Application Path Assurance enforce
Can I prove it happened end-to-end?
Enforce all declared intents, and continuously prove every application flow follows its intended path — from A to B, through Y. Encryption proves who the two ends were. It never proves where the packet went between them.
SRv6 enforce needs Network Truth underneath lab: Linux 6.8 · 100 sent · 100 counted · 0 at the undeclared segment
0100 from reach to path
The segment list is the declared path.
Classic routing is emergent: the path is observed after the fact, never declared, with no artifact to check against. With the path written into the packet, comparison stops being interpretation and becomes a set operation.
Themis compiles the path policies; your controller applies them; per-segment counters say whether each was executed — including the negative. “No undeclared segment ever ran” is a number that reads zero.
sampled→every packet
5→1
39,800→0
0200 what is unproven, and stamped so
Counters prove segments. Everything above them is stated as what it is.
e000 End.DT6 deliver
Start where it is already provable.
The free audit, read-only, on what runs today — you keep the gap list either way.