Platform Vision

Infrastructure for the post-static-surface world

Every industry that relies on digital infrastructure — defence, finance, cloud, critical infrastructure — is built on a flawed assumption: that surfaces stay static long enough to protect. ACSE eliminates that assumption. One platform. Six domains. A trillion-dollar opportunity.

$10.5T
Annual cybercrime cost by 2025
$350B
Global cybersecurity spend
71%
YoY rise in credential attacks
1
Patent Published · IN202641070690
Why Now

The threat landscape has fundamentally shifted

Static surfaces have always been a liability. What changed is the speed, scale, and automation of the attacks exploiting them — and the regulatory cost of getting it wrong. The timing for ACSE has never been more critical.

Minutes
AI Reconnaissance Time

AI-Assisted Attackers

WormGPT, FraudGPT, and AutoGPT-based attack frameworks cut reconnaissance from days to minutes. AI now maps surfaces, correlates fingerprints, and drafts exploit chains faster than any human analyst can respond. ACSE's answer: the surface expires before any AI model can act on what it observed.

6 hrs
Internet Rescan Frequency

Automated Continuous Scanning

Shodan and Censys re-index the entire internet every few hours. Every static API endpoint, every service fingerprint, every TLS certificate is catalogued before you've noticed the scan. ACSE: what they index is cryptographically stale by the time they serve the result.

71%
YoY Increase in Credential Attacks

Identity is the Primary Attack Vector

IBM X-Force 2024: credential-based attacks rose 71% year-over-year. Valid accounts were used in 30% of all incidents. The root cause isn't weak passwords — it's that stolen credentials remain valid after theft. ACSE closes this at the root: credentials expire at mutation cycle boundaries.

1,000+
Cloud Services Per Enterprise (Gartner 2024)

Cloud Sprawl Explodes the Attack Surface

The average enterprise now uses over 1,000 cloud services. Each service is an API. Each API is an endpoint. Each endpoint is a static fingerprint accumulating in attacker databases. ACSE: every API surface rotates on every access event — the sprawl stops being a liability.

10 days
Median Attacker Dwell Time (Mandiant 2024)

Dwell Time Remains Catastrophic

Mandiant M-Trends 2024: median attacker dwell time is 10 days. Change Healthcare: 9 days and $2.457B in damage. SolarWinds: 14 months. These attacks don't succeed instantly — they succeed because surfaces stay static long enough to stage. ACSE's staging window is measured in microseconds.

4 days
SEC Breach Disclosure Deadline

Regulatory Liability is Now Personal

SEC cybersecurity disclosure rules (December 2023) require material incident disclosure within 4 business days. EU NIS2 Directive (2024) imposes personal liability on board directors. India DPDP Act (2023) and CERT-In mandatory reporting. The cost of a static surface failure is now measured in fines, criminal liability, and stock price.

"

An attacker can't exploit a surface they mapped yesterday
if that surface no longer exists today.

The Kali Invariant  ·  ACSE Core Principle  ·  Published Patent IN202641070690
Applications

Six domains. One platform. Trillion-dollar opportunity.

ACSE is infrastructure — like TLS, it sits beneath everything else and makes everything else more effective. Every industry built on digital surfaces is a potential deployment. These six represent the highest-value, highest-urgency applications of the first generation.

Sector 01 · Priority

National Defence & Intelligence

Command, control, intelligence, and surveillance surfaces are the most targeted in the world. Nation-state adversaries with unlimited time and resources rely on long-duration reconnaissance — the exact capability ACSE eliminates. A surface that expires in 10 microseconds cannot be mapped in 14 months.

ScaleDRDO (India) · DoD (USA) · NATO · Five Eyes alliance · national military networks
ProfilesKrakenNet (AD/credential), LeviathanGrid (network topology), KaliCoreTarget (estate-wide)
Sector 02

Critical Infrastructure

16 CISA-designated sectors — power grids, water systems, hospitals, transportation networks — run on legacy OT/IT systems with static surfaces. Colonial Pipeline was stopped by one leaked VPN password. Change Healthcare cost $2.457B. New mandatory resilience requirements are incoming globally.

