Haute Lumière · The Circle · Published in full

The Protocol

The security, vetting and sovereignty standard for every Haute Lumière engagement — the island, the circles, and every private session. Published rather than promised, because a woman at this altitude has been assured of things her whole adult life and what moves her is being shown the architecture.

The governing principle is stated once and holds throughout: we do not hold what we do not need, and we cannot disclose what we do not hold. Most privacy policy is a promise about behaviour. This is a set of decisions about architecture, and the difference is that architecture survives a change of management, a subpoena, and a bad actor on the inside.

Every item below is either in force now or named as a target. Nothing is described as operational that is not.

Messaging & video
Our own servers. Our own iron. No third party in the path.
Encryption
End-to-end, plus metadata suppression above it
Network identity
No IP address recorded, ever, anywhere
Session record
None created. No audio, no video, no transcript.
Vetting
Every member, every practitioner, every hand on the island
Cohort list
Does not exist in any circulable form

Part I

The Stack

The communications layer is built on hardware we own, in space we control, with no commercial platform anywhere in the path. This is the expensive answer and it is the only one that closes the actual exposure.

Our own iron

Messaging, voice and video run on private servers under our own administration. Not a managed instance, not a virtual private server inside somebody else's hypervisor, not a self-hosted application on rented compute — our own machines, physically, in facilities where access is logged against named individuals and we hold the only keys to the cabinet.

This matters for a reason that has nothing to do with cryptography. A cloud-hosted service, however well encrypted, sits inside an infrastructure whose operator can be compelled, breached or bought, and whose hypervisor can in principle read the memory of the machine running your process. Owning the iron removes an entire adversary class rather than encrypting around it.

Beyond end-to-end

End-to-end encryption is the floor, not the standard. It protects content and leaves the far more revealing layer exposed: who spoke to whom, for how long, how often, from where, and in what pattern. For this cohort the metadata is the sensitive material — the fact that a named woman had four unscheduled ninety-minute calls in a week is a disclosure regardless of what was said.

So above the content encryption we suppress the pattern. Sealed sender, so the server cannot determine who originated a message. Constant-rate padding, so message length reveals nothing. Cover traffic, so silence and conversation are indistinguishable from the outside. Sessions addressed by rotating ephemeral identifiers rather than by account, so a long relationship does not present as a long thread.

Content encryption protects what was said. Only metadata suppression protects that anything was said at all.

No address, no route

No IP address is written to any log, on any machine, at any layer — not by the application, not by the reverse proxy, not by the operating system. Logging is configured off at source rather than scrubbed afterwards, because a scrubbed log is a log that existed.

Client connections reach the service through an anonymising route, so the server never learns the originating address even transiently in memory. The practical consequence is worth stating plainly: if we were compelled tomorrow to disclose every address that had ever connected to our infrastructure, the truthful and complete answer would be that we do not have one.

Where a member elects it, the entire engagement runs without a persistent identifier at all — booking, payment and correspondence through a designated intermediary, no legal name in any system we operate, no device of hers ever joining a network that could log. Available on request, without explanation required.

Nothing retained

Retention is where most privacy architecture quietly fails, because storage is cheap and deletion requires a decision.

Message content is held encrypted on the server only until delivered, then removed — measured in seconds, not days. Video and voice are never recorded at any point in the path. Scheduling data is minimised to what the calendar strictly requires and purged on a fixed cycle. Backups are encrypted, offline, key-separated, and expire on a schedule that is enforced by the system rather than remembered by a person.

The keys

Keys are generated on the member's device and never leave it. We cannot read a message, join a call, or recover a conversation, and this is a structural property rather than a policy — there is no administrative override, no master key, and no support process that can retrieve content, because none can exist without defeating the whole design.

The honest cost of that: a member who loses her device loses her history. We say so at the outset, we make the trade-in explicit, and we do not build the recovery mechanism that would quietly undo everything above.

Part II

The Vetting

Every person in the room has been vetted, and every member is entitled to know that the other ten were. This is a condition of the work rather than a courtesy: the material that surfaces on day four does not surface in a room containing one unverified person.

