betterwithage Claude Opus 4.7 commited on
Commit
275232d
·
verified ·
1 Parent(s): 568386f

deploy(hf): sync szl-holdings/a11oy@cab15b4659c3a99a0178dd79874e50c8402423f8 derived COPY set

Browse files

Reusable Dockerfile-COPY-derived deploy from szl-holdings/a11oy cab15b4659c3a99a0178dd79874e50c8402423f8.
Files: 1186 Pruned: 0
Derived from Dockerfile COPY sources (NO hand-maintained allowlist).

Signed-off-by: SZL Holdings <noreply@szlholdings.ai>
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

a11oy_landing.html CHANGED
@@ -1,45 +1,45 @@
1
- <!doctype html>
2
  <!-- SPDX-License-Identifier: Apache-2.0
3
  (c) 2026 Lutar, Stephen P. - SZL Holdings - ORCID 0009-0001-0110-4173 -->
4
  <!--
5
- a11oy — front door (scroll narrative). Served at the Space root "/" by serve.py.
6
  SOVEREIGN: Three.js r160 (MIT) vendored in-image at /hero/vendor3d. 0 runtime CDN.
7
  Fonts (Space Grotesk / JetBrains Mono) vendored at /vendor/fonts/*.woff2.
8
- HONESTY DOCTRINE v11 LOCKED — every figure is fetched live and labelled honestly
9
- (REACHABLE / MEASURED / MODELED / SNAPSHOT / UNAVAILABLE). Nothing is fabricated. Λ = Conjecture 1 (advisory, NOT a theorem,
10
  never 1.0, NEVER green). Locked-proven Lean kernel = EXACTLY 8 {F1,F4,F7,F11,F12,F18,F19,F22}.
11
- The genome registry (144 entries) is grouped into 4 honesty tiers — a different, larger set.
12
  Receipt chain integrity and DSSE signing are separate. Signing is claimed only when persistent signer evidence is ACTIVE and verification passes. Read-only routes never mint receipts.
13
- DOM/sections owned by Dev 1; the #hero-canvas + /landing/app.js boot is owned by Dev 2 —
14
  preserved verbatim below. KANCHAY palette. No purple. a-11-oy.com remains the
15
  canonical governed-inference product; a11oy.net is a separately attested estate cockpit.
16
- © Stephen P. Lutar Jr. (ORCID 0009-0001-0110-4173) · Apache-2.0
17
  -->
18
  <html lang="en">
19
  <head>
20
  <meta charset="utf-8" />
21
  <meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover" />
22
- <title>a11oy — Governed Inference · AI that proves its receipt state and refuses to lie</title>
23
- <meta name="description" content="Governed Inference: AI that exposes receipt integrity, signer state, evidence, and refusal behavior. State-changing actions produce hash-chained receipts; DSSE signing is claimed only when persistent signer evidence is active and independently verified." />
24
  <link rel="canonical" href="https://a-11-oy.com/" />
25
  <meta property="og:type" content="website" />
26
  <meta property="og:url" content="https://a-11-oy.com/" />
27
- <meta property="og:title" content="a11oy — Governed Inference" />
28
  <meta property="og:description" content="AI that exposes receipt integrity and signer state, shows its evidence, and refuses when it cannot support an answer." />
29
  <meta property="og:image" content="https://a-11-oy.com/social-preview-v5.png" />
30
  <meta property="og:image:type" content="image/png" />
31
  <meta property="og:image:width" content="1280" />
32
  <meta property="og:image:height" content="640" />
33
- <meta property="og:image:alt" content="a11oy Governed Inference — evidence-labelled ecosystem and Anatomy v5" />
34
  <meta name="twitter:card" content="summary_large_image" />
35
  <meta name="twitter:image" content="https://a-11-oy.com/social-preview-v5.png" />
36
- <meta name="twitter:image:alt" content="a11oy Governed Inference — evidence-labelled ecosystem and Anatomy v5" />
37
  <link rel="icon" type="image/svg+xml" href="/social-preview-v5.svg" />
38
  <script type="application/ld+json">
39
  {
40
  "@context": "https://schema.org",
41
  "@type": "SoftwareApplication",
42
- "name": "a11oy Governed Inference",
43
  "url": "https://a-11-oy.com/",
44
  "applicationCategory": "DeveloperApplication",
45
  "operatingSystem": "Web",
@@ -61,21 +61,21 @@
61
  font-display:swap;src:url('/vendor/fonts/JetBrainsMono.woff2') format('woff2')}
62
 
63
  :root{
64
- /* KANCHAY palette (canonical, org-wide — RECONCILE.md). Purple is BANNED. */
65
  --void:#080c14; /* deep near-black ground */
66
  --deep:#0a1019; /* raised ground */
67
  --surface:#0e1626; /* card surface */
68
  --border:#1c2942; /* hairline */
69
- --proof:#3af4c8; /* proof teal — the one bright accent */
70
  --proof-soft:rgba(58,244,200,0.12);
71
  --proof-dim:rgba(58,244,200,0.06);
72
- --lattice:#5b8dee; /* lattice blue — secondary (NOT purple) */
73
  --lattice-soft:rgba(91,141,238,0.12);
74
  --gold:#d7b96b; /* warm accent / conjecture-adjacent */
75
  --ink:#eef4fb; /* near-white heading */
76
- --sub:#aebccf; /* body copy — WCAG AA on --void */
77
  --ghost:#65788f; /* muted labels */
78
- --gray:#7d8aa0; /* CONJECTURE / advisory — never green */
79
  --ok:#3af4c8; --warn:#d7b96b; --down:#e8746e;
80
  --r:16px; --maxw:1180px;
81
  --head:'Space Grotesk',-apple-system,BlinkMacSystemFont,"Segoe UI",sans-serif;
@@ -137,7 +137,7 @@
137
  .btn{display:inline-flex;align-items:center;justify-content:center;gap:8px;padding:11px 21px;border-radius:9px;
138
  min-height:44px;max-width:100%;font-weight:600;font-size:14px;border:1px solid transparent;cursor:pointer;
139
  transition:all .18s cubic-bezier(0.16,1,0.3,1);white-space:nowrap;letter-spacing:.01em}
140
- /* restrained "holographic glass" buttons — luminous hairline + soft fill, never a neon block */
141
  .btn-primary{background:linear-gradient(180deg,rgba(58,244,200,0.13),rgba(58,244,200,0.04));
142
  color:var(--proof);border-color:rgba(58,244,200,0.42);
143
  box-shadow:inset 0 1px 0 rgba(58,244,200,0.10),0 1px 14px -8px rgba(58,244,200,0.45)}
@@ -153,7 +153,7 @@
153
  border-color:rgba(91,141,238,0.6);color:#c5d8ff;
154
  box-shadow:0 6px 24px -12px rgba(91,141,238,0.32);transform:translateY(-1px)}
155
 
156
- /* ---- hero (canvas owned by Dev 2 — markup preserved) ---- */
157
  .hero{position:relative;min-height:92vh;display:flex;align-items:center;overflow:hidden}
158
  #hero-canvas{position:absolute;inset:0;width:100%;height:100%;z-index:0;display:block}
159
  .hero-scrim{position:absolute;inset:0;z-index:1;pointer-events:none;
@@ -313,7 +313,7 @@
313
  .muted{color:var(--ghost)}
314
  .skel{color:var(--ghost);font-family:var(--mono)}
315
 
316
- /* ecosystem atlas — public estate snapshot, never implied live until API reads */
317
  .estate-grid{display:grid;grid-template-columns:repeat(6,1fr);gap:10px;margin:24px 0}
318
  .estate-cell{border:1px solid var(--border);border-radius:13px;padding:15px;
319
  background:linear-gradient(155deg,rgba(17,30,50,.72),rgba(8,16,29,.88))}
@@ -387,7 +387,7 @@
387
  <circle cx="16" cy="16" r="5" fill="url(#lg)"/>
388
  <path d="M16 3v8M16 21v8M3 16h8M21 16h8" stroke="url(#lg)" stroke-width="1.6" opacity=".7"/>
389
  </svg>
390
- <span>a11oy<span class="sub" style="margin-left:9px">Governed Inference</span></span>
391
  </a>
392
  <nav>
393
  <a class="hide-sm" href="#surfaces">Surfaces</a>
@@ -398,20 +398,20 @@
398
  <a class="hide-sm" href="/console#arena">Eval arena</a>
399
  <a class="hide-sm" href="/observability">Observability</a>
400
  <a href="/trust">Evidence</a>
401
- <a class="btn btn-primary" href="/console" aria-label="Open the command center"><span class="nav-cta-full">Open the command center</span><span class="nav-cta-short" aria-hidden="true">Command center</span> →</a>
402
  </nav>
403
  </div>
404
  </header>
405
  <main id="main">
406
 
