cortex​mesh

Component · built

Two ways in: authorized, or not at all.

There is no unauthenticated surface on a running node. Every link is mutual TLS 1.3 where each side presents a self-signed certificate over its Ed25519 identity key and proves that key carries a membership certificate signed by your mesh root. No CA chain, no central directory, no "open port."

What's built

What's still design

Covered by real two-node mTLS tests, including foreign-root rejection, expired certs, and replay under a new identity.


Request a trust-model feature →