Keelson Labs

Product

Two pieces, one guarantee.

A protected delegation device in a person’s hand, and an enforcement appliance your own servers cannot reprogram. The card does not decide whether an effect may happen. The controller does.

Layer 1 · the card

The effect card

A protected delegation device, not the authorization system. It holds a non-exportable key in a secure element, is registered to a named principal, and releases exactly one token per physical press or tap.

  • Challenge-bound. The controller issues a challenge carrying the manifest hash and a nonce; the token answers that challenge and nothing else. It cannot be cached, relayed, or spent after the card is removed.
  • Domain-scoped and expiring. Valid for one controller domain and one short epoch. No globally spendable tokens.
  • Trusted display, for high value. A card without a screen can be tricked by a compromised reader. High-value grants use a verified reader with its own display showing the real transaction.
  • Attributable. Every token traces to a principal and a grant.
The controller

The effect controller

A sealed appliance on a proven microkernel, running on its own board in your data center, the way an HSM already does. Your servers can ask. Only the controller can release.

  • Its own sensors. It reads the state of the world directly, and never trusts the host’s account of it.
  • Its ledger is the truth. Not the card’s counter. Consumption is recorded once, under delegation, concurrency, retry and restart.
  • Physically gated updates. Maintenance ports, firmware updaters and management controllers sit behind the same boundary. There is no bypass path.
  • It logs everything, and refuses everything it did not admit.

The four checks

Run separately, in order, for every proposal.

A matching manifest is not sufficient. The controller also has to know who authorized that manifest, and why the authorization applies to this resource.

01

Resource authorization

A grant exists for this principal, this action, this resource. No protected effect happens without an applicable grant, and delegation can only ever shrink one.

02

Token validity

Correct challenge, correct domain, current epoch, unspent. A replayed token, an off-domain token, and a token released without a press are all refused.

03

Remaining budget

Per resource and multidimensional. There is no universal effect unit: a config change and a database export are not comparable, so envelopes name what actually varies: records, recipients, instances, duration, cumulative disclosure.

04

State-dependent constraints

Is this transition admissible from the current state, as the controller’s own sensors report it? Safe trajectories, not merely safe end states: two acceptable valve settings can have an unacceptable transition between them.

Threat model

Assume the host is already lost.

Untrusted

The host side

The application host, its operating system, the AI agent and the card reader can all be owned by the attacker. They can send the controller hostile input. They cannot administer it, rewrite it, or press a button they do not hold.

What an attacker must defeat

The enforcement side

A controller on its own board with its own sensors and ledger; an assurance chain from the authority model through the implementation and configuration to the executor; updates only through a physically gated path; and an executor that refuses anything not admitted.

With full control of the host, an adversary cannot create authority, spend it twice, redirect it to another resource, or exceed the approved envelope, under stated assumptions. Never “impervious.”

Deployment

One gate per critical operation, in five parts.

Hardware makes the guarantee possible. Software fits it to your environment. The assurance evidence is what your auditors and regulators read. It is an appliance, not a cloud service.

PartKindWhat it is
Enforcement applianceHardwareA sealed box in your data center, like an HSM. Your servers cannot reprogram it.
Approval keysHardwareOne per approver, reusable. The high-value version shows the real transaction on its own screen.
ConnectorSoftwarePlugs the appliance into the payment, change or command system, and closes every side route around it.
Rules consoleSoftwareWhere you write limits, envelopes and approvers. Changing the rules takes a stronger ceremony than using them. Feeds audit logs.
Assurance subscriptionServiceUpdates, support, and independent test evidence for regulators and auditors.
Pilot and licence terms are set per engagement against your gate, your integration and your evidence requirements. We publish no price list while the first pilots are still establishing what a gate actually costs to deploy.