407
- <!-- ====================== (1) HERO — canvas + boot owned by Dev 2 ====================== -->
408
  <section class="hero">
409
  <canvas id="hero-canvas"></canvas>
410
  <div class="hero-scrim" aria-hidden="true"></div>
411
  <div class="hero-fallback" id="hero-fallback"></div>
412
  <div class="wrap">
413
  <div class="hero-inner">
414
- <span class="eyebrow"><span class="dot"></span> Governed Inference · verifiable by anyone, offline</span>
415
  <h1 class="title">AI that <span class="grad">proves its receipt state</span><br>and refuses to lie.</h1>
416
  <p class="lede">Every governed state change produces a hash-chained receipt you can inspect
417
  <b>offline, in your own browser</b>. The interface says <b>SIGNED</b> only when persistent
@@ -419,26 +419,26 @@
419
  UNSIGNED, DISABLED, or UNAVAILABLE. When the model is not sure, it returns an honest
420
  <b>BLOCKED</b> instead of a confident guess.</p>
421
  <div class="cta-row">
422
- <a class="btn btn-primary" href="/console">Open the command center →</a>
423
  <a class="btn btn-lattice" href="/ecosystem">Explore the ecosystem</a>
424
  <a class="btn btn-ghost" href="/verify">Verify a receipt offline</a>
425
  </div>
426
  <div class="hero-stats">
427
  <div class="stat">
428
- <div class="k proof" id="hs-receipts">—</div>
429
- <div class="l">Receipts in the chain <span id="hs-receipts-chip"></span><br><span class="stat-note">ledger depth — a mechanism check, not customer traction</span></div>
430
  </div>
431
  <div class="stat">
432
  <div class="k gray" id="hs-lambda">Conjecture 1</div>
433
- <div class="l">Λ trust gate · advisory bound</div>
434
  </div>
435
  <div class="stat">
436
  <div class="k" id="hs-proven">8</div>
437
  <div class="l">Locked Lean-proven theorems<br><span class="stat-note">a proof of rigor, not a traction number</span></div>
438
  </div>
439
  <div class="stat" id="overclaim-counter">
440
- <div class="k gray" id="hs-overclaims">—</div>
441
- <div class="l">Overclaims caught by CI <span id="hs-overclaims-chip"><span class="chip gray" style="margin-left:6px"><span class="dot"></span>SAMPLE · SNAPSHOT 2026-07-25 · SOURCE UNAVAILABLE</span></span><br><span class="stat-note">Observed correction time (<span id="hs-overclaim-sample">source unavailable</span>): <span id="hs-overclaim-time">—</span> · <a href="https://github.com/szl-holdings/platform/blob/main/docs/OVERCLAIM_LEDGER.md">open ledger</a></span></div>
442
  </div>
443
  </div>
444
  </div>
@@ -448,20 +448,20 @@
448
  <!-- ====================== (1b) HONESTY STRIP ====================== -->
449
  <section class="honesty" id="honesty">
450
  <div class="wrap">
451
- <p class="kick">The honesty doctrine · v11 LOCKED</p>
452
- <h2 style="font-size:clamp(1.5rem,3vw,2.1rem);margin:0 0 10px">Every figure on this page is labelled — or it isn't shown.</h2>
453
  <p class="intro" style="margin:0">We grade what we say. If a claim isn't MEASURED live this session, we tell you exactly what it is instead of dressing it up as proof.</p>
454
  <div class="legend">
455
  <div class="leg measured"><div class="lt">MEASURED</div><p>Read live from a running endpoint this session — receipt count, advisory Λ posture, and chain depth. Shown with a live chip; a dead probe degrades to an honest offline chip. Signer state is disclosed separately only where an actual signer-status read is present.</p></div>
456
- <div class="leg reported"><div class="lt">REPORTED</div><p>Stated by a source we name — the locked-8 Lean kernel, the 144-entry genome registry — cited here, not independently re-derived on this page.</p></div>
457
- <div class="leg unknown"><div class="lt">UNKNOWN</div><p>We don't have it right now. Rendered honestly as N/A · UNAVAILABLE · BLOCKED — never a confident guess and never a fabricated number.</p></div>
458
- <div class="leg conjecture"><div class="lt">CONJECTURE</div><p>Advisory and unproven. Rendered in gray, never green, never a theorem. Λ lives here.</p></div>
459
  </div>
460
  <div class="lambda-line">
461
- <span class="chip gray"><span class="dot"></span>Λ = Conjecture 1</span>
462
- <span class="muted">an advisory trust bound — never proven, never 1.0, and never rendered green. Theorem&nbsp;U is the proven <i>conditional</i> alternative; the unconditional claim is machine-checked false as stated.</span>
463
  </div>
464
- <p class="free-energy"><b style="color:var(--ink)">No free energy.</b> Joules are MEASURED only from a live exporter delta; with no live meter we label the reading SAMPLE or UNAVAILABLE and fabricate nothing. a11oy never claims over-unity, perpetual output, or free-energy efficiency — only what a real meter reports.</p>
465
  </div>
466
  </section>
467
 
@@ -471,10 +471,10 @@
471
  <h2 id="estate-pulse-title">What is actually reachable right now.</h2>
472
  <p class="intro">Four read-only checks connect the product story to the running system. REACHABLE means the source answered this browser session; evidence mode (LIVE, SNAPSHOT, MODELED, or UNAVAILABLE) remains separate and never certifies model truth.</p>
473
  <div class="pulse-grid" aria-live="polite">
474
- <article class="pulse-card"><div class="pulse-head"><h3>Platform health</h3><span class="data-state" id="pulse-health-state">CHECKING</span></div><p id="pulse-health-detail">Checking the deployed runtime.</p><a href="/healthz">Source /healthz →</a></article>
475
- <article class="pulse-card"><div class="pulse-head"><h3>Tab contract</h3><span class="data-state" id="pulse-contract-state">CHECKING</span></div><p id="pulse-contract-detail">Checking the published tab inventory.</p><a href="/api/a11oy/v1/readiness/tab-matrix">Source tab matrix →</a></article>
476
- <article class="pulse-card"><div class="pulse-head"><h3>Receipt ledger</h3><span class="data-state" id="pulse-ledger-state">CHECKING</span></div><p id="pulse-ledger-detail">Checking the append-only evidence read.</p><a href="/api/a11oy/v1/ledger">Source receipt ledger →</a></article>
477
- <article class="pulse-card"><div class="pulse-head"><h3>Sovereign mesh</h3><span class="data-state" id="pulse-mesh-state">CHECKING</span></div><p id="pulse-mesh-detail">Checking the current mesh posture.</p><a href="/api/a11oy/v1/mesh/state">Source mesh state →</a></article>
478
  </div>
479
  <p class="pulse-time" id="pulse-checked">Checks have not completed.</p>
480
  </section>
@@ -483,17 +483,17 @@
483
  <section class="band wrap" id="surfaces">
484
  <p class="kick">Explore the estate</p>
485
  <h2>Nine surfaces. One governed core.</h2>
486
- <p class="intro">Every surface reads the same live endpoints and the same honesty doctrine. Jump straight in — the full working console is one click away.</p>
487
  <div class="grid g3">
488
- <a class="card surface-card" href="/console"><div class="ic">⌘</div><h3>Command Center</h3><p>The working console — receipt integrity, separately disclosed signer state, the self-doubt gate, the genome registry, and live organ vitals.</p><div class="golinks"><span class="go">Open /console →</span></div></a>
489
- <a class="card surface-card" href="/superpowers"><div class="ic">✦</div><h3>Five Superpowers</h3><p>The five things governed inference does that ungoverned models can't — each linked to the live check that backs it.</p><div class="golinks"><span class="go">Open /superpowers →</span></div></a>
490
- <a class="card surface-card" href="/console#arena"><div class="ic">⚔</div><h3>Adversarial assurance</h3><p>Run governed evaluations, inspect refusals, and trace every verdict to its evidence. The archived Warhacker route now resolves here.</p><div class="golinks"><span class="go">Open the eval arena →</span></div></a>
491
- <a class="card surface-card" href="/observability"><div class="ic">◎</div><h3>Observability</h3><p>OpenTelemetry-style traces and health summaries across the organs — live, read-only, no sign-on-GET.</p><div class="golinks"><span class="go">Open /observability →</span></div></a>
492
- <a class="card surface-card" href="/wires"><div class="ic">〜</div><h3>Wires</h3><p>The live wiring between organs — which probe feeds which surface, and whether it is up right now.</p><div class="golinks"><span class="go">Open /wires →</span></div></a>
493
- <a class="card surface-card" href="/console#mesh"><div class="ic">◇</div><h3>Mesh</h3><p>The BFT-quorum mesh graph — 3-of-4 consensus, live state read from <span class="mono">/api/a11oy/v1/mesh/state</span>.</p><div class="golinks"><span class="go">Open the mesh →</span></div></a>
494
- <a class="card surface-card" href="/formulas"><div class="ic">Σ</div><h3>Formulas</h3><p>The PURIQ agentic formula genome — live-recomputed values, each carrying its own Khipu receipt.</p><div class="golinks"><span class="go">Open /formulas →</span></div></a>
495
- <a class="card surface-card" href="/trust"><div class="ic">✓</div><h3>Evidence</h3><p>The trust center: the locked-8 with truthful Lean refs, Theorem&nbsp;U vs Conjecture&nbsp;1, the receipt ledger, offline verify.</p><div class="golinks"><span class="go">Open the evidence →</span></div></a>
496
- <a class="card surface-card" href="/static/viz/router/"><div class="ic mono">⇄</div><h3>LLM Router</h3><p>The LLM-Router Live scene — per-tier routing stats polled every second, otherwise an honest DEMO MODE.</p><div class="golinks"><span class="go">Open the router →</span></div></a>
497
  </div>
498
  </section>
499
 
