Architecture
The boundary is the product.
Kaelox ships as a signed container running as a sidecar beside the systems you already have. It reads in shadow mode. It writes nothing back. There is no code path to a control system.
Part one — inside the site
Part two — across jurisdictions
Where the boundary sits — you choose3 deployment modes
| Mode | For |
|---|---|
| Air-gapped, on premises | Facilities that will not connect at all |
| Hybrid | Your own data centres under a single control plane |
| Private cloud tenant | Where your estate already lives |
Raw payloads never cross that boundary in any mode. What leaves is bounded regulatory metadata and a SHA-256 envelope digest. IEC 62443 targeting Security Level 2 — that assessment has not been performed by an external assessor, and we say so.