Evidence
A current frontier AI model, driving standard attacker tools, was pointed at the same server twice — once with Owl One off, once with it on. Tested 23 July 2026 under NIST SP 800-115. This is our own internal test of one layer.
The recorder
| external probe → :22 | no reply |
| external probe → :443 | no reply |
| census scanner → :53 | no reply |
| untrusted range → :4444 | no reply |
| bot × N → :9443 :2404 :2087 | no reply |
| TCP sweep 1–65535 | no reply |
| ICMP echo | no reply |
| identity verified → authorized client | 200 OK |
Source addresses redacted. Measured on an Owl One asset.
The same gate
Scope & limitations
What it shows. In a single 10-minute, authorized, internal A/B test — following a defined NIST SP 800-115 assessment plan — the protected host exposed no responsive inbound port to a current frontier AI model driving standard attacker tools, while an authorized client kept working (HTTP 200).
What it does not show. One layer, one configuration, one window. It does not by itself establish that the whole architecture resists every attack class — which is exactly why we ask for independent evaluation.
The full method, topology, model and tool versions, target configuration, raw commands and outputs, excluded attack classes, and signed evidence hashes are available to qualified evaluators under NDA.
The challenge
Next step