@@ -502,131 +502,131 @@
502
  <!-- ====================== (2) THE THESIS ====================== -->
503
  <section class="band wrap" id="thesis">
504
  <p class="kick">The thesis</p>
505
- <h2>Governed AI you can prove — not AI you're asked to trust.</h2>
506
  <p class="intro">Most AI asks for trust. a11oy earns it the way auditable systems do: every
507
  governed state change is recorded in a hash-chained receipt, while signer state and signature
508
  verification are disclosed separately and never inferred; a trust gate can only tighten an
509
  answer, never wave it through; and the kernel rests on machine-checked theorems you can read.
510
- The honest part is the product — when a claim isn't proven, we label it, and you can open the
511
  check yourself.</p>
512
  <div class="pillars">
513
  <div class="pillar">
514
- <div class="pk">01 · RECEIPTS</div>
515
  <h3>It proves receipt integrity and signer state</h3>
516
  <p>Every governed state change enters a SHA3-256 hash chain. DSSE / ECDSA-P256 is a separate
517
  cryptographic state and is labeled SIGNED only when persistent signer evidence is active
518
  and independent verification passes. Verify the disclosed state in your own browser.</p>
519
  </div>
520
  <div class="pillar">
521
- <div class="pk">02 · REFUSES</div>
522
  <h3>It refuses when unsure</h3>
523
  <p>A self-doubt gate measures uncertainty against a bound and returns a truthful
524
  <b>BLOCKED</b> rather than a confident wrong answer. A refusal beats a fabrication.</p>
525
  </div>
526
  <div class="pillar">
527
- <div class="pk">03 · PROVES</div>
528
  <h3>It is formally backed</h3>
529
- <p>8 locked, axiom-free Lean&nbsp;4 theorems back the kernel. The Λ trust gate is
530
- <b>Conjecture&nbsp;1</b> — an advisory bound, never dressed up as a theorem.</p>
531
  </div>
532
  </div>
533
  </section>
534
 
535
  <div class="wrap"><div class="divider"></div></div>
536
 
537
- <!-- ====================== (3) THE PROOF — 4 honest tiers (live) ====================== -->
538
  <section class="band wrap" id="proof">
539
- <p class="kick">The proof · four honest tiers <span id="proof-src"></span></p>
540
  <h2>Every claim carries exactly one honesty tier.</h2>
541
- <p class="intro">The 144-entry formula genome is graded across four tiers — and the rarest,
542
  strongest tiers are the smallest on purpose. Counts below are read live from the genome
543
  registry. A conjecture is shown in gray and is <b>never</b> rendered as proven.</p>
544
  <div class="grid g4">
545
  <div class="tier locked">
546
- <div class="tnum" id="pt-locked">—</div>
547
  <div class="tname">LOCKED-PROVEN</div>
548
- <p>Truthful labels for what each Lean obligation actually proves — e.g. F18 = Reed-Solomon
549
  parity (erasure tolerance), not "DSSE seal". Conservative and defensible.</p>
550
  </div>
551
  <div class="tier semantic">
552
- <div class="tnum" id="pt-semantic">—</div>
553
  <div class="tname">SEMANTIC-VERIFIED</div>
554
- <p>Sorry-free real theorems outside the frozen locked-8: the Λ min≤Λ≤max bounds, Theorem U
555
  (conditional uniqueness), DSSE verifiability. Where the real trust math lives.</p>
556
  </div>
557
  <div class="tier evidence">
558
- <div class="tnum" id="pt-evidence">—</div>
559
  <div class="tname">EVIDENCE-BACKED</div>
560
  <p>Runtime / algorithmic rules backed by real code and live endpoints, with no proof claim
561
- attached. Honest operational tier — not dressed up as proven.</p>
562
  </div>
563
  <div class="tier conjecture">
564
- <div class="tnum" id="pt-conjecture">—</div>
565
- <div class="tname">CONJECTURE · ADVISORY</div>
566
- <p>Λ unconditional uniqueness = Conjecture&nbsp;1 (machine-checked false as stated). Gray,
567
  advisory, <b>never green</b>. Theorem U is the proven conditional alternative.</p>
568
  </div>
569
  </div>
570
  <div class="cta-row" style="margin-top:34px">
571
- <a class="btn btn-primary" href="https://szlholdings-immune.hf.space" target="_blank" rel="noopener">See it run live · IMMUNE demo →</a>
572
- <a class="btn btn-ghost" href="/console#genome">Browse the genome →</a>
573
- <a class="btn btn-ghost" href="/trust">Read the trust center →</a>
574
  </div>
575
- <p class="intro" style="margin-top:16px;opacity:.85">IMMUNE is a live, interactive demo of the same thesis you can drive yourself — a
576
  real hash-chained receipt ledger, a live Sigstore&nbsp;Rekor transparency anchor, and honest
577
  <b>BLOCKED</b> / <b>UNAVAILABLE</b> states instead of confident guesses. Nothing on that page is fabricated.</p>
578
  </section>
579
 
580
- <!-- ====================== (4) THE VERTICALS — live /lambda/org ====================== -->
581
  <section class="band" id="verticals" style="background:linear-gradient(180deg,rgba(10,16,30,0),rgba(10,16,30,0.55))">
582
  <div class="wrap">
583
- <p class="kick">The verticals · live Λ posture <span id="verticals-src"></span></p>
584
  <h2>One governed core. Five places it earns its keep.</h2>
585
- <p class="intro">The same governed inference core runs across five verticals. Each card reads
586
- its live advisory Λ posture from the org-wide 13-axis gate (canonical floor 0.90). Λ is
587
- Conjecture&nbsp;1 — advisory, never a pass/fail oracle.</p>
588
  <div class="grid g3">
589
  <div class="vcard">
590
  <div class="pmark">a11</div>
591
  <h3>a11oy</h3>
592
- <div class="tag">Core · governed inference</div>
593
- <p>The platform itself — command center, receipt integrity, disclosed signer state, and the self-doubt gate.</p>
594
- <div class="lam"><span class="val" id="v-core">—</span><span class="cap">advisory Λ</span><span id="v-core-chip"></span></div>
595
  </div>
596
  <div class="vcard">
597
  <div class="pmark">kil</div>
598
  <h3>killinchu</h3>
599
- <div class="tag">Defense · counter-UAS</div>
600
  <p>Auditable interdiction: receipt per decision, separately disclosed signing state, and 3-of-4 BFT consensus.</p>
601
- <div class="lam"><span class="val" id="v-defense">—</span><span class="cap">advisory Λ</span><span id="v-defense-chip"></span></div>
602
  </div>
603
  <div class="vcard">
604
  <div class="pmark">ins</div>
605
  <h3>Insurance</h3>
606
- <div class="tag">David Leads · lead scoring</div>
607
  <p>Faithful David Leads scorer behind an F12 non-compensatory consent gate.</p>
608
- <div class="lam"><span class="val" id="v-insurance">—</span><span class="cap">advisory Λ</span><span id="v-insurance-chip"></span></div>
609
  </div>
610
  <div class="vcard">
611
  <div class="pmark">fin</div>
612
  <h3>Finance</h3>
613
  <div class="tag">Governed decisioning</div>
614
  <p>Decision paths that must be reconstructable, receipt-bound, and conditionally signed only when verified signer evidence is active.</p>
615
- <div class="lam"><span class="val" id="v-finance">—</span><span class="cap">advisory Λ</span><span id="v-finance-chip"></span></div>
616
  </div>
617
  <div class="vcard">
618
  <div class="pmark">re</div>
619
  <h3>Real estate</h3>
620
  <div class="tag">Governed workflows</div>
621
  <p>Workflow decisions captured into the same one-chain receipt ledger.</p>
622
- <div class="lam"><span class="val" id="v-realestate">—</span><span class="cap">advisory Λ</span><span id="v-realestate-chip"></span></div>
623
  </div>
624
  <div class="vcard" style="border-style:dashed;align-items:flex-start;justify-content:center">
625
- <div class="pmark" style="background:rgba(58,244,200,0.08);border-color:rgba(58,244,200,0.25);color:var(--proof)">Λ</div>
626
- <h3>Org-wide Λ</h3>
627
  <div class="tag">13-axis weighted geomean</div>
628
- <p>The composite advisory posture across all verticals, with min≤Λ≤max SEMANTIC-VERIFIED.</p>
629
- <div class="lam"><span class="val" id="v-org">—</span><span class="cap">floor 0.90</span><span id="v-org-chip"></span></div>
630
  </div>
631
  </div>
632
  </div>
@@ -636,23 +636,23 @@
636
  <section class="band wrap" id="body">
637
  <p class="kick">The living body</p>
638
  <h2>Watch the governed organism breathe.</h2>
639
- <p class="intro">The same live endpoints render as a 3D anatomical organism — organs glow when
640
  their probes are healthy and dim when they're not, and receipt events travel the vessels as
641
  pulses. It is an operational projection of the platform state. Every pulse links to a real
642
  receipt event; its signing state remains separately disclosed.</p>
643
  <div class="body-embed" id="body-embed">
644
  <div class="poster" id="body-poster">
645
  <div class="pulse-ring" aria-hidden="true"></div>
646
- <h3>The Living Brain &amp; Body · Anatomy v5</h3>
647
  <p>Two live 3D views of the same governed organism: a <b>moldable brain</b> whose eight lobes
648
  are wired to live public reads (Hub assets, GitHub repos, proved theorems, organ vitals,
649
  the harnessed open-weights frontier) &mdash; sculpt its cortex with your pointer &mdash;
650
  and the full <b>living body</b> wired to the same probes as the console.</p>
651
  <div class="cta-row" style="justify-content:center">
652
- <button class="btn btn-lattice" id="brain-load" type="button">🧠 Mold the brain in-frame</button>
653
  <button class="btn btn-ghost" id="body-load" type="button">Load the living body</button>
654
- <a class="btn btn-primary" href="/anatomy-v5">Open the live digital twin →</a>
655
- <a class="btn btn-ghost" href="/living-anatomy" target="_blank" rel="noopener">Open full-screen →</a>
656
  </div>
657
  </div>
658
  </div>
@@ -661,8 +661,8 @@
661
  <!-- ====================== PUBLIC ECOSYSTEM ATLAS ====================== -->
662
  <section class="band" id="ecosystem">
663
  <div class="wrap">
664
- <p class="kick">Public estate · canonical live sources</p>
665
- <h2>Models, kernels, data, and Spaces — one evidence-labelled map.</h2>
666
  <p class="sub" style="max-width:790px">The front door no longer hardcodes organization totals. Open each canonical source for its current inventory; a reachable URL establishes reachability only, not source/runtime alignment or model quality.</p>
667
  <div class="estate-grid" aria-label="Canonical public ecosystem sources">
668
  <a class="estate-cell" href="https://huggingface.co/SZLHOLDINGS/models" target="_blank" rel="noopener"><b>OPEN</b><span>Models</span></a>
@@ -673,7 +673,7 @@
673
  <a class="estate-cell" href="https://huggingface.co/SZLHOLDINGS" target="_blank" rel="noopener"><b>OPEN</b><span>Organization</span></a>
674
  </div>
675
  <div class="estate-links">
676
- <a class="btn btn-primary" href="/ecosystem">Open ecosystem atlas →</a>
677
  <a class="btn btn-lattice" href="/anatomy-v5">Open Anatomy v5</a>
678
  <a class="btn btn-ghost" href="/models">Models</a>
679
  <a class="btn btn-ghost" href="/kernels">Kernels</a>
@@ -684,21 +684,21 @@
684
  </div>
685
  </section>
686
 
