Powered by Phrakton

Zero-Trust Security.
Seamless for You. Unreachable for Them.

Phrakton is Delteris’s zero-trust network overlay, built on OpenZiti. It abstracts your network away entirely: your factory infrastructure becomes invisible to external threat actors while remaining seamlessly accessible to authorized personnel — with End-To-End Post-Quantum-Safe Encryption for the application running under it, and support for full cryptographic isolation between facilities.

  • No open ports · no public attack surface
  • Post-quantum-safe encryption
  • Cryptographic multitenant isolation

A Network That Isn’t There

Conventional network security guards the door: firewalls, VPNs, and open ports that must be defended around the clock. Phrakton removes the door. Your services have no listening ports exposed to the public internet — there is nothing to scan, nothing to probe, and nothing to move laterally through. Connections are established outbound-only and brokered by cryptographic identity, so a resource is reachable only after a device has proven who it is. To everyone else, your factory simply does not exist on the network.

Core Principles

Zero Trust, End to End Encryption, Post Quantum Safe Cryptography

Every capability of the platform run under the Phrakton overlay, allowing for Post-Quantum-Safe End-To-End Encryption for it's applications, and support for physical and cryptographic isolation — so security isn’t a feature you switch on, it’s the ground the whole system stands on.

01

The Invisible Factory

Services are unreachable from the public internet — no open ports, no exposed attack surface, no lateral network movement, no room for corporate espionage.

02

Identity, Not Location

Access is granted to verified cryptographic identities, never to an IP address or a network position. A stolen credential on an unknown device reaches nothing, so no more memorizing a new password every rotation.

03

Multitenant by Design

Each facility operates inside its own cryptographically isolated tenant. Strict separation between sites, centrally managed using identities, no horizontal network to explore.

04

Post-Quantum-Safe

Traffic is protected with post-quantum-hybrid key exchange and encryption, closing the door on “harvest now, decrypt later” — the data you protect today stays protected tomorrow.

05

Effortless Remote Reach

On-premise doesn't mean on-site-only. With the optional Remote Access Module, monitor operations and run audits from home, on mobile data, or abroad — the connection just works, over a post-quantum-safe encrypted tunnel, with the floor never exposed and nothing for IT to configure.

06

Absolute Data Sovereignty

Your data never touches a cloud database. The physical hardware, and the jurisdiction it sits in, remain entirely yours and only you can read it.

How It Works

Deny by Default. Prove to Connect.

Phrakton is built on OpenZiti, an open-source zero-trust networking fabric. Rather than opening your network and then trying to defend it, Phrakton keeps everything closed and grants access one verified identity at a time.

  • Outbound-only connections: Your appliance dials out to the fabric. It never accepts an inbound connection from the open internet, so there is no port for an attacker to find.
  • Brokered by the controller: A central controller authenticates every identity and authorizes every session before a single byte of application data flows.
  • Encrypted end-to-end: Traffic is Post-Quantum-Safe encrypted the moment it leaves one endpoint and only decrypted at the other — never in transit, never on a shared server.
  • Least privilege by construction: An identity can reach only the specific services it has been granted. There is no wider network to explore.
Under the Hood

The Encryption Layers on a Connection

A worker reaching an app on your box travels through three nested encrypted tunnels. The two that cross the wire — Link TLS and App TLS — use post-quantum-safe key exchange; the inner Ziti E2E layer already encrypts its payload with a quantum-fine cipher, and its one classical component (the X25519 key exchange) is never exposed on the wire, so it is not a harvest-now-decrypt-later concern. Each tunnel is opened only at the two endpoints — never on the network. Pick an observer and see exactly how far each one can read.

outer shell = what actually crosses the wire ↓

Select an observer — see how far into the layers it can read:

All three layers

Three nested tunnels — Link TLS (green) and App TLS (blue) are post-quantum-safe. Ziti E2E (amber) already uses a quantum-fine payload cipher; only its X25519 key exchange is classical, and Link TLS shields that on the wire — so it is not an HNDL exposure. Each is opened only at the endpoints, never on the network.

Where each layer reaches on the path

Link TLS — quantum-safe · wraps every edge & router hop on the wire Ziti E2E — quantum-fine AEAD, classical X25519 KEX (wire-shielded) · opens only at the endpoints App TLS — quantum-safe · carries the actual data external network server network CLIENT LAN PHRAKTON BOX firewall remote worker tenant- router ziti controller box- router boxctl · tunneler Caddy apps workflow manage LAN worker box dials OUT only · outbound 443 · never inbound no port exposed to the internet control channel same 3 layers, one on-LAN hop

Each connection between nodes is drawn as the encryption layers that travel it. Ziti E2E (amber) and App TLS (blue) run the whole way from the worker to the boxctl tunneler. Link TLS (green) is the transport layer — a PQ-safe TLS 1.3 session on every hop that crosses the wire, both the edge-tunneler↔router hops and the router↔router fabric; it terminates and re-wraps at each router but is present on every network segment. The tunneler unwraps Ziti E2E and splices only App TLS across to Caddy on the same box; Caddy terminates App TLS, leaving plain data (dashed) for the final hop to the apps. A LAN worker reaches the tunneler over the same three layers in a single on-LAN hop.

LayerKey exchange / cipherQuantumIn the clear only at
Link TLSX25519MLKEM768 + AES-256-GCM (or ChaCha20-Poly1305) · TLS 1.3 · mTLS · Go 1.26 (GODEBUG=tlsmlkem=1)QUANTUM-SAFEinside each router / edge terminator (re-wrapped per hop)
Ziti E2EX25519 (classical KEX, Shor-breakable) + XChaCha20-Poly1305 (256-bit → ~128-bit under Grover, quantum-fine)KEX WIRE-SHIELDEDworker device & box endpoint — KEX never exposed un-wrapped on the wire
App TLSX25519MLKEM768 + AES-256-GCM (or ChaCha20-Poly1305) · TLS 1.3 · Caddy 2.10+QUANTUM-SAFEbrowser edge & Caddy on the box (E2EE, payload terminates)
Identities / CAEd25519 · ECDSA P-256 (signatures) → ML-DSA once upstream supports itAUTH ONLYsignatures authenticate — they carry no data, so no HNDL concern
Post-Quantum Defense

Protected Against Tomorrow’s Attacks, Today

Adversaries already capture encrypted traffic now, intending to decrypt it once quantum computers mature — a strategy known as “harvest now, decrypt later.” For manufacturing IP with a decade-long lifespan, that is a live threat, not a future one. Phrakton defends against it with post-quantum-hybrid key exchange, pairing a proven classical algorithm with a quantum-resistant one so your tunnels stay secure even against an adversary who breaks one of them. Your intellectual property is encrypted for the threat landscape of the next decade, not the last one.

Reliability

Security You Can Depend On — In Writing

Invisible is only useful if it’s also available — and because the fabric carries every connection to your appliance, we treat its uptime as our own responsibility. We run Phrakton ourselves, commit to 99.9% monthly availability, and engineer for as close to 100% as the technology allows, backed by automatic service credits on any month we fall short. No claim to file, no argument, a simple percentage discount on your invoice.

Deployment

Make Your Factory Invisible

Every Phrakton appliance is installed and configured on-site by our own engineers, which means deployment slots each quarter are deliberately limited. Contact us today to secure yours — or reach out for a deeper technical walkthrough of the architecture.

Contact the founders — no sales layers, no call queues.