Scale$27.5T GDP dependent on protected infrastructure across 195 countries
ProfilesJellyNet (elastic), MantisNet (intrusion response), AnglerShield (API surface)
Sector 03

Financial Systems & Payments

SWIFT, central banks, payment processors, and trading platforms handle $120T+ in annual global flows. SquidShield delivers 100% fingerprint uniqueness at 76.1k transactions per second with full PCI-DSS audit trail. Credential replay and session hijacking are structurally impossible — not just mitigated.

Scale$120T+ annual global payment flows · 2B+ card holders · 10,000+ financial institutions
ProfilesSquidShield (payments), NautilusVault (data vault), GlassFrog (compliance/audit)
Sector 04

Cloud Platforms & SaaS

AWS, Azure, and GCP integration at the platform layer means one deployment protects every tenant workload. ACSE becomes a cloud-native security primitive — deployed once by the hyperscaler, enforced everywhere. The distribution model: one hyperscaler partnership scales to billions of endpoints with zero additional sales.

Scale$650B+ global cloud services market · 1,000+ cloud services per enterprise
ProfilesChameleonNet (cooperative enclaves), JellyNet (elastic), KaliCoreTarget
Sector 05

Data Centres & COLO

Equinix, Digital Realty, and hyperscale operators host the internet's infrastructure. ElectricEelGrid is the only available solution defending the power side-channel in COLO environments — where physical co-location allows observable electromagnetic and thermal side channels that no other product addresses. Red team correlation: 0.03%.

Scale10,000+ commercial data centres globally · $200B+ data centre market
ProfilesElectricEelGrid (COLO/side-channel), MantisNet (intrusion response)
Sector 06

National Cyber Defence

Government CERTs, national SOCs, election infrastructure, and classified national systems face nation-state adversaries with unlimited resources. LeviathanGrid provides 16-node simultaneous rotation for nation-scale topology — the capability that would have stopped SolarWinds at all 18,000+ victim organisations simultaneously.

Scale195 countries × national cyber defence budgets · government frameworks
ProfilesLeviathanGrid (nation-scale), KrakenNet (AD), KaliCoreTarget (estate-wide)
The ACSE Advantage

Infrastructure, not a point product

ACSE doesn't replace your SIEM, your EDR, or your Zero Trust architecture. It changes the surface all of those tools protect. Like TLS — it's not a product you evaluate against alternatives; it's infrastructure that makes your entire stack more effective.

Zero Rip-and-Replace

Three lines of code. ACSE deploys alongside your existing stack — firewalls, SIEM, EDR, Zero Trust all remain in place and become more effective because they now protect surfaces that change rather than surfaces that don't.

Signature-Free Zero-Day Defence

ACSE doesn't need to know about a vulnerability to defend against it. The Kali Invariant holds against zero-day exploits, supply-chain implants, and credential theft equally — because the protection is at the surface identity layer, not the exploit signature layer.

Formally Verified Security Properties

Three ProVerif models. ZK authentication: TRUE. Cascade authentication: TRUE. TEE-bound management: CORRECT across all queries. These are mathematical proofs, not performance claims. No other defensive architecture in production has this level of formal rigour.

Domain-Adaptive — 11 Profiles

Finance, healthcare, defence, cloud, COLO, and nation-scale — each domain has a tuned mutation profile with specific latency, compliance, and threat-model alignment. Swap profiles with one configuration line. No architectural changes required.

Hyperscale-Ready

Sub-millisecond mutation cycles. 956 tests with zero failures. All cycles complete in 10–144 microseconds depending on profile. Estate-wide rotation in under 200 microseconds via KaliCoreTarget. Performance characteristics that survive cloud-scale deployment without degradation.

IP-Protected & Patent Published

Indian Patent Application IN202641070690 — Published 19/06/2026, Journal No. 25/2026 (Indian Patent Office). Expedited examination in progress. The Kali Invariant, the PME architecture, ASMP/1.0, and all 11 profiles are covered. First-mover advantage backed by intellectual property protection.

Management Layer

ACSE Control Plane

● v0.3.0 RELEASED

One dashboard. Every estate. Real-time Kali Invariant status across every protected node — with SIEM dispatch, firewall orchestration, and TEE-attested policy management built in from day one.

