QShield · evaluation overlay · demonstration
Oregon to Reykjavík, sealed across the North Atlantic.
Two Linux hosts. One inner Ethernet. Packets leave as UDP on the public internet and arrive as a sealed inner overlay path. This page is a demonstration of a measured evaluation overlay. It is not ATLAS, not FIPS, and not a release stamp.
What is happening on the path
- Control plane. Mutual TLS 1.3 with ML-KEM-1024 only. Session keys stay in process memory. Port 34900.
- Data plane. Inner Ethernet on TUN qshield0 is sealed as S29SP-1 UDP + AES-256-GCM. Port 34999. Outer capture has no inner canary.
- Integrity agent. Every minute the evaluation clock copies 64 KiB and matches SHA-256 end to end.
- Fail-closed. Looking-glass the service port was probed from fifteen countries across four continents: Germany, India, Iran, Israel, Poland, Russia, Singapore, Slovenia, Spain, Sweden, Turkey, Ukraine, the United Kingdom, the United States and Vietnam. Every one failed to connect. Not one joined the session. Management SSH refused eleven of twelve vantages and accepted one, which is why management access is not part of this boundary claim.
Two clocks, one daemon
- USA 24h · complete
- Oregon → Virginia · 1,363 samples · 0 aborts · 86,438 s · done 2026-09-10T22:09:48Z
- Atlantic 72h · running
- Oregon → Reykjavík · started 2026-09-10T11:39:02Z · due 2026-09-13T11:39:02Z · typical inner RTT ~170 ms, operator-reported
- Daemon bytes · unchanged
- 43ece1b40fb8752bd8b0ea751725428f7538b7c8b2c7e7eccea675f5bc6344b5
Regions only. Host addresses are not published here. 36 MiB/s is lab offered load, not WAN. Hour release_go is not flipped by this page.