Skip to content
Historical revision — this record as it stood on 3 July 2026, not the current version. View the current record →

Diode standard

An attacker who breaches one machine rarely wants that machine. They want the next one. Lateral movement — pivoting from a first compromised node to more valuable nodes — is the dominant pattern in modern breach reports 1.

The Diode Standard removes the pivot. In electrical engineering a diode conducts current one way and blocks the other; the Diode Standard applies the same rule to commands across the PointSav operating-system family — traffic flows from authority to subject, and never the reverse 2.

A Subject operating system has no code to initiate an authority relationship: no shell client, no peer-to-peer routing table. Upstream control is not blocked by a firewall rule — the code to express it does not exist on the Subject.

For a regulated buyer the consequence is concrete. An entire breach category is removed by structure, and a complex fleet stays auditable because every connection obeys one uniform rule. This article covers the authority hierarchy, the three traffic categories, the structural removal of lateral movement, and the adapter that enforces the standard.

The hierarchy

The Diode is the foundational topology of the whole operating-system family — not a feature of one operating system, but the law governing how all of them communicate.

Position Operating system Privilege
Authority os-console and os-orchestration Issues commands; receives telemetry
Subject os-totebox, os-mediakit, os-privategit, os-infrastructure, os-network-admin Executes commands; emits telemetry; never originates a command

A Totebox cannot command a MediaKit; a MediaKit cannot reach into a Totebox. A compromised Subject cannot move laterally to another Subject, because the protocol stack contains no routing logic to do so.

The three traffic categories

Traffic Direction Status
Downstream control Authority → Subject Permitted: configuration, content, commands, updates
Upstream telemetry Subject → Authority Permitted but strictly sanitised: logs, heartbeats, status
Upstream control Subject → Authority Structurally blocked: no shell access, no RPC, no admin requests

Upstream control is blocked because the Subject is structurally incapable of initiating an authority relationship. The absence is the control.

Why this matters

Lateral movement — an attacker compromising one node and using it to reach more valuable nodes — is the dominant pattern in modern breach reports 1. The Diode Standard removes it structurally.

Scenario Without the Diode With the Diode
A plugin on os-mediakit is compromised The attacker rides the management tunnel back to the corporate os-totebox The adapter has no upstream route; the attacker is contained on the public-facing host
A Totebox kiosk is physically compromised The attacker scans the local network and pivots to the MediaKit The kiosk Totebox cannot route to other Subjects; it is a dead end
os-orchestration is compromised The attacker holds the keys to every Totebox in the fleet os-orchestration holds no Totebox keys; it requests signed capabilities per query, so a full Orchestration compromise yields no Totebox decryption material

The adapter

The Diode is enforced by a small, hot-pluggable service, service-pointsav-link (the pointsav-protocol package). It is the only code that translates authority commands into Subject-executable operations.

Property Behaviour
Default state Not installed; the Subject has no concept of phoning home
Activated state Hot-plugged by the operator with a single command; brings the Subject under fleet management
Failure mode If the adapter crashes, the link severs cleanly; the Subject keeps running standalone; the fleet-management surface goes dark
Code path Diode policy lives inside the adapter, not the OS kernel — the policy can be updated without touching the rest of the system

The universal standard

The Diode is not a MediaKit feature or a Totebox feature; it applies identically to every os-* operating system. The same service-pointsav-link package, with different policy bindings, sits between any pair of nodes that communicate.

This single uniform standard is why a complex fleet stays auditable: every connection looks the same and obeys the same rules.

See also

  1. MITRE. 'ATT&CK Tactic: Lateral Movement (TA0008).' MITRE Corporation, 2023. https://attack.mitre.org/tactics/TA0008/ 2

  2. Rose, S. et al. 'Zero Trust Architecture.' NIST SP 800-207, 2020. https://doi.org/10.6028/NIST.SP.800-207

Important Information

Important Information

Corporate structure. PointSav Digital Systems ("PointSav") is a trade name of Woodfine Capital Projects Inc. ("Woodfine"). PointSav does not itself offer, sell, or solicit any security. Any securities offering associated with Woodfine's real-property direct-hold solutions is made exclusively by Woodfine, and only by means of the applicable Private Placement Memorandum.

No investment advice. This wiki's content is provided for engineering, operational, research, and development purposes. Nothing on this wiki constitutes investment advice or a solicitation to invest in any Woodfine partnership or direct-hold solution.

Intellectual property. The PointSav name, trade name, wordmark, and marks, together with all current and future PointSav- and Totebox-branded products, services, and offerings — and the software, source code, documentation, design system, and all related materials — are proprietary to Woodfine and its affiliates, except for components identified as open source. No rights are granted except as expressly set out in a written license or agreement. See TRADEMARK.md in this repository for the full trademark notice.

Open source components. Portions of the platform are made available under permissive open-source licenses identified in the accompanying repository. Use of those components is governed by their respective license terms.

No warranty; informational use. Content on this wiki is provided for general informational purposes only and does not constitute a representation, warranty, or commitment with respect to product functionality, availability, pricing, or roadmap. Some articles describe planned or intended features, capabilities, and milestones — language such as "planned," "intended," "targeted," "may," and "expected" marks this forward-looking content, which is subject to change and does not constitute a commitment regarding future performance.

Confidentiality. Where an article describes an operational or deployment detail that is not intended for public disclosure, that article is not published on this wiki. Content here is general-purpose engineering documentation, not customer-specific configuration.

Jurisdiction. Woodfine Capital Projects Inc. is organized in British Columbia, Canada. References to the Sovereign Data Foundation on this wiki describe a planned or intended initiative only, not a current equity holder or active governance body.

Changes to this notice. PointSav may update this notice from time to time; the version posted on this page governs.

Not a filing system. This wiki is not a securities filing system, an electronic disclosure repository, or a substitute for SEDAR+ or any other regulatory filing system. Formal securities filings are made through the applicable regulatory filing system, not through this wiki.

Full disclaimer. This notice supplements, and does not replace, the full Disclaimers article. In the event of any conflict, the full Disclaimers article governs.

Read the full disclaimer →