Members

Vetting runs alongside the application and is separate from it — the application asks who she is becoming; the vetting establishes who she is.

Identity is verified against government documentation, in person or by supervised live session, never by uploaded photograph. Source of wealth is established to the standard a private bank would require, both because we will not be an unwitting laundering vector and because the origin of the capital is clinically relevant to the work. Adverse media and litigation history are reviewed across the jurisdictions she operates in. Sanctions and politically-exposed-person screening runs against the full international lists. And two references are taken up and actually spoken to.

Vetting is also a clinical screen, and this is the part most programmes omit. A structured conversation with a licensed clinician establishes whether a nine-day container of this intensity is appropriate — active psychiatric instability, current substance dependence, an acute bereavement, or a medication regime incompatible with the physiological protocols are all grounds for decline, and decline in these cases comes with a genuine referral rather than a form letter.

Practitioners and staff

Held to a higher standard than members, because they are the greater exposure.

Every facilitator, clinician, bodyworker, cook, captain and housekeeper is vetted for the specific cohort rather than held on a general roster. Credentials are verified at source with the issuing body, not accepted as stated. Full background and criminal-record checks in every jurisdiction of residence. Professional liability confirmed as current, with certificates on file. Employment history verified with actual conversations. And a signed confidentiality instrument with defined, enforceable consequence that survives the engagement permanently.

Nobody is on the island incidentally. There is no agency labour, no day staff, no subcontracted service, and no person present whose name we could not produce and account for.

Continuous, not once

Vetting at intake is a snapshot, and a snapshot ages. Sanctions and adverse-media screening re-runs quarterly for every active member and practitioner. Credentials and insurance are re-verified annually. A change in a member's circumstances that bears on the cohort's safety is grounds for a conversation, and in the rare case, for exit.

Part III

On the Ground

Light-touch posture

Visible security is worse than none. It keeps the autonomic system reading threat all week, disrupts the therapeutic environment, and advertises to anyone watching that there is something here worth guarding.

So: no uniform anywhere on the island. No visible hardware in any room a guest occupies. No fixed camera grid and no scheduled patrol, both of which are learnable by anyone who observes for a week. Perimeter awareness runs on unpredictable coverage instead, and personnel are selected for behavioural anomaly detection rather than presence. The measure of success is that no guest ever has a reason to think about it.

Counter-surveillance

A full technical counter-surveillance sweep is conducted before every cohort arrives — every suite, every working room, the dining room, the boat, the vehicles. Radio-frequency spectrum analysis, non-linear junction detection, thermal survey, and physical inspection of every fixture, fitting and furnishing.

The sweep is documented and the documentation is available to any member who asks to see it. Sweeps repeat mid-stay, unannounced. Every network-capable device on the property was brought by us and leaves with us; nothing installed by the property is permitted to remain powered.

Arrival and anonymity

Private aviation to a field with no commercial traffic, then water. No public terminal, no shared transfer, no queue, no lobby — no moment at which a guest is a member of the public.

Cohort composition is never circulated in advance and never published after. No guest is asked to consent to being named. There is no delegate list, no name badge, no seating plan and no group photograph, because a group photograph is the single most common way a container like this is broken. Members meet in the room and nowhere else; what they do with each other's names afterwards is entirely theirs.

Part IV

The Record

What we never create

No session is recorded in any medium. No audio, no video, no transcript, no automated note-taking, no clinical file in the medical sense. No photography of any guest at any time, by anyone, including her. No attendance record naming who was present at which retreat. No archive of the written application beyond the decision period.

The reasoning is the governing principle: a record that exists can be leaked, breached, compelled or stolen. The only reliable protection is that it was never made.

What exists, and where

Honesty requires enumerating what does exist, because "we keep nothing" is never true and claiming it destroys trust.

The contract and the payment record. Required by law and by the bank. Held encrypted, minimised to the legal necessity, retained for the statutory period, then destroyed.

The vetting file. Held encrypted with separated keys, accessible to two named people, purged on a fixed schedule after the engagement ends.

The physiological data. Held on the member's own device and under her own account with the device manufacturer. We read it with her, in session. We do not hold a copy, and the manufacturer's terms are hers to review rather than ours to interpret.

