Your developers trust Copilot.
Copilot never read your rulebook.
BANK SDK - APPROVED
[email protected] - SAFE
[email protected] - SAFE
[email protected] - SAFE
Approved manifest - CICD enforced - Signed
DEVELOPER
TRUSTED
THIS
COPILOT SESSION - LIVE
Generating code...
import lodash from 'lodash'
[email protected] PULLED
CVE-2024-1337 CRITICAL
PROTOTYPE POLLUTION
Copilot used public weights - no SDK lookup
DEVELOPER CODES
COPILOT SUGGESTS
PUBLIC LIB PULLED
CVE INJECTED
AUDIT FAILS
CLIENT COMPLAINS
RELEASE BLOCKED
🛑
CVE FLOOD
Copilot pulls vulnerable public libraries. Security blocks the release.
Copilot adds [email protected]. CVE found. Release blocked. Client waits 2 weeks.
🧠
ZERO MEMORY
Every AI session starts blank. No knowledge of bank rules or approved SDKs.
New dev opens Copilot. Uses public logger instead of bank SDK. Audit catches it 3 months later.
⚠️
COMPLIANCE DRIFT
AI doesn't check if code follows bank architecture standards.
Copilot picks Express.js — not approved. Passes unit tests. Fails architecture review. 4 weeks rework.
"WE ALREADY HAVE SAST / CONTAINER SCANNING / RENOVATE — WHY V4?"
REACTIVE — FIND PROBLEMS AFTER
CODE WRITTEN
BUILD
SAST SCAN
🔴 CVE!
TICKET
FIX
RESCAN
SAST — false positive noise
Container — scans after image built
Renovate — bumps version, doesn't patch source
Hundreds of alerts. Weeks of rework. Developers hate it. CVE enters first, then you chase it.
PREVENTIVE — BLOCK PROBLEMS BEFORE
CODE WRITTEN
SDK GATE
✅ APPROVED ONLY
BUILD
DEPLOY ✓
SDK Gate — only approved libs enter
FOSS Vault — patched at source code
Zero noise — nothing bad gets in
Zero CVE alerts. Zero rework. Developers love it. The gate prevents, not the scanner that chases.
SAST and Renovate are firefighters. V4 is the fireproof building. You still run scanners — but they find nothing.
AI is replacing software engineers.
55%
of production code is already
AI-generated
— GitHub Copilot Report
2–3yr
until AI handles
most engineering tasks
— Anthropic, OpenAI, DeepMind
0
banks with a governed
AI engineering pipeline
— the gap Illicium fills
👁️
NOBODY CAN READ CODE
AI writes everything. Developers lose the skill. When AI is wrong — who fixes it?
📦
BINARY IS UNAUDITABLE
AI generates → compiles to binary → regulators ask what's running. No trail.
👤
HUMAN REVIEW AT SCALE
Banks need humans accountable. AI generates thousands of lines. Who reviews without governance?
🎯
AI CAN BE HACKED
Prompt injection, adversarial inputs, poisoned data — AI code is an attack surface.
The question is not whether AI replaces engineers. It is who governs the AI that replaces them.
Where does your engineering
intelligence go?
PATH A — BUY SaaS
Your code leaves the bank perimeter
Vendor learns your patterns & workflows
Licensing fees — every year, forever
AI burns tokens scanning vendor CVEs repeatedly
Blind spots — code outside your wall
💰💰💰
They own your intelligence. You pay forever.
PATH B — BUILD SOVEREIGN
Code stays inside the bank perimeter
Your architect writes the libraries — bank owns IP
Build once — own forever, zero licensing
AI reuses your kernel — fraction of tokens
Zero blind spots — everything inside your wall
💰→✓
You own the intelligence. It compounds.
Every SaaS vendor you use gets smarter about your bank.
Every project on Illicium makes your bank smarter about itself.
One sovereign loop. Everything governed.
ILLICIUM V4 400+ PROJECTS MODEL EXECUTION GOVERNED RUNTIME GOVERNED AI OPS READY ML PLATFORM FOSS VAULT
THE SOVEREIGN LOOP — HOW EVERY AI OUTPUT IS GOVERNED
AI OUTPUT
INTERCEPT
VALIDATE SDK
ENFORCE OPA
SIGN CRYPTO
EMIT ✓ APPROVED
Every AI output. Every team. Intercepted, validated, enforced, signed, emitted. No exceptions. No bypasses.
