Tartarus™ is a physical containment layer for generative computing. This assessment scores whether your AI infrastructure can be stopped by a wire — not by a policy the system itself can override.
Four decades of fault-tolerant control systems for nuclear instrumentation, aerospace, and heavy industrial environments across six continents. The same separation principle that keeps critical infrastructure safe — the layer that protects is never the layer that operates — is now applied to generative compute.
Tartarus™ treats authorization as a physical constraint, not a policy declaration. In myth, Tartarus is the sealed vault beneath the world where the most dangerous forces are held behind walls of bronze. The engineering principle is identical.
The layer that stops a generative system must be electrically and physically independent of the system it contains. If the only thing between an untrusted model and the outside world is software the model can influence, you do not have containment — you have a request.
Tartarus™ is the physical enclosure in the AI² hardware-governance stack — a sealed, sensed chassis with independent power domains that gives the authorization architecture a physical boundary the enclosed system cannot reach around. The enclosure is the subject of our twelfth USPTO provisional patent. The architecture it holds — the quaternary inhibition lattice, typed egress channels, and the atomic-commit gate — is the subject of a separate provisional filing, in which generation and execution are structurally separated so that no candidate output takes external effect except by traversing a deterministic, hardware-enforced gate.
The assessment on this page scores your current infrastructure against that framework — before you ever touch our hardware. It runs entirely in your browser and tells you where your containment gap is widest.
Each layer restrains the one inside it. The inner layers — the inhibition lattice, permission runtime, and typed-egress gate — are the authorization-architecture filing. The outer envelope is the Tartarus™ physical-enclosure filing: the layer that can halt the assembly without the cooperation of anything it contains.
Patent basis — two distinct USPTO provisional filings. Inner layers: the authorization-architecture filing (structural separation of generation from execution, the ordered inhibition lattice, typed egress with pre-generation binding, atomic-commit gate). Outer envelope: the Tartarus™ physical-enclosure filing. The assessment below scores the physical envelope; the architecture is the system it is built to contain.
The moment that matters is the moment of failure. Most systems cannot reconstruct their own state at that moment, cannot prove what was authorized, and cannot be halted without the cooperation of the thing that just failed. That distance — between what a system is permitted to do and what it can actually be stopped from doing — is the Authorization Gap™.
RBAC, guardrails, and policy layers all live inside the blast radius. A privileged process on the compute node can, on most deployments, disable the very controls meant to restrain it.
Power, electromagnetic, timing, thermal, and acoustic emanations carry information across any air gap. Few AI deployments have ever been measured for it.
Eight domains, forty controls, scored against the Tartarus™ framework — with per-finding remediation and a phased roadmap you can act on Monday.
Red-team reviews, audits, and AI-system underwriting increasingly ask for evidence of physical containment. This assessment is where that evidence starts.
If an unauthorized external effect from your AI system carries real-world cost, this assessment is calibrated for you.
Teams running agentic or high-capability generative systems where a single unauthorized action, transaction, or exfiltration is materially expensive.
Facilities hosting untrusted or third-party models who must reason about physical, power-domain, and interface isolation — not just network security.
Regulated and high-assurance environments that are required to demonstrate containment rather than assert it in a policy document.
Anyone preparing for red-team engagement, security audit, or insurance underwriting of an AI system, who needs a defensible starting posture.
AI² — Asymmetric Intelligence & Innovation. We build the layer that sits beneath the model: hardware that enforces what software can only request. Our doctrine comes from four decades of fault-tolerant control systems, where the layer that protects is always separated from the layer that operates.
Founded by David P. Reichwein — four decades in nuclear instrumentation, aerospace, and heavy industrial control — with Dr. Khaliah Parker-Reichwein as COO. Based in Nashville, Tennessee. Tartarus™ is one component of a coherent hardware-governance stack:
A structured intake across eight containment domains. The scoring engine runs on your machine — nothing is transmitted until you decide to send it.
Answer the eight-domain questionnaire below — physical enclosure, power, interfaces, side channels, authorization, supply chain, and incident response.
The gauge updates as you answer. Every unanswered or unconfirmed control is counted at worst case — you start fully exposed and buy the gap down with each verified control.
A weighted gap score, ranked findings with specific remediation, and a phased roadmap from immediate fixes to full Tartarus™ deployment.
Escalate to a certified review: validated findings, a hardware remediation roadmap, and a working session with the AI² team.
Start free. Escalate when the gap is real.
Scheduled and invoiced after a short scoping call.
Answer what you can. Every scored item left blank is counted at worst case, so a partial intake gives you a deliberately conservative floor.