrid provides 16-node simultaneous rotation for nation-scale topology — the capability that would have stopped SolarWinds at all 18,000+ victim organisations simultaneously.
Infrastructure, not a point product
ACSE doesn't replace your SIEM, your EDR, or your Zero Trust architecture. It changes the surface all of those tools protect. Like TLS — it's not a product you evaluate against alternatives; it's infrastructure that makes your entire stack more effective.
Zero Rip-and-Replace
Three lines of code. ACSE deploys alongside your existing stack — firewalls, SIEM, EDR, Zero Trust all remain in place and become more effective because they now protect surfaces that change rather than surfaces that don't.
Signature-Free Zero-Day Defence
ACSE doesn't need to know about a vulnerability to defend against it. The Kali Invariant holds against zero-day exploits, supply-chain implants, and credential theft equally — because the protection is at the surface identity layer, not the exploit signature layer.
Formally Verified Security Properties
Three ProVerif models. ZK authentication: TRUE. Cascade authentication: TRUE. TEE-bound management: CORRECT across all queries. These are mathematical proofs, not performance claims. No other defensive architecture in production has this level of formal rigour.
Domain-Adaptive — 11 Profiles
Finance, healthcare, defence, cloud, COLO, and nation-scale — each domain has a tuned mutation profile with specific latency, compliance, and threat-model alignment. Swap profiles with one configuration line. No architectural changes required.
Hyperscale-Ready
Sub-millisecond mutation cycles. 956 tests with zero failures. All cycles complete in 10–144 microseconds depending on profile. Estate-wide rotation in under 200 microseconds via KaliCoreTarget. Performance characteristics that survive cloud-scale deployment without degradation.
IP-Protected & Patent Published
Indian Patent Application IN202641070690 — Published 19/06/2026, Journal No. 25/2026 (Indian Patent Office). Expedited examination in progress. The Kali Invariant, the PME architecture, ASMP/1.0, and all 11 profiles are covered. First-mover advantage backed by intellectual property protection.
ACSE Control Plane
One dashboard. Every estate. Real-time Kali Invariant status across every protected node — with SIEM dispatch, firewall orchestration, and TEE-attested policy management built in from day one.
TEE-Attested Authentication
Every API call is validated inside a Trusted Execution Environment — SGX, Nitro, SEV-SNP, or ARM CCA. Admin / Operator / ReadOnly RBAC enforced per endpoint.
Estate-Wide Dashboard
Live organ-state view across every registered estate. EWMA anomaly score, torpedo count, channel fingerprint, JA3 hash, p0f signature — all updating every 5 seconds.
SIEM Integration
Every mutation event and Torpedo firing dispatches to your SIEM automatically. Splunk HEC, IBM QRadar, RFC 5424 Syslog, and stdout all supported out of the box.
Firewall Orchestration
When a surface mutates, the connected firewall updates automatically. Palo Alto Networks XML API (Dynamic Address Groups), Cisco ASA REST, and Fortinet FortiOS — all three integrated.
Policy Management
Define mutation schedules, EWMA thresholds, and active profiles per estate from a single API. Assign policies across hundreds of nodes with one call.
Cryptographic Audit Chain
Every mutation event from every node is aggregated into a tamper-evident PostgreSQL audit chain. Paginated API for compliance review, forensics, and regulatory reporting.
Compliance Reports
Four report types — Summary, EWMA Anomaly History, Attack & Defence Log, Audit Extract — generated in the background and downloaded as CSV or JSON. One-click from the dashboard.
Probe & Discover
From the dashboard: enter a CIDR range and click TCP Probe — every live host appears, classified by port signature, with a suggested mutation profile. SSH Scan for Linux estates. Scan All Sources for LDAP/Azure AD/Cloud.
KaliCore System Tray
The KaliCore Mandala icon sits in the system notification area (Windows + Linux). One click opens the dashboard. Live health polling shows Connected / Not Connected. Installed automatically by the MSI or DEB.
mTLS Production Transport
The ACSE CA issues a unique X.509 client certificate to every registered agent. Mutual TLS verifies both sides of the agent-to-Control-Plane channel at the TLS handshake layer. Government evaluation gate — required by DRDO, CERT-In, and banking sector pilots.
HSM Adapter — PKCS#11
All HSM-resident key operations via the PKCS#11 standard. Dynamic library loading — no compile-time vendor dependency. Compatible with Thales Luna, SafeNet, Entrust nCipher, Utimaco, and SoftHSM2 for development. Government key management requirement met without source code changes per HSM vendor.
