Independent Systems & AI Lab

Sovereign infrastructure and AI, owned end to end.

We build sovereign products and take on the engineering problems most companies delegate: bare-metal Kubernetes, carrier-grade networks, on-premise AI.

Principles, not promises.

Three rules that decide every architecture we ship, and every product we run.

01

Data Sovereignty & Privacy

Complete data retention, local AI inference on your own servers, and zero reliance on black-box third-party dependencies.

02

Architectural Rigor

End-to-end Zero Trust security, applied from BGP network routing down to LLM token-stream filtering.

03

Cost Efficiency & Control

Pragmatic engineering focused on eliminating cloud waste, reducing operational overhead, and delivering high ROI.

Our products.

Every brand is built, hosted and operated by us: sovereign by design, from scheduling to security.

KronoCal

Coming soon

Sovereign meeting scheduling for teams: no trackers, no third-party cookies, your calendar stays yours.

Get early access

Range Zero

In preparation

Security suite: external attack surface monitoring, LLM privacy gateway and security drills, built for MSPs.

range-zero.com

KronoForms

R&D

High-integrity surveys and structured feedback collection, designed for analysis without surveillance.

Follow the build

Attack surface & AI privacy, under one watch.

One suite for external attack surface monitoring, LLM privacy and security training, built for MSPs, enterprise teams and infrastructure managers. Below: the product, in action.

Range Zero - SuiteIn preparation
AtlasAttack surface, continuously scanned.

Automated visibility over your external infrastructure.

Continuous monitoring of external digital assets. Atlas ingests domains or IP ranges and automatically discovers subdomains, open ports, SSL health and configuration drift in real time.

Monitored assets
Continuous scan
SSL & DNS drift
Real-time alert
Port discovery
Auto-inventory
ACTIVE MESHdns.primarydb.masterapp.clustervault.seccore.gateway
Network topology5 NODES ONLINE
Atlas in detail
PaladinSecurity drills for real readiness.

Security training your team will actually follow.

A continuous training platform: short modules adapted to each role, covering phishing, passwords, data handling and physical security, with harmless drills that measure what sticks. Compliance-ready reporting for auditors.

Team path - Finance

Week 4 of 12
  • Passwords & MFA4 min
  • Spotting phishing6 min
  • Data handling (GDPR)
  • Physical security5 min

After 90 days with Paladin

Team awareness index0%
Awareness level: High+13.8% MoM
Paladin in detail
VanguardLLM privacy gateway.

Real-time sensitive data masking for LLMs.

A high-performance proxy that redacts confidential credentials, API keys, e-mails and personal identifiers before prompt dispatch, then seamlessly restores them into the model's response stream.

Vanguard in detail
MSP Program

Multi-tenant governance & volume licensing for MSPs.

Deliver turnkey security visibility and LLM privacy control to your entire client portfolio through a unified MSP control plane, with tiered volume discounts, automated API provisioning and dedicated onboarding.

ArchitectureMulti-Tenant
ProvisioningAutomated API
ReportingWhite-Label
Pricing modelTiered volume

Ready to expand your managed services?

Get in early, help shape the suite: direct line to the team building it.

Explore the programEarly accessrange-zero.com

Engineering & advisory, hands on the metal.

Hands-on architectural advisory, cost optimization and crisis engineering for high-assurance systems.

Step 1 / 3

Request a scoping call

What do you need?

Technical case studies.

Carrier-grade routing, air-gapped AI, sovereign Kubernetes: real infrastructure work, anonymized by design.

Clear answers, no jargon.

The questions we get asked most often, answered with the depth we'd want to find elsewhere. Missing yours? Ask it directly.

Ask us directly
01What is Cardinal Codes?

Cardinal Codes is an independent systems and AI lab. We design sovereign infrastructure and carrier-grade engineering: bare-metal Kubernetes clusters, BGP/IPv6 networking, on-premise AI inference, and LLM privacy protection. Our product suite, Range Zero, covers external attack surface management (Atlas), security drills (Paladin), and LLM privacy gateway (Vanguard).

02What is sovereign AI infrastructure?

Sovereign AI infrastructure means running large language models entirely on your own hardware, with zero data leaving your network. This involves on-premise inference engines like vLLM, vector databases like Qdrant for retrieval-augmented generation, and open-weight models such as Llama or Mistral. No API keys sent to third parties, no usage telemetry, full control over your data pipeline.

03How does Vanguard protect LLM prompts?

Vanguard is a real-time LLM proxy that intercepts outbound prompts before they reach external AI models. It redacts API keys, email addresses, internal IP addresses, and personal identifiers (SSN, financial data) in under 1 millisecond. After the model responds, Vanguard restores the redacted values in-flight so the user sees their original data. Zero configuration changes needed on the AI provider side.

04What does Atlas monitor?

Atlas performs continuous external attack surface management (EASM). It discovers unauthorized subdomains, detects expired or misconfigured SSL certificates, monitors open ports and configuration drift, and alerts on DNS changes in real time. Deployment is zero-agent: provide your domains or IP ranges, and Atlas begins scanning immediately with no software to install on your infrastructure.

05How does Paladin train teams against cyber threats?

Paladin is a continuous cybersecurity training platform with short modules adapted to each role: phishing awareness, password hygiene, data handling, and physical security. It runs harmless simulated phishing drills to measure what sticks, then adapts content accordingly. Compliance-ready reporting for auditors, with a team resilience index that tracks improvement over time.

06What is bare-metal Kubernetes and why does it matter?

Bare-metal Kubernetes means running container orchestration directly on physical servers instead of cloud VMs. This eliminates cloud markup (typically 3-5x over hardware cost), removes vendor lock-in, and provides deterministic performance. We deploy it with Talos OS for immutable infrastructure, ArgoCD for GitOps, Cilium for networking, and StackGres for distributed PostgreSQL.

Tell us what you run.

Describe the stack and the constraint. We answer within 48 hours with a scoped proposal.

Work with us