Bastion
One deterministic platform for risk, compliance, and operations.
Teams drown in fragmented risk and compliance tools. Bastion consolidates them onto a single verifiable, offline-safe core with a shared cryptographic kernel — no AI, no external services, and full provenance on every number (measured vs. asserted).
$ bastion analyze --graph estate.json --lens spof
✔ loaded 12,480 nodes · 31,902 edges (sub-second)
! single points of failure: 3
→ auth-db-primary blast radius 214 nodes
→ payroll-gateway blast radius 88 nodes
$ bastion evidence seal
✔ ed25519 signed · hash-chain intact · provenance tagged
Representative output — not a live instance.
●Entity-graph analysis — blast-radius, single-point-of-failure (articulation points), path enumeration and orphan detection, verified on 100k-node chains.
●Cryptographic evidence vault — hash-chained, ed25519-signed, tamper-evident records with measured-vs-attested provenance tagging.
●Multi-lens risk reporting — 7 of a planned 22 lenses built and byte-parity-proven so far (dead code, vendor risk, permission explosion, data lineage, tech debt, asset life, entropy).
●Local-first search — BM25 full-text indexing with deterministic ranking and zero network dependency.
●Scenario simulation — what-if failure propagation plus bounded optimization for impact modelling, and a compliance control crosswalk.
0
unit tests
<0.5s
100k-node chain (release)
7/22
lenses built & parity-proven
byte-exact
parity harness vs. originals
Rustblake3ed25519-dalekserdeclapCargo workspace
🔒
Architecture and verified results shown. Source and binaries are private — this is a capability showcase, not a distribution.
Consolidating
risk tooling?
I build verifiable, offline-safe platforms that replace a pile of spreadsheets and point tools. Tell me what you're trying to consolidate.
Start a project →