Axowl.com
000
%

No single operator can take down a grid, a network, or a pipeline.

Power grids, telecom backbones, and water treatment plants run on decades-old SCADA stacks where a stolen admin password can cascade into national-scale outages. DPSM enforces hardware-bound identities and quorum approval for every consequential command — Colonial Pipeline-class incidents become structurally impossible.

Where Critical Infrastructure breaks today

Cascading failures from stolen credentials

A single compromised SCADA login can issue dozens of breaker-open commands in seconds, faster than any human reviewer.

$4.4M — Colonial Pipeline ransom · DOJ, 2021

Vendor maintenance backdoors

Dial-in support channels and unverified vendor toolchains remain the leading initial-access vector for OT incidents.

62% — of OT intrusions begin via vendor remote access · Mandiant M-Trends, 2024

Insider command spoofing

Operators with legitimate access can issue catastrophic commands that look identical to routine work in unsealed logs.

NIS2 · NERC CIP — explicitly require non-repudiable command logging

Three patents, deployed against this industry's threat model

Each of Axowl's three filed patents maps to a specific structural failure mode in Critical Infrastructure. Together they form a single, end-to-end defense.

Hierarchical Distributed Trust Fabric — Substation (L1) · Regional SCADA (L2) · National HQ (L3)

Every breaker, every router, every pump carries a PUF identity at L1. Regional control rooms serve as L2; national operations and the regulator-mirrored archive serve as L3. A cascade-class command (e.g. open multiple substation breakers in coordinated fashion) requires k-of-n agreement, so a single compromised control room cannot trigger national impact.

Transition-Sealed Integrity System — Every breaker, every routing change, sealed

Each consequential transition — breaker open/close, BGP route change, voltage setpoint adjustment — is sealed in real time. Forensic teams can answer "who issued this command, from which device, when" with cryptographic certainty, replacing log-chain reconstruction that today takes regulators weeks.

Pre-grant LLM Conflict Verification — Toxic permission combinations blocked at grant time

A grant such as "operator A + close-all-breakers + bypass-confirmation" is detected as a toxic combination by the LLM gate and refused before it reaches a roster. Pre-commit conflict detection neutralizes the entire class of "single-operator catastrophic action" scenarios.

Deployment that fits the threat model

Most utility deployments begin at the Defense tier (TPM-anchored, software watchdog) and transition to Iron for the largest national operators where regulator-grade integrity is mandatory.

Recommended tier: T2 · Defense → T3 · Iron

Deployment path: AWS Nitro Enclave for control rooms · F2 (FPGA) for substation gateways

Operational detail: Day-1 deployment of the IRON sealed chain runs on AWS Nitro Enclaves in regional control rooms. Substation-side gateways receive F2-class FPGA appliances on a 72-hour cycle, with custom ASIC available for hardened field deployment.

Three concrete deployments

Power grid command authority

A breaker close-open command must be co-signed by an L2 regional supervisor and at least one L3 national observer, eliminating single-operator cascades.

Telecom BGP route protection

Each BGP advertisement at the edge is sealed by the router's L1 PUF; spoofed routes from a compromised admin workstation are rejected at the carrier core.

Water treatment safety interlocks

Chemical dosing setpoints carry a sealed grant chain. A poisoned-input scenario (e.g. Oldsmar 2021) is structurally blocked because the dosing PLC will not accept any setpoint without a fresh k-of-n authorization.

Versus what's deployed today

Today — SCADA + bastion-host VPN

Once an attacker reaches the bastion, command authority is delegated by trust, not by hardware. Logs are kept on the same systems an attacker has compromised.

With DPSM — Axowl DPSM

Authority is never delegated by trust — it is enforced by hardware quorum. Logs are sealed at IRON grade and mirrored to a regulator-readable L3 region the operator cannot reach.

Standards & regulatory frameworks aligned

  • NERC CIP-005 / -007 / -013
  • FERC Order 706
  • EU NIS2
  • TSA Pipeline SD02C
  • IEC 62351
  • ENISA OT Guidelines