UK-sovereign AI security
Attack yourself before others do.
Varangian runs the operating doctrine PureTensor uses on its own estate: continuous self-attack, bounded self-healing and a disaster-recovery copy no agent can reach. We publish the ledger every day. Then we run the same doctrine for you.
- Jurisdiction
- United Kingdom
- Recovery site
- Iceland
- Compute
- Own Blackwell-class GPUs
- Client data
- No foreign model APIs
Services
Six engagements. One doctrine.
Each engagement applies the doctrine we already run on our own production estate, and the evidence is published in the ledger every day.
-
01Rule I
Continuous adversarial validation
Autonomous penetration testing and exposure validation with documented production-safety rails; threat-led testing ready for DORA and TIBER-EU.
-
02Rule I
AI-system red teaming
Prompt injection, memory poisoning, tool abuse and agent authority-boundary testing against the systems you deploy.
-
03Rule III
Resilience engineering
3-2-1-1-0 backup architecture, immutable and logically air-gapped copies, isolated recovery environments, restore drills with published recovery objectives.
-
04Rule IV
Trustless architecture
Workload identity, just-in-time access, four-eyes authorisation and zero-trust backup.
-
05Rules II and V
Agentic operations design
Bounded-authority self-healing loops and the enforcement pattern that keeps every agent out of the vault.
-
06Own compute
Sovereign deployment
On-premise or UK/EU-sovereign inference for workloads that must not leave your jurisdiction.
Operating doctrine
Five rules, applied to ourselves first.
We apply every rule to our own estate before we sell it. The ledger shows whether we are keeping them today, red included.
- I
Attack yourself continuously.
Live evidenceIn our estate
Independent model seats review our repositories adversarially every day and open evidence-bearing pull requests; a human re-runs every claim before merge. Exposure is probed from outside our own network, never from inside it. Monitors are audited for the ability to go red.
For yours
Continuous adversarial validation of your estate, on our sovereign compute, mapped to DORA threat-led testing and NCSC CAF.
- II
Self-heal with bounded authority.
Live evidenceIn our estate
A deterministic scan-and-fix loop with models only at the edges, promoted from shadow to suggest to canary to auto, with a Tier-0 carve-out. Outcomes are graded resolved, recurred or indeterminate, and never green by default.
For yours
Autonomous remediation designed with a written authority boundary and a human approval gate for everything outside it.
- III
Three copies, two media, one out of reach.
Live evidenceIn our estate
Nightly backups to erasure-coded storage with read-only mounts and no cluster-admin key, staggered mirrors to Iceland, and a send-only to receive-only topology so the recovery site can never push damage upstream. Restores are tested weekly by automation and quarterly by a manual drill.
For yours
3-2-1-1-0 resilience engineering with published recovery objectives and an isolated recovery environment.
- IV
Trustless by construction.
Live evidenceIn our estate
Rotation with completeness proof, same-day privilege reduction, a private mesh, and trust tiers graded by surface.
For yours
Workload identity, short-lived credentials, four-eyes on destructive actions, and zero-trust backup: the identity that writes a backup cannot delete it.
- V
Agents run the estate. Agents never touch the vault.
Live evidenceIn our estate
Enforced and audited daily: audit/agent_vault_audit.py probes every model-driven seat from inside its own sandbox and proves no agent credential can read, list or delete disaster-recovery snapshots. The ledger row below is that measurement, and it goes red the day a path appears.
For yours
An agentic operations design where no agent credential has a path to disaster-recovery or crucial backup storage. It is the control that turns an AI incident into an inconvenience instead of an extinction event.
Production evidence
The live doctrine ledger
Generated from our own fleet, refreshed daily and rendered from ledger.json. Every row can go red. A ledger that cannot go red is not a ledger.
- Controls
- 11
- Holding
- –
- Warning
- –
- Red
- –
Values are measured on PureTensor's production estate. "Red" means the doctrine is not met today and the fix is scheduled; it is published anyway. A missing or unknown measurement is shown as red, never as green.
Regulatory drivers
The regulatory clock
The obligations that make this doctrine mandatory, with the date each one bites, and the threat evidence behind them. Every line links to its primary source.
Obligations, in date order
- UK
UK GDPR Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of security measures.
Source legislation.gov.uk - EU
NIS2 Article 21(2)(c) makes backup management and disaster recovery a mandatory measure, and Article 20 places personal accountability on management bodies.
Source EUR-Lex - EU
DORA Article 26 requires threat-led penetration testing at least every three years, on live production systems, under the TIBER-EU framework.
