Regen Designs

VeriMASH

A private mesh that verifies itself

VeriMASH is lightweight software installed on every machine you own — servers, robots, gateways, laptops, industrial PCs. Each device mints its own identity, discovers its peers, and forms a private encrypted mesh with no central server and no cloud account. Connections self-heal after an outage, every trust decision is written to a tamper-evident record you can audit offline, and access can be revoked across the whole mesh in seconds. Machines can also send each other signed messages that every node keeps, that survive an outage, and that put safety commands first.

NO CENTRAL SERVER SELF-HEALING TAMPER-EVIDENT LOG SIGNED MESSAGES
HOW IT WORKS

VeriMASH is a small program you install on each machine you own: servers, robots, gateways, laptops, industrial PCs. They discover each other, check each other's identity in both directions, and form a private encrypted network among themselves. There is no central server to run and no cloud account to create. Connections repair themselves after an outage, without a restart or a site visit. Every trust decision an operator makes is written to a tamper-evident record that you can recheck offline, so you verify it yourself instead of taking the software's word for it.

FEATURES
  • No central server, no cloud account. Every machine mints its own identity the first time it starts.
  • Self-healing by default. After a partition or an outage, nodes keep retrying on their own and rejoin as soon as the path returns. A dead link that goes quiet is detected and replaced rather than left hanging.
  • Works behind NAT and firewalls. A machine that can only dial out still joins the mesh. One outbound UDP port is enough.
  • On-demand service links. Expose one service, such as a database, a cache, or a data feed, to one named machine. A VPN opens a whole network; this opens a single door.
  • Revoke in seconds. Withdraw a machine's access and its live connections close across the whole mesh within seconds, not at the next renewal.
  • Tamper-evident trust record. Every admit, revoke, and retire is signed and recorded, and an offline command recomputes the record so it can be audited independently.
  • Runs where your fleet runs. Linux on x86 and ARM, macOS, Windows, and containers, from a single-board computer to a rack server.
  • Live console. Every node, its health, its links, and its services on one page, with your own names for your own machines.
  • One mesh across sites. Automatic discovery on a local network, seeded anchors between sites, a single fleet view over both.
  • Picks its own speed. Each link negotiates the fastest safe channel available to it, so bulk transfers and short control messages share the same connection without competing.
REGENNEXUS // PROTOCOL REGISTRY 3 PEERS CORE APPLICATIONS 3 connected DEVICES 7 connected AI AGENTS 2 connected registry.log — self-discovering peers [ok] handshake complete — auth: verified · channel: encrypted [ok] agent registered — context session opened message format: standard · discovery: automatic FIG. 05 · UNIVERSAL ADAPTER PROTOCOL