Not a concept. Running today.
TODAY — V3 (JENKINS) · FINANCIAL ENGINEERING DEVOPS
Kelvin
1 ARCHITECT
V3 FRAMEWORK
shared governance
Team A — quantitative models & libraries
Team B — end-user computing
Team C — platform & runtime services
Team D — AI model training & serving
Chain DAG pipelines · Monorepo subprojects · Zero manual gates
ISTIO ✓
HARBOR ✓
KAFKA
CLICKHOUSE
+ MORE
V4 — NEW FRAMEWORK (REPLACES JENKINS · REWRITE FROM SCRATCH) · BANK-WIDE
V4 gets bank approval → every DevOps team can adopt
WHAT EVERY TEAM GETS OUT OF THE BOX:
🔧 Default Templates
Ready-made pipeline patterns
🖱️ Drag & Drop Canvas
Visual workflow builder
🧪 Debug Sandbox
Input/output test stages
⚡ Own Tool Choice
nx, dagger.io, Jenkins, custom
Teams design their own workflows — like customising Jira. Default templates get them started fast. Framework governance stays consistent underneath.
IT DevOps · Risk DevOps · Finance DevOps → all inherit, all design their own way
✗ Jenkins NOT APPROVED by bank CICD
V4 removes Jenkins. Teams keep their tools. Framework is bank-approved.
Approve once. Win every platform.
WITHOUT FRAMEWORK — WHAT MOST BANKS DO
Every new product = build from scratch
NEW PRODUCT
NEW TEAM
NEW CODE
NEW APPROVAL
💰💰💰
× repeat for EVERY product. AI rewrites from zero each time = more tokens, more cost, more risk.
WITH ILLICIUM — APPROVE ONCE, REUSE FOREVER
Every new product = plug into the approved kernel
NEW PRODUCT
SAME KERNEL
SAME POLICY
NO RE-APPROVAL
✓ LIVE
AI reuses the kernel patterns = fraction of tokens, fraction of cost, zero new procurement.
Libraries & Framework
Built by Kelvin's Special Force Team — Rust, WASM, DAG. FOSS-inspired, CVE-patched. Bank owns the IP.
BUILT ONCE
Platform Products
V4 SDLC, Canvas, AI Ops, FOSS Vault — each platform inherits the same approved policy & compliance rules.
APPROVED ONCE
Team Rules
Each team gets default templates — then customises their own workflows, like Jira. Team A, B, C, D — all reuse, all different.
TEAM DESIGNS
"WHY NOT JUST USE PREFECT / TEMPORAL / KARPENTER?"
FOSS ENGINES = WORKERS
Prefect, Temporal → execute workflows
Karpenter → scales compute
n8n → connects nodes visually
They run what you give them. They don't ask if it's allowed.
vs
ILLICIUM = GOVERNANCE ABOVE ALL
Decides what is authorised to run
Enforces bank policy before execution
Signs every artifact cryptographically
Remembers every decision (sovereign memory)
Then tells Prefect / Karpenter / n8n what to execute.
We don't replace execution engines. We govern them. They become workers inside the framework.
ONE APPROVAL → THE FACTORY THAT BUILDS EVERYTHING ELSE
V4 SDLC
THE FRAMEWORK
BUILDS:
FOSS Vault
first delivery ✓
Canvas
drag-and-drop DAG
AI Ops
when LLM approved
ML Platform
dev env governance
Without V4, there is no FOSS Vault, no Canvas, no AI Ops. V4 is the factory. One approval → every product.
How it actually works. V3 today.
