# Liminal

- **Event:** [National Security Hackathon (by Army xTech)](https://cerebralvalley.ai/e/3rd-annual-natsec-hackathon)
- **When:** May 2 at 9:00 AM – May 3 at 4:00 PM (PDT)
- **Where:** Shack15, San Francisco, CA
- **Team:** [Shruti](https://cerebralvalley.ai/u/LiminalShruti), [Sean Nejad](https://cerebralvalley.ai/u/kuzushi_security)
- **GitHub:** https://github.com/liminalshruti/liminal-natsec
- **Demo video:** https://www.loom.com/share/5f522ce2ba4c45c8921322d8869833c9
- **Gallery:** https://cerebralvalley.ai/e/3rd-annual-natsec-hackathon/hackathon/gallery
- **Page:** https://cerebralvalley.ai/e/3rd-annual-natsec-hackathon/hackathon/gallery/22

Liminal Custody, a pre-command evidence integrity system, ensures that the operator remains in the judgment seat rather than the correlation seat. Most command-and-control systems begin after a signal becomes commandable. Liminal Custody handles the preceding layer by ingesting open-source intelligence (sanctions lists, Global Fishing Watch records, Sentinel imagery, and archived AIS data), aggregating it into a knowledge graph, and allowing bounded agents to propose hypotheses. The analyst can click into a hypothesis to review the entire reasoning chain, which consists of individually unremarkable markers chained together to form a pattern of suspicious intent. The agent performs the correlation work, while the operator makes the judgment.

The cognitive pipeline operates in a left-to-right manner: Ingest, Relate, Hypothesize, and Review with Reasoning.

Liminal Custody was demonstrated on real Strait of Hormuz OSINT data, specifically an Iranian crude tanker (HUGE / IMO 9357183) that has been spoofing MMSI through seven broadcast identities since 2012. OFAC-sanctioned vessels engaged in gray-market evasion, loitering clusters, and ships changing identity over time. Each individual behavior could have gone unnoticed, but when chained together, the system revealed the pattern.

Refusal is structurally enforced rather than requested. Every AI specialist output passes through a server-side guard that enforces citation minimums, indicator-evidence requirements, and posterior thresholds. AI cannot overclaim; restraint is a security feature.

The track consists of three primary components: PS1 (Sensor Analysis & Integration), PS4 (Digital Defense), and PS3 (Mission C2) architecture. The structural guard in PS4 treats the evidence chain as a defensible attack surface, while PS3 provides a narrative that allows us to slot one layer earlier than CJADC2 or Maven Smart.    
System.

Team: Shruti Rajagopal (founder, Liminal — pre-decisional infrastructure for unresolved context) and Shayaun (Sean) Nejad (co-founder, OffSec-certified offensive-security professional, top-100 Hack The Box; the structural guard is his architecture).

Pilot Ask: 90 days with a maritime watchfloor or xTech-aligned sponsor on contested AIS replay data.

Maven is the foundation; we are the substrate.

---

Markdown version of https://cerebralvalley.ai/e/3rd-annual-natsec-hackathon/hackathon/gallery/22. Site index for agents: https://cerebralvalley.ai/llms.txt · full text: https://cerebralvalley.ai/llms-full.txt
