01 / CHECK
Check who may do what
At connected processing boundaries, Ardamire checks identity, current authority and the permitted request state. Failed checks stop the affected request and retain the reason for investigation
PROTECTS AUXTHO / INTERNAL DEFENCE LAYER
Ardamire is Auxtho's implemented internal defence layer. It checks who may act, on which target and in which state. Related signals, specific holds and recovery records stay connected so operators can investigate an exception and restore permitted work with its history intact
See the Auxtho productArdamire — connecting the affected file with hold reasons and recovery history
Edited image based on Auxtho's internal Console · owned QA case
PRODUCT / TECHNOLOGY / RESEARCH / Ardamire Defense Layer
From a refused request to authorised recovery, keep the affected target, the reason and the recorded outcome together
01 / CHECK
At connected processing boundaries, Ardamire checks identity, current authority and the permitted request state. Failed checks stop the affected request and retain the reason for investigation
02 / HOLD
Ardamire ties the issue to a specific file or operation. Targeted containment governs that target; unrelated work is checked separately. In the designated PDF test, the held PDF was blocked while the same job's JSON remained available
03 / RECOVER
An authorised operator verifies the current file and hold before releasing its quarantine. Recovery preserves the file's approved content and records the reason, operator and time in the same incident. File recovery and incident closure are separate decisions
IMPLEMENTED CAPABILITIES
Case-scoped evidence candidates, progress, questions requiring human judgment and handoff records stay in one investigation context
Ardamire Agent answers questions about supported Console contexts and points staff to the next checks. Other routes provide Screen Help; decisions remain in authorised workflows
Entry connects recorded work to review, handoff and Lab. Separate re-execution and result comparison preserve the original record; Ardamire’s target-specific path presents verification and baseline evidence
Execution-summary signing and verification connect with case-specific evidence packs that operators can inspect alongside the investigation
File recovery and incident closure are distinct. In this capture, the file is released while the associated incident remains open
What has been verified
Recorded first-party cases connect identity and request checks, targeted containment, execution evidence and authorised file recovery
Open the record
Recorded controlled tests linked related authentication signals to stronger checks and targeted holds. Own-server tests rejected unknown operators, wrong token issuers and replay requests that did not meet the required state. A separate local workflow excluded invalid replay evidence and required a different authorised reviewer before a disabled defensive proposal returned to shadow evaluation; production rules were unchanged
A bounded own-server test detected a changed hash, contained the affected artifact/export, used real execution-summary signature verification and checked the evidence pack against the same incident. The unrelated comparison target remained outside containment
A controlled mismatch in the designated PDF's file-format metadata caused download refusal and an incident record. After that metadata was restored, the PDF was separately quarantined and released by an authorised operator. Downloads before and after recovery matched byte for byte; the same job's JSON remained unchanged and available during the PDF hold. The App and Console retained the linked recovery history
The selected policy is now bound to re-execution judgment and the result record in the local implementation. Targeted backend and UI checks passed
Local implementation and verification are complete. Hosted rollout and acceptance of this new connection remain separate
First-party tests of identified Auxtho paths, not a named financial-breach reproduction or independent certification. The October 9 case changed file-format metadata, not PDF content. Releasing a file did not close the incident; Replay does not automatically choose the best policy or authorise production changes
In development
START WITH THE WORK
Tell us about one document workflow, one review decision, or one task you need to keep under human direction. Start with the problem—not a list of features
Talk to Auxtho