The substrate everything else runs on.
A private compute and storage fabric spanning our sites, built on the assumption that any site can be unreachable at any time and that the institution must keep functioning while it is. Every record has custody in at least three places and can prove it.
- Zero-trust between sites; no implicit intra-network authority
- Content-addressed storage with independent integrity audit
- Partition-tolerant by construction, not by configuration
- Full state reconstructible from any two surviving sites
Architecture & failure modes →
Turns thirty years of inconsistent records into something answerable.
The retrieval and reasoning layer over the institutional record. Its defining constraint is attribution: Atlas will decline to answer rather than answer without a citable source, and every response carries the provenance of the material it drew on.
- Refuses unsourced synthesis by design
- Provenance chain attached to every result
- Operates on the Archive of record, not on a copy
- Contradictions surfaced rather than resolved silently
Architecture & failure modes →
Observation and integrity monitoring
since 2006 Watches our own instruments for the moment they begin to lie.
Argus monitors the health and honesty of SENTINEL's own sensing estate. It does not observe people or public spaces. Its purpose is narrow and internal: detecting the drift, miscalibration and quiet failure that turn an instrument into a confident source of wrong numbers.
- Cross-instrument corroboration before alerting
- Calibration drift detection over multi-year baselines
- Explicit false-positive budget per class of alarm
- No collection against individuals, by charter
Architecture & failure modes →
Power and thermal continuity
since 1989 Keeps the lights on at sites where nobody is coming to help.
Islanded generation, storage and thermal management for remote stations. Helios assumes no grid, no fuel delivery for the season, and no engineer on site, and is designed to shed load in a defined order rather than fail as a unit.
- Deterministic load-shedding order, rehearsed annually
- Multi-season autonomy at reduced draw
- Thermal envelope maintained ahead of compute
- Manual override reachable without power
Architecture & failure modes →
An agreed answer to what time it is, when nothing else agrees.
Distributed time and frequency reference for sites that may go months without external synchronisation. Polaris exists because a surprising share of our historical data quality incidents reduced, eventually, to two instruments disagreeing about when something happened.
- Holdover measured in months, not hours
- Disagreement surfaced rather than averaged away
- Signed time attestations attached to observations
- Independent of any single external reference
Architecture & failure modes →
How material leaves the institution, when it leaves at all.
The controlled boundary between SENTINEL and everyone else: partner exchange, coordinated disclosure, and Archive publication all pass through it. Nexus enforces the redaction the Disclosure Board approved, and records what was released and when.
- Redaction applied at the boundary, not by the requester
- Every release recorded, dated and attributable
- End-to-end encrypted partner channels
- Publication is append-only; withdrawal is itself a record
Architecture & failure modes →