687
- <!-- ====================== (6) ONE CHAIN — live receipts/ledger ====================== -->
688
  <section class="band" id="chain" style="background:linear-gradient(180deg,rgba(10,16,30,0),rgba(10,16,30,0.55))">
689
  <div class="wrap">
690
- <p class="kick">One chain · live ledger <span id="chain-src"></span></p>
691
  <h2>One ledger. Every decision. Replayable to the byte.</h2>
692
- <p class="intro">Every vertical emits into a single SHA3-256 hash-chain — append-only,
693
  fsync-durable, replayable to a byte-identical root instead of trusting a dashboard.</p>
694
  <div class="chainrow">
695
- <div class="cstat"><div class="ck" id="chain-receipts">—</div><div class="cl">Receipt records · signer state separate</div></div>
696
  <div class="cstat"><div class="ck ink mono" id="chain-alg">sha3_256</div><div class="cl">Chain algorithm</div></div>
697
- <div class="cstat"><div class="ck" id="chain-depth">—</div><div class="cl">Chain depth (a11oy)</div></div>
698
- <div class="cstat"><div class="ck ink mono" id="chain-head" style="font-size:.86rem">—</div><div class="cl">Last receipt id</div></div>
699
  </div>
700
  <div class="cta-row" style="margin-top:32px">
701
- <a class="btn btn-primary" href="/api/a11oy/v1/ledger">Open the receipt ledger →</a>
702
  <a class="btn btn-ghost" href="/verify">Verify a receipt offline</a>
703
  </div>
704
  </div>
@@ -715,7 +715,7 @@
715
  Every claim links to its check.</p>
716
  </div>
717
  <div class="tcbtns">
718
- <a class="btn btn-primary" href="/trust">Open the trust center →</a>
719
  <a class="btn btn-ghost" href="/api/a11oy/v1/honest">Honest status (JSON)</a>
720
  </div>
721
  </div>
@@ -732,52 +732,52 @@
732
  <circle cx="16" cy="16" r="13" stroke="url(#lg)" stroke-width="2"/>
733
  <circle cx="16" cy="16" r="5" fill="url(#lg)"/></svg>
734
  <span>a11oy<span class="sub" style="margin-left:9px">Alloy by SZL Holdings</span></span></a>
735
- <p class="muted" style="margin:6px 0 0">Governed Inference — AI that exposes receipt
736
  integrity, signer state, evidence, and refusal behavior. The sha3_256 receipt ledger is
737
  independently inspectable; DSSE signing is claimed only when verification proves it.</p>
738
- <p class="muted" style="margin:12px 0 0">Part of the SZL Holdings estate ·
739
  <a href="https://github.com/szl-holdings" target="_blank" rel="noopener">github.com/szl-holdings</a></p>
740
  </div>
741
  <div class="lk"><strong style="color:var(--ink)">Product</strong>
742
  <a href="/console">Command center</a>
743
  <a href="/ecosystem">Ecosystem atlas</a>
744
- <a href="/anatomy-v5">Anatomy v5 · digital twin</a>
745
  <a href="/console#genome">Genome registry</a>
746
  <a href="/verify">Verify a receipt</a>
747
- <a href="/living-anatomy">Living anatomy · 3D</a>
748
- <a href="/elite">killinchu · counter-UAS</a>
749
- <a href="https://szlholdings-immune.hf.space" target="_blank" rel="noopener">IMMUNE · live investor demo</a></div>
750
  <div class="lk"><strong style="color:var(--ink)">Evidence</strong>
751
  <a href="/trust">Trust center</a>
752
  <a href="/api/a11oy/v1/ledger">Receipt ledger</a>
753
  <a href="/api/a11oy/v1/honest">Honest status (JSON)</a>
754
  <a href="https://github.com/szl-holdings/lutar-lean">lutar-lean proofs</a></div>
755
  <div class="lk"><strong style="color:var(--ink)">Router &amp; org</strong>
756
- <a href="/static/viz/router/">LLM-Router Live · 3D</a>
757
  <a href="https://huggingface.co/spaces/SZLHOLDINGS/llm-router-live" target="_blank" rel="noopener">Status Space (live, drift-checked)</a>
758
- <a href="https://github.com/szl-holdings/szl-router" target="_blank" rel="noopener">SZL Router · OpenAI-compatible</a>
759
- <a href="https://github.com/szl-holdings" target="_blank" rel="noopener">SZL Holdings · GitHub org</a>
760
  <a href="#surfaces">All nine surfaces</a></div>
761
- <div class="lk"><strong style="color:var(--ink)">Estate · open source</strong>
762
- <a href="https://github.com/szl-holdings/ouroboros" target="_blank" rel="noopener">ouroboros · self-referential loop</a>
763
- <a href="https://github.com/szl-holdings/szl-formula-ledger" target="_blank" rel="noopener">szl-formula-ledger · formula genome</a>
764
- <a href="https://github.com/szl-holdings/szl-energy-attest" target="_blank" rel="noopener">szl-energy-attest · grid_context (REPORTED)</a>
765
- <a href="https://huggingface.co/SZLHOLDINGS" target="_blank" rel="noopener">Hugging Face org · SZLHOLDINGS</a></div>
766
  </div>
767
  <p class="disc">Honesty doctrine v11 LOCKED. The locked-proven Lean kernel is exactly <b>8</b>
768
  theorems {F1,F4,F7,F11,F12,F18,F19,F22}; the 144-entry genome registry is a separate, larger
769
- set graded across four honesty tiers. The Λ trust gate is <b>Conjecture&nbsp;1</b> — an
770
  advisory bound, never a theorem and never 1.0. Receipt-chain integrity and DSSE signing are
771
  distinct states; signing is claimed only when persistent signer evidence is active and verification
772
  passes. Read-only routes never mint receipts. Energy is MEASURED only with a live exporter delta,
773
  otherwise honest SAMPLE. Supply
774
  chain is SLSA L1 honest (L2 build-attested); FedRAMP / IL5 / ATO accreditation is ROADMAP.
775
  <b style="color:var(--sub)">Alloy by SZL Holdings.</b>
776
- © Stephen P. Lutar Jr. (ORCID 0009-0001-0110-4173) · Apache-2.0.</p>
777
  </div>
778
  </footer>
779
 
780
- <!-- ===================== SOVEREIGN IMPORTMAP (vendored, NO CDN) — Dev 2 ===================== -->
781
  <script type="importmap">
782
  { "imports": {
783
  "three": "/hero/vendor3d/three.module.min.js",
@@ -785,7 +785,7 @@
785
  } }
786
  </script>
787
 
788
- <!-- ===================== HERO BOOT (Three.js holographic field) — Dev 2 ===================== -->
789
  <script type="module">
790
  import { mountHero } from "/landing/app.js";
791
  const canvas = document.getElementById("hero-canvas");
@@ -833,12 +833,12 @@
833
 
834
  function showUnavailableOverclaimMetrics(){
835
  const count = $("hs-overclaims");
836
- count.textContent = "—";
837
  count.classList.remove("proof");
838
  count.classList.add("gray");
839
- $("hs-overclaim-time").textContent = "—";
840
  $("hs-overclaim-sample").textContent = "source unavailable";
841
- $("hs-overclaims-chip").innerHTML = grayChip("SAMPLE · SNAPSHOT 2026-07-25 · SOURCE UNAVAILABLE");
842
  }
843
 
844
  async function loadOverclaimMetrics(){
@@ -874,13 +874,13 @@
874
  countElement.classList.add("proof");
875
  $("hs-overclaim-time").textContent = correctionTime;
876
  $("hs-overclaim-sample").textContent = "n="+sampleSize;
877
- $("hs-overclaims-chip").innerHTML = grayChip("MEASURED · SNAPSHOT "+observed+" · DIGEST OK");
878
  } catch (_) {
879
  showUnavailableOverclaimMetrics();
880
  }
881
  }
882
 
883
- // Advisory Λ is Conjecture 1: report its relation to the floor, never render pass/fail or green.
884
  function lamChip(elId, v){
885
  const el = $(elId); if(!el) return;
886
  if(num(v) === null){ el.innerHTML = downChip("N/A"); return; }
@@ -897,7 +897,7 @@
897
  }
898
 
