CATEGORYCRITICAL-INCIDENT AUTHORISATION INFRA
POSTUREADVISORY-MODE · HUMAN-IN-LOOP
DEPLOYMENTSOVEREIGN · ON-PREM
JURISDICTIONEU · UK · NATO

Decision

Latency.the latency every post-incident review names.

We do not sell better awareness. We sell faster lawful action — cryptographically-signed multi-party authorisation packets that compress the crisis-decision path from 2-6 hours to under 30 minutes, with the audit trail CER Article 15(3), NIS2 Article 23(4) and AI Act Article 14(4) require by default.

SCROLL TO READ
0%
Faster authorisation
2-6 hours → 20-30 minutes
0
Scenarios end-to-end
Pipeline runtime under 5 s on a laptop
0.971
Layer-1 inference confidence
1 000-reading window · EA Carlisle
Ed25519
Production signing
PQC dual-stack roadmap
/M.0 · LIVE TELEMETRY

Cross-sector cascade-trigger feed, live.

LIVE · 0 EVENTS · LAST 24-72HEQ 0 · WF 0 · FL 0 · GR 0
EQUIRECTANGULAR · WGS84 · 60S POLL
◯ EQ   ◯ WF   ◯ FL   ◯ GR
RECENT EVENTS0 OF 0
·· awaiting feed ··
SOURCES · USGS · NASA EONET · UK ENVIRONMENT AGENCY · NOAA SWPC. Visual demonstration of the event-class universe Munin's playbooks address. Munin's production telemetry is operator-supplied (SCADA, sensor networks, ministry feeds).
WHAT EVERYONE ELSE BUILDS

Better awareness.
Dashboards. Data fusion. Contextualisation.

WHAT MUNIN BUILDS

Faster lawful action.
Signable, auditable, advisory-mode decisions.

/M.W · OPERATOR WORKFLOW

Five verbs, in order.
From signal to signed action to evidence pack.

/01See.

Cross-sector telemetry surfaces an anomaly. Shadow-link discovery makes the dependency legible.

/02Understand.

The cascade engine forecasts which sectors fail next, in what order, on what timescale.

/03Review.

A pre-formed authorisation packet arrives with evidence, predicted impact, and legal basis.

/04Sign.

Named ministries authorise via M-of-N quorum, gated on each signatory's hardware-token Ed25519 key.

/05Prove.

Every recommendation, signature, and override hashes into a tamper-evident audit chain.

/M.1
The authorisation latency problem

Cascades move in minutes. Cross-agency authorisation moves in hours. The gap is named in every post-incident review on the page below.

BUILT ONDetectionCoordinationAuthority
SCOPEEU + UK critical infrastructure
STATUSDocumented from the Pitt Review (2008) to the ENTSO-E Iberian Expert Panel (2026)
TRADITIONAL COORDINATION · 2-6 HOURS
Incident detection~10 min
Cross-agency phone calls45 min
Legal review60 min
Multi-ministry approval120 min
Command execution10 min
TOTAL2-6 HOURS
WITH MUNIN · 20-30 MINUTES
Incident detection (same)~10 min
Playbook retrieval< 1 s
Authorisation packet generated< 1 s
3× biometric multi-sig15 min
Command execution (same)10 min
TOTAL20-30 MIN
/M.2
The evidence · seven decades of the same failure mode

The technology to detect the problem existed.
The authority to act did not arrive in time.

Iberian Peninsula Blackout 2025

90s collapse · 16h recover

47 million people lost power when Spain and Portugal's grids collapsed in under 90 seconds. The ENTSO-E Expert Panel's final report (March 2026) attributed the collapse to "institutional rather than technical" failures — "governance fragmentation [that] impeded coordinated crisis response."

ENTSO-E Expert Panel, 20 March 2026

Hurricane Helene 2024

Comms collapse

Hurricane Helene took North Carolina's public-safety communications network offline within hours of landfall. The state's after-action review cites interoperability failures and unclear cross-agency roles as the primary delay drivers.