Source EUR-Lex - UK
The NCSC and DSIT Cyber Governance Code of Practice asks boards for tested recovery plans and independent assurance.
Source GOV.UK - UK
NCSC Cyber Assessment Framework v4.0 adds outcomes for AI-related and autonomous-software risk.
Source NCSC - UK
The UK Cyber Security and Resilience Bill brings managed service providers, data centres and critical suppliers into scope, with 24-hour early warning and 72-hour incident reports.
Source UK Parliament - UK
Cyber Essentials 'Danzell' requirements mandate 14-day vulnerability remediation and hardware-backed MFA for cloud administrative access.
Source NCSC - EU
EU AI Act Article 15 requires high-risk systems to be resilient against adversarial attack, prompt injection and data poisoning.
Source EUR-Lex - EU
The Cyber Resilience Act's 24-hour reporting of actively exploited vulnerabilities to ENISA begins 11 September 2026; full application follows on 11 December 2027.
Source EUR-Lex
Threat evidence
- Breach data, 202562%
Verizon's 2025 Data Breach Investigations Report puts the human element in 62% of breaches, vulnerability exploitation at 31% of initial access and credential abuse at 13%.
Source Verizon DBIR - NCSC guidance, 2025Assume breach
The NCSC describes large language models as confusable deputies that cannot reliably separate instruction from data, and advises an assume-breach stance on prompt injection.
Source NCSC - Zero-click, 2025CVE-2025-32711
EchoLeak (CVE-2025-32711) was a zero-click prompt injection in Microsoft 365 Copilot that exfiltrated corporate data from a single inbound email.
Source NIST NVD
Infrastructure
Built, owned and operated by us.
Client work runs on hardware we own, in jurisdictions we chose, with a recovery path no agent can reach.
- Compute
- 6× NVIDIA RTX PRO 6000 Blackwell
- VRAM
- 576 GB
- Fabric
- 200 GbE
- Storage
- Erasure-coded, distributed
- Primary site
- United Kingdom
- Recovery site
- Iceland, outside the Fourteen Eyes
Sovereign source control and memory. Resident open-weight models.
This website is served from a content delivery network; client engagement data is never processed there.
Recovery path
Rule III- United KingdomProduction estateNightly backups to erasure-coded storage with read-only mounts and no cluster-admin key.Staggered mirror, send-only
- IcelandRecovery siteReceive-only and append-only: the push identity cannot forget or delete, and the site can never push damage upstream.Pulled every 2 h, read-only
- VaultHardlinked generations, 90 daysNo fleet or agent identity can log in. An agent that destroyed the recovery copy would find the previous generations intact here.
Leadership
Leadership
Varangian is led by the engineer who built and runs the estate the ledger measures, with advisers drawn from capital markets and the boardroom.
-
Heimir Helgason
Founder & Director
Builds and operates the Blackwell-class cluster behind Varangian and the autonomous operating doctrine it runs. Previously algorithmic trading and cross-border financial advisory across Europe and the Middle East; co-founded and exited a technology-driven brokerage in Iceland.
-
Ahmed W. Khalil
Strategic Advisor
CFA charterholder and former infrastructure finance lawyer; international law, institutional capital allocation and European private equity. Advises on capital strategy and market expansion.
-
Alan B. Apter
Advisory Board
Investment banker with over 40 years advising multinationals and boards: Morgan Stanley, Merrill Lynch, Renaissance Capital, Eaglestone Group. Columbia Law School. Founder of Bretalon Ltd.
Trust
Trust and disclosure
What we publish about ourselves, and what we do not claim until it is held.
Coordinated vulnerability disclosure
Report a security issue under our disclosure policy. Our contact details are published in a standard security.txt file.
Contact: mailto:ops@varangian.ai Expires: 2027-09-01T00:00:00.000Z Policy: https://varangian.ai/vulnerability-disclosure.html
Certifications targeted
- Cyber Essentials PlusApplication planned Q4 2026planned
- ISO/IEC 42001Gap analysis, 2027planned
None claimed until held.
Programmes
PureTensor is a member of NVIDIA Inception, the programme for AI start-ups.
Contact
Start with a short problem statement.
If there is fit, we schedule a technical call.
- 01Problem statement
A few paragraphs: the estate, the concern, and any deadline or regulation you are working to.
- 02Technical call
A call with us to agree scope, people and timing.
- 03Doctrine gap assessment
Your estate measured against the five rules, with the gaps written down.