Aloom

Security boundary / Stage 0

Trust starts with the boundary.

The public Aloom website uses a normal publicly trusted certificate. You do not need to install an Aloom certificate to read it.

Aloom does not currently offer a customer-production root certificate, trust bundle or public security attestation. Stage-0 PKI work is experimental and is not an instruction to trust a production service.

ALOOM TRUST / PUBLIC STATUS MAP / 2026-08-10

Current posture, target model, required gates

STAGE 0 · NO PRODUCTION ASSURANCE CLAIM
Status summary only. Public web PKI and Stage-0 telemetry do not establish a customer-production trust chain, certified control set or SLA. Production controls remain configuration-specific and require accepted evidence. Detailed current posture, target controls and the six required gates follow below.

What is live today

Moorooka — Stage-0 telemetry

connecting…

Moorooka is Aloom’s Stage-0 host in Brisbane. When the feed is current it publishes source accelerator telemetry every 60 seconds, read live from the host. Fields without live telemetry are absent rather than placeholdered.

This is laboratory hardware. It proves that Aloom instruments what it runs and publishes the result unedited. It does not prove facility efficiency, rack cooling capacity, production resilience or an SLA, and the Stage-0 accelerator is not representative of the C250 or MW1 production silicon described under Systems.

Stage-0 lab — Moorooka, Queensland · Raw JSON ↗ ·

The intended production trust model

The production design is configuration-specific. It must bind an identified operator, customer, workload, location, hardware state and data-flow policy to evidence the customer can inspect.

  1. Explicit identity. Legal entity, service names and certificate scope match the contracted deployment.
  2. Separated keys. Transport identity, code signing and workload attestation do not share one root key.
  3. Offline root control. Root material is generated and retained under a documented offline ceremony with recovery and revocation procedures.
  4. Short-lived service credentials. Online intermediates issue narrowly scoped certificates with observable rotation.
  5. Independent verification. Fingerprints and evidence are delivered through a second authenticated channel, not merely repeated on the same website.

This is the design target. It is not a statement that those production controls are operating today.

Before the first customer production deployment

All six gates are required and none is declared complete. This list does not imply a named site, delivery date, certification or SLA.

Verify before relying.

Aloom will publish or supply only the evidence that matches an accepted deployment configuration. If you are assessing a C250, MW1 or MW50 project, include security, residency, retention and attestation requirements in the site study.

Request a deployment and security review