SystemsIndex
PointSav builds a family of purpose-built operating systems that share a common seL4 and Rust substrate. Each does one job, contains no features it does not need, and communicates through a common Diode-based protocol discipline. The result is a family that can be audited component by component, upgraded independently, and deployed in any configuration without unexpected coupling between systems.
Start here: OS family — eight operating systems, one substrate — the entry point for readers new to the family; it explains the common substrate, the Capability-based security model every OS inherits, the Diode standard that governs how they communicate, and the seL4 microkernel substrate that anchors them all.
The archive layer
The core record-keeping systems at the foundation of every deployment — where the canonical record lives and how it is coordinated across a fleet.
- Sovereign vault and service host — The archive layer: one isolated, kernel-level vault per entity, storing records as inert flat files with no delete operation, exposed only through the Diode on command from os-console or os-orchestration.
- Totebox orchestration — The coordination layer that manages multiple Totebox data-archive containers, keeping software execution engines isolated from passive corporate ledgers across deployments.
- VM-* architecture and OS family — The five named VM types (Totebox, MediaKit, Orchestration, PrivateGit, Infrastructure) and how each maps exactly to one
os-*source binary. - Scaling coordinated development across many Totebox Archives — The coordination bottlenecks that appear past twenty archives, and the path toward per-archive process isolation.
- os-totebox: the sovereign WORM data vault — os-totebox's intended end-state design as a Type I bare-metal seL4 OS: the WORM data vault enforced by a compiled capability graph rather than a policy an administrator could override.
- How service-* Become seL4 Protection Domains on os-totebox — How os-totebox is designed to map its Rust service binaries onto seven seL4 Protection Domains, with capability confinement guaranteeing a compromised service-slm PD can never reach the storage-holding service-fs PD.
Operator surfaces
The systems through which a human operator interacts with the platform — keyboard-driven, F-key-structured, and built around muscle memory rather than discoverability.
- os-console — the Command Ledger — The human-facing surface: a Command Ledger and single Rust binary that connects to a Totebox and renders its state through a keyboard-driven, cartridge-based, F-key-structured interface.
- os-console: The Totebox Orchestration Browser — The browser-analogy explainer for os-console's design philosophy: cartridges as tabs, machine pairing as the certificate store.
- Input machine — The mandatory document ingest gate in os-console, bound permanently to F12 and backed by
service-inputon the Totebox Archive. - Sovereign desktop — The free desktop operating system: a native-Rust sovereign desktop that pairs with a Totebox archive and serves as the adoption gateway to the commercial product line.
- Fleet aggregator — The Fleet Aggregator for multi-entity portfolios: one operator sees, queries, and commands many Totebox archives at once.
Network control and infrastructure
The systems that manage the network fabric, the bootstrap path, and the underlying compute substrate.
- OS network admin — The control plane for a fleet: manages the pairing registry, Diode rules, and mesh routing policy; commands broadcast as 16-byte binary packets across the WireGuard mesh.
- Private git OS — Private Git hosting for sovereign version control within a fleet.
- Browser workbench — The browser-based file editor included in os-privategit: a three-column interface for working with archive files without a terminal session.
- os-infrastructure — PPN node operating system — The OS layer for PPN nodes: managing WireGuard tunnels, hosting guest VMs for other platform services, and running the Genesis Protocol node-join ceremony.
Publishing and media
The public-facing OS that hosts the company's marketing surface, internal wiki, and compliance newsroom on a single sovereign appliance.
- OS mediakit — The guest OS image for the vm-mediakit tier, isolating knowledge wikis, marketing sites, the proofreader, and BIM orchestration from the vault and orchestration tiers. Ubuntu 24.04 today; a seL4 Microkit image is the planned long-term form.
See also
- Architecture — cross-cutting platform architecture and the three-ring model
- Services — the autonomous services that run within and across operating systems
- Infrastructure — fleet deployment topology and cloud operational runtime
- Substrate — the substrate disciplines and microkernel primitives the OS family inherits