Atomic Authority
Technology Solutions Company Research Talk to us
ATTESTED ZERO TRUST

Authorization as an independent, hardware‑enforced security boundary.

Modern authentication already answers who you are, quickly and well. The slow, fragile part is deciding what you may do. AZT moves that decision onto a trust anchor the requesting software cannot subvert, and signs a receipt either way.

Talk to us Read the architecture
BUILT ON NIST SP 800-207NIST NGACseL4FIPS 140-3IETF RFC 9334 (RATS)FIPS 203/204/205CNSA 2.0W3C PROV-O
THE STRUCTURAL WEAKNESS

Today's systems equate authorization with possession of a valid credential.

01 / THE PROBLEM

Once software authenticates, it is treated as authorized. A compromised application, a coerced operator, or a subverted AI holding valid credentials acts within that authority while appearing fully legitimate. The access decision is made inside the same software environment that issues the request.

02 / THE BOUNDARY

AZT moves authorization outside the host. A policy decision point runs inside a formally verified separation microkernel, roughly 10 kLOC of trusted computing base with machine-checked isolation proofs, measured and attested by a FIPS 140-3-class programmable secure element.

03 / THE EVIDENCE

Every grant and every denial produces a signed, tamper-evident receipt, hash-chained into an append-only evidence ledger. You get the immutability and independent verifiability associated with blockchains, with no consensus-liveness dependency.

04 / DISCONNECTED BY DESIGN

Per-flow attested channel tokens are enforced from cache: millisecond data tempo, no round-trip in the hot path. The system works fully disconnected, where cloud-tethered Zero Trust products fail or fail closed.

TECHNOLOGY

Anatomy of an access decision

Five steps, none of which trust the software that asked.

01
A request arrives with a valid credential. Authentication is the solved part of the problem. Authority is not assumed from it.
OIDC / PKI /
CAC-CLASS
02
The requesting host is measured. Device-agnostic remote attestation establishes what is actually running before it is allowed to ask, and onboards heterogeneous fleets without new silicon.
IETF RATS
RFC 9334
03
The decision runs outside the host. The policy decision point executes inside a formally verified separation microkernel, itself measured and attested by a programmable secure element. The mission software cannot reach the policy, the keys, or the log.
seL4 · ~10 kLOC TCB
FIPS 140-3-CLASS SE
04
An attested channel token opens the compartment. Data lives in micro-segmented compartments with per-compartment cryptographic keys. Tokens are enforced from cache at millisecond tempo; there is no round-trip in the hot path.
PER-FLOW TOKENS
NGAC POLICY
05
A receipt is signed either way. Grant or denial, the decision is hash-chained into the evidence ledger. Anyone with the anchor's public key can verify, offline, that the approved policy and only that policy made each decision.
HASH-CHAINED
W3C PROV-O
UNTRUSTED HOST ENVIRONMENT HOST / OPERATOR / AI AGENT 01 PROPOSES · ATTESTED FIRST 02 03 · DECISION BOUNDARY seL4 PDP ~10 kLOC TCB · NGAC SECURE ELEMENT 04 · ATTESTED TOKEN COMPARTMENT A · KEY a COMPARTMENT B · KEY b COMPARTMENT C · KEY c DENIED SIGNED RECEIPT · GRANT OR DENIAL 05 · EVIDENCE LEDGER HASH-CHAINED · APPEND-ONLY · VERIFIABLE OFFLINE

What ships

Decision boundary

Policy evaluation isolated in a formally verified microkernel, measured by a secure element. Independent of the OS, the application, and the network.

Micro-segmented compartments

Per-compartment cryptographic keys with enforcement points guarding each compartment. Compromise of one grants nothing about the next.

Evidence ledger

Append-only, hash-chained, independently verifiable. Auditable after the fact without trusting the operator, the vendor, or us.

Advisory AI, bounded adaptation

Analytics emit signed risk signals that drive pre-authorized, bounded adaptation. They advise; they never grant.

Retrofit without new silicon

Deploy as a hypervisor beneath an existing OS, or as an inline bump-in-the-wire enforcement appliance in front of systems that cannot change.

Post-quantum ready

Signature and key-establishment paths track FIPS 203/204/205 and NSA CNSA 2.0 so evidence stays verifiable for the life of the record.

WHAT WE CLAIM, PRECISELY

The building blocks are mature and independently validated; our contribution is the integration. Formal proofs cover specific, stated configurations, not everything we ship. Where an assurance has limits, we will tell you where they are.

SOLUTIONS

One architecture, wherever software or AI is granted authority over sensitive data.

DEFENSE & NATIONAL SECURITY

The DoD Zero Trust mandate assumes connectivity that contested environments do not offer. AZT makes and proves access decisions with no cloud tether, on disconnected, degraded, intermittent, and limited links.

FINANCIAL INFRASTRUCTURE

Digital-asset custody already runs on verify-then-release governance, and regulators already expect hardware-rooted controls. AZT gives every release a hardware-attested decision and an independently verifiable receipt.

AGENTIC AI GOVERNANCE

As enterprises delegate authority to agentic software, the question becomes what an agent may do, provably, on systems that matter.

AI may propose; the trust boundary decides.

COMPANY

Built by people who ship trusted systems

Atomic Authority Inc is a Delaware corporation based in Vancouver, Washington, founded on a simple observation: the access decision should not live inside the software that asks for it.

Blake Regalia
FOUNDER & PRINCIPAL INVESTIGATOR

Ph.D. in data science and graph database systems (UC Santa Barbara). Five years at NASA JPL as lead developer of a transactional, version-controlled graph DBMS for spacecraft systems engineering. Chief engineer of a fielded non-custodial privacy router built on TEEs, threshold ECDSA, and zero-knowledge proofs; security researcher and technical advisor on systems securing over $1B in digital assets. Author of constant-time cryptographic implementations and 20+ peer-reviewed publications.

CONTACT

We are in active design-partner discussions.

If your organization releases value, grants access, or delegates authority to software, we would like to compare notes.

blake.regalia@atomic-authority.com
VANCOUVER, WASHINGTON
Atomic Authority Inc · Delaware · © 2026
Technology Solutions Company