Invariant Vector Defense

Two control planes for two forms of systemic cyber risk.

IVD-N controls coordinated malicious traffic before network convergence. IVD-ACP controls malicious or non-admissible execution influence before indexing, persistence, or action.

IVD-N: distributed evidence becomes one bounded attack object, a governed mitigation decision, and an auditable lifecycle.

IVD-ACP: artifacts, commands, retrieved content, memory writes, and tool actions receive explicit authority before they can influence execution.

Two filed U.S. non-provisional patent applications. Controlled validation across network and execution domains. Independent third-party verification and validated reproduction within defined scope.

Portfolio Strategy

Different growth profiles strengthen the same company.

IVD-ACP | Near-term commercial engine

Broader buyer base. Bounded integration surfaces. Faster pilot path.

ACP can enter through one RAG ingestion gate, agent-tool boundary, CI/CD workflow, administrative API, or privileged automation surface without requiring carrier participation or router-policy change.

Its commercial advantage is breadth. Its competitive burden is proving that deterministic admission, authority state, durable policy, and replay are more valuable than bundled prompt screening.

IVD-N | Long-duration infrastructure asset

Narrower buyer set. Deeper infrastructure integration. Potentially stronger scarcity.

IVD-N requires more demanding network access, router validation, and operator trust, but addresses a high-consequence control-plane problem with a distinctive architecture and strategic relevance to carriers, critical infrastructure, and federal networks.

Its commercial burden is validation friction. Its potential advantage is deeper infrastructure defensibility once operationally proven.

Why Now

Networks are automating mitigation while software systems are automating execution.

Network risk

Attack traffic converges faster than manual policy can respond.

Distributed attacks are larger, more adaptive, and more costly once they reach downstream chokepoints. Automation helps only when install, scope, expiry, withdrawal, rollback, and audit are governed.

Execution risk

External information is increasingly converted directly into action.

AI agents, RAG systems, administrative APIs, CI/CD pipelines, and automated workflows can turn retrieved content or artifacts into privileged behavior. The control question is whether that influence should become execution-eligible at all.

In both domains, detection alone is no longer the central issue. The issue is whether harmful behavior becomes operational before a trusted control plane intervenes.

Two Commercial Products

One control-plane doctrine. Two distinct buyer problems.

IVD-N

Network control before attack convergence

IVD-N identifies coordinated behavior across distributed observations, forms a canonical attack object, and translates that object into bounded upstream mitigation. The value is not FlowSpec alone; it is the governed chain from evidence to install, expiry, withdrawal, rollback, relief, and reconstruction.

  • Control and evidence plane can govern IVD or third-party telemetry
  • Distributed invariant-pattern detection and macro-object synthesis
  • Policy generation independent of source cardinality
  • Identity-aware relief and tamper-evident evidence

Explore IVD-N

IVD-ACP

Execution admission before trust and action

IVD-ACP evaluates artifacts, commands, retrieved content, memory writes, and tool actions before they become execution-eligible. It assigns bounded authority states and preserves durable, replayable enforcement records outside the system seeking permission to act.

  • Pre-index, pre-persistence, and pre-execution policy gates
  • Explicit READ_ONLY, SANDBOXED, or QUARANTINED authority
  • Deterministic replay, quarantine, and audit reconstruction

Explore IVD-ACP

Buyer Value

Infrastructure value, not another alert stream.

IVD-N economic case
  • Reduce the time between distributed attack formation and bounded mitigation
  • Reduce rule sprawl, policy churn, and withdrawal uncertainty
  • Improve rollback, operator review, and incident evidence quality
  • Complement existing scrubbing and downstream network-defense investments
IVD-ACP economic case
  • Prevent unsafe influence from becoming a trusted system input
  • Reduce the blast radius of agent, automation, and supply-chain failures
  • Create durable authority-state and quarantine records
  • Apply one control discipline across multiple models, tools, and execution surfaces
Shared Control-Plane Doctrine

Observe. Decide. Enforce. Preserve the evidence.

IVD-N
Distributed traffic evidence
Canonical attack object
Governed mitigation lifecycle
IVD-ACP
Artifact / command / tool action
Admissibility decision
Bounded execution authority
Current Status

Built, validated, and commercially offered are different claims.

ProductBuiltControlled evidenceCurrent commercial path
IVD-NPrototype control-plane systemMacro-object, policy, multi-vendor virtual-router, and mitigation-lifecycle evidencePaid technical evaluation, design partnership, and licensing discussion
IVD-ACPPrototype admission-control systemPre-index, authority-state, execution, replay, restart, and quarantine evidence within defined scopePaid protected-surface evaluation, design partnership, and licensing discussion

IVD maintains a TRL-6 public baseline. Controlled evidence and independent third-party validation do not constitute production deployment, accreditation, completed federal-lab validation, physical provider-edge validation, or a blanket TRL-7/TRL-8 claim.

Patent Position

Two filed patent families. Separate markets. Shared doctrine.

Review IP status
IVD-N patent family

Network control-plane architecture

Directed to distributed invariant-vector detection, macro-object synthesis, bounded upstream mitigation, service-aware relief, and related control-plane coordination.

IVD-ACP patent family

Execution control-plane architecture

Directed to pre-index and pre-execution admissibility control, authority-state enforcement, quarantine, replay, and separation of decision authority from execution.

Patent applications are pending. Claim scope remains subject to USPTO examination; these summaries are illustrative and do not define the claims under review.

Commercial Pathways

Designed for evaluation, direct deployment, and platform integration.

Technical evaluation

Defined-duration review with test plans, evidence packages, technical documentation, and bounded acceptance criteria.

Design partnership

Controlled IVD-N or IVD-ACP deployment against one protected domain, surface, workflow, or operational environment.

OEM and licensing

Potential integration into network-security, routing, cloud, AI-security, SaaS, and automation platforms.

Strategic development

Investment or corporate partnership to accelerate field validation, hardening, patent strategy, and go-to-market execution.

Review engagement paths

Platform Fit

A common control-plane doctrine across network resilience and execution integrity.

IVD is designed for direct deployment, design-partner evaluation, and potential integration into established network-security, AI-security, cloud, routing, and automation platforms. The two products share architectural discipline and evidence infrastructure while retaining separate buyers, deployment paths, and commercial models.

Strategic Development Priorities

What capital and the right operating partners accelerate.

Field validation

Physical provider-edge and real-traffic shadow-mode validation for IVD-N.

Protected-surface pilots

Live RAG, agent-tool, CI/CD, or privileged-automation evaluation for IVD-ACP.

Platform hardening

High availability, multi-tenancy, integrations, operator workflows, and continued patent prosecution.

Resources

Technical diligence without burying the business case.

View all resources
White Paper

Unified Architecture White Paper

Unified overview of IVD-N and IVD-ACP as complementary security architectures.

Download PDF
White Paper

IVD-ACP White Paper

Technical overview of the Admissibility Control Plane for pre-execution and pre-index control.

Download PDF
Library

Exploit / Remedy Card Library

Canonical exploit-card destination with technical exhibit previews and full-screen timelines.

View library
Federal Posture

Federal Evaluation

TRL-6 validation scope, review posture, and evaluation boundaries.

Review
Simulator

Run the Architecture Simulator

See how IVD-N and IVD-ACP make bounded, auditable policy decisions. The simulator illustrates doctrine; it is not a production environment or validation substitute.

Open simulator
Strategic Engagement

Evaluate the technology. Integrate the platform. Help define the category.

IVD is engaging qualified evaluators, design partners, strategic investors, federal and critical-infrastructure stakeholders, and platform companies interested in network resilience or execution integrity.