Correct the org card: remove protected engine internals, drop false public-availability claims, fix demo links and status
Browse files
README.md
CHANGED
|
@@ -10,192 +10,171 @@ license: other
|
|
| 10 |
|
| 11 |
# ARF AI
|
| 12 |
|
| 13 |
-
**
|
| 14 |
|
| 15 |
-
|
| 16 |
-
|
| 17 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
| 18 |
|
| 19 |
---
|
| 20 |
|
| 21 |
-
##
|
| 22 |
|
| 23 |
-
|
| 24 |
-
|
| 25 |
|
| 26 |
-
|
| 27 |
-
|
| 28 |
-
|
| 29 |
|
| 30 |
-
|
| 31 |
|
| 32 |
---
|
| 33 |
|
| 34 |
-
## What ARF
|
| 35 |
|
| 36 |
-
|
| 37 |
|
| 38 |
-
- ✅ **
|
| 39 |
-
- ⚠️ **
|
| 40 |
-
|
|
|
|
| 41 |
|
| 42 |
-
|
| 43 |
-
|
| 44 |
-
|
| 45 |
-
- **Signed** (Ed25519) for non‑repudiation.
|
| 46 |
|
| 47 |
-
|
| 48 |
|
| 49 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 50 |
|
| 51 |
-
|
| 52 |
-
|
| 53 |
-
| **VP of Engineering** | Reduce operational risk from AI‑generated actions. |
|
| 54 |
-
| **CTO / CIO** | Maintain speed while adding governance. No full redesign required. |
|
| 55 |
-
| **Head of Compliance** | Complete, tamper‑evident audit trail for regulators. |
|
| 56 |
-
| **Security Officer** | Deterministic policy gates that cannot be silently overridden. |
|
| 57 |
-
| **AI/ML teams** | Get your models into production *with* trust and oversight. |
|
| 58 |
|
| 59 |
---
|
| 60 |
|
| 61 |
-
##
|
| 62 |
-
|
| 63 |
-
ARF’s core is a Bayesian governance engine. Key technical components:
|
| 64 |
-
|
| 65 |
-
### Bayesian risk fusion
|
| 66 |
-
Combines online conjugate priors, offline HMC logistic regression, and optional hierarchical hyperpriors.
|
| 67 |
-
|
| 68 |
-
$$
|
| 69 |
-
\text{risk} = w_{\text{conj}}\cdot\frac{\alpha}{\alpha+\beta} + w_{\text{hmc}}\cdot p_{\text{hmc}} + w_{\text{hyper}}\cdot \mu_{\text{hyper}}
|
| 70 |
-
$$
|
| 71 |
|
| 72 |
-
|
|
|
|
| 73 |
|
| 74 |
-
|
| 75 |
-
|
|
|
|
|
|
|
|
|
|
| 76 |
|
| 77 |
-
|
| 78 |
-
\begin{aligned}
|
| 79 |
-
L_{\text{approve}} &= \text{COST\_FP}\cdot R + \text{COST\_IMPACT}\cdot b_{\text{mean}} \\
|
| 80 |
-
L_{\text{deny}} &= \text{COST\_FN}\cdot(1-R) + \text{COST\_OPP}\cdot v_{\text{mean}} \\
|
| 81 |
-
L_{\text{escalate}} &= \text{COST\_REVIEW} + \text{COST\_UNCERTAINTY}\cdot\psi
|
| 82 |
-
\end{aligned}
|
| 83 |
-
$$
|
| 84 |
|
| 85 |
-
|
| 86 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
| 87 |
|
| 88 |
-
|
| 89 |
-
|
| 90 |
-
|
| 91 |
-
### Cryptographic signing
|
| 92 |
-
Ed25519 signatures for `HealingIntent` – non‑repudiable governance.
