Solarion AI ™ · Compute Passport ™ technical system

Roadmap

What this build does today, what it does not, and the four stages from MVP to an issuer other organizations can trust.

CompanySolarion AI ™
ProductCompute Passport ™
StatusMVP
Edition2026
IssuerSolarion AI Systems ™
Evolution path

What this build actually does — and what it does not claim.

An identity product that overstates its own assurance defeats its purpose. Each stage below names the gaps that keep it from being the next one.

Status

Compute Passport is an early implementation of a technical design. It supports governance and auditability. It is not a certification, an accreditation, a security authorization or a guarantee of interoperability, and it requires independent security, legal, procurement and operational validation before production use.

Stage 1

MVP

Built

This build. Real identifiers, real signatures, a real decision path and a verifiable evidence chain, all inside one application.

Scope
  • CPID minting with UUIDv7 and a published identifier syntax
  • ES256 issuance with a four-tier key hierarchy and a JWKS endpoint
  • Registry with live status resolution and revocation
  • Policy engine returning permit, restrict or deny with named obligations
  • Hash-chained evidence with recomputed digests and portable bundles
  • Private portal with operator and reviewer separation
Known gaps
  • Keys are held in software on the host, not in an HSM
  • Nothing is enforced at a real gateway yet — decisions are advisory
  • Single tenant, single issuer, no federation
Stage 2

Enforced pilot

Next

The decision reaches a real enforcement point in one controlled workflow, with one sponsor and one accountable owner.

Scope
  • Model gateway adapter that blocks unapproved provider, endpoint or version
  • MCP/A2A tool interceptor evaluating individual tool calls
  • Enterprise IdP federation: OIDC assertions in, sponsor mapping out
  • KMS-backed issuer keys with rotation and separation of duties
  • Evidence export to an external append-only store with a trusted time source
  • Revocation service objective measured from request to confirmed containment
Known gaps
  • Cross-organization trust is still out of scope
Stage 3

Platform

Planned

Multi-tenant control plane with deployment profiles for SaaS, sovereign cloud, hybrid edge and controlled on-premises.

Scope
  • Per-tenant issuer keys and isolation boundaries
  • Kubernetes admission controller and workload attestation binding
  • Cloud reference profiles for Entra Agent ID and Bedrock AgentCore
  • Offline continuity: cached trust anchors, bounded decisions, later reconciliation
  • Compatibility tests proving each implementation preserves passport semantics
Stage 4

Issuer of record

Planned

A passport issued in one domain is accepted, verified and acted on in another — with the receiving domain still deciding.

Scope
  • W3C Verifiable Credentials 2.0 and COSE profiles for the passport object
  • Issuer allowlists, assurance-profile mapping and selective disclosure
  • Independent cryptographic review and third-party security assessment
  • Conformance suite and published schema versioning policy
  • Post-quantum algorithm agility in the signing profile
Operating model

Identity infrastructure works when ownership, engineering, operations and evidence stay connected.

RoleAccountability
Identity and securityTrust anchors, authentication integration, delegation, privileged control and revocation.
AI platformModel registry, gateway integration, agent registration and runtime telemetry.
Cloud and infrastructureWorkload identity, region, network, keys, compute, attestation and containment.
Business ownerPurpose, permitted actions, approval authority, impact and service outcomes.
Risk and auditEvidence requirements, exceptions, monitoring, review cadence and assurance.

Coverage

Share of active agents with a sponsor, a CPID and a passport.

Revocation

Time from suspension request to confirmed containment, by risk tier.

Evidence

Share of material actions with a complete decision chain.