// EXECUTIVE COMMAND PROGRAMME · COMMISSION-ONLY · COMPANIES HOUSE 16019829 // // PROGRAMM EXECUTIVE COMMAND · NUR AUF AUFTRAG · COMPANIES HOUSE 16019829 //
CS CYBERSENTINEL SOLUTIONS LTD · Salisbury, UK · est. 2024 LTD · Salisbury, GB · gegr. 2024
CITADEL HQ ONLINE LDN --:--:--
CSS-AEGIS.026 · EXECUTIVE TERMINAL CSS-AEGIS.026 · EXECUTIVE TERMINAL

A laptop. A satellite. A private line. Ein Laptop. Ein Satellit. Eine Privatleitung.

AEGIS is a complete sovereign communications system for one operator. A hardened laptop, cabled to a dedicated Starlink terminal, talking through a double-encrypted tunnel that terminates on a physical relay we operate inside our communications centre in Salisbury — and nowhere else. No public Wi-Fi. No shared exit nodes. No infrastructure you do not control or we do not name.

AEGIS ist ein vollständiges, souveränes Kommunikationssystem für einen Operator. Ein gehärteter Laptop, per Kabel verbunden mit einem dedizierten Starlink-Terminal, kommuniziert durch einen doppelt verschlüsselten Tunnel, der auf einem physischen Relay endet, das wir in unserer Kommunikationszentrale in Salisbury betreiben — und sonst nirgendwo. Kein öffentliches WLAN. Keine geteilten Exit-Knoten. Keine Infrastruktur, die Sie nicht kontrollieren oder wir nicht benennen.

STARLINK DEDICATED TERMINAL [ CAT6A · WIRED ] AEGIS EXECUTIVE COMMAND ▸ TUNNEL UP ▸ STARLINK 187 Mbps ▸ CITADEL HQ AUTH'D ▸ YUBIKEY · VERIFIED ▸ HEADS ATTESTATION OK CITADEL HQ · SALISBURY [ DOUBLE-ENCRYPTED TUNNEL ] CYBERSENTINEL · CSS-AEGIS.026 · COMMISSION-ONLY
§ 01 · WHAT IT IS
§ 01 · WAS ES IST
AEGIS is three pieces of hardware and one tunnel, built for one principal, run from one address.
AEGIS sind drei Hardware-Komponenten und ein Tunnel, gebaut für einen Prinzipal, betrieben aus einer Adresse.
§ 02 · HOW IT WORKS
§ 02 · WIE ES FUNKTIONIERT
CSS-AEGIS.026 / FLOW

Four stages. Watch each one.

Vier Stufen. Sehen Sie jede.

From the moment you press a key to the moment the bits land on our relay, every step is named and visible. Below: how data moves through AEGIS, layer by layer, with no mystery.

Vom Moment, in dem Sie eine Taste drücken, bis zu dem Moment, in dem die Bits auf unserem Relay landen, ist jeder Schritt benannt und sichtbar. Unten: Wie Daten Schicht für Schicht durch AEGIS fließen — ohne Geheimnisse.

STAGE 01 · BOOT
STUFE 01 · BOOT

The laptop verifies itself before the OS loads.

Der Laptop verifiziert sich selbst, bevor das OS lädt.

Power on. Coreboot+Heads firmware reads the SHA-256 of every binary in the boot chain — bootloader, kernel, initramfs — and measures each into the TPM. Your YubiKey signs the measurement set. If one byte changed since the last clean boot, the firmware refuses to load the kernel and the screen turns red.

Einschalten. Die Coreboot+Heads-Firmware liest den SHA-256 jedes Binarys in der Boot-Kette — Bootloader, Kernel, Initramfs — und misst jeden Wert in das TPM. Ihr YubiKey signiert das Messungsset. Hat sich ein Byte seit dem letzten sauberen Boot geändert, weigert sich die Firmware, den Kernel zu laden, und der Bildschirm wird rot.

