A confidence floor that flags. Deny-by-default gates that block. A cryptographically signed receipt for every turn — and the real joules it took, measured on our own sovereign GPUs.
Answer is returned only on decision = allow. On review/deny you get the verdict + receipt and no answer — by design. Real turn on live GPU: ~30–60s.
Every governed turn reports the real joules it consumed. This is our sovereign mesh drawing power right now — measured from hardware, never estimated. The number you can't fake is the one buyers trust.
The same receipt that satisfies a compliance auditor satisfies an operational reviewer. Built for air-gap, for deny-by-default, and for proving — after the fact — exactly what an autonomous system was and was not allowed to do.
Runs on your own GPUs / air-gapped enclave. Zero data egress. "Sovereign" is asserted only when it truly reaches your box — never as a marketing word.
When a gate denies an action, the receipt records that the unsafe action was stopped — an auditable artifact for rules-of-engagement and oversight.
Every decision is hash-chained and signed, replayable into a common operating picture or after-action review. Provenance, not assertion.
Deny-by-default threat & PII gates can block an unsafe request in real time. The block is recorded, never silent.
A Λ advisory score flags low-confidence outputs for human review instead of passing them. Λ is a conjecture — never an overclaimed theorem.
Every turn is hash-chained (Khipu) and DSSE-signed with an ECDSA P-256 key. Verify it offline against the published key.
Real per-turn joules from NVML hardware telemetry, labeled MEASURED or UNAVAILABLE. We never invent a number.
| Obligation | What the receipt satisfies |
|---|---|
| FDA 21 CFR Part 11 | Signed, timestamped, hash-chained record of every inference — verifiable offline |
| Genomics / bioinformatics reproducibility | Provenance of every compute step sealed into the receipt |
| SR 11-7 / EU AI Act high-risk | Every decision receipted with gate verdicts and the Λ floor |
| Defense rules-of-engagement / oversight | Deny-by-default proof + replayable after-action record |
Eight formulas are kernel-verified in Lean (machine-checked, sorry-free). The rest of the corpus is in the open — each labeled by its true stage. The number that matters isn't how many we wrote; it's how many a machine has checked.
sorry-free, machine-checked & CI-locked
F1–F23 formula registry
theorems at mixed honest stages
CI sorry-gate forbids increase
Λ (the aggregator) is Conjecture 1 — advisory, NOT a theorem. Khipu BFT safety is Conjecture 2. Everything beyond the locked 8 is honestly staged PROVEN-ON-PAPER / CONJECTURE / ROADMAP — never counted as proven. That discipline is the product.
| Tier | For | Anchor |
|---|---|---|
| Design-partner pilot | First regulated / defense logos · 60–90 days | $35k–$50k |
| Sovereign license | On-prem / air-gap deployment | $50k–$250k/yr |
| Managed governed API | Hosted, metered per governed turn | per-1k turns |