Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.2 KiB

HSM Key Storage Configuration Template

HSM Selection Matrix

HSM FIPS Level Cloud On-Premise Cost
SoftHSM2 N/A (dev) N/A Yes Free
AWS CloudHSM 140-2 L3 Yes No ~$1.60/hr
Azure Dedicated HSM 140-2 L3 Yes No ~$5,500/mo
Thales Luna 140-2 L3 Both Yes License
YubiHSM 2 140-2 L3 No Yes ~$650

PKCS#11 Key Attributes

CKA_TOKEN = True          # Persistent storage
CKA_PRIVATE = True        # Requires login
CKA_SENSITIVE = True      # Cannot be revealed in clear
CKA_EXTRACTABLE = False   # Cannot be exported
CKA_MODIFIABLE = False    # Cannot change attributes
CKA_LABEL = "my-key"      # Human-readable label
CKA_ID = <byte_string>    # Unique identifier

Key Ceremony Checklist

  • Prepare air-gapped workstation with HSM
  • Assemble M-of-N key custodians (quorum)
  • Initialize HSM and set SO/User PINs
  • Generate root CA key in HSM (non-extractable)
  • Generate and sign root CA certificate
  • Export root CA certificate (public only)
  • Verify certificate independently
  • Secure HSM in physical vault
  • Document ceremony in audit log
  • Distribute key custodian tokens/smart cards