  • FIRMWARECoreboot + Heads, flashed externally before chassis sealedCoreboot + Heads, extern geflasht vor Gehäuseversiegelung
  • TPMTPM 2.0 · PCR 0–7 measured · sealed to YubiKeyTPM 2.0 · PCR 0–7 gemessen · an YubiKey gebunden
  • YUBIKEY5C · primary + 2 backups · FIDO2 + PIV + PGP5C · Haupt + 2 Backups · FIDO2 + PIV + PGP
  • RESULTGreen attestation, or it does not bootGrüne Attestierung — oder kein Bootvorgang
[01] FIRMWARE Coreboot + Heads [02] BOOTLOADER GRUB · signed [03] KERNEL linux-hardened [04] INITRAMFS measured · attested ▸ ATTESTATION OK KERNEL CLEARED TO LOAD SHA-256 MEASUREMENTS PCR0 a3f1b9e2c4d8... PCR1 7e2c84b1d3a9... PCR2 1f8c92ae45b6... PCR3 b9d4e1c7f203... PCR4 5c0a8d3f9e21... PCR5 28e9c1b4a76f... PCR6 4d72f9e0c8a3... PCR7 9b3e5a8c1d04... YUBIKEY SIGNATURE: 3045 0220 7c1f 9a2e 8b0d 1c43 ... VERIFIED AGAINST OFFLINE SIGNING KEY ✓ ALL HASHES MATCH // boot continues
STAGE 02 · TRANSIT
STUFE 02 · TRANSIT

From laptop to satellite, by cable only.

Vom Laptop zum Satelliten, nur per Kabel.

The Wi-Fi radio is disabled in firmware. The Bluetooth radio is disabled in firmware. The laptop reaches the network through one path: a shielded CAT6A cable to the Starlink terminal sitting on your roof or balcony. The terminal is registered to a corporate identity that does not name you. The PoE injector is sealed shut with tamper-evident epoxy before the unit leaves Salisbury.

Die WLAN-Funkeinheit ist in der Firmware deaktiviert. Die Bluetooth-Funkeinheit ist in der Firmware deaktiviert. Der Laptop erreicht das Netz über einen Weg: ein geschirmtes CAT6A-Kabel zum Starlink-Terminal auf Ihrem Dach oder Balkon. Das Terminal ist auf eine Unternehmensidentität registriert, die Sie nicht benennt. Der PoE-Injektor wird mit manipulationssicherem Epoxidharz versiegelt — bevor die Einheit Salisbury verlässt.

  • CABLECAT6A · S/FTP shielded · LSZH jacketCAT6A · S/FTP geschirmt · LSZH-Mantel
  • WI-FIDisabled at firmware · M.2 module removedIn Firmware deaktiviert · M.2-Modul entfernt
  • TERMINALStarlink Gen 3 · corporate-identity registrationStarlink Gen 3 · Registrierung auf Firmenidentität
  • PoETamper-sealed epoxy · break to inspectManipulationssicheres Epoxid · zerstören zum Prüfen
AEGIS LAPTOP [ ENDPOINT ] NO WI-FI CAT6A · S/FTP SHIELDED [no RF · no leak · no broadcast] STARLINK DEDICATED STARLINK MESH ONE CABLE · ONE PATH · NO WIRELESS terminal registered to corporate identity · principal not named on account
STAGE 03 · TUNNEL
STUFE 03 · TUNNEL

Every packet is wrapped twice.

Jedes Paket wird zweimal verpackt.

Your data leaves the laptop as plaintext, then passes through two encryption layers before it touches the cable. The inner layer is a Noise Protocol session with keys pinned to the relay's public key — so even if someone substitutes a relay endpoint, the session refuses to establish. The outer layer is WireGuard with ChaCha20-Poly1305, providing transport-level confidentiality and integrity. Both layers rotate keys every twenty-four hours, and both use forward secrecy — a captured packet stream tomorrow cannot decrypt what passed today.