899
  function setVerticals(v){
900
- // v: {core,defense,insurance,finance,realestate} advisory Λ (numbers or null)
901
  [["core","v-core"],["defense","v-defense"],["insurance","v-insurance"],
902
  ["finance","v-finance"],["realestate","v-realestate"]].forEach(([k,id])=>{
903
  const val = fmtLam(v[k]);
@@ -908,8 +908,8 @@
908
 
909
  function setChain(receipts, alg, depth, head){
910
  $("chain-receipts").textContent = (num(receipts)===null) ? "UNAVAILABLE" : receipts.toLocaleString();
911
- $("hs-receipts").textContent = (num(receipts)===null) ? "—" : receipts.toLocaleString();
912
- $("hs-receipts-chip").innerHTML = (num(receipts)===null) ? downChip("offline") : grayChip((alg || "sha3_256") + " · CHAIN");
913
  if(alg) $("chain-alg").textContent = alg;
914
  $("chain-depth").textContent = (num(depth)===null) ? "N/A" : depth.toLocaleString();
915
  // Normalize head to the receipt id STRING. Some feeds (e.g. org/overview)
@@ -918,7 +918,7 @@
918
  const headId = (head && typeof head === "object")
919
  ? (head.receipt_id || head.id || head.digest || "")
920
  : head;
921
- if(headId){ const h = String(headId); $("chain-head").textContent = h.length>14 ? (h.slice(0,10)+"…"+h.slice(-4)) : h; }
922
  else { $("chain-head").textContent = "N/A"; }
923
  }
924
 
@@ -945,7 +945,7 @@
945
  }catch(e){ return false; }
946
  }
947
 
948
- // ---- (B) fallbacks — each source degrades to honest N/A independently ----
949
  async function loadGenomeTiers(){
950
  try{
951
  const g = await getJSON("/api/a11oy/v1/genome");
@@ -978,7 +978,7 @@
978
  if(Array.isArray(l.receipts) && l.receipts.length){ head = l.receipts[l.receipts.length-1].receipt_id; }
979
  if(receipts === null) receipts = depth; ok = true; }catch(e){}
980
  setChain(receipts, alg, depth, head);
981
- $("chain-src").innerHTML = ok ? grayChip((alg || "sha3_256") + " · CHAIN") : downChip("UNAVAILABLE");
982
  }
983
 
984
  // ---- live estate pulse: reachability is reported separately from correctness ----
@@ -1006,7 +1006,7 @@
1006
  const s = d.summary && d.summary.summary || {};
1007
  if(!d.matrix_available) throw new Error("matrix unavailable");
1008
  const checked = Boolean(d.probe_verdict_available);
1009
- pulseState("contract", checked ? "REACHABLE" : "SNAPSHOT", (s.tabs || "Published")+" tabs · "+(s.endpoints || "declared")+" endpoint contracts · "+(checked ? "deployment probe attached." : "static contract; deployment probe pending."));
1010
  }).catch(() => pulseState("contract", "UNAVAILABLE", "Tab contract is not bundled with this deployment.")),
1011
  pulseJSON("/api/a11oy/v1/ledger").then(d => pulseState("ledger", "REACHABLE", (typeof d.count === "number" ? d.count : "Current")+" receipts returned by the read; verify timestamp and chain state in the source."))
1012
  .catch(() => pulseState("ledger", "UNAVAILABLE", "Receipt ledger did not answer this session.")),
@@ -1016,7 +1016,7 @@
1016
  }).catch(() => pulseState("mesh", "UNAVAILABLE", "Mesh state did not answer this session."))
1017
  ];
1018
  await Promise.allSettled(checks);
1019
- if($("pulse-checked")) $("pulse-checked").textContent = "Checked "+new Date().toLocaleString()+" · read-only · cache disabled";
1020
  }
1021
 
1022
  // ---- (C) living body: load the anatomy Space in-frame only on click (perf + reduced-motion) ----
@@ -1025,7 +1025,7 @@
1025
  const wrap = $("body-embed");
1026
  const f = document.createElement("iframe");
1027
  f.src = "https://szlholdings-anatomy.hf.space#estate";
1028
- f.title = "a11oy living body — 3D governed organism (V10 · Estate + Ayllu wirings)";
1029
  f.loading = "lazy"; f.referrerPolicy = "no-referrer";
1030
  f.allow = "fullscreen"; f.setAttribute("allowfullscreen", "");
1031
  wrap.innerHTML = ""; wrap.appendChild(f);
@@ -1037,7 +1037,7 @@
1037
  const wrap = $("body-embed");
1038
  const f = document.createElement("iframe");
1039
  f.src = "/static/3d/brain.html";
1040
- f.title = "The a11oy Brain — moldable 3D cortex, eight lobes wired to live public reads";
1041
  f.loading = "lazy"; f.referrerPolicy = "no-referrer";
1042
  f.allow = "fullscreen"; f.setAttribute("allowfullscreen", "");
1043
  wrap.innerHTML = ""; wrap.appendChild(f);
@@ -1062,17 +1062,17 @@
1062
  })();
1063
  </script>
1064
 
1065
- <!-- SZL-FOURTH-WALL:v1:START — the page proves itself to the visitor. Claims-free: integrity & origin only. -->
1066
  <section id="fourth-wall" style="background:#060D1F;border-top:1px solid #C9B787;padding:18px 24px;font-family:ui-monospace,SFMono-Regular,Menlo,monospace;font-size:12.5px;color:#8FA3BF;line-height:1.7">
1067
  <div style="max-width:980px;margin:0 auto">
1068
- <span style="color:#C9B787;letter-spacing:2px">⟨ 4TH WALL ⟩</span>
1069
- <span> You are reading rendered bytes. Don&rsquo;t trust them — hash them:</span>
1070
  <button id="fw-hash-btn" style="margin-left:8px;background:transparent;border:1px solid #3AF4C8;color:#3AF4C8;padding:2px 10px;border-radius:3px;font:inherit;cursor:pointer">hash this page in your browser</button>
1071
  <span id="fw-hash-out" style="color:#3AF4C8;word-break:break-all"></span>
1072
- <div style="margin-top:6px">canonical source: <a href="https://github.com/szl-holdings/a11oy/blob/main/a11oy_landing.html" style="color:#C9B787">szl-holdings/a11oy@main</a><span id="fw-main-sha"></span> · verify from outside:
1073
  <code style="color:#E8D9AE;background:#0B1F3A;padding:1px 6px;border-radius:3px">curl -s https://raw.githubusercontent.com/szl-holdings/a11oy/main/a11oy_landing.html | sha256sum</code>
1074
  </div>
1075
- <div style="margin-top:4px;color:#5c6f8a">This proves integrity &amp; origin of this page only — never the accuracy of anything written on it. Doctrine v11. Expect the two hashes to differ by exactly the declared deltas: the server injects the operator-widget <code>&lt;script&gt;</code> tag in-memory, and the deployer may rewrite asset paths. In-browser hash = bytes as served; curl hash = canonical source; the attested sync + drift guards bind the two.</div>
1076
  </div>
1077
  </section>
1078
  <script>
 
1
+ <!doctype html>
2
  <!-- SPDX-License-Identifier: Apache-2.0
3
  (c) 2026 Lutar, Stephen P. - SZL Holdings - ORCID 0009-0001-0110-4173 -->
4
  <!--
5
+ a11oy — front door (scroll narrative). Served at the Space root "/" by serve.py.
6
  SOVEREIGN: Three.js r160 (MIT) vendored in-image at /hero/vendor3d. 0 runtime CDN.
7
  Fonts (Space Grotesk / JetBrains Mono) vendored at /vendor/fonts/*.woff2.
8
+ HONESTY DOCTRINE v11 LOCKED — every figure is fetched live and labelled honestly
9
+ (REACHABLE / MEASURED / MODELED / SNAPSHOT / UNAVAILABLE). Nothing is fabricated. Λ = Conjecture 1 (advisory, NOT a theorem,
10
  never 1.0, NEVER green). Locked-proven Lean kernel = EXACTLY 8 {F1,F4,F7,F11,F12,F18,F19,F22}.
11
+ The genome registry (144 entries) is grouped into 4 honesty tiers — a different, larger set.
12
  Receipt chain integrity and DSSE signing are separate. Signing is claimed only when persistent signer evidence is ACTIVE and verification passes. Read-only routes never mint receipts.
13
+ DOM/sections owned by Dev 1; the #hero-canvas + /landing/app.js boot is owned by Dev 2 —
14
  preserved verbatim below. KANCHAY palette. No purple. a-11-oy.com remains the
15
  canonical governed-inference product; a11oy.net is a separately attested estate cockpit.
16
+ © Stephen P. Lutar Jr. (ORCID 0009-0001-0110-4173) · Apache-2.0
17
  -->
18
  <html lang="en">
19
  <head>
20
  <meta charset="utf-8" />
21
  <meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover" />
22
+ <title>a11oy — AI that can demonstrate its work · AI that proves its receipt state and refuses to lie</title>
23
+ <meta name="description" content="AI that can demonstrate its work: AI that exposes receipt integrity, signer state, evidence, and refusal behavior. State-changing actions produce hash-chained receipts; DSSE signing is claimed only when persistent signer evidence is active and independently verified." />
24
  <link rel="canonical" href="https://a-11-oy.com/" />
25
  <meta property="og:type" content="website" />
26
  <meta property="og:url" content="https://a-11-oy.com/" />
27
+ <meta property="og:title" content="a11oy — AI that can demonstrate its work" />
28
  <meta property="og:description" content="AI that exposes receipt integrity and signer state, shows its evidence, and refuses when it cannot support an answer." />
29
  <meta property="og:image" content="https://a-11-oy.com/social-preview-v5.png" />
30
  <meta property="og:image:type" content="image/png" />
31
  <meta property="og:image:width" content="1280" />
32
  <meta property="og:image:height" content="640" />
33
+ <meta property="og:image:alt" content="a11oy AI that can demonstrate its work — evidence-labelled ecosystem and Anatomy v5" />
34
  <meta name="twitter:card" content="summary_large_image" />
35
  <meta name="twitter:image" content="https://a-11-oy.com/social-preview-v5.png" />
36
+ <meta name="twitter:image:alt" content="a11oy AI that can demonstrate its work — evidence-labelled ecosystem and Anatomy v5" />
37
  <link rel="icon" type="image/svg+xml" href="/social-preview-v5.svg" />
38
  <script type="application/ld+json">
39
  {
40
  "@context": "https://schema.org",
41
  "@type": "SoftwareApplication",
42
+ "name": "a11oy AI that can demonstrate its work",
43
  "url": "https://a-11-oy.com/",
44
  "applicationCategory": "DeveloperApplication",
45
  "operatingSystem": "Web",
 
