What you can engage today.
InvarOS is in public soft launch. Software packaging is in progress, but the platform is real and demonstrated — and the engagements below are available now as consulting, pilot, deployment, and licensing work. No fabricated outcomes. No invented customers. We say precisely what is deployable today.
Governed Agent Pilot
Available nowDeploy InvarOS interception in front of your agent tool surface — OpenClaw, MCP, or LangChain — and put deterministic, pre-execution authorization on real tool calls. Deterministic DENY and ALLOW, signed Decision Receipts, and single-use Authorization Leases are live-qualified today.
- Interception across the agent tool surface
- Deterministic authorization decisions before execution
- Signed Decision Receipts and Authorization Leases
- Fail-closed behavior and recovery validation
Deterministic Deployment
Available nowInstall governance the way it was demonstrated on real hardware: an immutable release, offline artifact qualification, side-by-side install, activation, health verification, and read-only reconciliation — air-gap capable. Suited to server, edge, and sovereign targets, including an AI-in-a-Box form factor.
- Immutable, hash-verified release manifest
- Offline qualification and side-by-side install
- Health verification and reconciliation
- Rollback and recovery drills
AI Infrastructure & Governance Assessment
Available nowDeploy the invarosd daemon in observe-only mode to produce an authenticated TBoM of the infrastructure your AI systems touch, then deliver a governance gap analysis and recommended policy boundaries.
- Authenticated TBoM topology artifact
- Interface, bridge, and agent-composition map
- Shadow tool / unmanaged connection identification
- Architecture report with governance gaps
Regulated & Disconnected Deployment Planning
Available nowFor defense, intelligence, critical-infrastructure, and highly regulated operators where always-on cloud is architecturally prohibited. Assess restricted network architecture, design asynchronous evidence transport, and define air-gapped operating procedures.
- Offline policy compilation and distribution
- Local evidence generation without cloud telemetry
- Air-gapped transport for evidence records
- Isolated-cluster deployment configuration
Kubernetes Governance Integration
Available nowConfigure the ValidatingAdmissionWebhook handler, define SLSA attestation requirements, configure attestation descriptor registries (structural validation, not live TPM/SGX/SEV verification), and set cross-tenant namespace trust contracts. Fail-closed posture.
- Webhook deployment and cert-manager TLS
- SLSA annotation policy per namespace
- Cross-tenant trust contract enforcement
- Fail-closed posture and rollback procedures
Research & Academic Collaboration
Available nowEligible universities, non-profit AI safety laboratories, and independent researchers may receive approved access to enterprise capabilities under the InvarOS Public Benefit License for non-commercial research.
- Access to enterprise capabilities for research
- Open schemas and cryptographic receipt formats
- Formal agent verification and ZK-compliance topics
- Non-commercial public-benefit agreement
Honest scoping. Defined deliverables.
Every engagement has defined outputs — a TBoM artifact, an architecture report, a policy scope definition, a governed pilot, or a deployment plan. We tell you exactly what is deployable today, what requires manual configuration, and what is on the roadmap. We do not charge for slide decks, and email goes directly to the engineering team.