🛡

TEE-Attested Authentication

Every API call is validated inside a Trusted Execution Environment — SGX, Nitro, SEV-SNP, or ARM CCA. Admin / Operator / ReadOnly RBAC enforced per endpoint.

📊

Estate-Wide Dashboard

Live organ-state view across every registered estate. EWMA anomaly score, torpedo count, channel fingerprint, JA3 hash, p0f signature — all updating every 5 seconds.

🔗

SIEM Integration

Every mutation event and Torpedo firing dispatches to your SIEM automatically. Splunk HEC, IBM QRadar, RFC 5424 Syslog, and stdout all supported out of the box.

🔥

Firewall Orchestration

When a surface mutates, the connected firewall updates automatically. Palo Alto Networks XML API (Dynamic Address Groups), Cisco ASA REST, and Fortinet FortiOS — all three integrated.

📋

Policy Management

Define mutation schedules, EWMA thresholds, and active profiles per estate from a single API. Assign policies across hundreds of nodes with one call.

🔍

Cryptographic Audit Chain

Every mutation event from every node is aggregated into a tamper-evident PostgreSQL audit chain. Paginated API for compliance review, forensics, and regulatory reporting.

📊

Compliance Reports

Four report types — Summary, EWMA Anomaly History, Attack & Defence Log, Audit Extract — generated in the background and downloaded as CSV or JSON. One-click from the dashboard.

Probe & Discover

From the dashboard: enter a CIDR range and click TCP Probe — every live host appears, classified by port signature, with a suggested mutation profile. SSH Scan for Linux estates. Scan All Sources for LDAP/Azure AD/Cloud.

🔱

KaliCore System Tray

The KaliCore Mandala icon sits in the system notification area (Windows + Linux). One click opens the dashboard. Live health polling shows Connected / Not Connected. Installed automatically by the MSI or DEB.

🔐

mTLS Production Transport

The ACSE CA issues a unique X.509 client certificate to every registered agent. Mutual TLS verifies both sides of the agent-to-Control-Plane channel at the TLS handshake layer. Government evaluation gate — required by DRDO, CERT-In, and banking sector pilots.

🔑

HSM Adapter — PKCS#11

All HSM-resident key operations via the PKCS#11 standard. Dynamic library loading — no compile-time vendor dependency. Compatible with Thales Luna, SafeNet, Entrust nCipher, Utimaco, and SoftHSM2 for development. Government key management requirement met without source code changes per HSM vendor.

🧙

First-Run Setup Wizard

On first boot with no database configured, the Control Plane launches a browser-based wizard on port 9000. Three screens: PostgreSQL connection (live test) → admin account creation → API key reveal. Writes .env, runs all migrations, creates admin user. Zero manual configuration required.

📄

Licensing Enforcement

SHA3-signed license tokens enforce estate limits per tier — trial (3 estates), professional (configurable), enterprise (unlimited). HTTP 402 on limit breach. License infrastructure is JSON-forward-compatible: new fields (per-node, per-feature, site-lock) can be added without invalidating existing keys.

🔄

Auto-Update

Version manifest hosted at arulraj.live/releases/manifest.json (Cloudflare CDN — live now). On startup: applies staged .next binary and re-execs. Background check every 24 hours. SHA3-256 hash verification before staging. Operator controls restart timing — no surprise downtime. ACSE_AUTO_UPDATE=true to enable.

🤖

Client Endpoint Agent

The acse-agent binary runs on every protected node. First boot: self-registers with the CP via token, writes api_key + estate_id to .env. Subsequent boots skip registration. PME engine runs in a dedicated thread (EWMA scoring, torpedo count). Push loop sends live state to CP every 30 seconds with automatic exponential back-off.

🏢

Multi-Tenant + Row Level Security

The Control Plane is a full multi-tenant system. Every estate, user, API key, policy, SIEM sink, and firewall device belongs to an organisation. Existing single-tenant deployments migrate to the default org automatically. Two isolation layers: application-level org_id filtering on every query + PostgreSQL Row Level Security policies on every table. REST API: GET/POST/PATCH/DELETE /v1/orgs.