NC DPS After-Action Review, 2025

Hurricane Katrina 2005

37 days

FEMA, state, and Red Cross operated in parallel without coordination. Meals took 37 days to reach some areas. The Select Bipartisan Committee found "the single most important failure was coordination."

Select Bipartisan Committee Report, 2006

Fukushima Daiichi 2011

7+ hours

Reactor venting was delayed seven hours while operators, TEPCO management, and the Prime Minister's office negotiated authorisation across three levels of decision authority. Evacuation was uncoordinated across jurisdictions.

NAIIC Report to the Japanese Diet, 2012

UK Summer Floods 2007

3-5 hours

Cross-government coordination took 3-5 hours per decision. The Pitt Review recommended "a single framework for multi-agency response" — partially implemented through Local Resilience Forums, but no national cross-sector authorisation layer exists.

The Pitt Review, Cabinet Office, 2008

Storm Desmond · Carlisle 2015

2-6 hours

Power substation flooded → water pumps failed → treatment offline → hospitals on emergency supply. Each agency responded independently. Cross-sector cascade was not predicted.

Environment Agency Post-Incident Review, 2016
/M.3
The platform · shadow-link discovery

Cross-sector dependencies exist in physics, not in any database.

BUILT ONTime-series correlationLag detectionSensor health
SCOPEPower · Water · Telecom · Health
STATUSLayer 1 validated on live UK Environment Agency data

A power substation and a water pump station three kilometres away are causally linked in physics. No database records the dependency. Munin infers it from temporal co-movement and lag — and writes it down.

Once shadow links are surfaced, Munin runs cascade simulations across the implied graph and pairs each predicted failure with a pre-validated playbook and the legal basis for action.

Temporal correlation
Statistical co-movement between sensor feeds across sectors
Lag detection
Physical delay between cause and effect (e.g. 30 s power → water)
Evidence windows
Sliding confidence intervals with stability and health scoring
30s2min45sSubstation APOWERPump Station 7WATERCell Tower 3TELECOMHospital AHEALTHTreatment PlantWATER
SHADOW LINK (DISCOVERED)KNOWN DEPENDENCY
/M.4
Cascade prediction

Project the cascade trajectory in advance.

T+0 → T+45MIN · STORM DESMOND · CARLISLE
T+0:00POWER
Substation A trips
T+0:30WATER
Pump Station 7 loses power
T+2:00WATER
Treatment plant pressure drops
T+5:00TELECOM
Cell Tower 3 on backup battery
T+15:00HEALTH
Hospital A water pressure critical
T+45:00TELECOM
Cell tower battery depleted
MUNIN RECOMMENDATION
Activate backup power to Pump Station 7

Prevents downstream cascade to treatment plant and hospital. Estimated impact reduction: 4 sectors → 1 sector.

Flood and Water Management Act 2010, s.39EA Standing Order 7
PLAYBOOK PRE-VALIDATED · EVIDENCE PACKAGED · READY FOR SIGN-OFF
/M.5
M-of-N quorum approval

No single entity can unilaterally authorise an action with cross-sector consequences.

BUILT ONEd25519M-of-N quorumHash-chained audit
SCOPECross-jurisdictional sign-off
STATUSEd25519 in production · FIPS 204 / ML-DSA dual-stack on roadmap
QUORUM POLICY · 2 OF 3 MINISTRIES REQUIRED
/01 · EA
Environment Agency
·· PENDING
/02 · NESO
National Energy System Operator
·· PENDING
/03 · CCS
Cabinet Office · Civil Contingencies Sec.
·· PENDING
SIGNATURES · 0 OF 3COLLECTING…
/M.5b
Inside the authorisation packet

One document. Eight fields. Tamper-evident from generation.

Munin's output is not a dashboard. It is a single signable document — a packet that travels with its evidence, its predicted cascade, the legal basis for the action, and a quorum of named signatories. Every field is deterministic. Every byte is hashed.