|
| 93 |
|
| 94 |
---
|
| 95 |
|
| 96 |
-
##
|
| 97 |
-
|
| 98 |
-
- [Data models & API contracts](https://github.com/arf-foundation/arf-spec) – `InfrastructureIntent`, `HealingIntent`, `RiskScore`, `GovernanceLoop`
|
| 99 |
-
- [Mathematics](https://arf-foundation.github.io/arf-spec/mathematics/) – Full derivations, Lyapunov proof
|
| 100 |
-
- [Governance loop](https://arf-foundation.github.io/arf-spec/governance/) – Constants (`COST_FP`, `COST_FN`, `EPISTEMIC_ESCALATION_THRESHOLD`)
|
| 101 |
-
|
| 102 |
-
---
|
| 103 |
|
| 104 |
-
|
|
|
|
| 105 |
|
| 106 |
-
| Demo |
|
| 107 |
-
|------|-------------|------|
|
| 108 |
-
|
|
| 109 |
-
|
|
| 110 |
|
| 111 |
-
|
| 112 |
|
| 113 |
---
|
| 114 |
|
| 115 |
-
## Public
|
|
|
|
|
|
|
|
|
|
|
|
|
| 116 |
|
| 117 |
-
|
| 118 |
-
|
| 119 |
-
|
| 120 |
|
| 121 |
-
|
|
|
|
| 122 |
|
| 123 |
---
|
| 124 |
|
| 125 |
-
## Access
|
| 126 |
|
| 127 |
| Layer | Availability | Purpose |
|
| 128 |
|-------|--------------|---------|
|
| 129 |
-
| **
|
| 130 |
-
| **Pilot
|
| 131 |
-
| **Enterprise
|
| 132 |
|
| 133 |
-
-
|
|
|
|
| 134 |
|
| 135 |
-
|
| 136 |
|
| 137 |
-
|
| 138 |
-
|
| 139 |
-
👉 **[Apply for pilot access →](https://www.arf-ai.com/signup)**
|
| 140 |
-
|
| 141 |
-
When applying, include:
|
| 142 |
-
- Organization name
|
| 143 |
-
- Use case (e.g., infrastructure change review, AI‑assisted operations)
|
| 144 |
-
- Expected volume (approx. evaluations per month)
|
| 145 |
-
- Cloud environment (AWS, Azure, GCP, on‑prem)
|
| 146 |
-
|
| 147 |
-
Pilot is **time‑limited and free** for qualified organizations. No commitment – just validation.
|
| 148 |
|
| 149 |
---
|
| 150 |
|
| 151 |
-
##
|
| 152 |
|
| 153 |
-
|
| 154 |
-
|
| 155 |
-
|
| 156 |
-
|
| 157 |
-
|
| 158 |
-
|
|
|
|
|
|
|
| 159 |
|
| 160 |
---
|
| 161 |
|
| 162 |
## Trust & compliance
|
| 163 |
|
| 164 |
-
ARF is architected for
|
| 165 |
-
|
| 166 |
-
|
| 167 |
-
- Mechanical enforcement – policy gates cannot be bypassed.
|
| 168 |
-
- Explainable reasoning – suitable for third‑party audits.
|
| 169 |
-
- Supports GDPR, SOC2, ISO27001 alignment.
|
| 170 |
-
|
| 171 |
-
---
|
| 172 |
-
|
| 173 |
-
## Product principles
|
| 174 |
-
|
| 175 |
-
1. Governance should be deterministic where possible.
|
| 176 |
-
2. High‑impact decisions must be explainable.
|
| 177 |
-
3. Human review remains available for uncertainty.
|
| 178 |
-
4. Auditability is built in, not retrofitted.
|
| 179 |
-
5. Enterprise deployment must not require abandoning existing infrastructure.
|
| 180 |
-
6. Commercial terms reflect actual value delivered (risk reduction).
|
| 181 |
-
|
| 182 |
-
---
|
| 183 |
-
|
| 184 |
-
## Short version
|
| 185 |
-
|
| 186 |
-
ARF AI is the decision layer between AI intent and production execution.
|
| 187 |
-
It evaluates, decides, and logs – so you can move fast without losing control.
|
| 188 |
|
| 189 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
| 190 |
|
| 191 |
---
|
| 192 |
|
| 193 |
-
## Legal
|
| 194 |
|
| 195 |
-
- **Core engine
|
| 196 |
-
|
| 197 |
-
- **
|
|
|
|
|
|
|
|
|
|
| 198 |
|
| 199 |
---
|
| 200 |
|
| 201 |
-
*© ARF Foundation. All rights reserved.*
|
|
|
|
| 10 |
|
| 11 |
# ARF AI
|
| 12 |
|
| 13 |
+
**Control plane for autonomous AI.**
|
| 14 |
|
| 15 |
+
ARF sits between an agent's intent and its execution. Every proposed action is
|
| 16 |
+
evaluated against deterministic policy before anything happens, and the
|
| 17 |
+
decision is recorded before the action runs — not after it succeeds.
|
| 18 |
+
|
| 19 |
+
> 🔒 **ARF is commercial software and is not open source.** The core engine,
|
| 20 |
+
> API control plane, gateway and enterprise extension are access-controlled.
|
| 21 |
+
> Access is through the sandbox, a pilot, or an enterprise agreement.
|
| 22 |
|
| 23 |
---
|
| 24 |
|
| 25 |
+
## The problem
|
| 26 |
|
| 27 |
+
An agent that can restart a service, delete a volume, move money or approve a
|
| 28 |
+
claim is not a chatbot. It is an operator without a review process.
