VARDR
VARDR is our defensive security layer for local systems and data centres. It secures not just the detection of attacks, but above all the decisions around them: every security-relevant action must be signed, target-bound and locally released – and stays tamper-evident in the record afterwards.
How VARDR protects
A signature is not enough
A valid key authorizes nothing on its own. Target, freshness, replay state and a local release must match as well – central authority and the on-site operator share control.
Closed when in doubt
VARDR is fail-closed: on a damaged or unclear state it blocks rather than proceed riskily. Security comes before a convenient pass-through.
Purely defensive
Deception, decoys and isolation act only within our own infrastructure. VARDR slows down and documents attackers – it does not attack foreign systems.
What VARDR can do
Signed actions
Two-key principleControl commands are signed and bound to target node, action and time. Only what the endpoint additionally permits locally is executed.
Encrypted container
Argon2id · XChaCha20Files are encrypted and authenticated chunk by chunk with established methods. Plaintext appears only once everything is verified – a failed attempt leaves no half file.
Replay & rollback protection
Nothing twice, nothing backMessages are accepted at most once; older policies and replayed states are rejected.
SafeOpen & quarantine
Before it is openedLinks and attachments are pre-checked – disguised file types, double extensions, suspicious addresses. Critical items go into isolated quarantine with a clear lifecycle.
Tamper-evident audit
Anchor & witnessSecurity events are chained and signed, anchored externally and witnessed by an independent party – so tampering, truncated ends and rollback become detectable.
Secure export
Safe & sealedFiles leave the system only checked, without active content and with a manifest. Sensitive exports stay useless without a separate grant.
VARDR is a complementary protection and evidence layer, not a replacement for EDR, SIEM or firewall – and no guarantee of absolute security.
Not just detect – make it provable
The difference from classic detection: VARDR secures not only that a response happens, but that it was authorized and stays provable afterwards. Between sensor, decision, execution and log there is no blind trust.
- Every privileged action is signed, target-bound and locally released
- Stale or repeated requests are rejected
- Privileged commands run only from trusted system paths, without a shell
- Audit chains are signed and anchored externally
- An independent witness chain makes even truncated ends detectable
- The chain of custody keeps origin, order and integrity
This creates a verifiable chain from detection to evidence – the strength of VARDR is in provability, not in promising absolute security.
A thin layer above your security
VARDR replaces neither firewall, EDR nor SIEM – it complements them. Your existing systems detect and correlate; VARDR ensures the resulting decisions stay signed, controlled and tamper-evident. As a subsystem in the Berlin network it runs locally in Germany, without any cloud.
Your data stays in Germany.
Security governance for your data centre
We pilot VARDR in a tightly bounded way – from signed policy distribution to external audit anchors to controlled response on test nodes. Tell us what you want to secure.
kontakt@45technologies.de