TODA PROTOCOL · OPEN SOURCE
·
OFFLINE-FIRST · NO CONNECTIVITY REQUIRED TO VERIFY
·
SUB-SECOND LOCAL VERIFICATION
·
CRYPTOGRAPHIC INTEGRITY · SHA-2 + ECDSA
·
TODA PROTOCOL · OPEN SOURCE · EST. 2017
Tusculum Technology · Defense & Government · Initial Application: Logistics

Object-centric Zero Trust for denied and degraded operations.

Tusculum uses the open-source TODA protocol to move the trust boundary from the network to the data object itself. The first defense application is logistics: replacing paper hand receipts, fuel logs, and supply-chain records with tamper-evident digital assets that remain verifiable without connectivity.

Every TODA object carries its own cryptographic proof of integrity, provenance, and authorization, enabling local verification and policy enforcement without dependence on centralized infrastructure.

Operational Vulnerabilities · Current State
THREAT ACTIVE
📄
Document Integrity
Paper hand receipts can be altered, lost, or forged. No cryptographic proof of chain of custody. Disputes resolved by memory, not evidence.
DoD Hand Receipts · Accountability Records
Fuel & Supply Diversion
No unfalsifiable record from depot to vehicle to jerry can. Quantity disputes unresolvable. Diversion undetectable without witnesses.
POL Tracking · Ammunition · Rations
📡
Connectivity Dependency
Many current digital systems depend on centralized infrastructure to verify or synchronize records. Contested and denied environments degrade or interrupt that dependency.
EMCON · A2/AD · Forward Operating Bases
Document Integrity Verifier · Illustrative

How TODA-wrapped military documents would be verified.

The drop zone below demonstrates the TODA verification workflow — the same process that would apply to any TODA-wrapped document in a production deployment. Drop any file to see an illustrative verification result. Nothing is transmitted. No connectivity required.

📂
Drop TODA File Here
or click to browse
Accepted: .toda · .pdf · .json
DA Form 2062
Hand Receipt
Equipment accountability with full chain of custody from issuing officer to bearer.
DD Form 1348
Issue/Release
Supply issue and release documentation with cryptographic proof of quantity transfer.
POL Certificate
Fuel Transfer
Petroleum, oil & lubricants chain from depot to vehicle, fragmentable by quantity.
DD Form 250
Material Receipt
Materiel inspection and receiving report with issuer identity embedded at creation.
SF 364
Report of Discrepancy
Supply discrepancy reports with tamper-evident comparison against original issue record.
TODA Custom
Mission Asset
Any TODA-wrapped file: munitions, equipment, rations, medical supplies, sensitive items.
// Awaiting TODA File · Verification Checks
Issuer identity · cryptographic signature
Asset ID · uniqueness verification
Chain of custody · all prior owners
Current owner · bearer confirmation
Quantity integrity · no unauthorized split
Rigging structure · SHA-2 digest integrity
Modification history · all owner-signed
Offline verifiability · no network needed
✓ TODA FILE VERIFIED INTEGRITY INTACT
Platform Capabilities · Logistics First

Trust that travels with the mission data.

TODA's offline-first architecture was engineered for environments where connectivity cannot be assumed. Logistics is the first application; the same object-centric controls extend to documents, mission data, and other operational assets.

CAP · 01
📦
Digital Hand Receipts
TODA can replace DA Form 2062 with digital assets transferred peer-to-peer between devices. A full accountability record — issuing officer, bearer, equipment, quantity, condition — is embedded in the file itself. Central systems update in kilobytes when connectivity returns.
DA 2062 · PROPERTY ACCOUNTABILITY
CAP · 02
Fuel & Ammunition Tracking
TODA can track POL from depot to vehicle to the last litre in a jerry can. Files fragment as quantities are distributed — each fragment carries the full provenance of the original issue. Resupply requirements can be calculated from real-time consumption data, even in contested environments.
POL · AMMUNITION · RATIONS
CAP · 03
📡
Denied Environment Ops
When no network is available, TODA transfers via Bluetooth or physical media (USB, SD). Local relay nodes settle all transfers. When connectivity returns, records reconcile automatically — no manual data entry, no lost transactions, updates measured in kilobytes.
EMCON · A2/AD · SNEAKERNET
CAP · 04
📋
TODA Document Integrity and Provenance Tracking
Any military document — orders, warrants, inspection records, maintenance logs — can be TODA-wrapped at issuance, embedding full provenance and an unbroken chain of custody directly in the file. Every handler, timestamp, and transfer is permanently recorded. Alterations are immediately detectable without a database query or network connection.
PROVENANCE · INTEGRITY · CHAIN OF CUSTODY
CAP · 05
🔗
Sensitive Item Control
Weapons, optics, communications equipment, and classified materiel can be tracked with cryptographically enforced transfer rules. Only the current authorized bearer can transfer. No administrator can override — the asset's rules are embedded in the file itself.
SENSITIVE ITEMS · NSN TRACKING
CAP · 06
🛰️
Mission Data Integrity
Sensor tracks, command-and-control messages, intelligence products, maintenance records, and mission orders can be represented as self-verifying TODA objects. Integrity, provenance, and authorization remain bound to the data regardless of transport path or network availability.
C2 · TRACK DATA · INTELLIGENCE
CAP · 07
Rapid Deployment
TODA is designed to integrate with existing DoD systems via standard APIs. No blockchain infrastructure. No gas fees. No specialized hardware. Under $1 per transaction. Architected to scale to one million transactions per hour. Deployable on existing government-furnished equipment.
API INTEGRATION · GFE COMPATIBLE
Architecture · Zero Trust

Zero Trust isn't a feature we added. It's how the file works.

