Inspect the foundation.
Understand the frontier.
A public-source review of what is implemented, what remains a beta limitation and what is proposed for enterprise deployment.
Code available to inspect
Separate address spaces, signed capsule admission and runtime capability checks appear in the tagged source.
Readiness is constrained
Persistence, installation, multicore, power management and broad hardware support have explicit development gates.
Management design
Blockchain-anchored fleet policy, complete device enrolment and enterprise recovery remain a proposed architecture.
Follow the claim to the code.
Capsule admission
Preflight precedes process creation in the verified-spawn path.
Inspect v0.9.2 source ↗Separate address spaces
Fresh user mappings and a supervisor-only kernel half.
Inspect v0.9.2 source ↗Capability grants
Required and optional grants are bounded by the publisher certificate.
Inspect v0.9.2 source ↗Runtime enforcement
Token, boot session, address-space binding and syscall permission checks.
Inspect v0.9.2 source ↗Publisher attestation boundary
Publisher capsules may omit the STARK trailer after certificate and manifest validation.
Inspect v0.9.2 source ↗Session teardown
Memory and key sanitisation paths reduce intended residual state.
Inspect v0.9.2 source ↗Hardware build features
v0.9.2 includes IOMMU enforcement features; presence is not hardware validation.
Inspect v0.9.2 source ↗Current policy interface
Policy primitives are available in the source; a complete enterprise fleet service remains proposed.
Inspect v0.9.2 source ↗Pinned release commit: 9996d7037e5ff380af0b1e52a9ad0ea2e5ca2624. Repository HEAD reviewed separately at 74e75d8aa70a114675f7d5f10d14e55a39a51d9f (18 September 2026).
Gates, not promised dates.
x86_64 evaluation
A signed source release and bounded hardware coverage. The public roadmap says sessions do not yet persist across reboot and shipped profiles use one CPU.
Practical operation
Persistence and multicore work are described in the public roadmap. Installation and hardware qualification are prerequisites for ordinary deployment.
Update & power lifecycle
The project outlines update and power-management work. Reliability and recovery must be demonstrated alongside security properties.
Architecture parity
Signed ARM parity is a roadmap target. Experimental source targets do not imply current signed release support.
What a managed pilot must prove.
Threat model & policy schema
Publish the trust assumptions, failure modes, signer recovery model and deterministic verification tests.
Single-device control
Demonstrate signed policy loading, expiry, rollback rejection and denial of unauthorised actions.
Managed pilot
Validate enrolment, staged rollout, group changes, revocation, receipts and offline recovery on named hardware.
Enterprise release candidate
Complete independent review, failure-injection tests, operational recovery, support processes and measured fleet performance.
These are qualification targets for the proposed management layer. They remain future validation steps, with no committed release dates.
The next era needs
a stronger foundation.
Explore the technology. Evaluate a pilot. Discuss a partnership.