🍎

macOS Support

The Rust codebase is fully cross-platform. CI now builds acse-cp and acse-agent on macos-latest, packages as .tar.gz, and publishes SHA3-256 hash verification alongside every GitHub release. Zero Rust code changes required — the platform compiles natively on Apple Silicon and Intel.

🧠

AI/ML Hybrid — Foundation-A

Every mutation cycle feeds a 16-dimensional feature vector (fingerprint entropy, Hamming distance, EWMA, torpedo delta, organ state, consecutive failures) into a local anomaly classifier — Normal, Suspicious, or Critical. Stub classifier ships in the default binary (zero deps). A custom trained ONNX model slots in via ACSE_ML_MODEL_PATH without recompiling. Pure Rust via tract-onnx — air-gap safe, DRDO-compatible.

● LIVE — v0.3.0 Available Now
  • ✅ PostgreSQL persistence
  • ✅ TEE-attested auth & RBAC
  • ✅ Estate management REST API
  • ✅ SIEM dispatch (Splunk / QRadar / Syslog)
  • ✅ Palo Alto · Cisco ASA · Fortinet adapters
  • ✅ Live estate dashboard
  • ✅ Kali Invariant global monitor
  • ✅ Windows MSI + Linux DEB packaging
  • ✅ Auto-Discovery engine — 22 source types
  • ✅ Agent zero-config self-registration
  • ✅ HCI & Storage fabric connectors
  • ✅ Compliance Reports — 4 types, CSV/JSON
  • ✅ Probe & Discover — TCP Probe · SSH Scan · Scan All
  • ✅ KaliCore Mandala system tray (Windows + Linux)
  • ✅ mTLS production transport — CA + agent certificates + ACSE_MTLS_REQUIRED gate
  • ✅ HSM Adapter — PKCS#11 dynamic loading (SoftHSM2 · Thales Luna · Entrust nCipher)
  • ✅ First-run browser setup wizard — zero .env editing required
  • ✅ Licensing enforcement — trial · professional · enterprise tiers (HTTP 402)
  • ✅ Auto-update — manifest-driven, SHA3-verified, atomic binary staging + re-exec
  • ✅ Client endpoint agent (acse-agent) — self-registers, runs PME, pushes live state
  • ✅ Multi-tenant + Row-Level Security — organisations table, org_id on all estate tables, PostgreSQL RLS
  • ✅ macOS support — acse-cp + acse-agent build on macos-latest, SHA3-verified release archives
  • ✅ AI/ML Hybrid — Foundation-A local ONNX inference, 16-feature anomaly classifier, air-gap safe
○ ROADMAP — v2 Coming Next
  • ○ ONNX model training pipeline — real anomaly data from estate telemetry
  • ○ SIEM connector depth + Ansible role
  • ○ Reporting module v2 + dashboards
  • ○ HA Control Plane (PostgreSQL streaming replication)
  • ○ macOS system tray (KaliCore Mandala on macOS)
  • ○ ASRK-ODS — second system (Indian defence organisations)

Auto-Discovery — Zero Manual Inventory

Before you can protect a node, you need to know it exists. The ACSE Control Plane discovers every server, VM, HCI node, and storage controller in your estate automatically — across 22 source types — then suggests the right mutation profile for each one. The admin reviews the catalog, clicks Protect, and the agent key is ready.

🔍
Configure Source
LDAP · SSH · Cloud · HCI · Storage · CSV
📋
Catalog Populated
Auto-classified · Profile suggested
Admin Approves
Click Protect — estate + api_key created
🤖
Agent Deploys
Key installed · Kali Invariant active
🔱
Protected
Mutation active · Surface non-existent
Identity & Directory
Active Directory · LDAP
Azure AD / Entra ID
Active Scan (No Agent)
SSH Linux Discovery
TCP Port Probe
Cloud
AWS EC2 · Azure VMs
GCP Compute Engine
HCI Management Planes
Nutanix Prism · Cisco UCS
VMware vCenter · Azure Stack HCI
Storage Fabric
Pure Storage · NetApp ONTAP
Dell PowerStore · Brocade FC
Cisco MDS · Ceph
Network & Import
Palo Alto Panorama
Fortinet FortiManager · SNMP
CSV · Agent Self-Register
Zero-Config Agent Deployment — New in v0.2.4

Set ACSE_REGISTRATION_TOKEN on the Control Plane and on each agent node. On first boot, the agent calls POST /v1/discovery/self-register, receives its api_key, and starts pushing immediately — no admin catalog step required. Ideal for Ansible/SCCM rollouts and cloud auto-scaling groups.