First-Run Setup Wizard
On first boot with no database configured, the Control Plane launches a browser-based wizard on port 9000. Three screens: PostgreSQL connection (live test) → admin account creation → API key reveal. Writes .env, runs all migrations, creates admin user. Zero manual configuration required.
Licensing Enforcement
SHA3-signed license tokens enforce estate limits per tier — trial (3 estates), professional (configurable), enterprise (unlimited). HTTP 402 on limit breach. License infrastructure is JSON-forward-compatible: new fields (per-node, per-feature, site-lock) can be added without invalidating existing keys.
Auto-Update
Version manifest hosted at arulraj.live/releases/manifest.json (Cloudflare CDN — live now). On startup: applies staged .next binary and re-execs. Background check every 24 hours. SHA3-256 hash verification before staging. Operator controls restart timing — no surprise downtime. ACSE_AUTO_UPDATE=true to enable.
Client Endpoint Agent
The acse-agent binary runs on every protected node. First boot: self-registers with the CP via token, writes api_key + estate_id to .env. Subsequent boots skip registration. PME engine runs in a dedicated thread (EWMA scoring, torpedo count). Push loop sends live state to CP every 30 seconds with automatic exponential back-off.
Multi-Tenant + Row Level Security
The Control Plane is a full multi-tenant system. Every estate, user, API key, policy, SIEM sink, and firewall device belongs to an organisation. Existing single-tenant deployments migrate to the default org automatically. Two isolation layers: application-level org_id filtering on every query + PostgreSQL Row Level Security policies on every table. REST API: GET/POST/PATCH/DELETE /v1/orgs.
macOS Support
The Rust codebase is fully cross-platform. CI now builds acse-cp and acse-agent on macos-latest, packages as .tar.gz, and publishes SHA3-256 hash verification alongside every GitHub release. Zero Rust code changes required — the platform compiles natively on Apple Silicon and Intel.
AI/ML Hybrid — Foundation-A
Every mutation cycle feeds a 16-dimensional feature vector (fingerprint entropy, Hamming distance, EWMA, torpedo delta, organ state, consecutive failures) into a local anomaly classifier — Normal, Suspicious, or Critical. Stub classifier ships in the default binary (zero deps). A custom trained ONNX model slots in via ACSE_ML_MODEL_PATH without recompiling. Pure Rust via tract-onnx — air-gap safe, DRDO-compatible.
- ✅ PostgreSQL persistence
- ✅ TEE-attested auth & RBAC
- ✅ Estate management REST API
- ✅ SIEM dispatch (Splunk / QRadar / Syslog)
- ✅ Palo Alto · Cisco ASA · Fortinet adapters
- ✅ Live estate dashboard
- ✅ Kali Invariant global monitor
- ✅ Windows MSI + Linux DEB packaging
- ✅ Auto-Discovery engine — 22 source types
- ✅ Agent zero-config self-registration
- ✅ HCI & Storage fabric connectors
- ✅ Compliance Reports — 4 types, CSV/JSON
- ✅ Probe & Discover — TCP Probe · SSH Scan · Scan All
- ✅ KaliCore Mandala system tray (Windows + Linux)
- ✅ mTLS production transport — CA + agent certificates + ACSE_MTLS_REQUIRED gate
- ✅ HSM Adapter — PKCS#11 dynamic loading (SoftHSM2 · Thales Luna · Entrust nCipher)
- ✅ First-run browser setup wizard — zero .env editing required
- ✅ Licensing enforcement — trial · professional · enterprise tiers (HTTP 402)
- ✅ Auto-update — manifest-driven, SHA3-verified, atomic binary staging + re-exec
- ✅ Client endpoint agent (acse-agent) — self-registers, runs PME, pushes live state
- ✅ Multi-tenant + Row-Level Security — organisations table, org_id on all estate tables, PostgreSQL RLS
- ✅ macOS support — acse-cp + acse-agent build on macos-latest, SHA3-verified release archives
- ✅ AI/ML Hybrid — Foundation-A local ONNX inference, 16-feature anomaly classifier, air-gap safe
- ○ ONNX model training pipeline — real anomaly data from estate telemetry
- ○ SIEM connector depth + Ansible role
- ○ Reporting module v2 + dashboards
- ○ HA Control Plane (PostgreSQL streaming replication)
- ○ macOS system tray (KaliCore Mandala on macOS)
- ○ ASRK-ODS — second system (Indian defence organisations)
Auto-Discovery — Zero Manual Inventory
Before you can protect a node, you need to know it exists. The ACSE Control Plane discovers every server, VM, HCI node, and storage controller in your estate automatically — across 22 source types — then suggests the right mutation profile for each one. The admin reviews the catalog, clicks Protect, and the agent key is ready.
