← MRM/Projects/Bastion
Risk & Compliance Working Rust · air-gapped

Bastion

One deterministic platform for risk, compliance, and operations.

Teams drown in fragmented risk and compliance tools. Bastion consolidates them onto a single verifiable, offline-safe core with a shared cryptographic kernel — no AI, no external services, and full provenance on every number (measured vs. asserted).

bastion — analysis kernel
$ bastion analyze --graph estate.json --lens spof loaded 12,480 nodes · 31,902 edges (sub-second) ! single points of failure: 3 → auth-db-primary blast radius 214 nodes → payroll-gateway blast radius 88 nodes $ bastion evidence seal ed25519 signed · hash-chain intact · provenance tagged

Representative output — not a live instance.

What it does
Entity-graph analysis — blast-radius, single-point-of-failure (articulation points), path enumeration and orphan detection, verified on 100k-node chains.
Cryptographic evidence vault — hash-chained, ed25519-signed, tamper-evident records with measured-vs-attested provenance tagging.
Multi-lens risk reporting — 7 of a planned 22 lenses built and byte-parity-proven so far (dead code, vendor risk, permission explosion, data lineage, tech debt, asset life, entropy).
Local-first search — BM25 full-text indexing with deterministic ranking and zero network dependency.
Scenario simulation — what-if failure propagation plus bounded optimization for impact modelling, and a compliance control crosswalk.
Proof
0
unit tests
<0.5s
100k-node chain (release)
7/22
lenses built & parity-proven
byte-exact
parity harness vs. originals
Rustblake3ed25519-dalekserdeclapCargo workspace
🔒
Architecture and verified results shown. Source and binaries are private — this is a capability showcase, not a distribution.

Consolidating
risk tooling?

I build verifiable, offline-safe platforms that replace a pile of spreadsheets and point tools. Tell me what you're trying to consolidate.

Start a project →