Security Bouncer
It doesn’t log the break-in. It hits back.
It doesn’t log the break-in. It hits back.
Detect — every packet, every connection
The Security Bouncer is an autonomous defensive entity with its own decision cycle. Always on. No idle state. No sleep mode. No human in the core loop. It reads every packet that crosses a node — headers, payload shape, protocol, timing — and holds that reading against a live baseline of what healthy traffic looks like on this mesh. Source, destination, ports, duration, size: the watch is the connection, not a sampled slice.
Detect is deep inspection plus a behavioral baseline. A port probe, a volume spike, a malformed payload, a brute-force rhythm, an exfil burst — those are known shapes. A zero-day is a coherence drop: the network’s own health breaks in a way no signature file has seen. The baseline is how well the flow holds together. When it tears, the node flags. When three or more nodes see the same source, the flag becomes a mesh fact.
Every packet is inspected. Every connection is watched. Every anomaly is flagged. There is no idle in that sentence. The first job is to see the hand on the door while the hand is still on the door.
Block — cut the source before it plants
When a source is admitted as hostile, the isolate is stateful. The packet is dropped at ingress. The live session is reset. The callback name is black-holed so the command channel has nowhere to resolve. A compromised peer is revoked from the overlay so it cannot walk the mesh as a friend. The cut travels with the fact. Once three nodes agree on a source, every node that can still hear applies the isolate.
Block is a foothold denied, not a polite drop that leaves the session hanging. If one node is taken, the rest still watch. That is a living perimeter. Self-protection is part of the same organism: signed commands, a binary that checks its own hash, a stealth mode that refuses to announce itself to a scan. The guardian does not become the hole.
Then hit back
Doctrine is three verbs. Detect. Block. Then counter-offense. The strongest defense is a mesh that answers so the attacker remembers the cost. Counter-offense is the load-bearing claim. The perimeter does not stop at “no.” It replies. Many nodes answer, not one IP an attacker can block and walk around. First-mover signals move outward. The overlay itself is the swarm. The attacker who came for a quiet log gets a field of sensors answering at once.
A silent firewall writes the incident and waits for a person.
Detect. Block. Then make the attacker regret the attempt.
Every node a sensor
Every node is a sensor. Each Bouncer watches its own interface first, then shares a first-mover signal outward. Local alert is one interface acting. Mesh fact is three or more. Global isolate follows the fact. There is no rack-box that dies and takes the watch with it. Distributed: an instance on every mesh node. If one node is cut, the rest still see, still cut, still answer.
That is why the watch scales with the install. Add a node, add a sensor. Add a sensor, add a mouth that can reply. The organism fights as a field, not as a box in a closet that goes dark when the closet does. The buyer’s floor is the perimeter. Every machine that holds the archive also holds a pair of eyes.
Every node watches. Every node can answer. Cut one, the rest still hit back.
The fingerprint stays
The memory does not forget. A fingerprint is stored — address, timing signature, payload shape, the graph of hosts and names that rode with the attempt. A blacklist only grows. Once a threat is admitted, it stays admitted. A later hop does not get to pretend the first hop never happened. The next attempt from the same hand meets a mesh that already knows the shape.
Infrastructure mapping rides with the fingerprint: the names, the providers, the peers that talked to the source. That map is shared. Any node can ask who this hand was last time. Continued pressure is the same memory staying awake — a probe that confirms the source is still there, a record that does not expire because the attacker went quiet for a week. Quiet is not innocence. Quiet is a gap the blacklist already covers.
The security a committee can sit today is already on the Memory install. Fail-closed recall sits on the path at ϑ = 0.70. Below that confidence the archive returns not found rather than a fabricated control, a CVE, or a containment state. Every write is admitted. That is why a later edit is visible. The Bouncer is the edge written to protect that store — detect, block, and hit back so the archive stays the archive.
House doctrine, later ops
This page is house doctrine and later mesh ops — how the edge wants to fight once the archive is on the floor. Isolated recall on a quiet machine is 13.834 µs. Under load we have also seen 5,127 µs. Those are memory clocks. We show both. They are the speed of the archive the edge is written to protect.
$20 million is an ask — not cash in hand and not a secured close. About eighty-five percent of that ask is product, deploy, evidence, and credits: the factory that can prove memory, fail-closed behavior, and an air-gap path. There are no customer logos yet. That is why the seed exists. The buyer already feels fail-closed recall, admitted writes, and air-gap. The Bouncer is the perimeter those three deserve.
Sources: Trinity Sky, Security Bouncer (docs/whitepaper-security-bouncer/chapters/). Detect / block / counter-offense, distributed sensing, fingerprint persistence, and mesh isolate are paper features. Isolated 13.834 µs and loaded 5,127 µs shown together as memory clocks. House doctrine / later ops. $20 million is an ask.