Where We Stand

You were never supposed to carry this alone.

For thirty years, the working agreement between you and the internet has been that your safety online is your responsibility. Install the antivirus. Change your passwords. Don't click the link. Turn on two factor. Update your software. Watch for phishing. Patch your router. Audit what apps you grant permission to. When something goes wrong, the failure gets treated as yours. We do not think that was ever a fair arrangement, and we do not think it is going to hold for another five years.

This page is not a pitch. It is us stating plainly what we believe about the work you have been expected to do, the industry that has been charging you to help you do it, and where we think the honest next move goes. If you read it and agree, the rest of the site tells you what we sell. If you read it and disagree, that is fine. You are welcome back later.

The weight you have been carrying

The security hygiene the industry asks an ordinary person to practice is a professional discipline that takes full time security engineers several years to learn well. Password policies, session management, network segmentation, threat modeling, patch cadence, data minimization, incident response. These are the skills of a career. The expectation that a parent, a small business owner, a college student, a retiree, and a kid with a laptop will each run a capable version of that discipline on the side of their actual life has always been unrealistic.

The fact that most people have mostly been fine most of the time is not because the arrangement worked. It is because attackers had bigger targets to go after first. That calculus is changing quickly. The cost of attacking an individual has dropped to near zero. Automation handles what used to take human effort. Credential stuffing, session hijacking, targeted phishing, fake updates, malicious browser extensions, these operate at industrial scale now, against whoever has not kept up with the full time job of defending themselves. The industry's answer has been to sell you more tools. The tools have helped. None of them have closed the underlying gap, because the underlying gap is not a missing tool. It is that the ground you are standing on was not designed to protect you from what is now possible on it.

The new weight

In the last two years the load got heavier in a way almost nobody has acknowledged honestly yet. You are now building things with tools that were science fiction in 2022. Coding assistants write programs you did not fully write. Local models run on your hardware with access you may not have intended to grant. Agents take actions on your behalf, send messages, move files, fill out forms, call external services. If you are a person shipping small projects with an assistant, a hobbyist running a local model on your own hardware, or a household using a voice assistant that answers your kids, you are doing work that sits in a security space the industry has no mature vocabulary for yet.

The specific shapes of the new risk are worth naming, briefly. Content that one AI reads can include instructions that change how that AI behaves, which means anything on the public web can quietly turn into a set of commands aimed at the model you are using. Information you type into an assistant can end up in places you did not intend, through channels you were not warned about. Code an assistant generates can contain patterns that look correct and are not, and you can ship them before the problem becomes visible. None of these are exotic edge cases. They are Tuesday.

The existing consumer security industry does not have a mature answer for any of this. It will, eventually. The question is whether you want to keep carrying the weight while they figure it out.

Our position, stated plainly

The arrangement where the individual is responsible for their own defense was structurally wrong when it was established, and it has become architecturally impossible now. No amount of user education closes the gap. No collection of tools closes the gap. The gap exists because the substrate computers run on was not built with identity or integrity as native properties. Every security product you have ever paid for exists to compensate for that fact.

We do not think the answer is more compensation. We think the answer is to change the substrate. What we sell on this site is a protection layer that operates inside the substrate that exists today and shields the devices you already own. That is real and we stand behind it. What we are also building, and what this company exists for in the longer frame, is the substrate that replaces the one you have been asked to live on. A mathematical field where identity is intrinsic, where addresses cannot be spoofed, and where most of the categories of attack you have been defending against cannot occur. When you are ready, you are welcome in it.

About the line

There is a conversation happening in the broader security community about who is on which side of the fence, and we want to be direct about where we stand on that conversation, because you will hear echoes of it whether you follow it closely or not.

We are not accusing researchers of anything. People who look for flaws in systems have been doing legitimate and necessary work for three decades, and the public internet is more trustworthy today than it would be without them. We are not threatening anyone who has worked on the offensive side of that same fence. We are not positioning ourselves as a new authority over any of it.

What we are saying is that the ground is changing. Participation in the field we are building is a privilege the field itself extends, based on the integrity each participant brings with them. What the field observes, it governs. This is not surveillance. It is not enforcement. It is the physics of how the substrate works. Participants whose behavior undermines the field lose cryptographic continuity with it automatically, not because anyone is watching and judging, but because the field is self healing and the mathematics does not accommodate incoherent participants.

What that means for you, reading this as an individual, is that the adversaries you have been defending yourself against do not follow you into the field. They cannot. The room where this has all been happening is not being defended harder. The room is emptying.

If you take nothing else from this page, take this. You have been doing something hard, mostly alone, for a long time, with tools that were never quite enough. We see that. We do not think it was your fault, and we do not believe the industry that billed you for the experience has a plan for getting you out of it.

You have been alone with this long enough.
You do not have to be.