Cyber-physical resilience / defensive intelligence

Killinchu / Defend

Evidence-bound detection becomes a deterministic case and a bounded containment proposal, then independent human approval, simulation-only rehearsal, rollback state and an independently verifiable receipt.

01 / Runtime proof

Operational truth

Status comes from the running store, exact source binding and signing-secret availability. Reachability is never promoted into an authorization claim.

PROBING

Control plane

Loading exact runtime status.

BOUNDED

Authority

Independent approval can authorize a rehearsal only. External effectors remain disabled.

APPEND-ONLY

Evidence

Every detection, proposal, approval and rehearsal extends a session-scoped receipt chain.

02 / Detect → approve → verify

Run the governed loop

The browser creates a private caller-held session token. The service stores only its SHA-256 scope, never the token.

Receipt-bound output
Ready. Submit an event to create a case and bounded proposal.

This is a real stateful decision-and-evidence workflow with deterministic calculations and durable process-local SQLite. The external action is intentionally not real: the public runtime cannot isolate an asset, disable a session, create a provider ticket or operate against another system.

03 / Capability map

What moved into Killinchu

Public-product consolidation preserves component provenance rather than erasing it.

CAPTURED

Sentra contract

Replay-safe ingestion, deterministic detection, cases, proposals, human independence, rehearsal and receipts.

CANONICAL

Aegis portfolio

The complete cyber-physical resilience family now resolves to this one product surface.

SEPARATE PLANE

Immune

AI admission, signed authority and tripwire parity remain a distinct same-origin migration gate; no false completion claim is made here.