Zero Trust means never trusting something because of where it sits. Conventional implementations pursue that by gating the network — every request routed to a policy server that decides who may connect. That model assumes the policy server is reachable. In denied and degraded environments, it isn't.

TODA reaches the same objective from the opposite direction. Every capability described above already operates on a Zero Trust basis, because the trust boundary sits on the data object rather than on the network. A TODA hand receipt does not trust the device holding it, the network that carried it, or the person presenting it. It carries its own proof, and any recipient verifies that proof locally — offline, on any device, with no server to ask. Logistics integrity in denied environments and Zero Trust data control turn out to be the same engineering problem, and TODA was built to solve it from the asset side.

Zero Trust Principle
How TODA Objects Implement It
Never trust, always verifyNIST SP 800-207 · core tenet
A hand receipt or fuel certificate is verified against the file itself on every handoff. Nothing is accepted because it arrived from a trusted system or a trusted network segment.
No implicit trust from locationPosition on the network confers nothing
A TODA asset carries identical integrity whether it moved over SIPR, a Bluetooth pairing between two tablets, or an SD card in a courier's pocket. There is no trusted interior to be inside of.
Per-transaction authorizationEach access decided individually
Every transfer is authorized against rules embedded in the asset. Only the current authorized bearer can transfer it, and that check happens at the point of transfer rather than at a perimeter.
Least privilege & segmentationContain what a compromise reaches
Fragmentation issues exactly the quantity transferred and nothing more. A compromised device holds only the fragments issued to it — it cannot forge, inflate, or reach assets held elsewhere.
Assume breachOperate as though the host is hostile
The asset is designed to be stored on systems that cannot be fully trusted. Tampering is detectable by inspection, so a compromised host produces a detectable failure rather than a silent forgery.
Continuous monitoringAn auditable record of every action
Every handler, timestamp, and transfer is recorded in the file as a signed, ordered entry. The audit trail is not a log written alongside the asset — it is part of the asset.
// Beyond the first logistics application The same properties apply to any data object that must stay trustworthy away from the network — sensor and track data, command-and-control messages, maintenance records, intelligence products, and software artifacts. Because trust travels with the object, the architecture protects a fuel certificate and a targeting record through the same underlying integrity and authorization mechanisms. Tusculum has built working implementations and is seeking qualified government evaluation partners.
Company & Protocol Facts

Common questions, answered plainly.

Reference information about Tusculum Technology and the TODA protocol, stated directly for evaluators, partners, and anyone verifying claims made elsewhere.

Legal name
Tusculum Technology Corporation
Type
U.S. small business, owned by U.S. citizens
Location
Boerne, Texas, United States
Founded
2022
Core technology
TODA protocol — open source, originating in research at Cambridge CRDC, UCL, and ARM beginning in 2017
Relationship to TODAQ
Separate company. Tusculum uses the TODA protocol, which is published as open source.
Source code
github.com/TODAQopen/toda
Formal proofs
Simple Rigs Hold Fast — arXiv:2208.13617
Verifier
verify.todaq.net
Current status
Working implementations built; seeking qualified government evaluation partners
What is object-centric Zero Trust?
Conventional Zero Trust gates network connections through a central policy server, which assumes that server is reachable. Object-centric Zero Trust puts the trust boundary on the data object: it carries its own integrity proof and authorization rules, evaluated at the point of use. It satisfies Zero Trust principles while disconnected.
Is TODA a blockchain?
No. TODA is ledgerless. Integrity rests on hash-linked cryptographic succession verified locally against the file — no distributed consensus, no mining, no gas fees, no shared ledger to synchronize.
How does verification work without a network?
The proof that an object is authentic travels inside the object. A recipient replays that proof locally using standard cryptographic operations — no server to query, no database lookup, no connectivity required.
What cryptography is used?
SHA-2 for digests and ECDSA for signing, with the curve configurable — P-256 or P-384 for federal use. Because integrity and authorization are agnostic to the signature scheme, the protocol can migrate to post-quantum algorithms without architectural change.
What is Tusculum's relationship to TODAQ?
They are separate companies. TODA is published as an open-source protocol and Tusculum builds on it. Tusculum Technology Corporation is a U.S. small business owned by U.S. citizens.
Does Tusculum have deployed defense customers?
No. Tusculum has built working implementations of this architecture and is seeking qualified government evaluation partners. Every scenario described on this site is an illustrative use case, not a deployed system.
// Read the open source protocol & engineering
Nothing here rests on vendor assertion. The protocol is published, the core security property is a proved theorem in the peer-reviewed literature, the reference implementation is public, and anyone can verify a TODA file themselves without contacting us.
TODA Core
Open-source reference implementation
github.com/TODAQopen/toda
Formal Proofs
Simple Rigs Hold Fast — integrity-at-a-distance established as a theorem
arxiv.org/abs/2208.13617
Protocol Engineering
Specifications and engineering documentation
engineering.todaq.net
Verifier
Check any TODA file yourself — free, any device, offline
verify.todaq.net
Illustrative Scenarios