V4 GOVERNANCE — CONTROL PLANE OPA Policy · PROD/DEV separation · Crypto Signing · Sovereign Memory · Deploy anywhere TEMPLATE Monorepo · All-in-one · Chain pipeline definition SCAN SUBPROJECTS Auto-detect language/type from each folder config BEHAVIOUR: Node.js harbor-portal detected npm build · test · package BEHAVIOUR: Golang harbor-core detected go build · FOSS clone · Docker BEHAVIOUR: Override special rules if needed custom per subproject DAG: LEVEL 1 (build first) harbor-portal harbor-base LEVEL 2 (depends on base) harbor-core db-exporter ADD FOLDER → AUTO-DETECT → RIGHT BEHAVIOUR → DAG RESPECTED → ZERO REWRITE V4 ORCHESTRATOR — "WE DON'T REPLACE ENGINES. WE GOVERN THEM." V4 decides what is authorised → tells the engine to execute → signs the output Karpenter Agent pod scaling EKS · GKE · Ali Cloud K8s Cloud Build CI/CD engine Prefect Workflow engine Temporal Durable execution Runtime Svc Bank infra Jenkins (V3 legacy — supported if needed) WORKERS execute. They don't decide. Illicium decides what is authorised → tells the worker to run → signs the output.
Same pattern powers V4 SDLC, Canvas, FOSS Vault, AI Ops. One control plane. One orchestrator. Engines execute — Illicium decides.
Canvas + AI. The future is already here.
Business users build governed workflows with AI — no code, no risk, any cloud.
ILLICIUM CANVAS quarterly_risk_report.flow
🔧 DEV MODE 🔒 RUNTIME ▶ Run in Sandbox 🧪 Debug
✓ SDK ENV: DEV TARGET: AWS
NODES drag →
📥 Source
⚙️ Transform
📊 Output
🔀 Branch
🔧 Custom
TARGET ▾
AWS EKS
GCP GKE
Cloud Build
Ali Cloud K8s
Model Exec
Runtime Svc
On-Prem
WORKFLOW CANVAS — drag nodes from sidebar or click to debug ↓
📥 Get Risk Data
risk_db · DEV · APAC
TARGET: EKS
⚙️ Filter & Aggregate
by region · quarterly
TARGET: GKE
📊 Load Analytics
analytics_dw · append
TARGET: On-Prem
Drop a node here to extend workflow
🧪 DEBUG — click a node above ↑ IDLE
📥 INPUT
-- click a node --
📤 OUTPUT
-- click a node --
✓ SDK 🔒 PROD/DEV ✍️ SIGNED 🛡️ AI SANDBOX ONLY each node targets different cloud
🤖 AI ASSISTANT
USER
"Get customer risk data for APAC, aggregate by quarter, load into analytics."
AI
Built 3-node workflow.
Worker: AWS K8s (sandbox).
✓ SDK validated · PROD safe
USER
"Looks good. Push to PROD."
⚠️ GOVERNANCE
PROD requires approval.
Sent to Kelvin. Waiting...
SAME CANVAS — DIFFERENT PRODUCTS — DIFFERENT TEAM ACCESS
n8n CANNOT DO THIS ✗
PRODUCT: Risk Analytics
✓ risk_db · ✓ market_data
✗ customer_pii · ✗ PROD write
AI: LangChain → risk scoring → report
Target: EKS + On-Prem
PRODUCT: AI Research
✓ model_registry · ✓ LLM-as-Judge
✗ production_db · ✗ customer data
AI: train → eval → guardrail → staging
Target: GKE sandbox
PRODUCT: Finance Reporting
✓ finance_dw (read-only) · ✓ export
✗ write access · ✗ external APIs
AI: query → validate → report → sign
Target: On-Prem only
Design behaviours. Ship immutably.
Each subproject gets its own behaviour. Debug any stage. Test before you ship.
ILLICIUM SDLC harbor-registry-chain.template
🔧 DEV MODE 🔒 RUNTIME ▶ Run 🧪 Debug
✓ SDK SIT DEV UAT →🔒→ PROD TARGET: EKS
BEHAVIOURS drag →
🟦 Node.js
🟦 Golang
🟨 Python
🟪 Java
🟩 FOSS Clone
🟥 Docker
🔧 Custom
STAGES drag →
📥 Clone
🔨 Build
🧪 Test
📦 Package
🚀 Publish
➕ Custom
🔒 L1 ONLY
Clients use RUNTIME.
Team rules restrict access.
TEMPLATE — MONOREPO SUBPROJECTS
🟦 harbor-portal/ Node.js v2.4.1 ✓ PASS
npm install npm build npm test docker build
🟩 harbor-core/ Golang FOSS Clone v1.8.3 ✗ BLOCKED
git clone (FOSS) go build go test ✗ docker build
🧪 Debug: click to inspect test output — identify root cause before deploying
🟪 db-exporter/ Golang v1.2.0 ✓ PASS
go build go test docker build
Drop a behaviour here to add subproject, or a stage to extend pipeline…
🏷️ VERSIONING
Semver auto-tagged per subproject. Each release gets its own version.
