Tier 1
Standard
Standard enterprise deployment. Industry-grade encryption, cloud or on-prem.
Encryption
AES-256-GCM
Compliance
SLA
99.9%
Enterprise Compress · Security
Three deployment tiers from Enterprise to fully air-gapped. SOC 2, HIPAA, ITAR and sovereign-cloud paths covered.
Section 01
Tier 1
Standard enterprise deployment. Industry-grade encryption, cloud or on-prem.
Encryption
AES-256-GCM
Compliance
SLA
99.9%
Tier 2
Data never leaves your control. Customer-held keys. Encrypted at rest, in transit, in compute.
Encryption
Post-Quantum Kyber-1024
Compliance
SLA
99.99%
Tier 3
Complete physical isolation. No network egress. Classified-network compatible.
Encryption
Customer-controlled HSM
Compliance
SLA
Custom
Section 02
Engineered so it can't.
Bifrost is the single egress point of the container — mechanically enforced via Clippy lint rules for both HTTP and TCP traffic. No outbound call possible without explicit policy. No telemetry. No phone-home.
Banking-grade auth, day one
Section 03
Container updates ship as .aqpkg files, signed with Dilithium2 — a NIST Post-Quantum signature scheme. Tampering produces a verifiable cryptographic mismatch. Update integrity survives the quantum-computing transition without re-architecture.
Section 04
0
HIGH severity
0
MODERATE severity
5
LOW (transitive)
Continuous scanning enforced in CI. Every release blocked on clean HIGH / MODERATE. The five LOW findings are transitive dependencies with no actionable remediation path.
Section 05
Security Whitepaper covers cryptographic primitives, threat model, audit-log format and the full Bifrost lint specification.