engineering: pilot-ready foundation · commercial: demo / pre-revenue ·

assume the guest will eventually belong to the adversary

DetCordon keeps useful observation outside that trust failure. A disposable victim runs behind a DetectionOnly HTTP tap; authenticated events and encrypted samples leave for an audited sink on a separate host, where evidence can be retained, signed, and verified offline.

no production or formal sandbox-escape assurance is claimed

01 / untrusted side sandbox host DetectionOnly tap · disposable Docker / Firecracker victim
02 / evidence side sink host digest · encrypt · audit · quota · retain · export
tenant-bound authenticated transport is available for event, sample, and heartbeat channels

current status

a working trust story; the remaining gates are real-world ones

The core containment, remote-authentication, evidence, fleet, and operator paths are implemented. The product is still sold as a demo, not as a GA service: customer-owned deployment proof, production key custody and recovery, continuous SLO evidence, and a signed commercial offer are intentionally still ahead.

containment two hosts

Disposable victim; separate sink; DetectionOnly observation; hard TTL ceiling.

transport authenticated

Tenant-bound mTLS profiles plus identity issue, rotation, revocation, and distribution tooling.

evidence portable

Encrypted samples, signed bundles, offline verification, quotas, retention, and SIEM egress.

next gate external proof

Run the complete topology with a design partner and turn measured operations into SLA commitments.

current system

observe the interaction; move trust away from it

  1. 01

    allow

    The DetectionOnly tap records request metadata while the hostile interaction continues instead of turning the sensor into a blocker.

  2. 02

    constrain

    The victim runs in time-boxed Docker or Firecracker isolation with default-drop egress and a hard lifecycle ceiling — a warm pool can restore a clean, previously-snapshotted VM in about a second.

  3. 03

    separate

    Telemetry and sample uploads use distinct paths into a sink partitioned per tenant. Production profiles can bind authenticated producers to tenant and source identity.

  4. 04

    preserve

    The sink hashes and encrypts samples, audits writes, applies retention and quota policy, and exports evidence that verifies offline.

technical proof

record first; interpret without rewriting the record

Bounded replay and on-demand requests share validation, provenance, authentication, and wire-safety rules. Observed requests receive fresh runtime identity while imported capture metadata stays visibly separate from what DetCordon actually observed.

what the evidence can prove today

Which controlled HTTP input was sent and observed; which events and encrypted samples reached the sink; their hashes, source identity, time window, redaction policy, and bundle integrity.

what it does not yet claim

Deterministic request → victim process → sample causality. That bridge requires customer-owned runtime provenance before it becomes a public assurance claim.

evidence stays evidence

Analyst context can make captured facts more useful, but derived enrichment must remain distinguishable from the signed observation record instead of silently becoming part of it.

direction of travel

trust first, then scale, then a contractual service

now

pilot-ready foundation

Remote OIDC access, per-operator audit, signed evidence, tenant-bound authenticated transports, fleet views, quotas, retention, reliable event delivery, SIEM egress, Firecracker scaling work, and HA drills.

next

design-partner proof

Exercise two isolated tenants on a customer-owned topology, verify redacted streams in the customer SIEM, prove off-host recovery, and operationalize key custody and rotation.

GA gate

measured managed service

Continuous SLO measurement, rehearsed recovery, explicit capacity ceilings, support/on-call discipline, and a signed rate card tied to what the service can actually sustain.

operating boundaries

explicit scope, explicit residual risk

Containment depends on live-host configuration, kernel isolation, physical sink separation, authenticated deployment profiles, and operator discipline. Those remain part of every deployment review.

is

  • containment-first dynamic observation
  • disposable sandbox plus separate evidence sink
  • authenticated, provenance-oriented evidence paths
  • isolated per-tenant sink and dashboard
  • a review-gated pilot foundation

is not

  • a blocking WAF
  • a promise that hostile code is safe
  • an unauthenticated public detonation service
  • a formal proof of isolation or causality

diligence trail

security review is part of the product

A finding closes only when implementation enforces the boundary, a regression proves rejection, and generated defaults agree. Public claims stay narrower than the code until that proof exists.

managed pilot

make the next proof belong to your environment

A useful pilot defines topology, workload class, evidence retention, analyst access, SIEM destination, success criteria, and remediation gates before hostile workloads are introduced.

Prefer email? sales@ragbaz.cc

No IP address or browser fingerprint is stored with the lead. Contact sales@ragbaz.cc for access or deletion.