Ihre Daten verlassen den Laptop als Klartext, durchlaufen dann zwei Verschlüsselungsschichten, bevor sie das Kabel berühren. Die innere Schicht ist eine Noise-Protocol-Sitzung mit auf den öffentlichen Schlüssel des Relays gepinnten Schlüsseln — selbst wenn jemand einen Relay-Endpunkt austauscht, weigert sich die Sitzung, sich aufzubauen. Die äußere Schicht ist WireGuard mit ChaCha20-Poly1305 für Vertraulichkeit und Integrität auf Transportebene. Beide Schichten rotieren Schlüssel alle vierundzwanzig Stunden, beide nutzen Forward Secrecy — ein morgen erbeuteter Paketstrom kann nicht entschlüsseln, was heute lief.

  • INNERNoise XK · X25519 + ChaCha20-Poly1305 + BLAKE2sNoise XK · X25519 + ChaCha20-Poly1305 + BLAKE2s
  • OUTERWireGuard · Curve25519 + ChaCha20-Poly1305WireGuard · Curve25519 + ChaCha20-Poly1305
  • ROTATIONBoth layers · every 24 hours · automaticBeide Schichten · alle 24 Stunden · automatisch
  • PINNINGRelay public key hard-coded · no substitutionÖffentlicher Relay-Schlüssel hartkodiert · keine Substitution
[OUTER] WIREGUARD · ChaCha20-Poly1305 [INNER] NOISE XK · X25519 [ YOUR PAYLOAD ] BEFORE TUNNEL (plaintext): Hello board, Q4 forecast +18% AFTER TUNNEL (ciphertext): 9f2a c4e1 b8d7 6f30 a51c 9e84 b2c0 KEY ROTATION · 24h forward secrecy active
STAGE 04 · ENDPOINT
STUFE 04 · ENDPUNKT

Tunnel ends on your relay. Not anyone else's.

Der Tunnel endet auf Ihrem Relay. Auf keinem anderen.

The tunnel does not exit at the Starlink ground station. It does not exit on a public VPN endpoint. It terminates on a 1U appliance physically present in our communications centre in Salisbury — purchased for one principal, racked under your serial, monitored by a named engineer. The master keys live on an air-gapped YubiHSM 2 in the same rack. The principal can visit and inspect the unit, by appointment.

Der Tunnel endet nicht an der Starlink-Bodenstation. Er endet nicht an einem öffentlichen VPN-Endpunkt. Er terminiert an einem 1U-Gerät, das physisch in unserer Kommunikationszentrale in Salisbury vorhanden ist — beschafft für einen Prinzipal, unter Ihrer Seriennummer eingebaut, von einem benannten Ingenieur überwacht. Die Master-Schlüssel liegen auf einem luftspaltgesicherten YubiHSM 2 im selben Rack. Der Prinzipal kann die Einheit nach Termin besuchen und inspizieren.

  • HARDWARE1U appliance · your serial · racked at Salisbury1U-Gerät · Ihre Seriennummer · in Salisbury eingebaut
  • HSMYubiHSM 2 · air-gapped · master keys never exitYubiHSM 2 · luftspaltgesichert · Master-Schlüssel verlassen es nie
  • TRAFFICNo other operator's traffic crosses this hardwareKein anderer Operator-Verkehr passiert diese Hardware
  • AUDITOn-site inspection by appointment · annual visitVor-Ort-Inspektion nach Termin · jährlicher Besuch
CITADEL HQ // SALISBURY · RACK 04 CSS-AEGIS.026 · YOUR APPLIANCE SN: CSS-A-026-7C1F · operator: [your codename] CSS-AEGIS.024 · [other operator] CSS-AEGIS.022 · [other operator] CSS-AEGIS.019 · [other operator] AIR-GAPPED HSM // YUBIHSM 2 master keys · never leave this device no network · physical access only // MONITOR FEED (LIVE) [00:00:01] tunnel established · 187 Mbps [00:00:01] handshake OK · noise-xk + wg [00:00:02] integrity ok · pcr match ONE OPERATOR · ONE 1U · ONE HSM SLOT
§ 03 · WHAT IT DOES
§ 03 · WAS ES MACHT
AEGIS keeps your traffic on infrastructure we run, encrypted twice, away from public Wi-Fi, shared VPN exits, and SIM-anchored carriers. The path from your hand to our rack contains nothing you do not control or we do not name.
AEGIS hält Ihren Verkehr auf Infrastruktur, die wir betreiben, zweifach verschlüsselt, weg von öffentlichem WLAN, geteilten VPN-Exits und SIM-gebundenen Providern. Der Pfad von Ihrer Hand zu unserem Rack enthält nichts, was Sie nicht kontrollieren oder wir nicht benennen.
§ 04 · WHY CABLE
§ 04 · WARUM KABEL
CSS-AEGIS.026 / RF

