Launched this week

Astartis x Codex
Enterprise developer security control plane around evidence
31 followers
Enterprise developer security control plane around evidence
31 followers
Astartis x Codex - evidence-led developer security control plane.

31 followers
31 followers
Swenest
@kgosi_blanda I really liked your inspiration and motivation to cut costs for different regions where hosting is costly. In this AI era cybersecurity is crucial. Congrats on shipping this!
@ashish_waikar Thanks Ashish , i really appreciate it
the hash-at-capture-time model is solid against tampering after the fact, but it only proves the evidence wasn't altered post-signing - not that it was honest to begin with. if the offline device itself is compromised before capture, or the signing key gets pulled off a laptop that was sitting disconnected for a while, you'd get a validly signed, internally consistent record of something that was fake from the start. what's the actual defense against a compromised endpoint signing bad evidence with a legitimate key, as opposed to catching tampering after the signature's already been applied?
@galdayan You’re right: hash-at-capture-time protects evidence integrity, not sensor honesty. Astartis does not treat endpoint signatures as absolute truth. They are authenticated claims. The control plane assigns trust based on key age, device posture, last contact, sequence continuity, policy epoch, and corroborating signals from NAC, network zones, audit chain, decoys, and server-side records. If an endpoint was offline too long or its key is suspected exposed, its signed evidence remains useful for forensics but is downgraded or quarantined; it cannot by itself authorize access or close an investigation.Thanks for asking. If you like this product, may you please talk about it on X , i will drop installers via github in ios, linux and playstore for it next month if i get funds , from the open ai competitions, and also my whole project is fully explained via my git repo and the demo vid
@kgosi_blanda makes sense, that's a solid layered answer. when evidence gets downgraded or quarantined, who actually looks at it next - is there always a human analyst in the loop for the quarantine queue, or can the system auto-resolve some of those cases on its own (say, corroborating server-side records are clean enough)? asking because for a solo team using this, i'd want to know how much manual triage that quarantine bucket actually creates day to day.
@galdayan Sorry sir , for answering this late as i work a 9-5 so I'm busy most of the time, to answer your question, evidence get assorted based on priority level , so evidence that can lead to destructive actions being committed is left for a human to look at but anything low level the ai triage agents will handle it, also the power and efficiency of astartis x codex rely on the scalability of compute, it can run from laptops to servers, configs via my github repo can be changed to improve efficiency , like swapping the ibm granite 4 models to 27 billion parameter bonsai models, this is the beauty of astartis x codex , which is resilience ,configurability , scalability and flexibility , and don't forget cheap lol as if everything goes down , the 77 routed agent roles can rebuild a whole environment from scratch using the backup repo thats gaurded by the active immutability, also i almost forgot , when i said this can be run on a laptop, i mean turning a dedicated one into a server instance via win server 2008 or 2022 so it should be on 24/7
@galdayan Also manual triage buckets for data quarantine depends on how much storage is even assorted as bad , so its not arbitrary in short
Congrats on shipping this. The local-first, disconnected-environment angle is the right call, most enterprise security tooling assumes constant connectivity and a budget most small teams don't have. Genuine question: how does evidence stay trustworthy once a device has been offline for a while and comes back online, do you reconcile state automatically or flag it for a human to review first?
@rahulladumor Thanks! Good question. When a device comes back online, we don't blindly merge state — evidence collected offline is hashed/signed at capture time, so on reconnect we verify integrity first, then auto-reconcile anything that passes those checks cleanly. Anything with conflicts, gaps, or tampering signals gets flagged for human review rather than silently merged. The goal is: boring, verifiable evidence beats fast-but-opaque automation
For any more inquires, look at this first and realize that if an attacker still manages to get is to your system, our latest updates can impose absolute immutability for backup repositories. But breaches are still rare though with a zero-trust network
Astartis’ defense is layered around reducing and detecting that failure mode, not pretending it is impossible:
Endpoint evidence is treated as a claim, not final truth
A signed record from an offline device proves “this key produced this record at this time,” not “the world definitely looked this way.” In Astartis, that evidence should be scored against independent signals: NAC posture, network-zone context, policy state, agent health, decoy activity, audit-chain continuity, and server-side records where available.
Keys should be scoped, rotatable, and revocable
A laptop-held key should not be a permanent root of trust. It should be device-scoped, short-lived where possible, bound to posture, and revocable once the endpoint shows drift, missed check-ins, suspicious attribution, or failed proof-mode checks. If a stale offline key signs evidence after a risk threshold, that evidence can remain cryptographically valid but operationally downgraded.
Offline capture needs freshness constraints
The system should enforce capture windows, counters, monotonic sequence numbers, key epochs, and “last trusted contact” metadata. If a device was disconnected too long, its signatures are not accepted at full trust. They become quarantine evidence: useful for investigation, not enough to authorize access or clear an incident.
Use cross-corroboration
Bad evidence from one compromised endpoint should have to agree with things it cannot easily forge: switch/NAC observations, DHCP or identity logs, firewall decisions, WORM audit sequence, decoy triggers, peer network telemetry, and known policy snapshots. Astartis’ strongest argument is that Codex can explain these contradictions instead of just showing a green checkmark.
Separate signing from high-trust authority
The endpoint can sign what it observed, but it should not be able to grant itself trust. Admission, Zero Trust access, WORM unlocks, quarantine release, and recovery decisions should be made by the control plane using multiple signals.
please give shoutouts , to anyone interested about cyber in your communities