AUTHORISATION PACKETFORMAT v1 · ED25519 · ADVISORY MODE
/01
IDENTIFIER
MUNIN-PKT-2026-04-26-001
/02
INCIDENT SUMMARY
Storm Desmond cascade trigger · Carlisle catchment.
Substation A flooded; downstream cross-sector cascade projected.
/03
EVIDENCE BASIS
source · environment.data.gov.uk/flood-monitoring
gauge · eden_sands_centre · 1000 readings
confidence 0.971 · lag 300s · stability 0.640
/04
PREDICTED CASCADE
T+0:30 · Pump Station 7 — power loss
T+2:00 · Treatment Plant — pressure drop
T+5:00 · Cell Tower 3 — backup battery
T+15:00 · Hospital A — water pressure critical
/05
RECOMMENDED INTERVENTION
Activate backup power supply at Pump Station 7. Estimated impact reduction: 4 sectors → 1 sector.
/06
LEGAL BASIS
Flood and Water Management Act 2010, s.39EA Standing Order 7
/07
SIGNATORIES · QUORUM 2 OF 3
EA · S. Patel · 13:42:18 UTC · ed25519:7c3a…f019
NESO · J. Müller · 13:43:47 UTC · ed25519:9b41…a8e2
· CCS · pending (advisory)
/08
INTEGRITY · HASH-CHAINED
prev sha256:a72f…c83a
curr sha256:3b9e…d447
ANNOTATIONS · WHY EACH FIELD MATTERS
/01

Stable cross-agency reference. Cited in audit, post-incident review, and regulator filings.

/02

Plain-language summary derived from the cascade engine. Designed to be readable by a non-technical signatory under time pressure.

/03

Source data references with reproducible provenance, time windows, and confidence scores. Anyone can re-run the inference.

/04

The downstream impact path Munin's engine forecasts if no action is taken, with sector-by-sector timing.

/05

A pre-validated playbook tied to the predicted cascade. Specific operational steps, not vague guidance.

/06

Citation to the specific statute that authorises the action. This is what makes the eventual signature lawful.

/07

Named signatories with biometric Ed25519 signatures and timestamped quorum policy. AI Act Article 14(2) by construction.

/08

Hash-chained audit anchor. The packet is tamper-evident from the moment it is generated.

THE WHOLE POINTThe packet is the product. Everything upstream — the engine, the graph, the playbooks — exists to assemble it. Everything downstream — operator review, ministry signing, audit trail — operates on it.
/M.6
Live demo · real Environment Agency data

EA Carlisle catchment, live.

Running on Environment Agency river-gauge telemetry from the Carlisle catchment. No synthetic data. No simulation. Munin discovered the known hydrological relationship between the River Eden and River Petteril — the 5-minute lag matches physical rainfall travel time.

MUNIN · REAL-DATA DEMOEA/FLOOD-MONITORING · 2026-01
Full walkthrough ↗
/M.7
Safety-first architecture

Read-only v1. Humans always decide.

BUILT ONWRITE_ACCESS=falseData-diode ingressSTPA-Sec hazard analysis
SCOPEAdvisory mode only — no SCADA writes
STATUSEU AI Act Article 14(1)-(2) compliant from first principles

WRITE_ACCESS = false

ENFORCED

Runtime read-only guard. CI static analysis scans every engine file for socket / HTTP writes to SCADA ports.

Data-diode architecture

TESTED

Ingestion is strictly one-way. Any attempt to open an outbound socket from the analysis enclave fails tests.

Structured safety case

DOCUMENTED

GSN-style claims → evidence mapping. STPA hazard analysis with 17 unsafe control actions identified and mitigated.

NIST 800-82 r3 · IEC 62443-3-3

COMPLIANT

Architecture mapped to OT security standards. Zones, conduits, security levels and foundational requirements traced to code.

