Northstar — security infrastructure & software

Built to watch. Designed to know.

We build enterprise defensive-security infrastructure and consumer software across a governed, hash-chained multi-repository architecture — every seam verified, every action audited.

281Passing tests
5Repositories
12Adversarial scenarios
0Systems reached into
Operational
Platform core
Live
WatchYoDog beta
Prototype ready
Vipps connector
Prototype ready
Rool substrate
All green
CI / test suite

What we build

Security infrastructure that stays on its side of the line.

Northstar's core platform — Leviathan — is a modular defensive-security system covering entropy generation, active deception, detection, and a governed agentic control plane. Every action passes through a policy gate before it runs. Every event lands in a hash-chained audit trail.

Our rule is non-negotiable: everything here either analyzes systems we're authorized to test, or reacts to inbound traffic on infrastructure we own. We don't reach past our own perimeter.

Alongside the security platform, we build consumer software — WatchYoDog — a community dog-safety application designed with the same privacy-first principles: no telemetry, no dark patterns, no IP logging.

System status
Leviathan Core (entropy)Operational
Leviathan Defense (deception/detection)Operational
Leviathan Control (governance)Operational
Leviathan Rool (persistence)Prototype ready
Whitehat Agent Suite (recon)Operational
WatchYoDog (consumer)Live beta
Vipps Canary ConnectorPrototype ready
TerminalIn development

Architecture

One trust boundary across five repositories.

No component gets a pass for living in a different codebase. Actions still clear the same policy gate. Events still land in the same evidence chain.

Trust & Action Gateway every action, policy-checked Leviathan Control plane Leviathan Defense honeypot · canaries · tarpit IOC blocklist · attribution Rool Substrate SHA-256 hash chain prototype ready Leviathan Entropy CSPRNG · health tests mixing reservoir Whitehat Agent Suite scope-gated recon Docker cyber-range Vipps Connector prototype ready

Modular tiers

Start with what you need. Add more when you're ready.

Each Leviathan tier is a standalone module. Deploy the entropy core for key generation, add the defense layer for active detection, scale up to the full governed control plane when agentic governance matters.

Tier 1 — Foundation
Leviathan Entropy
A cryptographically sound entropy core with continuous NIST-style health tests, a background mixing reservoir, and arbitrary-length key draws. Honest about what it is — a strong sanity gate, not a certified assessment.
Operational
Tier 3 — Governance
Leviathan Control
A full governance control plane: Trust & Action Gateway, Tool-Manifest admission, Memory Firewall, hash-chained Evidence Graph, anomaly detection, governed auto-arm daemon, and a multi-agent team model with enforced trust boundaries.
Operational
Tier 4 — Persistence
Leviathan Rool
An independent SHA-256 hash-chained persistence substrate that mirrors platform events in a separately-versioned Python codebase. Cross-language byte-for-byte parity with the .NET core is enforced as a CI-gated test.
Prototype ready

Products

Enterprise security. Consumer software.

Two distinct product lines under the same roof, built to the same standards.

Enterprise
Leviathan Platform
An integrated defensive-security platform that watches its own perimeter, catches what gets through, and keeps a tamper-evident record of everything it saw.
  • Health-tested CSPRNG for key and nonce generation
  • Canary honeytokens and decoy documents with live beacon attribution
  • Bounded tarpit with concurrency cap, verified under real concurrent flood load
  • Policy-gated auto-arm daemon that escalates deception against repeat hostile sources
  • Hash-chained evidence graph with automated retention and tamper verification
  • Prometheus metrics endpoint and HMAC-signed opt-in alert webhooks
  • Scope-gated whitehat recon suite and Docker cyber-range training lab
Consumer · Live beta
WatchYoDog
A community dog-safety app built with a privacy-first architecture — real-time danger and lost-dog alerts, community identity tiers, and a games layer — all with no telemetry, no IP logging, no dark patterns.
  • Real-time GPS danger and lost-dog alerts with map and feed
  • Community identity: Walker → Pack Leader → Alpha tiers earned by activity
  • Dog avatars with on-device ML cartoonification pipeline
  • Community Ad Council with voting and report-driven demotion
  • Full async Texas Hold'em with play-money treat chips — no real money
  • Offline-safe score sync, local leaderboards, no permanent global ranking
  • Android (Kotlin) + Ktor backend — live on Railway

Live demo

Watch a canary detection cycle.

Step through a real detection sequence: decoy credential tripped, event hash-chained, HMAC alert dispatched, auto-arm daemon escalates. All data is synthetic — the logic is the real system.

47Decoys armed
0Sources tracked
0Alerts sent
0Chain entries
Click ▶ Play to begin
leviathan-defense — event stream
Armed Probe Trip Chain Alert Arm Watch

Multi-repository

Five codebases. One verified ecosystem.

Each repository is independently versioned and maintained — connected through a governance layer that verifies every cross-system action before it runs.

.NET 8 + Python
leviathan-platform
The main platform: entropy core, deception/detection API, governance control plane, whitehat agent suite. 281 tests across .NET and Python, CI on every push.
Python
Leviathan Rool
Persistence and mirror substrate: SHA-256 event hash chain, Merkle state tree, cross-language parity with the .NET core verified as a CI test. Prototype ready.
Kotlin + Ktor
WatchYoDog
Community dog-safety app. Live on Railway. Android client + Ktor backend, built privacy-first — no analytics, no telemetry, no dark patterns.
TypeScript
Vipps Connector
Thin canary seam for a separate payment-gateway codebase. Canary keys minted in the gateway's own format. Detection only — gateway source untouched. Prototype ready.
PowerShell + Python
Agent Platform
Scope-gated bug-bounty recon toolkit and Docker cyber-range training lab. Imported as a clean copy into the main platform; original remains the source of truth.

Roadmap

What ships next.

All P0 and P1 milestones are complete. These are the verified next steps — no vaporware.

Now
All P1 milestones
Metrics, alert webhooks, canary connectors, tarpit abuse resilience, auto-arm daemon, Vipps rollout runbook — all shipped and tested.
Done
Q3 2026
Vipps Canary live rollout
Deploy the canary connector against a real payment gateway instance. Code complete, runbook written, deployment pending.
Prototype ready
Q3 2026
Compose/K8s deployment topology
Honeypot behind TLS reverse proxy, KnownProxies set, secrets injected, evidence volume mounted. Dockerfile complete, compose topology next.
In progress
Q3 2026
Python control-plane metrics export
Prometheus metrics for the Python governance control plane — paralleling the existing .NET /metrics endpoint.
Planned
Q4 2026
MCP Security Gate & capability tokens
HMAC-signed short-lived capability tokens for MCP tool calls — extending the existing tool-manifest gateway to intercept AI agent actions at the protocol level.
Roadmap
Q4 2026
Independent security review
External pen test of the honeypot attack surface. We want an independent verdict before any commercial deployment.
Roadmap
2027
Semantic versioning + packaged release
First consumable release: versioned packages, release notes, container image publish. Currently build-only.
Roadmap

Get in touch

Let's build something together.

Partners, investors, customers

We're open to conversations with security teams looking for a deployment partner, investors who want to understand the platform's depth, and enterprise customers who need something this platform was built for.

We don't do demos that obscure how it works. If you want to understand the architecture, the evidence chain, or the governance model, we'll show you the real thing.