Zentropy Labssecurity products

Security systems, each named for its actual job.

The work spans public security products, verification infrastructure, and a private operational line. Each project keeps its own runtime, capability, maturity, dependencies, and audience.

Every promoted item has a record in security-tools.json. Unknown release or CI state stays unknown until revalidated.

evidence through 2026-08-28 · shipped / active / toolkit / controlled-private

Public security maturity index.

Public systems Phantom v1.1.0 and EMET v1.2.0 have verified public releases. Accountable Surface is public source 0.1.0 with no release claim. Proof Surface is public source 0.2.0 with no release claim.
Toolkit Security toolkit: grouped review, redaction, provenance, and public-surface utilities with honest unknowns where release state has not been revalidated.
Product and theory Accountable Surface is the product route. Accountable Machines is the companion theory route.
Authorized private practice Private-system index: Array, Seed, Sofer, Isomorph, Bounds, Kun, ORCA, and Gate are distinct products for controlled campaigns, native assessment, orchestration, inference testing, trust verification, access recovery, execution, and release authority.

Private operational systems.

Array controls authorized campaigns and assessment waves. Seed supplies the native C++23 assessment engine. Sofer coordinates private-line agents, models, probes, tools, and domain packages. Isomorph tests model refusal and jailbreak-class inference boundaries. Bounds verifies agent, runtime, and release trust. Kun records path-only access-recovery memory without retaining raw credentials. ORCA operates engagement state, modules, findings, reports, and bundles. Gate decides whether the connected line is ready to release or hand off.

Read the capability-level practice map. It describes what each project does while keeping targets, credentials, live payloads, client data, and engagement findings private.

Authorization boundary.

Public tools may be read and run within their licenses and documented limits. Written authorization first: private security practice begins only after written authorization, written scope, and lawful authority are established. This page does not publish source for private systems, counterparties, sensitive deployment detail, target specifics, or operational methods.

A request without a lawful basis receives only public material.

Data-backed claims.

The claim registry is public: security-tools.json. It records purpose, maturity, source, install or entry route, verification command, evidence date, limitations, and authorization boundary for each promoted item.

Public: Phantom · Accountable Surface · Proof Surface · EMET  ·  Toolkit: Security toolkit  ·  Private: System index · Array · Seed · Sofer · Isomorph · Bounds · Kun