Skip to content
Technology How it works Breeder — Hyperion Burner — Aegis Burner — MetroVolt AI-Native Architecture Magnets Fuel cycle Safety Roadmap
Solutions AI & Data Centers Defense & Government Grid & Baseload Neutron Detection Quantum
Learn Technical Library
Proof Publications Whitepapers Technical Library Open Science & Reproducibility The Honest Gates
Company About / Mission Leadership Environment Health & Safety Investors Careers Press Contact
3D Model
AI Architecture › Security & Zero-Trust
Security & Zero-Trust

Insider-Threat Model

The design assumes a privileged insider may turn malicious or be coerced, and limits what any single trusted person can do without a second party detecting or blocking it.

STRATEGY / SLOW ▲ ▼ MICROSECOND REAL-TIMEL7Ecosystem & Strategytelemetry ▲ control ▼open ▸L6Experience & Visualizationtelemetry ▲ control ▼open ▸L5Applications & Copilotstelemetry ▲ control ▼open ▸L4Orchestrationtelemetry ▲ control ▼open ▸L3Twin Modeling & AItelemetry ▲ control ▼open ▸L2Data Fabrictelemetry ▲ control ▼open ▸L1Control Planetelemetry ▲ control ▼open ▸L0Foundationtelemetry ▲ control ▼open ▸PHYSICAL S.M.A.R.T. GENERATOR PLANTBREEDER · HYPERION1R0 1.2 m · A 2.5 · 16.84 T · δ −0.30BURNER · TANDEM MIRROR2317 T throat · 26.49 T plug · fₙ 5.44% · DEC1 center stack + plasma · 2 high-field plug · 3 expander → direct converterCOLOR GRAMMAR strategy AI-workflow infra/data models reactor/DECLINE SEMANTICStelemetry (µs)controlKRONOS FUSION ENERGYAI-NATIVE S.M.A.R.T. GENERATORMASTER BLUEPRINTSHEET 01REV. 2026-08L0-L7 · 2 MACHINES
The AI-Native S.M.A.R.T. Generator Master Blueprint — eight layers (L0→L7), one control stack, wired to both machines. Telemetry rises in microseconds; control descends the same path.

The hardest adversary

External controls do little against someone already trusted: an operator, an engineer with maintenance access, or an administrator of the control systems. A malicious or coerced insider is the hardest adversary because they hold legitimate credentials and knowledge of the machine. Kronos does not pretend to eliminate insiders; it designs so that no single insider can cause an unsafe plasma state or erase their tracks alone.

Structural mitigations

Threat scenarios considered

Insider scenario vs mitigating control (1=addressed): cols=SoD/JIT/audit/SIS
1111011010100010

Rows: unsafe actuation attempt, credential misuse, covering tracks, and data exfiltration. Unsafe actuation is blocked on multiple axes; exfiltration is caught by audit and constrained by the export-only diode and least privilege, though a determined insider with legitimate read access remains a residual risk that monitoring, not architecture alone, must address.

Honest limits

No design fully stops a sufficiently privileged, patient insider from misusing legitimate read access or from social-engineering a second approver. These residual risks are managed with monitoring, vetting, and rotation, which are organizational, not purely technical. Design status: the technical controls run in the twin; the personnel and vetting program is defined for plant operation and not yet operating.

Content reviewed August 2026 · design-and-simulation stage