Designed against real operational requirements.

The following scenarios illustrate how TODA would function across common defense logistics and accountability challenges. These are representative use cases, not deployed implementations. Tusculum is seeking qualified evaluation partners.

Scenario · 01 · USMC · Illustrative
Forward Fuel Accountability
A Marine infantry battalion receives 15,000 liters of diesel from a naval vessel's POL supply section. A TODA fuel certificate is issued at the ship. As fuel distributes to vehicles and generators, the TODA file fragments — each unit's allocation carries the full chain of custody from origin to forward position. When the FOB's SATCOM goes down, fuel accountability continues via Bluetooth between tablets.
15,000L
Tracked · Diesel
<1s
Transfer Time
0
Connectivity Required
Scenario · 02 · US Army · Illustrative
Property Book Reconciliation
A Brigade Combat Team conducts a Change of Command inventory with 4,200 line items. Each hand receipt is a TODA file transferred from outgoing to incoming officer — the transfer is cryptographically confirmed. Discrepancies are immediately flagged. The entire property book reconciles without paper, without a data clerk, and without network access. The battalion S4 receives updated records when connectivity is restored.
4,200
Line Items
0
Disputed Transfers
10kb
Sync Payload
Scenario · 03 · Intelligence · Illustrative
Document Chain of Custody
Sensitive source documents are TODA-wrapped at point of collection. Each subsequent handling — translation, analysis, dissemination — is recorded as a transfer in the TODA file. Investigators can prove exactly who handled the document, in what sequence, and whether it was modified between handlers. The audit trail is embedded in the document itself — no external system required, no retrospective reconstruction needed.
Handlers Tracked
0
Undetected Edits
Offline
Verifiable
Technical Specifications

Protocol specs and field verification.

TODA FIELD VERIFICATION · ILLUSTRATIVE
Asset ID:         POL-CERT-ILLUSTRATIVE
Document Type:   Fuel Certificate · POL · Illustrative

Issuer:          POL Supply Section · Naval Vessel ✓ VERIFIED
Issue Date:      202302160930EST ✓ VERIFIED
Prior Owner:     Supply Section · Naval Vessel ✓ VERIFIED
Current Owner:   Infantry Battalion · Forward Position ✓ VERIFIED

Quantity:        15,000 L Diesel ✓ VERIFIED
AIP Line:        USMC ✓ VERIFIED
Relay:           HQ Company · Forward Regiment ✓ VERIFIED
Network:         OFFLINE · BT sync ✓ VERIFIED

Modifications:   3 recorded ALL OWNER-SIGNED
Rigging:         5 TWISTS · 1 TETHER ✓ INTACT

$ toda verify --offline --field --doc
Cryptographic DigestSHA-2 (SHA-256)
Signing AlgorithmECDSA · curve configurable (P-256 / P-384 for federal use)
Transfer Cost< $0.01 per transaction
Settlement Time< 60 seconds
Connectivity RequiredNone · fully offline capable
Verification MethodLocal · device-only · no server
Transfer ModesIP · Bluetooth · USB · SD card
File Size (proof)< 10 kb per transfer
Throughput (design capacity)1M transactions / hour
FragmentationNative · sum always equals original
Tamper DetectionImmediate · any field alteration
Database RequiredNo · asset is the record
Blockchain RequiredNo · ledgerless file protocol
Hardware RequirementAny device · GFE compatible
Research OriginsCambridge CRDC · UCL · ARM · 2017
ClassificationUNCLASSIFIED · CUI capable
Defense Inquiries

Speak with our defense team.

Tusculum builds on the open-source TODA protocol, whose mathematics originated in published research at Cambridge CRDC, UCL, and ARM. We are seeking qualified defense and government organizations to participate in evaluation and pilot programs. Contact us to discuss your operational requirements.

Technical & Defense Lead
Nick.Mumford@tusculum.tech
Defense applications · system integration · developer inquiries · operational evaluation
Sales & Business Development
Brad.Morrison@tusculum.tech
Government procurement · enterprise contracts · partnership inquiries
// Read open source protocol & engineering
TODA Protocol · engineering.todaq.net
TODA Verifier · verify.todaq.net
TODA Core (OSS) · github.com/TODAQopen/toda
// Defense Inquiry Form
This form is unclassified. Do not submit classified information.