📂 AUTO-DETECT
Select git repo → framework scans project files → applies behaviour. Override with .illicium.yaml
🧪 DEBUG
harbor-core blocked at go test — click to inspect and fix before deploy.
DAG CHAIN ORDER
L1 harbor-portal · base L2 harbor-core · db-exporter
🤖 AI ASSISTANT
SOVEREIGN
ALERT: harbor-core go test failed — TestRegistryAuth panic: nil pointer
AI: Investigating SIT environment READ-ONLY
▸ Pulled SIT logs for harbor-core
▸ Root cause: mock registry client not initialised — missing NewTestClient() at line 47
AI: Fix ready + config update:
+ client := NewTestClient()
~ .illicium.yaml timeout: 30→60s
🔒 ROLE PERMISSION CHECK
Kelvin (L1) — delegate AI to push
AI can hotfix SIT/DEV configs
UAT/PROD requires approval
AI: Permission granted. Pushed fix to SIT.
✓ PR #189 created · Tests pass · SIT deployed
HARNESS HAS AIDA™ — SO WHAT?
Their AI runs on their cloud. Your code leaves.
V4 AI is sovereign — learns your patterns, governs by your roles.
Ask AI to debug, configure, or fix...
Send
🔧 DEV MODE
Edit behaviours · Debug bugs · Deploy to SIT/DEV/UAT
🔒
🚀 RUNTIME
Locked · Immutable · Crypto signed · Every release identical
V4 ships a default pipeline.
Every project gets CI/CD on day one. Teams customise. AI fixes what breaks.
ILLICIUM PIPELINE harbor-core.pipeline.yaml | ● LIVE RUN #247
DEFAULT STAGES
Git Clone
Setup Env
Version
Build
Package
Test
Publish
Scans
CD
CUSTOMISE
+ Add Stage
+ Add Target
+ Override
📥 Clone 2s
⚙️ Setup 5s
🏷️ v1.8.4 1s
🔨 Build 18s
📦 Package 8s
🧪 Test 12s
🚀 Publish 4s
🚢 CD ✓
✅ CI/CD COMPLETE — 50s
Artifact published. Deployed to SIT for testing.
Devs test in SIT/DEV playground while scans run — no waiting.
ASYNC SCANS RUNNING
SAST Container ✓ SonarQube ✓ FOSS
Non-blocking — AI auto-fixes when results arrive
🔒 RELEASE GATE
No bypass.
Scans must pass before
release or hotfix to
UAT / PROD
🤖 AI AGENTIC AUTO-FIX — Agent Swarm · Loop Engineering
Spawns agent pods via Karpenter — each pod runs in isolated env, targets any cloud. Subprocesses for dependent tasks. Parallel execution — not sequential.
1. SCAN DETECTS
CVE-2026-3891
golang.org/x/net
2. SPAWN AGENT
Karpenter → new pod
Isolated sandbox env
Target: EKS
3. AGENT FIXES
- x/net v0.17.0
+ x/net v0.23.0
go mod tidy ✓
4. VERIFY (subprocess)
Spawns CI/CD subprocess
Full pipeline on fix branch
Tests + scans pass
Pod terminates
5. PR CREATED
PR #248
CI/CD proof attached
✓ Verified by pipeline
✓ Ready for review
DEPLOY TARGETS:
EKS GKE On-Prem Cloud Build Ali Cloud K8s Model Exec Runtime Svc
🤖 AI ASSISTANT
SAST: Critical CVE detected in harbor-core go.mod — golang.org/x/net v0.17.0
AI: CVE-2026-3891 affects HTTP/2 handler. Upgrade to v0.23.0 patches it. No breaking API changes. Writing fix...
AI: Updated go.mod + go.sum. Ran go mod tidy. All tests pass. Created PR #248.
Container: All clear ✓ No vulnerabilities in base image.
V3 WOULD HAVE...