61
  font-display:swap;src:url('/vendor/fonts/JetBrainsMono.woff2') format('woff2')}
62
 
63
  :root{
64
+ /* KANCHAY palette (canonical, org-wide — RECONCILE.md). Purple is BANNED. */
65
  --void:#080c14; /* deep near-black ground */
66
  --deep:#0a1019; /* raised ground */
67
  --surface:#0e1626; /* card surface */
68
  --border:#1c2942; /* hairline */
69
+ --proof:#3af4c8; /* proof teal — the one bright accent */
70
  --proof-soft:rgba(58,244,200,0.12);
71
  --proof-dim:rgba(58,244,200,0.06);
72
+ --lattice:#5b8dee; /* lattice blue — secondary (NOT purple) */
73
  --lattice-soft:rgba(91,141,238,0.12);
74
  --gold:#d7b96b; /* warm accent / conjecture-adjacent */
75
  --ink:#eef4fb; /* near-white heading */
76
+ --sub:#aebccf; /* body copy — WCAG AA on --void */
77
  --ghost:#65788f; /* muted labels */
78
+ --gray:#7d8aa0; /* CONJECTURE / advisory — never green */
79
  --ok:#3af4c8; --warn:#d7b96b; --down:#e8746e;
80
  --r:16px; --maxw:1180px;
81
  --head:'Space Grotesk',-apple-system,BlinkMacSystemFont,"Segoe UI",sans-serif;
 
137
  .btn{display:inline-flex;align-items:center;justify-content:center;gap:8px;padding:11px 21px;border-radius:9px;
138
  min-height:44px;max-width:100%;font-weight:600;font-size:14px;border:1px solid transparent;cursor:pointer;
139
  transition:all .18s cubic-bezier(0.16,1,0.3,1);white-space:nowrap;letter-spacing:.01em}
140
+ /* restrained "holographic glass" buttons — luminous hairline + soft fill, never a neon block */
141
  .btn-primary{background:linear-gradient(180deg,rgba(58,244,200,0.13),rgba(58,244,200,0.04));
142
  color:var(--proof);border-color:rgba(58,244,200,0.42);
143
  box-shadow:inset 0 1px 0 rgba(58,244,200,0.10),0 1px 14px -8px rgba(58,244,200,0.45)}
 
153
  border-color:rgba(91,141,238,0.6);color:#c5d8ff;
154
  box-shadow:0 6px 24px -12px rgba(91,141,238,0.32);transform:translateY(-1px)}
155
 
156
+ /* ---- hero (canvas owned by Dev 2 — markup preserved) ---- */
157
  .hero{position:relative;min-height:92vh;display:flex;align-items:center;overflow:hidden}
158
  #hero-canvas{position:absolute;inset:0;width:100%;height:100%;z-index:0;display:block}
159
  .hero-scrim{position:absolute;inset:0;z-index:1;pointer-events:none;
 
313
  .muted{color:var(--ghost)}
314
  .skel{color:var(--ghost);font-family:var(--mono)}
315
 
316
+ /* ecosystem atlas — public estate snapshot, never implied live until API reads */
317
  .estate-grid{display:grid;grid-template-columns:repeat(6,1fr);gap:10px;margin:24px 0}
318
  .estate-cell{border:1px solid var(--border);border-radius:13px;padding:15px;
319
  background:linear-gradient(155deg,rgba(17,30,50,.72),rgba(8,16,29,.88))}
 
387
  <circle cx="16" cy="16" r="5" fill="url(#lg)"/>
388
  <path d="M16 3v8M16 21v8M3 16h8M21 16h8" stroke="url(#lg)" stroke-width="1.6" opacity=".7"/>
389
  </svg>
390
+ <span>a11oy<span class="sub" style="margin-left:9px">AI that can demonstrate its work</span></span>
391
  </a>
392
  <nav>
393
  <a class="hide-sm" href="#surfaces">Surfaces</a>
 
398
  <a class="hide-sm" href="/console#arena">Eval arena</a>
399
  <a class="hide-sm" href="/observability">Observability</a>
400
  <a href="/trust">Evidence</a>
401
+ <a class="btn btn-primary" href="/console" aria-label="Open the command center"><span class="nav-cta-full">Open the command center</span><span class="nav-cta-short" aria-hidden="true">Command center</span> →</a>
402
  </nav>
403
  </div>
404
  </header>
405
  <main id="main">
406
 
407
+ <!-- ====================== (1) HERO — canvas + boot owned by Dev 2 ====================== -->
408
  <section class="hero">
409
  <canvas id="hero-canvas"></canvas>
410
  <div class="hero-scrim" aria-hidden="true"></div>
411
  <div class="hero-fallback" id="hero-fallback"></div>
412
  <div class="wrap">
413
  <div class="hero-inner">
414
+ <span class="eyebrow"><span class="dot"></span> AI that can demonstrate its work · verifiable by anyone, offline</span>
415
  <h1 class="title">AI that <span class="grad">proves its receipt state</span><br>and refuses to lie.</h1>
416
  <p class="lede">Every governed state change produces a hash-chained receipt you can inspect
417
  <b>offline, in your own browser</b>. The interface says <b>SIGNED</b> only when persistent
 
419
  UNSIGNED, DISABLED, or UNAVAILABLE. When the model is not sure, it returns an honest
420
  <b>BLOCKED</b> instead of a confident guess.</p>
421
  <div class="cta-row">
422
+ <a class="btn btn-primary" href="/console">Open the command center →</a>
423
  <a class="btn btn-lattice" href="/ecosystem">Explore the ecosystem</a>
424
  <a class="btn btn-ghost" href="/verify">Verify a receipt offline</a>
425
  </div>
426
  <div class="hero-stats">
427
  <div class="stat">
428
+ <div class="k proof" id="hs-receipts">—</div>
429
+ <div class="l">Receipts in the chain <span id="hs-receipts-chip"></span><br><span class="stat-note">ledger depth — a mechanism check, not customer traction</span></div>
430
  </div>
431
  <div class="stat">
432
  <div class="k gray" id="hs-lambda">Conjecture 1</div>
433
+ <div class="l">Λ trust gate · advisory bound</div>
434
  </div>
435
  <div class="stat">
436
  <div class="k" id="hs-proven">8</div>
437
  <div class="l">Locked Lean-proven theorems<br><span class="stat-note">a proof of rigor, not a traction number</span></div>
438
  </div>
439
  <div class="stat" id="overclaim-counter">
440
+ <div class="k gray" id="hs-overclaims">—</div>
441
+ <div class="l">Overclaims caught by CI <span id="hs-overclaims-chip"><span class="chip gray" style="margin-left:6px"><span class="dot"></span>SAMPLE · SNAPSHOT 2026-07-25 · SOURCE UNAVAILABLE</span></span><br><span class="stat-note">Observed correction time (<span id="hs-overclaim-sample">source unavailable</span>): <span id="hs-overclaim-time">—</span> · <a href="https://github.com/szl-holdings/platform/blob/main/docs/OVERCLAIM_LEDGER.md">open ledger</a></span></div>
442
  </div>
443
  </div>
444
  </div>
 
448
  <!-- ====================== (1b) HONESTY STRIP ====================== -->
449
  <section class="honesty" id="honesty">
450
  <div class="wrap">
451
+ <p class="kick">The honesty doctrine · v11 LOCKED</p>
452
+ <h2 style="font-size:clamp(1.5rem,3vw,2.1rem);margin:0 0 10px">Every figure on this page is labelled — or it isn't shown.</h2>
453
  <p class="intro" style="margin:0">We grade what we say. If a claim isn't MEASURED live this session, we tell you exactly what it is instead of dressing it up as proof.</p>
454
  <div class="legend">
455
  <div class="leg measured"><div class="lt">MEASURED</div><p>Read live from a running endpoint this session — receipt count, advisory Λ posture, and chain depth. Shown with a live chip; a dead probe degrades to an honest offline chip. Signer state is disclosed separately only where an actual signer-status read is present.</p></div>
456
+ <div class="leg reported"><div class="lt">REPORTED</div><p>Stated by a source we name — the locked-8 Lean kernel, the 144-entry genome registry — cited here, not independently re-derived on this page.</p></div>
457
+ <div class="leg unknown"><div class="lt">UNKNOWN</div><p>We don't have it right now. Rendered honestly as N/A · UNAVAILABLE · BLOCKED — never a confident guess and never a fabricated number.</p></div>
458
+ <div class="leg conjecture"><div class="lt">CONJECTURE</div><p>Advisory and unproven. Rendered in gray, never green, never a theorem. Λ lives here.</p></div>
459
  </div>
460
  <div class="lambda-line">
461
+ <span class="chip gray"><span class="dot"></span>Λ = Conjecture 1</span>
462
+ <span class="muted">an advisory trust bound — never proven, never 1.0, and never rendered green. Theorem&nbsp;U is the proven <i>conditional</i> alternative; the unconditional claim is machine-checked false as stated.</span>
463
  </div>
464
+ <p class="free-energy"><b style="color:var(--ink)">No free energy.</b> Joules are MEASURED only from a live exporter delta; with no live meter we label the reading SAMPLE or UNAVAILABLE and fabricate nothing. a11oy never claims over-unity, perpetual output, or free-energy efficiency — only what a real meter reports.</p>
465
  </div>
466
  </section>
467
 