Her own writing. Hers entirely. It leaves with her. We keep no copy of a journal, an application answer, or a day-nine pact.

The facilitator's memory. Which is not a record, is not discoverable, and is the intended and only repository of what was said in the room.

Legal process

If served with valid legal process we will comply with the law, and we have built the architecture so that compliance discloses almost nothing. Where permitted we notify the member first and support her counsel. Where a gag prevents notification, a warrant canary published on a fixed schedule ceases to update.

What could be produced under compulsion: a contract, a payment record, a vetting file. What could not: any message content, any call content, any session material, any network address, any cohort list — because none of it exists to produce.

Part V

Beyond Standard

The following exceed what any comparable practice does, and several exceed what most banks do. They are set out as an implementation list rather than a claim.

Fourteen procedures

One

Two-person integrity

No single individual can access the vetting store, the payment system, or the server cabinet alone. Two named people, separated keys, logged access.

Two

Hardware key mandate

Every person with any administrative access holds a physical security key. No software authenticator, no codes by message, no exceptions for convenience.

Three

Clean-device provisioning

Every practitioner works from a device we issue, imaged from a known state before each cohort and wiped after. No personal hardware touches the work.

Four

Air-gapped key ceremony

Root key material generated and stored on hardware that has never been connected to a network. Split across three geographies, two required to reconstruct.

Five

Independent annual penetration test

A firm we did not choose ourselves, briefed to try genuinely, with the summary made available to any member who asks.

Six

Published warrant canary

A signed statement on a fixed monthly schedule affirming no compelled disclosure. Its absence says what a gag order prevents us from saying.

Seven

Reproducible client builds

The application a member installs can be independently rebuilt from published source to a byte-identical result, so nobody has to trust our word about what it does.

Eight

Rehearsed insider-threat drill

Twice a year, a rehearsal of the scenario nobody plans for: a trusted practitioner acting in bad faith. Detection, containment, member notification.

Nine

Faraday storage at the door

A shielded cabinet for every device on the island — including staff. Held, not confiscated, and no powered radio inside the working perimeter.

Ten

Non-attributable payment path

For members electing anonymity: an intermediary structure such that our own accounting system never holds a name against an engagement.

Eleven

Data-minimisation review, quarterly

A standing exercise whose only question is what we are holding that we could stop holding. Every quarter something is removed.

Twelve

Practitioner re-vetting on cadence

Not intake-only. Screening re-runs quarterly, credentials annually, and a lapse suspends participation immediately rather than at the next review.

Thirteen

Counter-surveillance mid-stay

The pre-arrival sweep is expected and therefore plannable around. An unannounced second sweep during the stay is not.

Fourteen

Member-side verification

Any member may commission her own security assessment of our infrastructure, at our expense, by a firm of her choosing. This has been taken up. It is the strongest signal available.

The audit before every cohort

Twelve checks, all of which must pass before a cohort is confirmed.

  1. Every member vetted, screened and clinically cleared, with files current?
  2. Every practitioner and staff member vetted for this cohort, credentials verified at source?
  3. Counter-surveillance sweep completed and documented within seventy-two hours of arrival?
  4. Every property-installed network device located and powered down?
  5. All service devices imaged from clean state and encrypted?
  6. Logging confirmed off at source across every layer, verified by inspection rather than assumed?
  7. Backups current, encrypted, offline, key-separated, expiry enforced?
  8. Warrant canary published on schedule?
  9. Professional liability current for every practitioner, certificates on file?
  10. Informed consent executed, describing the psychological risk in plain language?
  11. Emergency medical evacuation route rehearsed with named clinicians at the receiving end?
  12. Could any single person, acting alone and in bad faith, produce a member's name, address or session content? The answer must be no.

Item twelve is the one that matters. Everything above it exists to make its answer structural rather than aspirational.

Colophon

Published in full, in the same system as everything else we make, and revised as the standard rises. The Island sets out the retreats and the Circle; this document sets out what holds them.

We do not hold what we do not need, and we cannot disclose what we do not hold.