Phoenix / Proof

Receipts, not claims.

Every AI security vendor says the same three things: your data is safe, our AI is trustworthy, it works. Phoenix is built so you don't have to take any of them on faith. This page is the evidence.

0
customer logs sent to a hosted model — not a policy, an architecture you can audit and test
1

Your logs and internal indicators never leave your network — and you can prove it

Data residency is enforced by construction, not by promise.

A single egress chokepoint

All outbound access is funneled through one code path. Indicators are classified before any external lookup, and internal identity is withheld.

The build fails if that's violated

CI fails if any module outside the chokepoint can open a network socket — so a new egress path fails the build before it can merge.

Local models only

Reasoning runs on models you host. There is no external model endpoint to call — no per-token bill, no egress path to misconfigure.

Verify it adversarially

Deploy Phoenix behind your own deny-all firewall and watch it keep working. Trust your egress logs, not our privacy policy.

2

The AI can only act inside a boundary set in code — even when it's wrong

We assume the model is fallible, misreading, and jailbroken — then bound what it can do, so its mistakes stay inside a boundary set in code.

Authority lives in code, not the model

The model can name an action from a fixed list; it can never invent one. The number that gates anything is a code-owned constant. This guarantee survives a model swap, a bad release, a jailbreak.

The approver is an input, not an override

For actions that can take a network down, a code-owned refusal outranks a human "Allow" — approvals are made with far less context than executions.

Fail-open on notify, fail-closed on response

An unverifiable report is delivered stamped unverified, never dropped. What could cause harm waits.

Nothing is armed before it's measured

Every gate ships on an observe → shadow → enforce ladder, recording the decision it would have made against live traffic first.

3

It's actually working — and silence can't hide a failure

The most dangerous failure in security is the quiet one. Phoenix is built to make its own failure noisy.

A stuck process can't raise its own alarm

So an independent watchdog does. Per-process health reads healthy / degraded / escalated / stalled.

Absence is made countable

Declined triage is recorded with the severity present; coverage gaps are counted with the missing rule IDs. You can ask what was missed.

Deploys verified by disagreement

A content fingerprint per box is compared between boxes; drift is detected because they disagree, not because one claims to be fine.

Real operating history, stated honestly

Across ~18 months, hallucination cost about one afternoon. Three days blind while every health indicator read green cost considerably more.

4

What proof does not buy — stated out loud

Honesty is part of the receipt. The strongest guarantees have edges, and hiding them would be the same failure class we build against.

It bounds what the system can do — not whether everything it says is true

Containment checks that asserted facts appear in the gathered evidence. It cannot catch misattribution: a conclusion where every token is present and the reasoning is still wrong.

Omission is instrumented, not detected

An attack quietly not escalated produces no verdict and no alarm. Counting declines makes the absence visible later; it doesn't catch the miss in the moment.

"By construction" degrades to "by convention" when a setting is empty

Several guarantees read an operator-configured list. An unset value makes the guarantee vacuously true on that box.

A small local model is a real ceiling

It reasons worse than a frontier model, and no scaffolding closes that gap. Scaffolding bounds the damage and makes errors visible.

What we're building next

Named so you can hold us to it — not counted as evidence yet

Roadmap

The Faraday Ledger

A tamper-evident egress flight-recorder that produces a signed artifact showing zero customer bytes left the perimeter over a period — non-egress as an auditable record you can take into an audit.

Roadmap

Authority-as-Code Warrant

The machine's forbidden actions published as a versioned, inspectable "constitution," so every autonomous response is provably inside a pre-authorized boundary a reviewer can read.

Commitment

The Self-Attack Ledger

Phoenix runs Crucible (our own validation engine) against Phoenix, in the open, and publishes what breaks alongside the fix — trust earned by showing the company fail and recover, not by logos. A commitment we intend to honor, not a badge.

The argument underneath all of this

The constraint that no data may leave the building looks like a pure handicap. It forced a better safety posture than the unconstrained version ever would have. When you can't build a system whose safety argument is "the model is good," you're forced to build one whose safety argument is a handful of predicates a reviewer can read in an afternoon — each sited where the model can't reach it, each enforced twice, each pinned by a test that fails the day a new capability appears unguarded.

That is a worse analyst than a frontier model would be. It is a considerably better thing to put in front of a firewall.