|
| 29 |
|
| 30 |
+
The usual answer is to ask a model to check its own work. That produces a
|
| 31 |
+
judgment which can differ between two identical requests — so it cannot be
|
| 32 |
+
audited, cannot be appealed, and cannot be shown to anyone as a rule.
|
| 33 |
|
| 34 |
+
ARF's answer is that some decisions must not be delegated to judgment at all.
|
| 35 |
|
| 36 |
---
|
| 37 |
|
| 38 |
+
## What ARF does
|
| 39 |
|
| 40 |
+
Every request returns one of three outcomes:
|
| 41 |
|
| 42 |
+
- ✅ **APPROVE** — within policy, and uncertainty is low enough to act.
|
| 43 |
+
- ⚠️ **ESCALATE** — the system could not establish that this is permitted. An
|
| 44 |
+
input is missing, or the action is above the bar this policy clears alone.
|
| 45 |
+
- ❌ **DENY** — violates policy or exceeds risk tolerance.
|
| 46 |
|
| 47 |
+
**ESCALATE is not a softer DENY.** Collapsing the two destroys the difference
|
| 48 |
+
between *this is forbidden* and *this needs a person*, and that difference is
|
| 49 |
+
the whole of what a reviewer needs in order to act.
|
|
|
|
| 50 |
|
| 51 |
+
Every decision is:
|
| 52 |
|
| 53 |
+
- **Deterministic** where it matters — identical inputs, identical policy
|
| 54 |
+
version, identical answer, every time.
|
| 55 |
+
- **Explained** — a refusal nobody can explain is not auditable, so a refusal
|
| 56 |
+
without reasons is rejected rather than passed downstream.
|
| 57 |
+
- **Recorded in a hash-chained audit log** — each entry carries the hash of
|
| 58 |
+
the entry before it, so modifying any past entry breaks every entry after
|
| 59 |
+
it. Entries are additionally **Ed25519-signed when a signing key is
|
| 60 |
+
configured**; without one they are still written and still chained, just
|
| 61 |
+
unsigned. Chaining is integrity, not authorship — the two are not the same
|
| 62 |
+
claim and we do not merge them.
|
| 63 |
|
| 64 |
+
Risk scoring is Bayesian and reports its own uncertainty, which is what drives
|
| 65 |
+
escalation rather than a coin-flip at the threshold.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 66 |
|
| 67 |
---
|
| 68 |
|
| 69 |
+
## Who this is for
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 70 |
|
| 71 |
+
ARF is built first for teams where **an agent can already change production
|
| 72 |
+
state and nobody owns governance yet**. A practical test:
|
| 73 |
|
| 74 |
+
- Can one of your agents take an action a customer would notice, without a
|
| 75 |
+
human in the loop?
|
| 76 |
+
- If it did that wrongly at 3am, would you be able to show what was decided,
|
| 77 |
+
by which rule, and on what inputs?
|
| 78 |
+
- Is there a named owner for that question today?
|
| 79 |
|
| 80 |
+
If the first two are *yes* and the third is *no*, that gap is what ARF closes.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 81 |
|
| 82 |
+
| Role | What they get |
|
| 83 |
+
|------|---------------|
|
| 84 |
+
| **Founder / CTO at an AI-native team** | Governance before the first incident, without a redesign or a compliance hire |
|
| 85 |
+
| **Platform & SRE leads** | Deterministic gates on agent-initiated production change |
|
| 86 |
+
| **Security & compliance leaders** | A tamper-evident record of what was decided and why |
|
| 87 |
+
| **AI/ML teams** | A route to production that survives review |
|
| 88 |
|
| 89 |
+
Larger and regulated deployments are served too — through the enterprise tier,
|
| 90 |
+
with SSO, multi-tenancy and an SLA — but the sandbox and pilot are designed for
|
| 91 |
+
small teams shipping agents now.
|
|
|
|
|
|
|
| 92 |
|
| 93 |
---
|
| 94 |
|
| 95 |
+
## Live demos
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 96 |
|
| 97 |
+
Both run on mock data. They demonstrate the decision surface; they do not
|
| 98 |
+
enforce anything.
|
| 99 |
|
| 100 |
+
| Demo | What it shows | Status |
|
| 101 |
+
|------|---------------|--------|
|
| 102 |
+
| [Risk Dashboard](https://huggingface.co/spaces/ARF-AI/Agentic-Reliability-Framework-v4) | Adjust priors, watch scoring and escalation respond | Running |
|
| 103 |
+
| [Sandbox API](https://huggingface.co/spaces/ARF-AI/ARF-Sandbox-API) — [`/docs`](https://arf-ai-arf-sandbox-api.hf.space/docs) | Interactive OpenAPI endpoint | Running |
|
| 104 |
|
| 105 |
+
Mock responses only. Real enforcement requires sandbox or pilot access.