⏱ Blocked CI for 15+ min
📋 Created 47 Jira tickets
👨‍💻 Developer reads each one
🔧 Manual fix, hours to days
V4 DELIVERED
⚡ CI never blocked
🤖 AI read the CVE advisory
🔧 Auto-wrote the fix
✓ PR ready in 90 seconds
📋 DEFAULT
9 stages out of the box. CI/CD on day one.
⚡ FAST
Deploy SIT/DEV instantly. Scans never block devs.
🔒 SAFE
No release or hotfix without scans passing. Zero bypass.
What this unlocks.
New team joins → productive in days
They inherit the framework. AI already knows the patterns. No 3-month onboarding. No per-team rewrite.
🧑‍💼
Business users build workflows
Canvas + AI assistant. Non-technical users create governed pipelines. No developers needed for routine work.
📋
Regulator calls → answer in minutes
ClickHouse sovereign memory has every decision, every approval, every signature. No forensics needed.
🔄
AI gets smarter about YOUR bank
Every project governed = patterns learned. The flywheel accelerates. After 12 months, no competitor can replicate this.
🛡️
AI can never wipe PROD
PROD/DEV enforced at the framework level. AI works in sandbox only. Human approves promotion. No accidental disasters.
📦
New FOSS tool → governed in days
AI reads the FOSS code, generates an Illicium version, SDK validates, CVE-patched. Available to every team. Not months of procurement.
AI is moving fast. The bank that governs it first doesn't just survive — it accelerates.
Beyond ReAct. The sovereign agentic mesh.
ReAct is already standard. V4 is built for what comes after.
2023 — STANDARD
ReAct
Reason + Act loop
Single agent. No memory.
2024 — EMERGING
Multi-Agent
CrewAI · AutoGen
Agents collaborate. No governance.
2025 — NOW
Cognitive Arch
Memory · Plan · Reflect
Claude Code, Devin. Still SaaS.
NEXT — V4
Sovereign Mesh
Governed · Memory · Crypto
Bank owns it. Nobody else has this.
SOVEREIGN AGENTIC MESH — HOW V4 GOVERNS AUTONOMOUS AGENTS
🧠 PLAN
🤖 DELEGATE
⚡ EXECUTE
🔒 VALIDATE
💾 REMEMBER
🔄 EVOLVE
Agents own tools
Agents negotiate
Persistent memory
Self-improve
Crypto signed
BUILD FROM SCRATCH — LangChain + OpenAI SDK
NEW AI APP
NEW APPROVAL
NEW SECURITY
6+ MONTHS
V4 INTERNAL SDK — PRE-APPROVED FOUNDATION
NEW AI APP
SAME SDK
INHERITED
DAYS ✓
🔄
Release Mgmt
AI agents review, test, approve, deploy. Autonomous release pipeline.
🎧
Help Desk
Agent triages, routes, resolves from sovereign memory. Governed responses.
📋
Kanban AI
Agents move cards, assign reviewers, enforce SLA. Teams set their rules.
🖱️
Canvas IDE
Business users drag-and-drop. Agents build the governed pipeline underneath.
Your team presented ReAct. V4 is already built for what comes after. The governance layer doesn't care which pattern the agents use — it governs them all.
V4 vs the market. Same vision. Sovereign.
Harness ($3.7B) is the world's leading SDLC DevOps platform — CI/CD, developer portals, AI testing, security, cost management. 15 products. Thousands of companies. This is V4's direct competitor.
n8n is the leading open-source workflow automation — drag-and-drop DAG canvas. This is Canvas's direct competitor.
Both are SaaS or FOSS with no bank governance. Illicium delivers both — sovereign, air-gapped — plus 3 capabilities neither will ever build ↓
CAPABILITYMARKETBANK HASILLICIUM
CI/CDHarnessIT CICDSovereign pipeline
WorkflowTemporalModel Execution (IT)Governs what Model Execution runs
RuntimeKarpenterRuntime-as-a-Service (bank)Intent layer above Runtime-as-a-Service
Dev EnvCodespacesMachine LanguagesSession SDK enforcement
PortalBackstage--Integrate or sovereign rewrite
Canvasn8n--Drag-and-drop DAG sovereign
AI Govern [STAR]NONENONELLM-as-Judge - LangChain eval - OPA
Memory [STAR]NONENONEClickHouse sovereign - never leaves
FOSS Library Vault [STAR]NONEV3 (Istio, Harbor live)Istio, Harbor, Kafka, ClickHouse + more — CVE-patched, bank-owned assets
DataHarness cloudPartial100% your perimeter
[STAR] = No market equivalent. No bank equivalent. Unique to Illicium.
