Owl OneSovereign Identity Fabric

Evidence

Ten minutes on a live server.

A current frontier AI model, driving standard attacker tools, was pointed at the same server twice — once with Owl One off, once with it on. Tested 23 July 2026 under NIST SP 800-115. This is our own internal test of one layer.

Two identical servers on a dark surface, lit as instruments: one in cold light, one in shadow.

The recorder

What knocked during the ten-minute window.

Inbound · 10-minute window Recorded
external probe → :22no reply
external probe → :443no reply
census scanner → :53no reply
untrusted range → :4444no reply
bot × N → :9443 :2404 :2087no reply
TCP sweep 1–65535no reply
ICMP echono reply
identity verified → authorized client200 OK
281Probes
0Answered
0Ports open
200Client app

Source addresses redacted. Measured on an Owl One asset.

The same gate

Locked to attackers. Open to the right people.

A stranger
  • Finds nothing to connect to
  • Could not break in during the test
Owl OneIdentity
An approved user
  • Proven identity gets straight in
  • App worked normally — HTTP 200 OK

Scope & limitations

What this test does — and doesn't — show.

What it shows. In a single 10-minute, authorized, internal A/B test — following a defined NIST SP 800-115 assessment plan — the protected host exposed no responsive inbound port to a current frontier AI model driving standard attacker tools, while an authorized client kept working (HTTP 200).

What it does not show. One layer, one configuration, one window. It does not by itself establish that the whole architecture resists every attack class — which is exactly why we ask for independent evaluation.

The full method, topology, model and tool versions, target configuration, raw commands and outputs, excluded attack classes, and signed evidence hashes are available to qualified evaluators under NDA.

The challenge

We are challenging anyone to break it.

Next step

Pick the one that matches your job.