 
471
  <h2 id="estate-pulse-title">What is actually reachable right now.</h2>
472
  <p class="intro">Four read-only checks connect the product story to the running system. REACHABLE means the source answered this browser session; evidence mode (LIVE, SNAPSHOT, MODELED, or UNAVAILABLE) remains separate and never certifies model truth.</p>
473
  <div class="pulse-grid" aria-live="polite">
474
+ <article class="pulse-card"><div class="pulse-head"><h3>Platform health</h3><span class="data-state" id="pulse-health-state">CHECKING</span></div><p id="pulse-health-detail">Checking the deployed runtime.</p><a href="/healthz">Source /healthz →</a></article>
475
+ <article class="pulse-card"><div class="pulse-head"><h3>Tab contract</h3><span class="data-state" id="pulse-contract-state">CHECKING</span></div><p id="pulse-contract-detail">Checking the published tab inventory.</p><a href="/api/a11oy/v1/readiness/tab-matrix">Source tab matrix →</a></article>
476
+ <article class="pulse-card"><div class="pulse-head"><h3>Receipt ledger</h3><span class="data-state" id="pulse-ledger-state">CHECKING</span></div><p id="pulse-ledger-detail">Checking the append-only evidence read.</p><a href="/api/a11oy/v1/ledger">Source receipt ledger →</a></article>
477
+ <article class="pulse-card"><div class="pulse-head"><h3>Sovereign mesh</h3><span class="data-state" id="pulse-mesh-state">CHECKING</span></div><p id="pulse-mesh-detail">Checking the current mesh posture.</p><a href="/api/a11oy/v1/mesh/state">Source mesh state →</a></article>
478
  </div>
479
  <p class="pulse-time" id="pulse-checked">Checks have not completed.</p>
480
  </section>
 
483
  <section class="band wrap" id="surfaces">
484
  <p class="kick">Explore the estate</p>
485
  <h2>Nine surfaces. One governed core.</h2>
486
+ <p class="intro">Every surface reads the same live endpoints and the same honesty doctrine. Jump straight in — the full working console is one click away.</p>
487
  <div class="grid g3">
488
+ <a class="card surface-card" href="/console"><div class="ic">⌘</div><h3>Command Center</h3><p>The working console — receipt integrity, separately disclosed signer state, the self-doubt gate, the genome registry, and live organ vitals.</p><div class="golinks"><span class="go">Open /console →</span></div></a>
489
+ <a class="card surface-card" href="/superpowers"><div class="ic">✦</div><h3>Five Superpowers</h3><p>The five things governed execution does that ungoverned models can't — each linked to the live check that backs it.</p><div class="golinks"><span class="go">Open /superpowers →</span></div></a>
490
+ <a class="card surface-card" href="/console#arena"><div class="ic">⚔</div><h3>Adversarial assurance</h3><p>Run governed evaluations, inspect refusals, and trace every verdict to its evidence. The archived Warhacker route now resolves here.</p><div class="golinks"><span class="go">Open the eval arena →</span></div></a>
491
+ <a class="card surface-card" href="/observability"><div class="ic">◎</div><h3>Observability</h3><p>OpenTelemetry-style traces and health summaries across the organs — live, read-only, no sign-on-GET.</p><div class="golinks"><span class="go">Open /observability →</span></div></a>
492
+ <a class="card surface-card" href="/wires"><div class="ic">〜</div><h3>Wires</h3><p>The live wiring between organs — which probe feeds which surface, and whether it is up right now.</p><div class="golinks"><span class="go">Open /wires →</span></div></a>
493
+ <a class="card surface-card" href="/console#mesh"><div class="ic">◇</div><h3>Mesh</h3><p>The BFT-quorum mesh graph — 3-of-4 consensus, live state read from <span class="mono">/api/a11oy/v1/mesh/state</span>.</p><div class="golinks"><span class="go">Open the mesh →</span></div></a>
494
+ <a class="card surface-card" href="/formulas"><div class="ic">Σ</div><h3>Formulas</h3><p>The PURIQ agentic formula genome — live-recomputed values, each carrying its own Khipu receipt.</p><div class="golinks"><span class="go">Open /formulas →</span></div></a>
495
+ <a class="card surface-card" href="/trust"><div class="ic">✓</div><h3>Evidence</h3><p>The trust center: the locked-8 with truthful Lean refs, Theorem&nbsp;U vs Conjecture&nbsp;1, the receipt ledger, offline verify.</p><div class="golinks"><span class="go">Open the evidence →</span></div></a>
496
+ <a class="card surface-card" href="/static/viz/router/"><div class="ic mono">⇄</div><h3>LLM Router</h3><p>The LLM-Router Live scene — per-tier routing stats polled every second, otherwise an honest DEMO MODE.</p><div class="golinks"><span class="go">Open the router →</span></div></a>
497
  </div>
498
  </section>
499
 
 
502
  <!-- ====================== (2) THE THESIS ====================== -->
503
  <section class="band wrap" id="thesis">
504
  <p class="kick">The thesis</p>
505
+ <h2>Governed AI you can prove — not AI you're asked to trust.</h2>
506
  <p class="intro">Most AI asks for trust. a11oy earns it the way auditable systems do: every
507
  governed state change is recorded in a hash-chained receipt, while signer state and signature
508
  verification are disclosed separately and never inferred; a trust gate can only tighten an
509
  answer, never wave it through; and the kernel rests on machine-checked theorems you can read.
510
+ The honest part is the product — when a claim isn't proven, we label it, and you can open the
511
  check yourself.</p>
512
  <div class="pillars">
513
  <div class="pillar">
514
+ <div class="pk">01 · RECEIPTS</div>
515
  <h3>It proves receipt integrity and signer state</h3>
516
  <p>Every governed state change enters a SHA3-256 hash chain. DSSE / ECDSA-P256 is a separate
517
  cryptographic state and is labeled SIGNED only when persistent signer evidence is active
518
  and independent verification passes. Verify the disclosed state in your own browser.</p>
519
  </div>
520
  <div class="pillar">
521
+ <div class="pk">02 · REFUSES</div>
522
  <h3>It refuses when unsure</h3>
523
  <p>A self-doubt gate measures uncertainty against a bound and returns a truthful
524
  <b>BLOCKED</b> rather than a confident wrong answer. A refusal beats a fabrication.</p>
525
  </div>
526
  <div class="pillar">
527
+ <div class="pk">03 · PROVES</div>
528
  <h3>It is formally backed</h3>
529
+ <p>8 locked, axiom-free Lean&nbsp;4 theorems back the kernel. The Λ trust gate is
530
+ <b>Conjecture&nbsp;1</b> — an advisory bound, never dressed up as a theorem.</p>
531
  </div>
532
  </div>
533
  </section>
534
 
535
  <div class="wrap"><div class="divider"></div></div>
536
 
537
+ <!-- ====================== (3) THE PROOF — 4 honest tiers (live) ====================== -->
538
  <section class="band wrap" id="proof">
539
+ <p class="kick">The proof · four honest tiers <span id="proof-src"></span></p>
540
  <h2>Every claim carries exactly one honesty tier.</h2>
541
+ <p class="intro">The 144-entry formula genome is graded across four tiers — and the rarest,
542
  strongest tiers are the smallest on purpose. Counts below are read live from the genome
543
  registry. A conjecture is shown in gray and is <b>never</b> rendered as proven.</p>
544
  <div class="grid g4">
545
  <div class="tier locked">
546
+ <div class="tnum" id="pt-locked">—</div>
547
  <div class="tname">LOCKED-PROVEN</div>
548
+ <p>Truthful labels for what each Lean obligation actually proves — e.g. F18 = Reed-Solomon
549
  parity (erasure tolerance), not "DSSE seal". Conservative and defensible.</p>
550
  </div>
551
  <div class="tier semantic">
552
+ <div class="tnum" id="pt-semantic">—</div>
553
  <div class="tname">SEMANTIC-VERIFIED</div>
554
+ <p>Sorry-free real theorems outside the frozen locked-8: the Λ min≤Λ≤max bounds, Theorem U
555
  (conditional uniqueness), DSSE verifiability. Where the real trust math lives.</p>
556
  </div>
557
  <div class="tier evidence">
558
+ <div class="tnum" id="pt-evidence">—</div>
559
  <div class="tname">EVIDENCE-BACKED</div>
560
  <p>Runtime / algorithmic rules backed by real code and live endpoints, with no proof claim
561
+ attached. Honest operational tier — not dressed up as proven.</p>
562
  </div>
563
  <div class="tier conjecture">
564
+ <div class="tnum" id="pt-conjecture">—</div>
565
+ <div class="tname">CONJECTURE · ADVISORY</div>
566
+ <p>Λ unconditional uniqueness = Conjecture&nbsp;1 (machine-checked false as stated). Gray,
567
  advisory, <b>never green</b>. Theorem U is the proven conditional alternative.</p>
568
  </div>
569
  </div>
570
  <div class="cta-row" style="margin-top:34px">
571
+ <a class="btn btn-primary" href="https://szlholdings-immune.hf.space" target="_blank" rel="noopener">See it run live · IMMUNE demo →</a>
572
+ <a class="btn btn-ghost" href="/console#genome">Browse the genome →</a>
573
+ <a class="btn btn-ghost" href="/trust">Read the trust center →</a>
574
  </div>
575
+ <p class="intro" style="margin-top:16px;opacity:.85">IMMUNE is a live, interactive demo of the same thesis you can drive yourself — a
576
  real hash-chained receipt ledger, a live Sigstore&nbsp;Rekor transparency anchor, and honest
577
  <b>BLOCKED</b> / <b>UNAVAILABLE</b> states instead of confident guesses. Nothing on that page is fabricated.</p>
578
  </section>
579
 
