Internal System · IT Security

VARDR

VARDR is our defensive security layer for local systems and data centres. It secures not just the detection of attacks, but above all the decisions around them: every security-relevant action must be signed, target-bound and locally released – and stays tamper-evident in the record afterwards.

Principles

How VARDR protects

01

A signature is not enough

A valid key authorizes nothing on its own. Target, freshness, replay state and a local release must match as well – central authority and the on-site operator share control.

02

Closed when in doubt

VARDR is fail-closed: on a damaged or unclear state it blocks rather than proceed riskily. Security comes before a convenient pass-through.

03

Purely defensive

Deception, decoys and isolation act only within our own infrastructure. VARDR slows down and documents attackers – it does not attack foreign systems.

Capabilities

What VARDR can do

Signed actions

Two-key principle

Control commands are signed and bound to target node, action and time. Only what the endpoint additionally permits locally is executed.

Encrypted container

Argon2id · XChaCha20

Files are encrypted and authenticated chunk by chunk with established methods. Plaintext appears only once everything is verified – a failed attempt leaves no half file.

Replay & rollback protection

Nothing twice, nothing back

Messages are accepted at most once; older policies and replayed states are rejected.

SafeOpen & quarantine

Before it is opened

Links and attachments are pre-checked – disguised file types, double extensions, suspicious addresses. Critical items go into isolated quarantine with a clear lifecycle.

Tamper-evident audit

Anchor & witness

Security events are chained and signed, anchored externally and witnessed by an independent party – so tampering, truncated ends and rollback become detectable.

Secure export

Safe & sealed

Files leave the system only checked, without active content and with a manifest. Sensitive exports stay useless without a separate grant.

VARDR is a complementary protection and evidence layer, not a replacement for EDR, SIEM or firewall – and no guarantee of absolute security.

The core

Not just detect – make it provable

The difference from classic detection: VARDR secures not only that a response happens, but that it was authorized and stays provable afterwards. Between sensor, decision, execution and log there is no blind trust.

  • Every privileged action is signed, target-bound and locally released
  • Stale or repeated requests are rejected
  • Privileged commands run only from trusted system paths, without a shell
  • Audit chains are signed and anchored externally
  • An independent witness chain makes even truncated ends detectable
  • The chain of custody keeps origin, order and integrity

This creates a verifiable chain from detection to evidence – the strength of VARDR is in provability, not in promising absolute security.

In the Network

A thin layer above your security

VARDR replaces neither firewall, EDR nor SIEM – it complements them. Your existing systems detect and correlate; VARDR ensures the resulting decisions stay signed, controlled and tamper-evident. As a subsystem in the Berlin network it runs locally in Germany, without any cloud.

All internal systems →

Your data stays in Germany.

Contact

Security governance for your data centre

We pilot VARDR in a tightly bounded way – from signed policy distribution to external audit anchors to controlled response on test nodes. Tell us what you want to secure.

kontakt@45technologies.de