Skip to content

Zephyr · Trusted Automation

Accountability and control for automated systems.

Automated systems execute commands, modify code, and interact with core infrastructure. Zephyr cryptographically signs every action to create an immutable record while enforcing strict operational policies before execution.

If a system executes a command, you have the proof. If an action violates policy, it is blocked.

Solving the trust deficit in automation.

The Zephyr architecture.

  1. Step 1

    Sign

    Every action generates a cryptographically signed record detailing the actor, the exact operation, and the timestamp. This signature is tied to a private key and cannot be forged.

  2. Step 2

    Gate

    Before execution, the gatekeeper verifies the signature and evaluates the request against your predefined policy. If either check fails, the action is blocked instantly.

  3. Step 3

    Record

    Authorized actions are written to an append-only ledger. Any subsequent modification breaks the cryptographic signature. Replays and duplicate requests are automatically rejected.

  4. Step 4

    Prove

    Session actions are bundled into a portable, verifiable proof. Auditors can validate this proof offline on their own hardware without requiring access to your internal systems.

Illustrative session
# A system attempts to deploy to production outside the allowed window$ zephyr gatekeeper --input system-action.json  ✗ demo.deploy   signature: VALID   policy: DENIED (outside allowed_times)  → BLOCKED # A legitimate, signed action passes and runs$ zephyr gatekeeper --input system-action.json  ✓ session.tool.run   signature: VALID   policy: OK  → executed. logged. # Prove the whole session offline$ zephyr replay --sbof session.sbof.json  4/4 envelopes verified ✓

Readable policy management.

Zephyr policies are written in plain text for complete team visibility. You define the exact parameters for authorization, execution windows, and data retention.

Authorization
Specify the exact entity required to approve an action. A standard build might require approval from your CI pipeline, while a production deployment requires human verification.
Scheduling
Execution times are signed alongside the action. Policies can automatically reject deployments attempted outside of approved operational hours.
Retention
Lifecycle management is built directly into your policy. Standard build records can expire quickly, while critical deployment records remain permanent.

Platform agnostic integration.

Zephyr integrates directly with your existing technology stack.

Simply attach the server to your system to automatically sign and verify every tool call. Your core codebase remains unchanged.

Integration Kit

Deploy Zephyr alongside your current infrastructure without modifying your core architecture. A lightweight adapter translates system events into standard formats for your product lifecycle platforms, data pipelines, or internal services. Zephyr handles the signing, gating, and recording. A standard conformance check validates the adapter prior to deployment.

Inside Ultimus, Zephyr serves as the primary signing and verification authority. See Context Management

Government and defense contracting.

Zephyr achieved Awardable status on the CDAO Tradewinds Solutions Marketplace on January 21, 2026. It serves as the foundational cryptographic layer enabling automated Authority to Operate (ATO) in strict federal environments.

Production timeline.

  1. April 2025Initial prototype completed.
  2. Late May 2025Deployed into production environments.
  3. May 26, 2025Software Bill of Function published.
  4. January 21, 2026Designated Awardable on CDAO Tradewinds.
  5. July 2026Sealing layer for Evidence-Sealed Authorization deployed to production.

Further reading