Skip to content
Technology How it works Breeder — Hyperion Burner — Aegis Burner — MetroVolt AI-Native Architecture Magnets Fuel cycle Safety Roadmap
Solutions AI & Data Centers Defense & Government Grid & Baseload Neutron Detection Quantum
Learn Technical Library
Proof Publications Whitepapers Technical Library Open Science & Reproducibility The Honest Gates
Company About / Mission Leadership Environment Health & Safety Investors Careers Press Contact
3D Model
AI Architecture › L7 · Ecosystem & Strategy
L7 · Ecosystem & Strategy

Authentication, Authorization, and Zero-Trust Boundary

Mutual TLS proves who is calling, scoped RBAC decides what they may do, and every external actor is treated as untrusted until cryptographically identified.

THE STACK · click to jumpL7Ecosystem & StrategyL6Experience & VisualizationL5Applications & CopilotsL4OrchestrationL3Twin Modeling & AIL2Data FabricL1Control PlaneL0Foundation▲tlmctl▼L7 · ECOSYSTEM & STRATEGYThe plant in its world — integrated through one unified API.1Unified API Layerone door in/out2Grid Integrationdispatch & firm supply3Supply Chainfuel, parts, isotopes4Maintenanceservice & spares loops5Regulatorycompliance & reporting6Fleet Strategymulti-unit planningMACHINE TIEConnects the machine to grid, suppliers, and regulators — the outermost loop.KRONOS FUSION ENERGYAI-NATIVE S.M.A.R.T. GENERATORECOSYSTEM & STRATEGYSHEET 09REV. 2026-08L7 · AI-NATIVE STACK
L7 · Ecosystem & Strategy — its place in the stack (left, click any layer) and its internal components (right). Telemetry rises; control descends.

Prove identity, then scope authority

The gateway assumes zero trust: no network location, no prior session, and no claimed identity is believed without proof. Each caller presents a client certificate; mutual TLS establishes a cryptographic identity before any request body is read. Machine-to-machine callers (a grid dispatcher, a fleet controller, a supplier system) hold short-lived certificates issued by the Kronos internal CA and rotated automatically.

Role-based scopes

Identity is necessary but not sufficient. Every action is checked against a role with an explicit scope. A grid operator may read availability and write dispatch setpoints within the certified envelope, but may not read isotope inventory. A regulator may read compliance and byproduct-material records but may write nothing. An isotope customer may place and track offtake orders for their own shipments only.

Role x Permission
read_statewrite_dispatchread_isotopewrite_offtakeread_compliance11000101101000111111

Rows above are grid operator, isotope customer, regulator, and fleet controller; columns are the coarse permission scopes. Fine-grained policy narrows these further per resource instance.

Authorization decisions are logged with the deciding policy and the caller identity, so any grant or denial is reconstructable. Denials fail closed and are rate-tracked: a caller repeatedly probing scopes it lacks is throttled and flagged to L5 compliance and security monitoring.

Because the write plane can move a real machine, dispatch and actuation-adjacent scopes require the strongest posture: hardware-backed keys, per-command idempotency keys, and clamping against the L1 safe operating envelope. No credential, however privileged, can command the plant outside its certified limits. All of this is exercised today against the digital twin; live certificates and regulator identities are provisioned at commissioning.

Content reviewed August 2026 · design-and-simulation stage