VERTEXPACE · DEFENCES

The Lumina Hive.
A digital immune system.

A small society of cooperating AIs that protect a person, a small business, or a coalition partner — with one human-held dialDialThe physical consent control you hold in the Lumina Hive. No admin override, no vendor backdoor. The dial state determines whether the system can sign any action at all — no state, no signature. that has the final word on anything serious. No cloud. No admin override. One flick of the dial and shared data dies on every machine that had it.

Local-firstMesh-nativeSovereign by designHonestly disclosed
The Hive

Four cooperating AIs.

Each one a cell in the body. Each one carrying a child key derived from the same master keypair on your dial. Each one speaking in concepts from the same fixed vocabulary. None can act alone on anything serious — quorumQuorumA minimum number of participants required to authorise an action. In the Hive, medium-stakes actions need at least two distinct kin to sign — no single AI can act alone on anything serious. is required. This is how biology avoids autoimmune disease.

Watcher
scout bee · sensor cell

Sees attacks happen. Classifies each one to a concept byteConcept ByteA single byte (0–74) from the Light Code concept table that labels the intent of an incoming connection — probe, recon, credential probe, exploit, or remote-code execution. One byte carries the full meaning so logs stay tiny and machine-readable.(probe, recon, credential probe, exploit, remote-code) and records only the type — never the raw exploit. Learns over time: notices when the same fingerprint comes back, when severity escalates, when multiple sensors fire together.

Defender
guard bee · T-cell

Picks the response from a small, named action library —tarpitTarpitA response that slows down an attacker by making the connection artificially lag — the attacker's tools stall, waste their scan budget, and reveal more about themselves while achieving nothing., decoy, block, quarantineQuarantineIsolating a suspected compromised process or file so it can't communicate with the rest of the system. Like a hospital quarantine — contained, not deleted, so it can be examined later., restore. Doesn't invent vocabulary. Escalates by stakes: low-stakes acts alone, medium-stakes asks the dial, high-stakes needs at least two of three distinct kin to sign.

Healer
nurse bee · RNA polymerase

Keeps signed snapshots of “known good” state. Checks integrity before restoring — never heals back to a poisoned snapshot. Repairs faulted code via a local LLM, the same pattern biology uses to mend broken DNA without ever phoning home.

Sentinel
hive guard · MHC marker

The tiny AI on the USB / handheld. Doesn't do much — its only job is to recognise. Three checks: right person (fingerprint), right place (wifi anchor), right family (kin DNA). Three yeses and the lock opens. The only AI without an internet connection.

The Queen

One dial. You hold it.

The dial is mechanical, not policy. There is no admin override, no emergency bypass, no vendor backdoor. The dial state controls whether the system signs at all. No state, no signature. No signature, no action.

AWAKE
CALM
FOCUS
OPEN
LOCKED
DISTRESS
COERCED
ASLEEP

Walk away with the dial AWAKE? A dead-man timer auto-LOCKs after a configured interval. Forced to sign under duress? A distress gesture flips the dial to DISTRESS — every peer sees the signature flagged, none honour it.

Three Stakes Levels

How an attack flows through.

LOW
Defender acts alone. Log only, tarpit, redirect to decoy. Reversible. No ceremony needed for slowing somebody down or wasting their time.
MEDIUM
The dial signs or refuses. Block an IP, refuse traffic, change a routing rule. If the dial drifts to LOCKED while you walk away, every medium-stakes action stops happening — automatically, without anyone telling the Defender.
HIGH
Two of three distinct kin must sign. Quarantine a host, rotate keys, restore a snapshot. Even if one AI is compromised and starts ordering crazy things, no other AI will sign with it — and you can refuse the final step.
Memory + Recovery

Nothing happens in the dark.

Tamper-evident audit chain

Every classification, execution, refusal, snapshot, and dial flick is signed and hash-linked into an encrypted append-only log on disk. Tamper with any single entry and the chain visibly breaks at exactly that entry.

Six months from now, somebody asks “did this kin really approve that action?” You walk the chain. If it verifies clean, every signature is real and every link holds. If it doesn't, it tells you where the lie is.

Five-of-three backup ritual

The master key is split into 5 cryptographic shares using Shamir's Secret Sharing. Distribute them across paper, USB, family, safe deposit, hardware wallet. Any 3 reconstruct the master perfectly. Fewer than 3 leak zero information.

If the dial is destroyed, three shares heal the kingdom. If a share is stolen, two more attackers must collude. Mathematically clean recovery; no platform required.

Honest Disclosure

What we defend against · what we concede.

Anyone who claims to protect against everything is either lying or doesn't know. Defence buyers respect honesty more than sales. Here is the line we draw, in our own words.

WE DEFEND AGAINST
  • Wire-level eavesdropping
  • Replay attacks within the validity window
  • Forged warnings from outsiders without a fresh grant
  • Quiet exfiltration after consent is revoked
  • Coerced sharing under “policy” — there is no policy
  • Raw exploit payloads ever leaving the sensor
WE OPENLY CONCEDE
  • Key compromise (malware, theft, leaked backup)
  • Coercion of the dial-holder ($5 wrench attack)
  • Root compromise of a sensor host
  • Honeypot detection by skilled attackers
  • Network-level jamming, flooding, traffic-analysis
  • Bugs in code that is still measured in months
  • Future quantum decryption of recorded traffic
Built For

Who actually uses this.

Small-business neighbourhoods

Three local businesses on the same street share attack-type warnings — not raw data — via cheap Pi sensors. The dial-holder controls every share, in real time.

Coalition partners

Allied teams share concept-fingerprints across sovereign borders without exposing source data. Pull the dial, cached warnings vanish from every peer at once.

Journalists & sources

Source-protection mesh with duress detection. If you're pressured, the dial knows; signatures get flagged COERCED; peers stop honouring them automatically.

Off-grid communities

Mesh-native by design. Works without ISPs. Same protocol on a Mac, a Pi 5, and an ESP32 handheld. No cloud anywhere on the path.

Talk to the dial-holder.

Vertexpace Defences is in active R&D. If you're working on a problem the Lumina Hive could fit — coalition mesh comms, sovereign warning networks, source-protection infrastructure — reach out directly.

EMAIL ZAC
robertpage@vertexpaceorganization.com
HONEST DISCLOSURE: ALL CRYPTO USES STANDARD PRIMITIVES (ED25519, CHACHA20-POLY1305, BLAKE3, SHAMIR-GF256, HKDF-SHA256).
STATUS: ACTIVE R&D · SOVEREIGN BY DESIGN · LOCAL-FIRST · NO CLOUD ON THE PATH
© 2026 VERTEXPACE · LUMINA HIVE · ALL RIGHTS RESERVED · PROPRIETARY TECHNOLOGY
UNAUTHORIZED REPRODUCTION, REDISTRIBUTION, OR DERIVATIVE USE IS PROHIBITED