The Opportunity

Not a feature. Not a product. Infrastructure.

$350B
Global cybersecurity market
100%
Built on static surface assumption
ACSE
Changes the assumption, not the mitigation
1
Patent Published · IN202641070690
The TLS Analogy — Why This Matters to Every Business

"If I have a firewall, locked-down ports, and a hardened server — what is the use of TLS?"

When HTTPS was introduced, that question was asked. The answer was simple:

TLS protects data in transit regardless of what the network looks like. Even if an attacker gets onto the network, even if they're on the same WiFi, even if a router is compromised — they cannot read the data. Because TLS encrypts it at the transport layer, independently of everything else.

TLS

Hardening protects the network. TLS protects the data independently of the network. Your firewall, your locked ports, your patched OS — TLS adds a layer that operates regardless of all of them.

ACSE

ACSE protects the surface identity independently of everything else. Your firewall, your patched OS, your Zero Trust policy — ACSE adds a layer that operates regardless of all of them.

In concrete terms — three scenarios every security team will recognise:

1
The OS has an unpatched CVE
The surfaces the attacker needs to exploit are rotating every few microseconds. The fingerprint they mapped to reach the vulnerability is stale before they can act on it.
2
A credential was phished
The session token that credential produces expires at the next mutation cycle. The attacker cannot replay it. The stolen credential is correct — but the surface it opens no longer exists.
3
A firewall rule was misconfigured
The endpoint fingerprint the attacker mapped through that open rule is stale. The path they found leads nowhere — not because the firewall was fixed, but because the destination no longer looks the same.

The point is the same as it was with TLS:

TLS is not a replacement for your firewall. ACSE is not a replacement for your EDR, your SIEM, or your Zero Trust architecture. It is an additional layer that operates independently of all of them — and makes all of them more effective, because the surfaces they protect are no longer static.

TLS IS NOT A PRODUCT — IT IS INFRASTRUCTURE  ·  ACSE IS THE SAME KIND OF THING  ·  PATENT IN202641070690

Built On

Technology Foundation

Every component of ACSE — engine, server, agent, tray, dashboard — is built on proven technology with no framework bloat and no AI-generated code. 36,358 lines of hand-written Rust. 956 tests. Zero warnings.

Rust
100% of the implementation — engine, server, agent, and tray
36,358 lines  ·  105 files  ·  956 tests  ·  0 failures  ·  0 warnings  ·  Memory-safe, zero garbage collection, sub-microsecond mutation cycles
GitHub →
Async Runtime & Web
Tokio — async runtime
Axum — REST API web framework
Tower HTTP — middleware (CORS, tracing)
Note: Axum (Tokio project), not Actix Web — both are Rust frameworks, ACSE uses Axum
Database
PostgreSQL v14+ — estates, audit chain, reports
SQLx — async DB driver, SQLX_OFFLINE compatible
SQL migrations — idempotent, embedded in binary
Cryptography & Verification
SHA3-256 — audit chain integrity
HMAC-SHA3 — frame & message authentication
rcgen + rustls — mTLS · X.509 CA · agent certificate signing
cryptoki (PKCS#11) — HSM dynamic loading · key sealing
ProVerif — formal verification, Dolev-Yao model
TEE adapters — SGX · Nitro · SEV-SNP · ARM CCA · PKCS#11 HSM
Frontend & Dashboard
HTML5 · CSS3 · Vanilla JavaScript — zero framework dependency
Serde / serde_json — JSON serialization
csv crate — compliance report generation
System Integration & Protocols
ASMP/1.0 — custom session protocol, formally verified
CEF — SIEM event format (Splunk / QRadar / Syslog)
tray-icon — system tray (Win32 · GTK3 · macOS)
Python / Pillow — KaliCore Mandala icon generation
axum-server + RustTLS — HTTPS / mTLS server
SHA3-keyed license tokens — trial · professional · enterprise
Packaging & Distribution
WiX Toolset — Windows MSI installer
DEB packaging — Linux installer (Ubuntu · Debian · Kali)
GitHub Actions — CI/CD · Linux DEB · Windows MSI · Release
Development Environment
Kali Linux — primary development OS
VS Code — IDE with rust-analyzer
GitHub Projects — project tracking & sprint management
tokei — code line counting & analysis
Infrastructure & Hosting
AWS EC2 — live deployment environment · ACSE Public Challenge instance
Cloudflare Pages — website hosting (arulraj.live)
Cloudflare Web Analytics — privacy-first traffic analytics
GitHub — version control (private repository)
What Was Not Used
No AI code generation  ·  No cloud build services  ·  No frontend framework (React/Vue/Angular)  ·  No managed database  ·  No third-party authentication  ·  No infrastructure-as-code  ·  No external security scanning tools
Every line written by a single inventor.
Coming Soon