A wireless laptop is a radio station.

Ein drahtloser Laptop ist ein Funksender.

Every Wi-Fi packet your laptop transmits is broadcast to anything within range with the right antenna — a directional gain antenna picks up office-grade signal from across a street. AEGIS removes the radio entirely.

Jedes WLAN-Paket, das Ihr Laptop sendet, wird an alles im Empfangsbereich ausgestrahlt, das die richtige Antenne hat — eine Richtantenne nimmt Bürosignale von der gegenüberliegenden Straßenseite auf. AEGIS entfernt das Funkmodul komplett.

◉ Standard Laptop · Wi-Fi ◉ Standard-Laptop · WLAN

A laptop on Wi-Fi.

Ein Laptop im WLAN.

Broadcasts in all directions at 2.4 / 5 / 6 GHz. Probe requests reveal SSIDs of every network the laptop has ever joined. The MAC address — even when randomised — leaks fingerprintable timing characteristics. Anyone with an SDR receiver within a few hundred metres can passively log the broadcast.

Sendet in alle Richtungen bei 2,4 / 5 / 6 GHz. Probe Requests offenbaren SSIDs jedes Netzes, dem der Laptop je beigetreten ist. Die MAC-Adresse — selbst randomisiert — leakt fingerabdrucktaugliche Timing-Merkmale. Jeder mit einem SDR-Empfänger in Reichweite einiger hundert Meter kann den Sendebetrieb passiv mitloggen.

LAPTOP SDR · 600m SDR · 200m PUBLIC BROADCAST
◉ AEGIS · Cable Only ◉ AEGIS · Nur Kabel

A laptop on cable.

Ein Laptop am Kabel.

No radio. The Wi-Fi M.2 module is physically removed. The Bluetooth module is disabled in firmware and the trace cut. The laptop emits no intentional RF in normal operation — TEMPEST-grade shielding mitigates incidental emanations. The only path to the network is the shielded cable in your hand.

Kein Funk. Das WLAN-M.2-Modul ist physisch entfernt. Das Bluetooth-Modul ist in der Firmware deaktiviert und die Leiterbahn durchtrennt. Der Laptop emittiert im Normalbetrieb keine absichtliche HF — TEMPEST-Schirmung mindert Streustrahlung. Der einzige Weg zum Netz ist das geschirmte Kabel in Ihrer Hand.

LAPTOP DISH NO BROADCAST · NO RF [ adversary with SDR · receives nothing ]
A communications system either has a perimeter you can name, or it has every perimeter at once.
Ein Kommunikationssystem hat entweder eine Grenze, die man benennen kann, oder es hat alle Grenzen auf einmal.
CYBERSENTINEL · Engineering Doctrine CYBERSENTINEL · Ingenieursdoktrin
§ 05 · CRYPTOGRAPHY
§ 05 · KRYPTOGRAFIE
CSS-AEGIS.026 / PRIMITIVES

Exact primitives. Auditable choices.

Exakte Primitive. Prüfbare Wahl.

