The third adaptive hybrid system

Protection does not stop at the device.

Citadel coordinates protected routing, DNS, containment, privacy-safe evidence, endpoint controls, and optional two-hop separation across one governed Internet journey.

  • Standalone or integrated
  • Client + server
  • One-hop or two-hop
A luminous information path moving through a sequence of Citadel protection boundaries and two gateway nodes
Journey viewRepresentative architecture

One tunnel.Multiple coordinated defenses.

Current truth.Not a decorative “connected” badge.

Bounded claims.Every capability carries its evidence state.

One protection fabric

Adaptive by design.
Honest by operation.

Citadel changes form without changing its responsibility: protect the approved journey, report what is actually happening, and avoid silently interrupting desired traffic.

Current / validated scope POC / under qualification V2 / standby
01

Standalone or integrated

Use Citadel as its own protection client or embed the governed protection boundary inside an application.

02

Android, Linux, Windows

One product family with platform-specific artifacts and qualification states—not one-size-fits-all claims.

03

Client and server defenses

Endpoint consent, route truth, gateway enforcement, continuity, and evidence work as separate observable responsibilities.

04

One-gateway or two-hop

Start with direct protected egress or select ingress/egress separation when the approved service tier requires it.

The system in one view

One dominant idea.
Details when you ask for them.

The architecture remains available to technical buyers without forcing every customer to decode it before understanding the benefit.

Citadel shown across standalone and integrated deployment, three operating systems, client and server controls, and one-gateway or two-hop routing

Protection that proves itself

“Running” is not the same as protected.

Citadel separates the signals that security products too often collapse into one reassuring icon.

01

Configured

The customer requested protection and an approved configuration exists.

02

Interface

The protected network interface is present.

03

Handshake

The peer exchange is current—not stale.

04

Traffic

Receive and transmit counters prove useful movement.

05

DNS

Resolution follows the approved protected path.

06

Egress

The public exit matches the selected route class.

A customer-facing dashboard is part of the product direction. Any displayed measurements must be identified as real evidence, representative data, or demonstration data.

Live threat evidence

What Citadel has stopped.

Only signed, production-observed blocks that meet the public privacy threshold appear here. Laboratory tests, demonstrations, raw addresses, customer identifiers, and small identifying buckets are excluded.

Checking verified evidence
Aggregate feed
Verifying the feed…

The live ledger is below its privacy threshold or has no eligible signed production events.

UIA means Unclassified Intrusion Attempt. Classification is evidence-led; automated analysis advises, while deterministic policy controls what can be published or enforced.

Independent connection tests

See what the outside world can observe.

Run these third-party checks with Citadel enabled, then compare the results with your approved route and DNS configuration. Each test supports specific ring evidence; none certifies an entire ring by itself.

Ring 01 AegisRing 02 TrueNorthRing 08 Infrastructure

IPLeak

Inspect the public IPv4/IPv6 address, visible DNS resolvers, and WebRTC exposure.

Open independent test
Ring 02 TrueNorthRing 03 Gatewatch

DNSLeakTest

Run a standard or extended test to see which DNS resolvers are visible outside the protected journey.

Open independent test
Ring 02 TrueNorthRing 03 Gatewatch

BrowserLeaks DNS

Inspect browser-visible DNS resolution and compare it with Citadel's approved resolver path.

Open independent test
Ring 01 AegisRing 05 Veil

BrowserLeaks WebRTC

Check whether the browser exposes another public address outside the selected Citadel route.

Open independent test
Ring 02 TrueNorth

Cloudflare Connection Information

Review resolver and encrypted-DNS characteristics reported by an independent network service.

Open independent test

These tests are operated by independent third parties. Their privacy policies apply when you leave the Citadel website. Citadel does not transmit your account identity to these links.

Route architecture

Choose the journey—not the jargon.

CoreOne-gateway
DeviceIngress + egressInternet

Protected transit and public-IP masking through one registered Citadel gateway.

Two-hop separation does not erase identity supplied to a destination, defeat authenticated accounts or cookies, or promise legal untraceability.

Citadel defense sequence

Ten rings. Ten honest states.

Evidence status is assigned by ring. Citadel’s ten-ring architecture should not be described as wholly deployed, universally qualified, or independently certified.

01

Aegis

Protected transit

Production-proven within the registered evidence scope
02

TrueNorth

Protected DNS

Production-proven within the registered evidence scope
03

Gatewatch

Resolution defense

Production-proven within the registered evidence scope
04

Sentinel

Behavior containment

Production-proven within the registered evidence scope
05

Veil

Minimized evidence

Production-proven within the registered evidence scope
06

Mirage

Bounded deception

Production-proven within the registered evidence scope
07

Obscura

Screen privacy

Client validated · server counterpart not deployed
08

Infrastructure Defense

Egress defense

Production-proven within the registered evidence scope · POC observation continues
09

Identity Cloaking

Edge tokenization

Standby · not integrated or deployed
10

Device Assurance

Device and key posture

Stage G v2 corpus-verified · managed continuity frozen design only · not deployed, activated, or qualified

Citadel products

Protection where the journey begins.

Release downloads will appear only after the corresponding artifact is approved, signed, and registered.

ANLaboratory tested

Citadel for Android

Standalone and application-integrated protection for Android and Android TV.

LIBuilt · evidence-specific

Citadel for Linux

amd64 and arm64 client surfaces with operator-managed service integration.

WIBuilt · qualification pending

Citadel for Windows

A staged client surface that preserves the existing Windows application.

MIProtected by Citadel

Citadel for MiraTV

A working integration that demonstrates Citadel without defining its limits.

M

Integration showcase

MiraTV.
Protected by Citadel.

MiraTV demonstrates that Citadel can protect a demanding customer application while activation, playback, series, VOD, and application sessions remain owned by the application itself.

Commercial readiness

Built for a responsible launch.

Checkout will activate only after product tiers, fulfillment, refunds, tax, privacy, release custody, and support responsibilities are approved.

Card

Credit and debit cards

Provider-neutral checkout integration point with no payment data stored by the marketing site.

Integration placeholder
Crypto

Cryptocurrency capability

Policy-reviewed payment option with explicit settlement, refund, jurisdiction, custody, and accounting controls.

Architecture placeholder
License

Business and embedded

Managed deployment, application integration, OEM, white-label, and infrastructure licensing paths.

Commercial design pending

The claim ledger

Confidence without mythology.

What Citadel is designed to do

  • Protect approved Internet-bound journeys
  • Expose current route and traffic truth
  • Separate ingress and egress when selected
  • Minimize routine protection evidence
  • Recover visibly from interruption

What Citadel does not claim

  • Absolute anonymity or untraceability
  • Root-proof or kernel-proof secrecy
  • Protection outside the selected route
  • Defeat of destination logins or cookies
  • Production status for roadmap capabilities

A new standard for visible protection

Protect the journey.
Prove the protection.

Citadel is moving through controlled qualification. Downloads, commercial availability, and checkout will open only when their evidence and operating responsibilities are ready.

Review availability