scriptkittyos & labs

sanction os

early access

Where Sanction runs. Not a member of it.

The platform is what makes it something an organization can operate: rules configured without writing code, a tenant boundary, the evaluation harness run against the deployed build, registry operators chosen per deployment, and a path to accreditation.

The default is maximal. Configuration goes downward.

The default is maximal and configuration goes downward, because a system that starts permissive and adds controls has a moment in its history when it was permissive.

One tree, one build, configured per customer. Government, healthcare and other high-sensitivity entities take the whole thing. An ordinary enterprise turns components off. Modularity is configuration, never a fork.

Configured down is a measurement. If a component is disabled, what the remaining system still guarantees is derived, not assumed. A supported configuration is one with a passing evaluation row. A configuration with no row is not supported.

Two offers, not one offer at two prices.

Self-hosted Sanction

The four systems, run on your infrastructure, under license.

Platform-hosted Sanction OS

The same systems, operated as a platform with a tenant boundary and a path to accreditation.

What the platform closes that the systems alone cannot.

  • Predicates configured without code, and a rule change is itself a governed act with its own witnesses and its own receipt.
  • A tenant boundary.
  • Continuous authority to operate.
  • Registry operators chosen per deployment across independent institutions. Never a single command in a defense deployment, never a carrier in a trade one.

Early access.

Sanction OS is in early access. The platform's evaluation rows are published as they are run, and a configuration with no row is not offered. Requests are reviewed by the owner.

Written to the standard the hardest deployment requires, then configured down. What is fielded in a given environment is stated on request, not on this page.