|
| 106 |
|
| 107 |
---
|
| 108 |
|
| 109 |
+
## Public code
|
| 110 |
+
|
| 111 |
+
| Repository | License | What it is |
|
| 112 |
+
|------------|---------|------------|
|
| 113 |
+
| [`arf-pattern-examples`](https://github.com/petter2025us/arf-pattern-examples) | Apache-2.0 | A runnable reference implementation of the **pattern** — propose, decide deterministically, record, then execute. Three worked domains, hash-chained audit with a tampering test, and a fail-closed external-policy delegation. Contains none of ARF's engine. |
|
| 114 |
|
| 115 |
+
That repository is independent reference code. It is not ARF, it does not
|
| 116 |
+
contain ARF's risk engine, authority system or execution-admission protocol,
|
| 117 |
+
and it is useful whether or not you ever talk to us.
|
| 118 |
|
| 119 |
+
Everything else — core engine, API control plane, gateway, enterprise
|
| 120 |
+
extension — is private and stays private.
|
| 121 |
|
| 122 |
---
|
| 123 |
|
| 124 |
+
## Access
|
| 125 |
|
| 126 |
| Layer | Availability | Purpose |
|
| 127 |
|-------|--------------|---------|
|
| 128 |
+
| **Sandbox** | Free, 1,000 evaluations/month, simulation only | Evaluate the decision surface |
|
| 129 |
+
| **Pilot** | Time-limited, free by review | Validate on your own use case |
|
| 130 |
+
| **Enterprise** | Custom deployment | Production enforcement, SSO, multi-tenancy, SLA |
|
| 131 |
|
| 132 |
+
Pilot pricing is outcome-based: you pay for verified risk reduction, not per
|
| 133 |
+
API call.
|
| 134 |
|
| 135 |
+
👉 **[Request pilot access →](https://www.arf-ai.com/signup)** · [arf-ai.com](https://www.arf-ai.com/)
|
| 136 |
|
| 137 |
+
When applying, include your organization, the use case, rough evaluation
|
| 138 |
+
volume, and where it runs.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 139 |
|
| 140 |
---
|
| 141 |
|
| 142 |
+
## Design principles
|
| 143 |
|
| 144 |
+
1. Deterministic where the decision must be reviewable; probabilistic only
|
| 145 |
+
where the world genuinely is uncertain.
|
| 146 |
+
2. A decision must be explainable to someone who was not there.
|
| 147 |
+
3. Uncertainty routes to a person; it never silently becomes approval.
|
| 148 |
+
4. The record is written before the action, not after it succeeds.
|
| 149 |
+
5. An unreachable dependency is not a permissive one — no control degrades
|
| 150 |
+
quietly into no control.
|
| 151 |
+
6. Auditability is built in, not retrofitted.
|
| 152 |
|
| 153 |
---
|
| 154 |
|
| 155 |
## Trust & compliance
|
| 156 |
|
| 157 |
+
ARF is **architected for SOC 2 readiness** and for review in regulated
|
| 158 |
+
environments: tamper-evident audit trails, policy gates that cannot be silently
|
| 159 |
+
bypassed, and explainable reasoning suitable for third-party audit.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 160 |
|
| 161 |
+
To be precise about what that does and does not mean: this describes how the
|
| 162 |
+
system is designed. It is not a certification, not an attestation, and nothing
|
| 163 |
+
here establishes your compliance with any framework. ARF is also **not** a
|
| 164 |
+
functional-safety layer — it governs decisions above certified safety systems
|
| 165 |
+
and does not replace them.
|
| 166 |
|
| 167 |
---
|
| 168 |
|
| 169 |
+
## Legal
|
| 170 |
|
| 171 |
+
- **Core engine, API control plane, gateway, enterprise extension** —
|
| 172 |
+
proprietary. No public access.
|
| 173 |
+
- **`arf-pattern-examples`** — Apache-2.0, and genuinely so.
|
| 174 |
+
- **This page and ARF marketing materials** — © ARF Foundation. Not to be
|
| 175 |
+
copied, redistributed, reverse engineered, or used for AI training without
|
| 176 |
+
written permission.
|
| 177 |
|
| 178 |
---
|
| 179 |
|
| 180 |
+
*© ARF Foundation. All rights reserved.*
|