Security in the Mickai beta, what we prove before you deploy
How the beta lets you confirm no data egress, a signed audit trail, and isolation you can test for yourself.

Security in the Mickai beta is something you verify, not something we ask you to believe. Mickai runs entirely on your own hardware, offline, communicating over loopback only, so no data leaves the machine. Every action is written to the Open Audit Record, a tamper-evident trail where each entry is signed with a post-quantum signature. You can test the isolation yourself: pull the network cable and the SIOS keeps working.
- No data egress. Mickai runs offline on hardware you control, over loopback only.
- Every action is signed and recorded to the Open Audit Record.
- Signatures use FIPS 204 ML-DSA, a post-quantum standard.
- Tamper-evident by design: a signed off-box checkpoint, an independent verify step, and anti-rollback.
- You bring the auditor. The beta is built to be checked, not taken on trust.
How do you prove no data leaves?
Proof begins with where the SIOS runs. Mickai is a sovereign inference environment that installs on the applicant's own hardware and operates offline. Its components talk to each other over loopback, the local address that never leaves the machine, so there is no outbound path for prompts, documents, or model output to travel.
That claim is testable in the plainest way possible. Disconnect the machine from every network, run your most sensitive workload, and watch the SIOS carry on. Nothing degrades, because nothing was reaching out. An auditor can place a packet capture beside the running system and confirm the same result from the wire.
Because there is no cloud endpoint in the design, there is nothing to intercept in transit and nothing held on someone else's server after the session ends. The data that enters the SIOS stays on the hardware you already control, which is the plainest form of data residency there is.
What is the Open Audit Record?
The Open Audit Record, or OAR, is the log every action writes to. When the SIOS acts, whether that is answering, retrieving from a private knowledge base, or running a studio workflow, the event is recorded as a discrete signed entry rather than a line of free text that anyone could later rewrite.
Each entry is signed with FIPS 204 ML-DSA, the post-quantum digital signature standard. This matters because a signature that holds today should still hold once quantum computers can break older schemes. ML-DSA is a signature standard, distinct from FIPS 203 ML-KEM, which performs key encapsulation and never signs anything.
The result is a trail that answers a precise question. Not only what happened, but what authorised it, in an order that cannot be quietly rearranged.
How is the audit trail tamper-evident?
Tamper-evident is the honest word, and we use it deliberately. No log is unbreakable. What the OAR guarantees is that interference shows, and three mechanisms work together to make sure of it.
First, a signed checkpoint is written off-box, to storage the SIOS cannot reach and edit after the fact, so anyone altering the local record still has to reconcile it against that external anchor. Second, an independent verify step re-checks the chain of signatures and reports any entry that does not match. Third, anti-rollback prevents the record from being wound back to an earlier, more convenient state and passed off as current.
Together these mean an auditor is never asked to trust that the log is intact. They run the verification and see for themselves whether it is.
What can an auditor check in the beta?
The beta is deliberately built for scrutiny. An auditor can confirm the SIOS runs offline, capture traffic to show the loopback-only claim holds, and generate activity while watching each action land in the Open Audit Record.
They can then run the verify step against the off-box checkpoint and satisfy themselves that the signatures are valid and the sequence is unbroken. Because the record is signed with a published standard, the verification does not depend on trusting Mickai. It depends on mathematics an independent party can rerun.
This is the whole point of the beta. Everything described here is a claim until you test it on your own hardware, with your own data, under your own watch.
Why is the Mickai beta selective?
Mickai admits a small number of beta participants rather than everyone who applies. Working closely with each participant is how we make sure the isolation, the audit trail, and the verification hold up against real workloads rather than a staged demonstration.
Selectivity also protects the standard. Every participant who verifies the isolation and the audit trail strengthens the evidence behind these claims, so we would rather onboard carefully than widely.
Mickai is built and led by Micky Irons, founder of Mickai, and the security posture described here reflects work protected by 104 filed UK patent applications covering approximately 2,340 claims, owned by Mickai LTD. To be considered, apply at mickai.co.uk/beta.
Frequently asked questions
Can I run Mickai completely offline during the beta?
Yes. Mickai installs on your own hardware and operates offline over loopback only. Disconnecting from the network is a valid way to confirm that no data egress is possible, and the SIOS is designed to keep working when you do.
What signs each entry in the Open Audit Record?
Every entry is signed with FIPS 204 ML-DSA, the post-quantum digital signature standard. It is a signature scheme rather than key encapsulation, which keeps it distinct from FIPS 203 ML-KEM. The choice is intended to keep signatures trustworthy as cryptography moves into a post-quantum era.
Can someone edit the audit trail without it being noticed?
No. The Open Audit Record is tamper-evident: a signed off-box checkpoint, an independent verify step, and anti-rollback protection mean that any interference shows when the record is checked. We call it tamper-evident rather than making an absolute promise, because the guarantee is reliable detection.
How do I verify the audit trail myself?
During the beta you run the verify step, which re-checks the chain of signatures against the off-box checkpoint and flags any entry that does not reconcile. Because the signatures use a published standard, an independent auditor can rerun the same check without taking anything on trust.
How do I apply for the Mickai beta?
Apply at mickai.co.uk/beta. Places are limited and participants are selected carefully, so the application asks enough to confirm the hardware you have and the workloads you want to put through the SIOS.