Powered by Phrakton

Zero-Trust Security.
Seamless for You. Unreachable for Them.

Phrakton is Delteris’s zero-trust network overlay, built on OpenZiti. It abstracts your network away entirely: your factory infrastructure becomes invisible to external threat actors while remaining seamlessly accessible to authorized personnel — with post-quantum-safe encryption end to end and full cryptographic isolation between facilities.

  • No open ports · no public attack surface
  • Post-quantum-safe encryption
  • Cryptographic multitenant isolation

A Network That Isn’t There

Conventional network security guards the door: firewalls, VPNs, and open ports that must be defended around the clock. Phrakton removes the door. Your services have no listening ports exposed to the public internet — there is nothing to scan, nothing to probe, and nothing to move laterally through. Connections are established outbound-only and brokered by cryptographic identity, so a resource is reachable only after a device has proven who it is. To everyone else, your factory simply does not exist on the network.

Core Principles

Zero Trust, End to End

Every capability of the platform runs on top of Phrakton — so security isn’t a feature you switch on, it’s the ground the whole system stands on.

01

The Invisible Factory

Services are unreachable from the public internet — no open ports, no exposed attack surface, no lateral network movement, no room for corporate espionage.

02

Identity, Not Location

Access is granted to verified cryptographic identities, never to an IP address or a network position. A stolen credential on an unknown device reaches nothing.

03

Multitenant by Design

Each facility operates inside its own cryptographically isolated tenant. Strict separation between sites, centrally managed, with no shared plane to cross.

04

Post-Quantum-Safe

Traffic is protected with post-quantum-hybrid key exchange, closing the door on “harvest now, decrypt later” — the data you protect today stays protected tomorrow.

05

Effortless Remote Reach

On-premise doesn't mean on-site-only. With the optional Remote Access Module, monitor operations and run audits from home, on mobile data, or abroad — the connection just works, over a post-quantum-safe encrypted tunnel, with the floor never exposed and nothing for IT to configure.

06

Absolute Data Sovereignty

Your manufacturing data never touches a shared cloud server. The physical hardware, and the jurisdiction it sits in, remain entirely yours.

How It Works

Deny by Default. Prove to Connect.

Phrakton is built on OpenZiti, an open-source zero-trust networking fabric. Rather than opening your network and then trying to defend it, Phrakton keeps everything closed and grants access one verified identity at a time.

  • Outbound-only connections: Your appliance dials out to the fabric. It never accepts an inbound connection from the open internet, so there is no port for an attacker to find.
  • Brokered by the controller: A central controller authenticates every identity and authorizes every session before a single byte of application data flows.
  • Encrypted edge-to-edge: Traffic is encrypted the moment it leaves one endpoint and only decrypted at the other — never in transit, never on a shared server.
  • Least privilege by construction: An identity can reach only the specific services it has been granted. There is no wider network to explore.
Under the Hood

The Encryption Layers on a Connection

A worker reaching an app on your box travels through three nested encrypted tunnels, each with post-quantum-safe key exchange and each opened only at the two endpoints — never on the network. Pick an observer and see exactly how far each one can read.

outer shell = what actually crosses the wire ↓

Select an observer — see how far into the layers it can read:

All three layers

Three nested post-quantum-safe tunnels — Link TLS (green), Ziti E2E (amber) and App TLS (blue). Each one is opened only at the endpoints, never on the network.

Where each layer reaches on the path

Link TLS — quantum-safe · re-wraps at each router Ziti E2E — quantum-safe · opens only at the endpoints App TLS — quantum-safe · carries the actual data box Caddy PHRAKTON VPS network CLIENT LAN behind your firewall firewall · dials OUT public internet remote worker tenant- router box- router boxctl· Caddy apps workflow·manage LAN worker HTTP same 3 layers, one on-LAN hop

The bars show how far each layer travels. Link TLS (green) is re-established at every router; Ziti E2E (amber) and App TLS (blue) run unbroken from the worker to the box and are never opened in between.

LayerKey exchange / cipherQuantumIn the clear only at
Link TLSX25519MLKEM768 · TLS 1.3 · mTLSQUANTUM-SAFEinside each router (re-wrapped per hop)
Ziti E2Epost-quantum hybrid + XChaCha20-Poly1305QUANTUM-SAFEworker device & box endpoint — never on the wire
App TLSX25519MLKEM768 · TLS 1.3 · Caddy 2.10+QUANTUM-SAFECaddy on the box (payload terminates)
Identities / CAEd25519 · ECDSA P-256 (signatures)AUTH ONLYsignatures authenticate — they carry no data
Post-Quantum Defense

Protected Against Tomorrow’s Attacks, Today

Adversaries already capture encrypted traffic now, intending to decrypt it once quantum computers mature — a strategy known as “harvest now, decrypt later.” For manufacturing IP with a decade-long lifespan, that is a live threat, not a future one. Phrakton defends against it with post-quantum-hybrid key exchange, pairing a proven classical algorithm with a quantum-resistant one so your tunnels stay secure even against an adversary who breaks one of them. Your intellectual property is encrypted for the threat landscape of the next decade, not the last one.

Reliability

Security You Can Depend On — In Writing

Invisible is only useful if it’s also available. We run the Phrakton fabric ourselves, so we own its uptime and put a number on it: a 99.9% monthly availability commitment, backed by service credits on any month we fall short. No claim to file, no argument, a simple percentage discount on your invoice.

Deployment

Make Your Factory Invisible

Every Phrakton appliance is installed and configured on-site by our own engineers, which means deployment slots each quarter are strictly limited. Contact us today to secure yours — or reach out for a deeper technical walkthrough of the architecture.

Contact the founders — no sales layers, no call queues.