Owl OneSovereign Identity Fabric

The technology

Sovereign Identity Fabric

A new security architecture for the AI era. Security is built around identity, not location — from getting in, to running software, to what an AI agent may do.

Constrain authority·Contain AI·Remove the attack surface

A fabric woven from countless fine threads of light, each thread continuous, interlacing into one seamless cloth with no hole anywhere in the weave.

The challenge

The security problem has moved beyond the perimeter.

AI has turned cyberattack into an automatic, machine-speed activity — what once took skilled people days now runs on its own, around the clock. So there are two things to defend against at once: outside attackers, and software that acts on its own.

Getting in

The external attack surface

  • Internet-facing services can be found and reached by anyone.
  • A single exposed or misconfigured service becomes the way in.
  • AI makes finding and exploiting that opening faster and cheaper.
What it can do

Authority once inside

  • Once admitted, software often holds far more power than it actually needs.
  • A self-directed agent acts faster than any human can supervise.
  • A rule on paper is not enough if the software still technically has the power to do harm.

The answer

Verify. Constrain. Remove.

One idea ties the three together: security follows identity — from getting in, to running software, to what an AI agent may do.

VERIFY

Prove control of a recognized identity with cryptographically verifiable signatures — before anything connects.

CONSTRAIN

Give each application or AI agent only the power it truly needs, and nothing more.

REMOVE

Hide what matters completely — a vault an intruder cannot even find.

Precisely: a protected service exposes no directly reachable inbound path to an unauthorized internet client. "Nothing to find" is the plain-language shorthand for that testable property.

How to picture it

The bank with no public vault door.

You don’t close the branch to protect the vault. You stay open for business — and make the vault impossible to find. What stands between the two is a clerk.

Public lobby— open to everyone. Your business keeps running normally.
The clerk— you present an identity key. It proves who is present; it opens nothing by itself. The clerk checks whether the bank trusts that identity, and what it is allowed to use. = Enclave
A private path— revealed to you, to your box, and to nowhere else. Someone not trusted is shown nothing at all. = hierarchical privilege
The vault itself— no visible door, no port; an intruder can’t even find it. = zero-port

The mechanism

Enclave is that clerk.

It is the point where an identity, the owner’s trust decision, and the protected service meet — and the owner decides who is trusted, not a central authority and not us. “I do not entertain everyone; only the one I trust can find me, and only the one I trust will I serve.”

Underneath, that makes it a new breed of router. Ordinary networking exposes a destination and lets the outside push connection requests at it. Enclave reverses the direction: the protected endpoint stays hidden, and the trusted side pulls in only what has already been identified and authorized.

The open internet, as built OutsideRouter / firewallProtected system
SIF — Enclave Outside requestIdentity verificationEnclaveProtected system
Identity-Aware Pull-Oriented Inbound-Reversing

Precisely: zero public ports; identity-resolved services for authorized users. From the public network, no unauthenticated inbound service is reachable. For an authorized identity, many policy-authorized logical services resolve without any of them exposing a physical port. This is not deception — nothing is pretending to be open, and there is no tarpit to fingerprint.

Ordinary routers route traffic. Enclave routes trust.

Your service is not public and guarded. It is private, and revealed only to the identities you choose to trust.

In productionThis is the layer the recorded penetration test exercised — see Evidence. It is what Osmo puts around the systems you already run.

The architecture

One identity architecture across the whole stack.

Staying invisible is only the first step. The same identity keeps control at every step after it.

Prove identity

Who can enter

Join the identity fabric

What can be reached

Grant only what's needed

What power is given

Run in a sealed runtime

What can execute

Reach approved resources

What can be affected

Accountable authority

The harder question: the identity you already trust.

A wall does nothing if the stranger is already inside with a key — a stolen credential, or an agent that goes wrong using access you handed it yourself. SIF’s answer is to make authority explicit and every action attributable afterward: identity tells you which agent acted, and the chain tells you who authorized it and what evidence it left behind.

Human authority Machine identity Scoped permission Protected operation Resulting data Verifiable evidence

“Nothing anonymous” does not mean we know who you are in the world. It means the system does not accept an unaccountable actor: an identity can be pseudonymous and still be persistent, recognizable, and carry its own history — so anyone deciding whether to trust it can look at that history and judge for themselves.

In four lines

What the architecture promises.

Identity before access.No anonymous actor enters the model at all.
Trust before discovery.A service becomes visible through established trust, rather than being exposed to everyone and then defended.
Capability with responsibility.Authority enables the action; the action stays attributable to whoever authorized it.
Evidence before assertion.Enough is preserved to establish who did what, and under whose authority.

Against today's best practice

Everyone else stops at the door.

Today’s leading zero-trust products all make a server unreachable and gate it by identity — that’s the zero-trust baseline (the shaded rows), and Enclave meets it in production today. Read past them: today’s best practice stops at who can get in; SIF keeps going — to what software and AI can do once inside, and who is accountable for it.

Dimension Open-source overlay Enterprise ZTNA appliance Global edge cloud Owl One SIF
No inbound listening port (server is "dark") Yes Yes Yes (tunnel) Yes
Access gated by cryptographic identity X.509 via controller IdP + endpoint agent via external IdP Yes
Trust path in the middle Central controller + edge routers Vendor gateway + vendor SASE cloud The provider's global edge cloud Broker-less, decentralized mesh
Where identity comes from Issued by the controller (central PKI) Central IdP + endpoint agent External IdP Self-authenticating identifier
How far trust reaches Network access Network access + device posture Network access + SASE (gateway, CASB) Network → runtime → AI-agent authority
Accountable AI — who authorized the agent Not a focus Not a focus Not a focus Core: verifiable human-to-action authority chain
Deployment & data sovereignty Self-host, or the vendor's cloud Appliance + US-based cloud US-based global cloud (required) On-prem / sovereign
Ownership Open source, US-based steward US public company US public company Canadian company; owns the IP

Baseline rows (shaded) are table stakes across zero-trust — no invention claimed there. Sources: published vendor documentation.

Two products, two jobs

One architecture, delivered as two products.

Sovereign Identity Fabric is the foundation. Osmo and Prime are the two products that sit on it — and everything Prime does happens inside the line Osmo draws.

Owl One Osmo security Owl One Prime enterprise
Sovereign Identity Fabric — the foundation