Your architect is building a sovereign FOSS vault — Kafka, ClickHouse, and more — CVE-patched at source, brought into the bank as institutional assets. No vendor. No licensing. No supply chain risk.
Harness is $3.7B. It cannot be used by a bank. Illicium delivers the same vision -- sovereign, air-gapped, with the AI governance and FOSS vault that banks actually need.
12 months from now.
When this moves forward.
400+
PROJECTS GOVERNED
One kernel. Every team governed. No manual gates.
Model Exec + Runtime
ABSORBED
Governed workers. Illicium is the intent layer above both.
CANVAS + ML
ENVIRONMENT LIVE
Visual drag-and-drop DAG live. Machine Languages sessions controlled.
AI OPS
ACTIVE
LLMs bank-approved. Sovereign loop running 24/7.
FOSS VAULT
EXPANDING
Istio, Harbor, Kafka, ClickHouse — CVE-patched. More every quarter.
BANK-WIDE
ADOPTION
IT DevOps, Risk, Finance — all teams on one framework. One standard.
One architect. Every AI workflow. Governed.
The knowledge accumulated in 12 months cannot be purchased from any vendor. Ever.
One more thing.
V3 migration codes itself.
📄
V3 JENKINS
PIPELINE
🤖
AI READS
V3 PATTERN
GENERATES
V4 DAG WORKER
SDK VALIDATES
DEPLOYED
Every V3 Jenkins pipeline migrates to V4 automatically. The Loop Engineering SDK reads the existing pattern, generates the equivalent V4 DAG worker, validates it, and deploys. No migration team. No big-bang project. Pipeline by pipeline.
Jenkins becomes optional. The migration writes itself.
The libraries are being written now.
The framework architecture is designed.
V3 proves the pattern works in production.
4 teams governed. FOSS assets flowing. Chain pipelines live.
The only question left is ownership.
The standard is being built.
The question is who owns it.
WAR ROOM BRIEF
TACTICAL DETAIL -- AVAILABLE ON REQUEST
INTERNAL POLITICAL LANDSCAPE
Model Execution is owned by IT. Replacing it directly creates conflict. Illicium governs above it -- not against it.
Runtime-as-a-Service is a bank infrastructure product. Illicium positions as the intent layer, not a competitor.
Machine Languages team controls developer environments. SDK enforcement is a capability add, not a constraint.
Jenkins rejection is structural -- V4 resolves it by removing the dependency entirely.
3-PHASE STRATEGY
Phase 1 -- GET APPROVED: Secure funding. Ship L1 kernel. Pass bank CICD review. Prove V4 replaces Jenkins cleanly.
Phase 2 -- PROVE CAPABILITY: Onboard two additional teams. Demonstrate Model Execution governance layer. Ship Canvas MVP. Activate AI Govern.
Phase 3 -- AI CODES MIGRATION: Loop Engineering SDK reads Model Execution patterns. AI generates Illicium DAG workers. Migration becomes self-executing. Model Execution becomes legacy on its own timeline.
COMPLIANCE WALL DETAIL
Jenkins not on bank approved CICD list. IT cannot use it in standard pipelines. V3 requires Jenkins -- this is the scaling ceiling.
V4 L1 Kernel uses Rust/WASM, no Jenkins dependency. Full sovereign pipeline from day one.
OPA Rego policies approved once at L2 and inherited -- no per-team compliance review per product.
BUDGET ARGUMENT BREAKDOWN
One architect. One kernel. Marginal cost per additional team is near-zero -- pattern inheritance, not per-team build.
Harness enterprise license equivalent: $500K+ per year. Illicium: one-time build cost, perpetual IP ownership.
Compliance re-approval per new SaaS product: significant overhead. Illicium: zero -- Bank Armor inherited automatically.
Institutional AI knowledge in ClickHouse sovereign memory compounds. Cannot be purchased later -- must be grown from day one.
✕ CLOSE (ESC)
Press Play to begin narration
1 / 10