UK-sovereign AI security

Attack yourself before others do.

Varangian runs the operating doctrine PureTensor uses on its own estate: continuous self-attack, bounded self-healing and a disaster-recovery copy no agent can reach. We publish the ledger every day. Then we run the same doctrine for you.

Jurisdiction
United Kingdom
Recovery site
Iceland
Compute
Own Blackwell-class GPUs
Client data
No foreign model APIs

Services

Six engagements. One doctrine.

Each engagement applies the doctrine we already run on our own production estate, and the evidence is published in the ledger every day.

  1. 01Rule I

    Continuous adversarial validation

    Autonomous penetration testing and exposure validation with documented production-safety rails; threat-led testing ready for DORA and TIBER-EU.

    DORA Art. 26TIBER-EUNCSC CAF
  2. 02Rule I

    AI-system red teaming

    Prompt injection, memory poisoning, tool abuse and agent authority-boundary testing against the systems you deploy.

    EU AI Act Art. 15NCSC CAF 4.0
  3. 03Rule III

    Resilience engineering

    3-2-1-1-0 backup architecture, immutable and logically air-gapped copies, isolated recovery environments, restore drills with published recovery objectives.

    NIS2 Art. 21Cyber Governance Code
  4. 04Rule IV

    Trustless architecture

    Workload identity, just-in-time access, four-eyes authorisation and zero-trust backup.

    Cyber EssentialsUK GDPR Art. 32
  5. 05Rules II and V

    Agentic operations design

    Bounded-authority self-healing loops and the enforcement pattern that keeps every agent out of the vault.

    NCSC CAF 4.0EU AI Act
  6. 06Own compute

    Sovereign deployment

    On-premise or UK/EU-sovereign inference for workloads that must not leave your jurisdiction.

    UK and EU jurisdiction

Operating doctrine

Five rules, applied to ourselves first.

We apply every rule to our own estate before we sell it. The ledger shows whether we are keeping them today, red included.

  1. I

    Attack yourself continuously.

    Live evidence

    In our estate

    Independent model seats review our repositories adversarially every day and open evidence-bearing pull requests; a human re-runs every claim before merge. Exposure is probed from outside our own network, never from inside it. Monitors are audited for the ability to go red.

    For yours

    Continuous adversarial validation of your estate, on our sovereign compute, mapped to DORA threat-led testing and NCSC CAF.

  2. II

    Self-heal with bounded authority.

    Live evidence

    In our estate

    A deterministic scan-and-fix loop with models only at the edges, promoted from shadow to suggest to canary to auto, with a Tier-0 carve-out. Outcomes are graded resolved, recurred or indeterminate, and never green by default.

    For yours

    Autonomous remediation designed with a written authority boundary and a human approval gate for everything outside it.

  3. III

    Three copies, two media, one out of reach.

    Live evidence

    In our estate

    Nightly backups to erasure-coded storage with read-only mounts and no cluster-admin key, staggered mirrors to Iceland, and a send-only to receive-only topology so the recovery site can never push damage upstream. Restores are tested weekly by automation and quarterly by a manual drill.

    For yours

    3-2-1-1-0 resilience engineering with published recovery objectives and an isolated recovery environment.

  4. IV

    Trustless by construction.

    Live evidence

    In our estate

    Rotation with completeness proof, same-day privilege reduction, a private mesh, and trust tiers graded by surface.

    For yours

    Workload identity, short-lived credentials, four-eyes on destructive actions, and zero-trust backup: the identity that writes a backup cannot delete it.

  5. V

    Agents run the estate. Agents never touch the vault.

    Live evidence

    In our estate

    Enforced and audited daily: audit/agent_vault_audit.py probes every model-driven seat from inside its own sandbox and proves no agent credential can read, list or delete disaster-recovery snapshots. The ledger row below is that measurement, and it goes red the day a path appears.

    For yours

    An agentic operations design where no agent credential has a path to disaster-recovery or crucial backup storage. It is the control that turns an AI incident into an inconvenience instead of an extinction event.

Production evidence

The live doctrine ledger

Generated from our own fleet, refreshed daily and rendered from ledger.json. Every row can go red. A ledger that cannot go red is not a ledger.

Measuring

Reading the ledger

Controls
11
Holding
–
Warning
–
Red
–

Values are measured on PureTensor's production estate. "Red" means the doctrine is not met today and the fix is scheduled; it is published anyway. A missing or unknown measurement is shown as red, never as green.

Regulatory drivers

The regulatory clock

The obligations that make this doctrine mandatory, with the date each one bites, and the threat evidence behind them. Every line links to its primary source.

Obligations, in date order

  1. UK

    UK GDPR Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of security measures.

    Source legislation.gov.uk
  2. EU

    NIS2 Article 21(2)(c) makes backup management and disaster recovery a mandatory measure, and Article 20 places personal accountability on management bodies.

    Source EUR-Lex
  3. EU

    DORA Article 26 requires threat-led penetration testing at least every three years, on live production systems, under the TIBER-EU framework.