The tunnel uses two layers, each with named cryptographic primitives. None of them are home-grown. All of them are the same primitives used by Signal Protocol, WireGuard upstream, and the NSA's Suite B for SECRET-classified traffic. We do not invent crypto. We use the crypto that has been beaten on by the field for a decade.

Der Tunnel nutzt zwei Schichten, jede mit benannten kryptografischen Primitiven. Keine davon sind eigene Konstruktionen. Alle sind dieselben Primitive, die das Signal-Protokoll, WireGuard upstream und die NSA-Suite-B für SECRET-eingestufte Daten verwenden. Wir erfinden keine Kryptografie. Wir nutzen die Kryptografie, die ein Jahrzehnt lang vom Fachgebiet geprüft wurde.

Plaintext your data in clear [00] [INNER] Noise XK X25519 ChaCha20 BLAKE2s [01] PIN TO RELAY KEY [OUTER] WireGuard noise-encrypted payload (inside) Curve25519 ChaCha20-Poly1305 [02] WRAP THE WRAPPED [OVER WIRE] ciphertext 9f2a c4e1 b8d7 6f30 a51c 9e84 b2c0 7d41 0a2f e8b9 36cd 1a07 [03] INDISTINGUISHABLE [RELAY] CITADEL HQ strip wg strip noise verify hmac → plaintext [04] YOUR ENDPOINT PLAINTEXT → NOISE → WIREGUARD → WIRE → RELAY → PLAINTEXT each layer · forward secret · key-rotated every 24 hours
// LAYER 01 · INNER

Noise Protocol XK

Noise Protocol XK

X25519 elliptic-curve key exchange, ChaCha20-Poly1305 authenticated encryption, BLAKE2s hashing. The same construction the Signal Protocol uses for its initial handshake. Mutual authentication with the relay's pinned public key — substitution attacks fail at the handshake.

X25519 elliptische-Kurven-Schlüsselaustausch, ChaCha20-Poly1305 authentifizierte Verschlüsselung, BLAKE2s-Hashing. Dieselbe Konstruktion, die das Signal-Protokoll für seinen initialen Handshake nutzt. Gegenseitige Authentifizierung mit dem gepinnten öffentlichen Schlüssel des Relays — Substitutionsangriffe scheitern am Handshake.

// LAYER 02 · OUTER

WireGuard

WireGuard

Curve25519 key exchange, ChaCha20-Poly1305 packet encryption, BLAKE2s for keyed hashing, SipHash24 for hashtable keys. Mainlined into the Linux kernel since 5.6. Audited by Trail of Bits, by Kudelski Security, and by the upstream community. Approximately four thousand lines of code total — small enough to read in an afternoon.

Curve25519-Schlüsselaustausch, ChaCha20-Poly1305-Paketverschlüsselung, BLAKE2s für gekeyte Hashes, SipHash24 für Hashtable-Schlüssel. Seit 5.6 im Linux-Kernel-Mainline. Auditiert von Trail of Bits, von Kudelski Security und von der Upstream-Community. Etwa viertausend Codezeilen insgesamt — klein genug, um an einem Nachmittag zu lesen.

// KEY MANAGEMENT

Forward Secrecy & Rotation

Forward Secrecy & Rotation

Session keys derived per-handshake via ephemeral Diffie-Hellman. Long-term keys never encrypt payload directly. A captured packet stream from today, decrypted tomorrow with a stolen long-term key, reveals nothing — the session keys are gone. Rotation forces a fresh handshake every twenty-four hours.

Sitzungsschlüssel werden pro Handshake über ephemeren Diffie-Hellman abgeleitet. Langzeitschlüssel verschlüsseln niemals direkt Nutzlast. Ein heute erbeuteter Paketstrom, morgen mit einem gestohlenen Langzeitschlüssel entschlüsselt, enthüllt nichts — die Sitzungsschlüssel sind weg. Rotation erzwingt alle vierundzwanzig Stunden einen frischen Handshake.

