Iberion PR Artifact Set v1.0 · Controlled external
A licensable, application-neutral Internet protection architecture — ten coordinated defensive rings, each with its own recorded evidence state.
Artifact A · IBR-PR-A-1.0 · Stage 2, pre-NDA · What Citadel is, why it exists, and what is actually real today.
Citadel is a licensable, application-neutral Internet protection architecture, developed and exercised inside a live production application.
Application-neutral is the important word. Citadel is not a streaming feature, not a browser add-on, and not a product tied to one industry. It protects an approved Internet journey — whatever application happens to be making it. It can be embedded inside another company's product, run standalone on a customer's device, or operated as managed infrastructure on a licensee's behalf.
It is built and owned by Iberion Holdings, the technology-licensing entity within Meridian Group Holdings. Iberion's business is licensing the architecture, not operating a consumer service.
Most security products protect one place: one application, one network boundary, one moment. Everything before and after that point is assumed to be fine.
Encryption is the clearest example. A tunnel encrypts traffic, and the customer is invited to believe the story ends there. It does not. Name resolution can leak outside the tunnel. IPv6 can route around it. A gateway sees both who is asking and what they asked for. The security tool itself often builds a browsing history — a new copy of exactly the information the customer was trying to protect. And when any of this quietly fails, the interface still says Connected.
Citadel exists because protection should not stop at encryption, and because a protection claim the customer cannot verify is not really a protection claim.
How much of the information journey can be protected without interrupting the traffic the customer actually wanted — and how can that protection be proven to the customer rather than asserted at them?
Ten coordinated defensive rings, not one tunnel. Each ring is a distinct defensive responsibility with its own scope, its own tests, and its own evidence record. Together they extend protection from transport, DNS and routing, through destination containment, resource and behavior defense, evidence minimization, bounded deception, endpoint and screen privacy, infrastructure hardening, identity handling, and device assurance.
They are composable controls — not ten VPNs stacked on each other, and not seven network layers renamed. A higher-numbered ring is never a substitute for a lower-numbered one that failed.
Citadel reports configuration state and actual protection state as separate facts. An interface being "up" is never treated as proof that traffic is protected. Handshake currency, real traffic flow, DNS posture, IPv4/IPv6 route posture, and confirmed public egress are each surfaced independently. When something is degraded, the system says so rather than showing a green badge.
A protection system that logs everything has simply moved the exposure. Citadel's operational receipts are minimized and expiring, and are scanned against a forbidden-data list — the security layer is not permitted to become the new collector.
Internally, no ring is described as operational until specific, named runtime evidence exists. Rings sit in explicit states — isolated, validated, deployed, runtime-verified, under observation, production-proven — and a status cannot advance without a change record, test evidence, and a rollback path. This is why we can hand a communications professional a per-ring evidence table instead of adjectives.
This is the part most technology companies blur. We do not.
| Maturity | Rings | Count |
|---|---|---|
| Production-proven within the registered evidence scope | Aegis · TrueNorth · Gatewatch · Sentinel · Veil · Mirage · Infrastructure Defense | 7 |
| Client-validatedUnder qualification. Validated on a physical device; the matching server-side capability is isolated and not connected. | Obscura | 1 |
| StandbyImplementation validated in isolation, deliberately not deployed. | Identity Cloaking and Edge Tokenization | 1 |
| Not deployedThe protocol is implemented and verified against its test corpus; the managed-continuity half is approved, frozen design only. | Device Assurance | 1 |
Supporting evidence includes live reboot-recovery testing (full node restart with zero manual intervention), adversarial burst-load testing showing measured containment, blocked-probe testing, and one real production incident that was root-caused, fixed, and independently re-verified end to end — with the entire account preserved as evidence rather than quietly closed.
Whole-system boundary. Evidence status is assigned by ring. Citadel's ten-ring architecture should not be described as wholly deployed, universally qualified, or independently certified.
Two further qualifiers are load-bearing and should survive into any public copy. "Production-proven within the registered evidence scope" means proven within the scope that was registered and tested — not a universal guarantee across every platform, configuration, or workload. And the newest infrastructure component remains inside an active observation window.
Citadel is the working, shipping expression of a larger proposition Iberion calls Information Defense.
The proposition: the digital economy has spent decades extracting information, building profiles, and monetizing identity — usually without meaningful consent, compensation, or defensible boundaries. The objective is not to stop information from moving. Information exchange is how commerce, medicine, and communication work.
The objective is to reduce involuntary information extraction while preserving legitimate, consensual information exchange — to make each information journey purpose-bound, policy-governed, privacy-minimized, recoverable, and economically measurable.
If you want my information — pay me.
If you want my identity — protect me.
If you want my enterprise — earn my trust.
Citadel is a component within that doctrine, not the whole of it. Iberion's doctrinal frameworks (PIDI and EIDI) cover a wider information lifecycle — admission, minimization, recipient control, evidence, expiration, revocation, recovery. Citadel is the transport and route-control layer of that idea, in production today. Citadel's ring numbers and the PIDI/EIDI doctrinal ring model are separate schemes and must never be mapped one-to-one in public material.
MiraTV — a live IPTV platform carrying real customer traffic on Android and Android TV, with Citadel integrated into it.
MiraTV is the demonstration environment. It is a demanding, latency-sensitive, customer-facing application, which makes it a genuine test: protection that breaks video playback is not protection anyone will accept.