EU AI ACT · ARTICLE 14 · LEGAL REQUIREMENT FROM 2 AUGUST 2026

Munin's advisory-mode architecture — humans authorise, never systems — is not a posture choice. Under the EU AI Act, human oversight is a legal requirement for high-risk AI systems. Autonomous-execution platforms must retrofit oversight scaffolding or exit the high-risk category. Munin is architecturally compliant from first principles.

/M.8
Engineering · empty repo to validated platform

Built solo. Fourteen weeks. Every commit public.

0 wk
Empty repo → validated
From 9 January 2026
0K
Lines of code
Python + TypeScript
0
Passing tests
144 Py · 249 JS
0·0
Stages · layers
Ingest → audit
< 5s
End-to-end on a laptop
Storm Desmond replay

Eight-stage pipeline — ingest → graph inference → sensor health → anomaly detection → incident build → cascade prediction → authorisation packets → governance audit. Seven-layer inference stack: physics-informed neural ODE, GNN message passing, ensemble Kalman filter, Rényi differential privacy. Layer 1 validated on live UK Environment Agency data; layers 2-7 on synthetic data pending pilot telemetry.

View repository ↗Read the doctrine ↗
PILOT STATUS · HONEST LINE

No named customer yet. First engagement: one sector pair (power + water, or flood + grid), one designated entity, 90-day shadow-mode evaluation. Exit deliverable is a compliance and response evidence pack mapped directly to CER Article 15(3), NIS2 Article 23(4) and AI Act Article 14(4) obligations — not a platform transformation. Open to introductions — jacob@muninsystems.com.

Every claim above is mapped to one of four chips — LIVE / DEMO / ROADMAP / VISION — on the maturity declaration. The line is published so it cannot be blurred.

/M.9
Why now · five forces converging

The regulatory window opens in weeks, not years.

28 APRIL 2025

Iberian blackout

47 million customers off-supply. ENTSO-E's final expert panel: the cascade "unfolded faster than human operators could respond" due to "governance fragmentation." The panel identified governance fragmentation as a primary contributor — among the technical and procedural drivers of the cascade.

17 JULY 2026

EU CER directive — designation deadline

All 27 member states must designate critical entities. ~3,000 entities into scope. Cross-sector risk assessment becomes a legal requirement. Resilience obligations apply 10 months post-designation.

ARTICLE 20 · IN FORCE

NIS2 — board-level personal liability

Article 20(1) makes management bodies personally accountable for cybersecurity risk-management measures. Article 23(4) sets the 24-hour early-warning, 72-hour incident-notification and one-month final-report cadence. Fines to €10M or 2% of global turnover. Personal liability is what actually drives procurement timing — not the fines.

2 AUGUST 2026

EU AI Act · Article 14

Article 14(1)-(2) makes human oversight a legal requirement for high-risk AI systems. Munin's "humans authorise, never systems" architecture is the compliance posture the regulation mandates.

NOV 2025 →

European sovereignty momentum

Franco-German sovereignty summit. €180M Commission sovereign cloud tender. ~90% of European digital infrastructure foreign-controlled. European-origin critical-infrastructure software has the strongest procurement tailwind in a decade.

FIPS 204 · CNSA 2.0

Post-quantum transition

NIST FIPS 204 finalised August 2024. CNSA 2.0 mandates pure PQC by 2035. Munin's signature stack is dual-stack-ready: Ed25519 in production today, ML-DSA on roadmap before any classical-signature deprecation deadline.

Authorisation, not awareness.
Munin makes the decision path fast enough — and lawful enough — to matter.

/M.10
Documentation · open to inspection

Deep technical depth.

/M.11
Founder

Jacob Sprake

FOUNDER · MUNIN SYSTEMS · MILAN

Built Munin solo from an empty repo in fourteen weeks — engine, cryptography, safety case, documentation. Every commit public.

  • Founder · City of London Youth Natural Environment Board
  • Head of Marketing · StudyStream (YC) — alongside Munin
  • Field research: Iceland, Norway
Seeking deployment partners · water · energy · civil protection

Munin deploys on your infrastructure.
Your data never leaves your jurisdiction.

Request a pilot briefingView repository ↗