    Source EUR-Lex
  4. UK

    The NCSC and DSIT Cyber Governance Code of Practice asks boards for tested recovery plans and independent assurance.

    Source GOV.UK
  5. UK

    NCSC Cyber Assessment Framework v4.0 adds outcomes for AI-related and autonomous-software risk.

    Source NCSC
  6. UK

    The UK Cyber Security and Resilience Bill brings managed service providers, data centres and critical suppliers into scope, with 24-hour early warning and 72-hour incident reports.

    Source UK Parliament
  7. UK

    Cyber Essentials 'Danzell' requirements mandate 14-day vulnerability remediation and hardware-backed MFA for cloud administrative access.

    Source NCSC
  8. EU

    EU AI Act Article 15 requires high-risk systems to be resilient against adversarial attack, prompt injection and data poisoning.

    Source EUR-Lex
  9. EU

    The Cyber Resilience Act's 24-hour reporting of actively exploited vulnerabilities to ENISA begins 11 September 2026; full application follows on 11 December 2027.

    Source EUR-Lex

Threat evidence

  • Breach data, 202562%

    Verizon's 2025 Data Breach Investigations Report puts the human element in 62% of breaches, vulnerability exploitation at 31% of initial access and credential abuse at 13%.

    Source Verizon DBIR
  • NCSC guidance, 2025Assume breach

    The NCSC describes large language models as confusable deputies that cannot reliably separate instruction from data, and advises an assume-breach stance on prompt injection.

    Source NCSC
  • Zero-click, 2025CVE-2025-32711

    EchoLeak (CVE-2025-32711) was a zero-click prompt injection in Microsoft 365 Copilot that exfiltrated corporate data from a single inbound email.

    Source NIST NVD

Infrastructure

Built, owned and operated by us.

Client work runs on hardware we own, in jurisdictions we chose, with a recovery path no agent can reach.

Compute
6× NVIDIA RTX PRO 6000 Blackwell
VRAM
576 GB
Fabric
200 GbE
Storage
Erasure-coded, distributed
Primary site
United Kingdom
Recovery site
Iceland, outside the Fourteen Eyes

Sovereign source control and memory. Resident open-weight models.

This website is served from a content delivery network; client engagement data is never processed there.

Recovery path

Rule III
  1. United KingdomProduction estateNightly backups to erasure-coded storage with read-only mounts and no cluster-admin key.
    Staggered mirror, send-only
  2. IcelandRecovery siteReceive-only and append-only: the push identity cannot forget or delete, and the site can never push damage upstream.
    Pulled every 2 h, read-only
  3. VaultHardlinked generations, 90 daysNo fleet or agent identity can log in. An agent that destroyed the recovery copy would find the previous generations intact here.
Restores are tested weekly by automation and quarterly by a manual drill. The latest result is the first row of the ledger.

Leadership

Leadership

Varangian is led by the engineer who built and runs the estate the ledger measures, with advisers drawn from capital markets and the boardroom.

  • Portrait of Heimir Helgason

    Heimir Helgason

    Founder & Director

    Builds and operates the Blackwell-class cluster behind Varangian and the autonomous operating doctrine it runs. Previously algorithmic trading and cross-border financial advisory across Europe and the Middle East; co-founded and exited a technology-driven brokerage in Iceland.

  • Portrait of Ahmed W. Khalil

    Ahmed W. Khalil

    Strategic Advisor

    CFA charterholder and former infrastructure finance lawyer; international law, institutional capital allocation and European private equity. Advises on capital strategy and market expansion.

  • Portrait of Alan B. Apter

    Alan B. Apter

    Advisory Board

    Investment banker with over 40 years advising multinationals and boards: Morgan Stanley, Merrill Lynch, Renaissance Capital, Eaglestone Group. Columbia Law School. Founder of Bretalon Ltd.

Trust

Trust and disclosure

What we publish about ourselves, and what we do not claim until it is held.

Coordinated vulnerability disclosure

Report a security issue under our disclosure policy. Our contact details are published in a standard security.txt file.

Contact: mailto:ops@varangian.ai
Expires: 2027-09-01T00:00:00.000Z
Policy: https://varangian.ai/vulnerability-disclosure.html

Certifications targeted

  • Cyber Essentials PlusApplication planned Q4 2026planned
  • ISO/IEC 42001Gap analysis, 2027planned

None claimed until held.

Programmes

NVIDIA Inception Program member

PureTensor is a member of NVIDIA Inception, the programme for AI start-ups.

Contact

Start with a short problem statement.

If there is fit, we schedule a technical call.

  1. 01
    Problem statement

    A few paragraphs: the estate, the concern, and any deadline or regulation you are working to.

  2. 02
    Technical call

    A call with us to agree scope, people and timing.

  3. 03
    Doctrine gap assessment

    Your estate measured against the five rules, with the gaps written down.

Email

Or draft it here

Nothing is sent from this page. Your email client opens with the draft addressed to ops@varangian.ai; if it does not, copy the draft and paste it into any email.

Reporting a vulnerability? Use the disclosure policy.