Lemma: releases reach machines you own.

Lemma carries signed releases and local models to plain Linux hosts, factory servers and vessels, without opening a single inbound port.

A fleet of ships fanning out across open water from a headland lighthouse, printed in coloured dots
The name

A lemma is a proven stepping stone.

In mathematics, a lemma is an auxiliary proposition proven in order to establish a larger theorem. In physical deployment, each edge node is one proven stepping stone: verified locally, isolated by ring, and safely rolled back if a single health check fails.

How it works

Outbound only, signed twice, reversible.

OUTBOUND MTLS ONLY · ZERO INBOUND PORTSLemma HubDECLARES INTENTEdge BoxLOCAL SAFETY & COW SNAPSHOTSATOMIC COW ROLLBACK
Figure 1. The edge boundary: machines poll outbound over mTLS. The hub declares intent, while the edge agent enforces local safety checks and CoW rollbacks.
Zero inbound ports
Nodes poll outbound over mutual TLS. No SSH keys, no listening ports, no reverse tunnels, and no firewall openings.
Two-key custody
Software bundles are signed by the vendor’s Release Key; rollout plans are signed by the customer’s Instruction Key. A compromised hub cannot forge software.
Edge safety check wins
The central hub declares intent; the edge agent checks local disk space, active locks and freeze windows before applying. The edge always has veto power.
Atomic CoW rollback
Instant rollback of application binaries and persistent data via CoW snapshots (LVM-thin / Btrfs) the moment a health check fails.
Dead man’s switch
An autonomous watchdog timer reverts to the previous verified release if communication with the hub is lost after an update.
Next

From edge to data.

Lemma manages deployments on hardware you own. Axiom resolves the data generated across those systems into a typed operational model.