Azure AD / Entra ID
TCP Port Probe
GCP Compute Engine
VMware vCenter · Azure Stack HCI
Dell PowerStore · Brocade FC
Cisco MDS · Ceph
Fortinet FortiManager · SNMP
CSV · Agent Self-Register
Set ACSE_REGISTRATION_TOKEN on the Control Plane and on each agent node.
On first boot, the agent calls POST /v1/discovery/self-register,
receives its api_key, and starts pushing immediately — no admin catalog step required.
Ideal for Ansible/SCCM rollouts and cloud auto-scaling groups.
Not a feature. Not a product. Infrastructure.
"If I have a firewall, locked-down ports, and a hardened server — what is the use of TLS?"
When HTTPS was introduced, that question was asked. The answer was simple:
TLS protects data in transit regardless of what the network looks like. Even if an attacker gets onto the network, even if they're on the same WiFi, even if a router is compromised — they cannot read the data. Because TLS encrypts it at the transport layer, independently of everything else.
Hardening protects the network. TLS protects the data independently of the network. Your firewall, your locked ports, your patched OS — TLS adds a layer that operates regardless of all of them.
ACSE protects the surface identity independently of everything else. Your firewall, your patched OS, your Zero Trust policy — ACSE adds a layer that operates regardless of all of them.
In concrete terms — three scenarios every security team will recognise:
The point is the same as it was with TLS:
TLS is not a replacement for your firewall. ACSE is not a replacement for your EDR, your SIEM, or your Zero Trust architecture. It is an additional layer that operates independently of all of them — and makes all of them more effective, because the surfaces they protect are no longer static.
TLS IS NOT A PRODUCT — IT IS INFRASTRUCTURE · ACSE IS THE SAME KIND OF THING · PATENT IN202641070690
Technology Foundation
Every component of ACSE — engine, server, agent, tray, dashboard — is built on proven technology with no framework bloat and no AI-generated code. 36,358 lines of hand-written Rust. 956 tests. Zero warnings.
The ACSE Public Challenge
A live ACSE endpoint — deployed on AWS, open to the world. No registration. No rules to fill out. Just a running instance of the Kali Invariant, and a question the mathematics already answers.
A fully operational ACSE instance running on AWS — the same engine, the same Kali Invariant, the same 10–143 microsecond mutation cycles that power the production platform. Open to any security researcher, red team, or penetration tester in the world.
The Kali Invariant states: every observed surface is destroyed and re-created before the next observation completes. The challenge is simple in principle — act on what you observed. The rules and specific objectives will be published with the formal announcement.
Benchmarks are evidence. A live endpoint under real-world adversarial conditions is proof. The ACSE Public Challenge is not a marketing exercise — it is the definitive test of whether cryptographic surface mutation does what the patent claims. Either it holds or it doesn't.
No material prize. Something more valuable — formal recognition in a published write-up, your name on record as the researcher who found a weakness in a formally verified, patent-published cryptographic system. And a direct conversation about joining the team as a penetration tester.
The ACSE Public Challenge will be announced formally under a registered organisation — company registration is currently in progress. The date, full rules, and challenge objectives will be published on LinkedIn and at arulraj.live when ready.
Enterprise Platform Roadmap
ACSE-PME is production-ready today. What comes next is the full enterprise control plane — 30 capabilities sourced from 12 years of service delivery experience across 100+ enterprise deployments, organised into four priority tiers.
Background Job Engine • Fleet Management • Agent Lifecycle • Operational Health Monitoring • Maintenance Windows • Config Change History + Approval Workflows • Backup / Restore
Bulk Operations • Asset Tagging & Dynamic Groups • Alert Centre • Notification Integrations (Teams, Slack, PagerDuty, ServiceNow) • Scheduled Reports • API Key Lifecycle Management
IAM & SSO (SAML 2.0 / OIDC / SCIM) • OpenAPI / Swagger at /api/docs •
Policy Templates (PCI, HIPAA, NIST, Defence) • Global Search •
Version Management with Canary Rollout • HA Control Plane
Compliance Centre (PCI, ISO 27001, SOC 2, DPDP) • Multi-region / Multi-site • Infrastructure Intelligence — live topology & dependency graph • Role Dashboards (SOC / CISO / Executive) • Automation Playbooks
Ready to explore this further?
For investment discussions, partnership enquiries, pilot deployments, or to review the full technical evidence base — reach out directly.