r9.ca
Separate protected recursive resolver service identity. It remains outside the authoritative serving path.
The designated protected administrative and authoritative-service apex within the Assurance Enclave architecture.
dns9.ca defines a policy-isolated namespace identity for regulated, enterprise, and high-assurance service classes. It is not the hidden primary and does not presently operate as a deployed DNS service.
The protected model separates recursive identity, administrative authority, authoritative service identities, operational telemetry, and a private provisioning function that is intentionally not named or shown.
Separate protected recursive resolver service identity. It remains outside the authoritative serving path.
Designated protected administrative and authoritative-service apex. It is not the hidden primary.
Proposed protected authoritative service identities for regulated, enterprise, and high-assurance classes.
Protected operations and telemetry namespace associated with the six authoritative identities; not a claim of operating Internet exchange points.
An unnamed provisioning and synchronization function exists conceptually but is deliberately not exposed as a public namespace identity.
Shared primitive taxonomy with policy isolation and cryptographic governance defined separately for the protected service class.
The protected plane is a policy and service-class boundary, not merely spare capacity. Its operational premise is independent access control, signing policy, telemetry, change governance, and service eligibility.
dns9.ca remains the protected administrative and service apex. The hidden-primary function is private, unnamed, and not illustrated as a public domain.
A production implementation would require explicit threat models, DNSSEC key-management procedures, routing-security controls, independent observability, incident response, and auditable separation of duties.