VENTEX / SECURITY DIGITAL TWIN
VX / MIRROR / M90Security digital twin · continuous assurance

See infrastructure as it actually was.

Mirror turns defensive observations into a local, time-aware infrastructure model. It reconstructs state, explains change, rehearses candidate controls on isolated copies and keeps integrity, authenticity, authorisation, freshness and historical completeness as separate, visible claims.

01M90engineering milestone
02280+test modules in state
03LOCALcore and operator model
04READ-ONLYcurrent operator boundary
Advanced engineering pre-alpha · operator path implemented

The reviewed state implements the temporal graph, Chronicle, diff, exposure, rehearsal, evidence and assurance layers plus a local read-only operator interface. Production, remote or multi-user operation and real deployment qualification are explicitly not yet approved.

STATE, TIME AND EVIDENCE

A security model that does not forget its past.

The current graph is only a materialised view. The Chronicle ledger preserves canonical observations as an append-only SHA-256-linked history; snapshots and event-time reconstruction make visible what was known at a specific point in time and which evidence supports that view.

Mirror is deliberately not a vulnerability scanner, exploitation framework, autonomous remediation system or replacement for a SIEM or EDR. It models, verifies and rehearses defensively—without inventing universal risk or security scores that the available evidence cannot support.

CAPABILITY REGISTER

What the current product line actually supports.

01Implemented

Temporal infrastructure graph

Canonical assets, relationships, trust zones, identities, roles and data flows are modelled deterministically. The current graph remains separate from the historical source.

02Implemented

Chronicle, snapshots and time travel

Append-only history, anchored snapshots, event-time reconstruction and structural diffs answer not only what exists, but what was different and when.

03Implemented

Defensive exposure and rehearsal

Defensive paths, blast radius and service impact are derived from explicit relationships. Candidate controls run only on isolated state copies and remain behind approval boundaries.

04Implemented

Evidence-backed assurance

Security claims bind to concrete evidence, checkpoints and validity rules. Integrity, signature authenticity, key trust, freshness and completeness remain machine-readable and separate.

05Implemented

Offline verification and federation

Versioned documents, bundles, verification receipts, deployment profiles and federation snapshots can be checked without a cloud dependency and reconciled across separate Mirror deployments.

06Implemented

Operator time-travel UI

The local read-only interface correlates T1/T2 graph, Chronicle timeline, state change, exposure reasons, evidence, entities, rehearsal and assurance in one navigation path.

ARCHITECTURE

Observation becomes state. State becomes evidence-backed history.

The layers prevent a convenient statement from imitating a stronger form of evidence. Observation, materialisation, derivation, signature, key trust, transfer and receipt remain separate trust decisions.

OBSERVE

Collectors and imports

Read-only host, Docker, Git and network adapters normalise observations with provenance, redaction, freshness and confidence.

01
MODEL

Graph and Chronicle

The graph materialises current state; Chronicle preserves canonical observations with linked integrity and event time.

02
EXPLAIN

Diff, exposure and rehearsal

Point-in-time comparison and defensive simulation derive change without automatically turning it into severity or remediation.

03
PROVE

Proof, assurance and exchange

Claims, checkpoints, offline bundles, federation, release provenance and authenticated history segments keep their proof boundaries explicit.

04
OPERATOR WORKFLOW

From observed state to a verifiable explanation.

  1. 01

    Acquire observations

    Authorised defensive sources provide normalised facts. Provenance and redaction are recorded at the collection boundary.

  2. 02

    Reconstruct T1 and T2

    Mirror verifies Chronicle and snapshot anchors, materialises both event-time states and computes a deterministic structural diff.

  3. 03

    Explain and rehearse change

    Exposure reasons trace to concrete graph edges and observations; candidate controls alter only an isolated simulation.

  4. 04

    Export and verify evidence

    Versioned artefacts preserve exact digests, policies and unproven prefixes. A recipient can verify them offline without assuming stronger history.

WHAT MIRROR DOES NOT CLAIM

Proof boundaries are part of the product—not fine print.

Mirror deliberately separates what a hash, signature, authorised identity, fresh observation and complete history actually prove. The same discipline applies to product maturity.

01

No production approval yet

Advanced engineering pre-alpha means substantial implementation, but not production, enterprise or SLA approval.

02

Loopback rather than remote operation

The current operator API binds only to 127.0.0.1. HTTP Basic/RBAC is a local pre-exposure boundary, not permission for unencrypted multi-user operation.

03

No autonomous remediation

Simulation remains defensive and isolated. Production changes require explicit approval, a deployment adapter and subsequent evidence-based verification.

04

No universal security score

Risk, policy severity, business impact and freshness thresholds belong to the specific organisation and remain deliberately unassessed without deployment policy.

MATURITY

Deep in engineering. Deliberately still before production.

The reviewed branch implements the architecture through M89 and consolidates it in M90 behind stable trust boundaries. The local operator path is navigable end to end; green exact-SHA CI, real deployments and remote hardening remain open product gates.

Implemented in source state
  • Graph, Chronicle, snapshots, event time and diff
  • Exposure, rehearsal, blast radius and service impact
  • Evidence, assurance, offline bundles and federation
  • Local read-only operator UI/API with RBAC foundation
Active qualification
  • M90 trust-layer consolidation with golden equivalence
  • Executable exact-SHA CI for Python 3.12 and 3.13
  • Durable service operation and real collector integrations
Open before production
  • Remote identity, TLS, rate limits and security audit logs
  • Multi-user and deployment credential model
  • Sustained operational qualification
  • Production, enterprise and SLA approval
TECHNICAL RECORD

A local verification core with explicit trust boundaries.

VX / MIRROR / M90
Product model
Security digital twin and continuous assurance
Development stage
Advanced engineering pre-alpha · M90
Runtime
Python 3.12+ · local-first · deterministic core
Persistence and integrity
JSONL Chronicle · SHA-256 hash chains · canonical artefacts
Operator surface
Read-only loopback UI/API · optional local auth/RBAC
Verification model
Offline bundles, signed checkpoints, policies and historical replay boundaries
Non-goals
Not a scanner, exploitation framework, SIEM/EDR or autonomous remediator
Product approval
No production, remote, enterprise or SLA approval
FAQ / FACTS

VENTEX Mirror questions

Short answers with the same status and claim boundaries as the technical product state.

Mirror reconstructs infrastructure state as a temporal graph, compares points in time, explains exposure change, rehearses defensive candidate controls and binds security claims to verifiable evidence. Offline verification, federation, release provenance and case, custody and evidence-delivery artefacts are also implemented in the engineering state.

No. Advanced engineering pre-alpha describes substantial technical depth, but not production, enterprise or SLA approval. Exact-SHA CI, real deployment integration, sustained operation and remote identity, TLS, rate-limit and audit hardening remain open gates.

Sentinel normalises security events and coordinates incidents, hunting, evidence and SOC workflows. Mirror models infrastructure state over time, reconstructs change and verifies which evidence actually supports a technical claim. The two product boundaries remain separate.

Not autonomously. Candidate controls are simulated on an isolated copy of state. A real production change requires explicit approval, a deployment-provided adapter and subsequent verification against actually observed state.

Because technical structure alone does not prove organisation-specific business severity. Mirror can derive paths, change, blast radius and service impact; weighting, policy and risk decisions deliberately remain with the deployment.