The ACSE Public Challenge

A live ACSE endpoint — deployed on AWS, open to the world. No registration. No rules to fill out. Just a running instance of the Kali Invariant, and a question the mathematics already answers.

What It Is

A fully operational ACSE instance running on AWS — the same engine, the same Kali Invariant, the same 10–143 microsecond mutation cycles that power the production platform. Open to any security researcher, red team, or penetration tester in the world.

The Question

The Kali Invariant states: every observed surface is destroyed and re-created before the next observation completes. The challenge is simple in principle — act on what you observed. The rules and specific objectives will be published with the formal announcement.

Why It Matters

Benchmarks are evidence. A live endpoint under real-world adversarial conditions is proof. The ACSE Public Challenge is not a marketing exercise — it is the definitive test of whether cryptographic surface mutation does what the patent claims. Either it holds or it doesn't.

If You Succeed

No material prize. Something more valuable — formal recognition in a published write-up, your name on record as the researcher who found a weakness in a formally verified, patent-published cryptographic system. And a direct conversation about joining the team as a penetration tester.

📢
Formal Announcement Coming

The ACSE Public Challenge will be announced formally under a registered organisation — company registration is currently in progress. The date, full rules, and challenge objectives will be published on LinkedIn and at arulraj.live when ready.

Where We Go Next

Enterprise Platform Roadmap

ACSE-PME is production-ready today. What comes next is the full enterprise control plane — 30 capabilities sourced from 12 years of service delivery experience across 100+ enterprise deployments, organised into four priority tiers.

Tier 1 — Before First Enterprise Pilot
Non-Negotiable Gates

Background Job Engine • Fleet Management • Agent Lifecycle • Operational Health Monitoring • Maintenance Windows • Config Change History + Approval Workflows • Backup / Restore

Tier 2 — Before Commercial Scale
Scale & Operations

Bulk Operations • Asset Tagging & Dynamic Groups • Alert Centre • Notification Integrations (Teams, Slack, PagerDuty, ServiceNow) • Scheduled Reports • API Key Lifecycle Management

Tier 3 — Enterprise Maturity
Procurement & Integration

IAM & SSO (SAML 2.0 / OIDC / SCIM) • OpenAPI / Swagger at /api/docs • Policy Templates (PCI, HIPAA, NIST, Defence) • Global Search • Version Management with Canary Rollout • HA Control Plane

Tier 4 — Platform
Security Platform

Compliance Centre (PCI, ISO 27001, SOC 2, DPDP) • Multi-region / Multi-site • Infrastructure Intelligence — live topology & dependency graph • Role Dashboards (SOC / CISO / Executive) • Automation Playbooks

Console Navigation — Final Architecture
Dashboard  •  Assets  •  Discovery  •  Protection  •  Policies  •  Operations  •  Reports  •  Compliance  •  Intelligence  •  Administration
Intelligence is the new section — live network topology & asset dependency graph. The differentiator no competitor can show in a demo.
See Full Roadmap →

Ready to explore this further?

For investment discussions, partnership enquiries, pilot deployments, or to review the full technical evidence base — reach out directly.