MiraTV is not Citadel. MiraTV is a production application environment in which Citadel has been integrated and exercised. Citadel is separately licensable technology with its own product identity, its own platform surfaces (Android, Linux, Windows), and its own standalone deployment modes.
Available demonstration material includes the running application with Citadel active, the customer-facing protection-verification surface (the screens showing route, DNS, egress and degradation state as separate facts), and recorded evidence of the reboot-recovery and containment tests.
Citadel is offered as an embedded module inside a licensee's platform, as a standalone one-gateway client, in an optional two-hop mode that separates customer-facing ingress from Internet-facing egress, as backend/platform licensing, or as Iberion-operated managed infrastructure.
Commercial paths run from a fixed-fee assessment, through a time-bounded pilot against a bounded production path, to annual licensing, managed-service retainer, or a First Production Partner arrangement. Pricing is not fixed by schedule; deployment scope, support burden, infrastructure, and reference rights determine terms.
We are not asking anyone to explain the engineering. We are asking for help placing the technology before credible journalists, researchers, and industry voices who can scrutinize its claims and determine whether the story merits independent coverage — and for help reaching the right buyers: privacy-conscious platforms, OEMs and application developers needing an embeddable protection layer, managed service providers, and enterprises that need protected egress they can actually verify.
The constraint is that everything said publicly must stay inside the recorded evidence. Artifact C — Claim & Evidence Sheet exists to make that constraint workable rather than paralyzing: it states what can be said, what backs it, and what must not be said, so a writer can be creative without accidentally putting words in our mouth that the architecture does not support. It is released under NDA.
Deeper technical substantiation exists — reference architectures, system specifications, component inventories, deployment registries, and qualification guides — and is released selectively when a specific journalist or analyst question requires it.
Artifact B · IBR-PR-B-1.0 · Stage 2, pre-NDA · Per-ring capability, maturity, and limitation.
Citadel composes ten independent defensive responsibilities around a single customer-approved Internet journey. They are coordinated controls, not ten VPN tunnels. Numbers describe responsibility, not activation order — a higher-numbered ring never substitutes for a lower-numbered one that failed.
| Ring | Name | Protects against / controls | Evidence status |
|---|---|---|---|
| 1 | Aegis | Encrypted transport. Owns the single approved route, its continuity, and visible degradation of it. | Production-proven within the registered evidence scope |
| 2 | TrueNorth | DNS and route integrity. Keeps name resolution inside the protected route instead of leaking around it. | Production-proven within the registered evidence scope |
| 3 | Gatewatch | Destination containment. Detects unsafe resolution and contains destination intent. | Production-proven within the registered evidence scope |
| 4 | Sentinel | Resource and behavior defense. Contains abuse and resource pressure without interfering with wanted traffic. | Production-proven within the registered evidence scope |
| 5 | Veil | Evidence minimization. Keeps operational receipts minimal and expiring; the security layer does not become a browsing-history collector. | Production-proven within the registered evidence scope |
| 6 | Mirage | Signed, bounded deception. Scoped, expiring, signed containment and decoy responses to verified probes. | Production-proven within the registered evidence scope |
| 7 | Obscura | Endpoint and screen privacy. Screen-capture protection and local hostile-device posture detection on the customer's own device. | Client-validatedUnder qualification. Android client physically live-validated; its server attestation/revocation counterpart is isolated and not connected. |
| 8 | Infrastructure Defense | Infrastructure-level containment. Firewall policy, service hardening, resource-pressure containment, and exact peer/CIDR validation — protection that holds on nodes where the transport ring deliberately does not apply. | Production-proven within the registered evidence scopeDeployed and evidenced on the second-hop egress node; still inside its observation boundary. |
| 9 | Identity Cloaking & Edge Tokenization | Identity handling. Replaces stable customer and device references with short-lived scoped tokens; adds scoped forensic markers. | StandbyValidated in isolation, deliberately not deployed. No production callers. Treat as a future capability. |
| 10 | Device Assurance | Device and key security posture. Records graded confidence in the device's key backing, credential authority, route witness, and platform integrity, for the rest of Citadel to observe. | Not deployedProtocol implemented and corpus-verified; the managed-continuity half is approved, frozen design only. Nothing deployed, activated, or qualified. |
Whole-system boundary. Evidence status is assigned by ring. Citadel's ten-ring architecture should not be described as wholly deployed, universally qualified, or independently certified.
Seven of ten rings are production-proven within their registered evidence scope. Three are stated honestly as something less. That distinction is the story, not a caveat to be smoothed over — a vendor that reports its own unfinished work is making a credibility claim no competitor's marketing can match.
Each ring's status is backed by a registered internal evidence package — test records, acceptance evidence, and, where applicable, incident and recovery history. These are controlled records rather than public documents. They are made available on request through Iberion, under NDA and scoped to the specific question being asked.
Citadel's ring numbers are independent of the PIDI/EIDI doctrinal ring model. The two schemes must never be mapped number-for-number in public material.
Artifact C · IBR-PR-C-1.0 · Released under NDA — not included in this public set.
This artifact is deliberately withheld from the public kit. It is the communications operating boundary — what may be said, the evidence backing each statement, and the explicit never-list — and it carries the substantiation references that Artifacts A and B omit by design.
It is released to communications partners, journalists, and analysts under NDA, scoped to the question being asked.
The discipline it encodes is not itself a secret, and applies to everything in this kit: no external material may make a claim stronger than the recorded evidence state. Where a capability is designed but not deployed, these documents say so.