Ownership and delivery

A clear boundary at handover.

Æstrum defines the checks with you, tests the delivery against saved cases, and hands over a sealed package. After handover, it runs in your environment under your credentials, terms, and data.

● Zero Subscription ● Zero Telemetry ● Zero Hosted Custody
REVIEW PANE delivery-manifest.sha256
● HERMETIC PACKAGE
DELIVERY // VERIFIED CANDIDATE PACKAGE #2026-09-V2
SEALED AT HANDOVER
● SHA-256 Verified
Verification Candidate verified against frozen regression test suite before handover.
Package integrity Signed SHA-256 hash guarantees delivered files are intact and unaltered.
Deployment Runs in your VPC or bare metal; zero telemetry, zero hosted custody.
Custody boundary Credentials, tokens, records, and client data remain strictly yours.
No subscription · Zero telemetry [ VERIFIED // SEALED AT HANDOVER ]

Delivery boundary

What is delivered, where it runs, and who holds what.

Standalone by design does not remove external limits. It means the delivery boundary is explicit, verifiable, and enforceable.

01 / DELIVERED package-contents.spec
● SEALED BINARY
DELIVERY // ARTIFACTS PACKAGE & GUIDANCE
SEALED PACKAGE
● Frozen Candidate
Deliverables Hermetic application package, operating instructions, and runbook.
Evidence Verification test suites and diff records for that exact candidate.
Stability Code does not change under you. Any modification is a new verified delivery.
Zero drift · Immutable [ VERIFIED PKG ]
02 / RUNS runtime-env.config
● AIR-GAPPED
RUNTIME // HOSTING YOUR ENVIRONMENT
CUSTOMER VPC
● Bare Metal to K8s
Hosting You choose the runtime: Kubernetes, private cloud VPC, or bare metal.
Isolation Zero telemetry, zero vendor callbacks, zero hosted multi-tenant risk.
Autonomy Runs independently of Æstrum's build systems and servers.
Your VPC · 0 phone-home [ SOVEREIGN ]
03 / HOLDS custody-boundary.spec
● ZERO VENDOR ACCESS
CUSTODY // GOVERNANCE CREDENTIALS & DATA
YOUR DATA & KEYS
● $0 SaaS Tax
Credentials Your deployment holds all tokens, secrets, and API credentials locally.
Records All execution logs, research dossiers, and client data remain yours.
Ownership No subscription recurring tax, no seat fees, no vendor lock-in.
0 lock-in · Your data [ CLIENT ONLY ]

Evidence & records

Different records answer different questions.

A recommendation or delivery should reveal the basis for it. We distinguish between build verification, file package integrity, and runtime operational traces.

AUDIT SPECS record-taxonomy.view
● 3 RECORD TYPES
Verification Records whether the exact delivery candidate passed agreed acceptance checks and regression tests.
Package integrity Signed SHA-256 hash guarantees delivered files are intact and unaltered in transit.
Run record Records what happened during a particular agent execution in your VPC and what raw evidence was retained.
Three distinct audit records · Zero ambiguity [ AUDIT TRAIL // VERIFIED ]

Questions

What the boundary does and does not promise.

Clear expectations make the handoff easier to review and operate.

Does the program need Æstrum to keep running?

No. The delivered program runs independently of the build system. The APIs, models, data sources, and other external services it uses still have their own availability, credentials, and terms.

Can the delivery be changed later?

Yes, through a new verified delivery. A changed package is a different candidate and carries the verification appropriate to that change.

Do you host it or keep a copy of my data?

No. The package runs where you choose. Credentials and data stay under your control, and nothing phones home.

Who can access an inquiry?

Use the contact page to prepare a draft inquiry. Nothing is sent from this static site unless a connected delivery channel is explicitly provided.