// HSM ANCHOR

YubiHSM 2 · Air-Gapped

YubiHSM 2 · Luftspaltgesichert

Master signing keys live on a YubiHSM 2 hardware security module in the same rack as your relay appliance — but on no network. Signing operations occur over a USB connection from the relay's monitor port. The master key cannot be exported. Compromising the relay does not compromise the master.

Master-Signierschlüssel leben auf einem YubiHSM-2-Hardware-Sicherheitsmodul im selben Rack wie Ihr Relay-Gerät — aber an keinem Netz. Signieroperationen erfolgen über eine USB-Verbindung vom Monitor-Port des Relays. Der Master-Schlüssel kann nicht exportiert werden. Eine Kompromittierung des Relays kompromittiert den Master nicht.

§ 06 · WHAT YOU RECEIVE
§ 06 · WAS SIE ERHALTEN
CSS-AEGIS.026 / MANIFEST

A Pelican case arrives in person.

Ein Pelican-Koffer wird persönlich übergeben.

The chief engineer attends in person. The case is opened in your presence. Seals are verified, photographed, and read aloud. The YubiKeys are provisioned in your presence — keys are generated on the device and never exit. You sign the manifest, the engineer signs the manifest, and the case is yours.

Der Chefingenieur erscheint persönlich. Der Koffer wird in Ihrer Anwesenheit geöffnet. Siegel werden verifiziert, fotografiert und laut vorgelesen. Die YubiKeys werden in Ihrer Anwesenheit bereitgestellt — Schlüssel werden auf dem Gerät generiert und verlassen es nie. Sie unterzeichnen das Manifest, der Ingenieur unterzeichnet das Manifest, und der Koffer gehört Ihnen.

[01]

AEGIS Laptop

AEGIS-Laptop

Hardened, Coreboot+Heads firmware, TPM 2.0, no wireless radio, tamper-evident chassis.

Gehärtet, Coreboot+Heads-Firmware, TPM 2.0, kein Funk, manipulationssicheres Gehäuse.

[02]

Starlink Terminal

Starlink-Terminal

Gen 3, registered to a corporate identity, PoE injector sealed with tamper-evident epoxy.

Gen 3, auf Unternehmensidentität registriert, PoE-Injektor mit manipulationssicherem Epoxid versiegelt.

[03]

CITADEL Relay

CITADEL-Relay

A 1U appliance racked in Salisbury under your serial — yours alone, no shared traffic.

Ein 1U-Gerät in Salisbury unter Ihrer Seriennummer eingebaut — Ihres allein, kein geteilter Verkehr.

[04]

3× YubiKey 5C

3× YubiKey 5C

Primary plus two backups — keys generated in your presence at handover.

Hauptschlüssel plus zwei Backups — Schlüssel in Ihrer Anwesenheit bei Übergabe generiert.

[05]

CAT6A Cabling

CAT6A-Verkabelung

Shielded S/FTP cabling — three lengths included, hand-tested for shield integrity.

Geschirmtes S/FTP-Kabel — drei Längen inklusive, handgetestet auf Schirmintegrität.

[06]

Principal's Binder

Prinzipal-Mappe

Threat model, OPSEC handbook, build attestation, recovery procedures — printed, leather-bound.

Bedrohungsmodell, OPSEC-Handbuch, Bau-Attestierung, Wiederherstellung — gedruckt, lederngebunden.

§ 07 · COMMISSION § 07 · AUFTRAG

Talk to the engineer.

Sprechen Sie mit dem Ingenieur.

First conversation is confidential, by encrypted channel of your choice, with our chief engineer. We map your threat model, we tell you what AEGIS can and cannot do, we agree the build. No sales team. No qualification call. No CRM.

Das erste Gespräch ist vertraulich, über einen verschlüsselten Kanal Ihrer Wahl, mit unserem Chefingenieur. Wir kartieren Ihr Bedrohungsmodell, wir sagen Ihnen, was AEGIS leisten kann und was nicht, wir vereinbaren den Bau. Kein Verkaufsteam. Kein Qualifizierungsgespräch. Kein CRM.