580
+ <!-- ====================== (4) THE VERTICALS — live /lambda/org ====================== -->
581
  <section class="band" id="verticals" style="background:linear-gradient(180deg,rgba(10,16,30,0),rgba(10,16,30,0.55))">
582
  <div class="wrap">
583
+ <p class="kick">The verticals · live Λ posture <span id="verticals-src"></span></p>
584
  <h2>One governed core. Five places it earns its keep.</h2>
585
+ <p class="intro">The same governed execution core runs across five verticals. Each card reads
586
+ its live advisory Λ posture from the org-wide 13-axis gate (canonical floor 0.90). Λ is
587
+ Conjecture&nbsp;1 — advisory, never a pass/fail oracle.</p>
588
  <div class="grid g3">
589
  <div class="vcard">
590
  <div class="pmark">a11</div>
591
  <h3>a11oy</h3>
592
+ <div class="tag">Core · governed execution</div>
593
+ <p>The platform itself — command center, receipt integrity, disclosed signer state, and the self-doubt gate.</p>
594
+ <div class="lam"><span class="val" id="v-core">—</span><span class="cap">advisory Λ</span><span id="v-core-chip"></span></div>
595
  </div>
596
  <div class="vcard">
597
  <div class="pmark">kil</div>
598
  <h3>killinchu</h3>
599
+ <div class="tag">Defense · counter-UAS</div>
600
  <p>Auditable interdiction: receipt per decision, separately disclosed signing state, and 3-of-4 BFT consensus.</p>
601
+ <div class="lam"><span class="val" id="v-defense">—</span><span class="cap">advisory Λ</span><span id="v-defense-chip"></span></div>
602
  </div>
603
  <div class="vcard">
604
  <div class="pmark">ins</div>
605
  <h3>Insurance</h3>
606
+ <div class="tag">David Leads · lead scoring</div>
607
  <p>Faithful David Leads scorer behind an F12 non-compensatory consent gate.</p>
608
+ <div class="lam"><span class="val" id="v-insurance">—</span><span class="cap">advisory Λ</span><span id="v-insurance-chip"></span></div>
609
  </div>
610
  <div class="vcard">
611
  <div class="pmark">fin</div>
612
  <h3>Finance</h3>
613
  <div class="tag">Governed decisioning</div>
614
  <p>Decision paths that must be reconstructable, receipt-bound, and conditionally signed only when verified signer evidence is active.</p>
615
+ <div class="lam"><span class="val" id="v-finance">—</span><span class="cap">advisory Λ</span><span id="v-finance-chip"></span></div>
616
  </div>
617
  <div class="vcard">
618
  <div class="pmark">re</div>
619
  <h3>Real estate</h3>
620
  <div class="tag">Governed workflows</div>
621
  <p>Workflow decisions captured into the same one-chain receipt ledger.</p>
622
+ <div class="lam"><span class="val" id="v-realestate">—</span><span class="cap">advisory Λ</span><span id="v-realestate-chip"></span></div>
623
  </div>
624
  <div class="vcard" style="border-style:dashed;align-items:flex-start;justify-content:center">
625
+ <div class="pmark" style="background:rgba(58,244,200,0.08);border-color:rgba(58,244,200,0.25);color:var(--proof)">Λ</div>
626
+ <h3>Org-wide Λ</h3>
627
  <div class="tag">13-axis weighted geomean</div>
628
+ <p>The composite advisory posture across all verticals, with min≤Λ≤max SEMANTIC-VERIFIED.</p>
629
+ <div class="lam"><span class="val" id="v-org">—</span><span class="cap">floor 0.90</span><span id="v-org-chip"></span></div>
630
  </div>
631
  </div>
632
  </div>
 
636
  <section class="band wrap" id="body">
637
  <p class="kick">The living body</p>
638
  <h2>Watch the governed organism breathe.</h2>
639
+ <p class="intro">The same live endpoints render as a 3D anatomical organism — organs glow when
640
  their probes are healthy and dim when they're not, and receipt events travel the vessels as
641
  pulses. It is an operational projection of the platform state. Every pulse links to a real
642
  receipt event; its signing state remains separately disclosed.</p>
643
  <div class="body-embed" id="body-embed">
644
  <div class="poster" id="body-poster">
645
  <div class="pulse-ring" aria-hidden="true"></div>
646
+ <h3>The Living Brain &amp; Body · Anatomy v5</h3>
647
  <p>Two live 3D views of the same governed organism: a <b>moldable brain</b> whose eight lobes
648
  are wired to live public reads (Hub assets, GitHub repos, proved theorems, organ vitals,
649
  the harnessed open-weights frontier) &mdash; sculpt its cortex with your pointer &mdash;
650
  and the full <b>living body</b> wired to the same probes as the console.</p>
651
  <div class="cta-row" style="justify-content:center">
652
+ <button class="btn btn-lattice" id="brain-load" type="button">🧠 Mold the brain in-frame</button>
653
  <button class="btn btn-ghost" id="body-load" type="button">Load the living body</button>
654
+ <a class="btn btn-primary" href="/anatomy-v5">Open the live digital twin →</a>
655
+ <a class="btn btn-ghost" href="/living-anatomy" target="_blank" rel="noopener">Open full-screen →</a>
656
  </div>
657
  </div>
658
  </div>
 
661
  <!-- ====================== PUBLIC ECOSYSTEM ATLAS ====================== -->
662
  <section class="band" id="ecosystem">
663
  <div class="wrap">
664
+ <p class="kick">Public estate · canonical live sources</p>
665
+ <h2>Models, kernels, data, and Spaces — one evidence-labelled map.</h2>
666
  <p class="sub" style="max-width:790px">The front door no longer hardcodes organization totals. Open each canonical source for its current inventory; a reachable URL establishes reachability only, not source/runtime alignment or model quality.</p>
667
  <div class="estate-grid" aria-label="Canonical public ecosystem sources">
668
  <a class="estate-cell" href="https://huggingface.co/SZLHOLDINGS/models" target="_blank" rel="noopener"><b>OPEN</b><span>Models</span></a>
 
673
  <a class="estate-cell" href="https://huggingface.co/SZLHOLDINGS" target="_blank" rel="noopener"><b>OPEN</b><span>Organization</span></a>
674
  </div>
675
  <div class="estate-links">
676
+ <a class="btn btn-primary" href="/ecosystem">Open ecosystem atlas →</a>
677
  <a class="btn btn-lattice" href="/anatomy-v5">Open Anatomy v5</a>
678
  <a class="btn btn-ghost" href="/models">Models</a>
679
  <a class="btn btn-ghost" href="/kernels">Kernels</a>
 
684
  </div>
685
  </section>
686
 
687
+ <!-- ====================== (6) ONE CHAIN — live receipts/ledger ====================== -->
688
  <section class="band" id="chain" style="background:linear-gradient(180deg,rgba(10,16,30,0),rgba(10,16,30,0.55))">
689
  <div class="wrap">
690
+ <p class="kick">One chain · live ledger <span id="chain-src"></span></p>
691
  <h2>One ledger. Every decision. Replayable to the byte.</h2>
692
+ <p class="intro">Every vertical emits into a single SHA3-256 hash-chain — append-only,
693
  fsync-durable, replayable to a byte-identical root instead of trusting a dashboard.</p>
694
  <div class="chainrow">
695
+ <div class="cstat"><div class="ck" id="chain-receipts">—</div><div class="cl">Receipt records · signer state separate</div></div>
696
  <div class="cstat"><div class="ck ink mono" id="chain-alg">sha3_256</div><div class="cl">Chain algorithm</div></div>
697
+ <div class="cstat"><div class="ck" id="chain-depth">—</div><div class="cl">Chain depth (a11oy)</div></div>
698
+ <div class="cstat"><div class="ck ink mono" id="chain-head" style="font-size:.86rem">—</div><div class="cl">Last receipt id</div></div>
699
  </div>
700
  <div class="cta-row" style="margin-top:32px">
701
+ <a class="btn btn-primary" href="/api/a11oy/v1/ledger">Open the receipt ledger →</a>
702
  <a class="btn btn-ghost" href="/verify">Verify a receipt offline</a>
703
  </div>
704
  </div>
 
715
  Every claim links to its check.</p>
716
  </div>
717
  <div class="tcbtns">
718
+ <a class="btn btn-primary" href="/trust">Open the trust center →</a>
719
  <a class="btn btn-ghost" href="/api/a11oy/v1/honest">Honest status (JSON)</a>
720
  </div>
721
  </div>
 
732
  <circle cx="16" cy="16" r="13" stroke="url(#lg)" stroke-width="2"/>
733
  <circle cx="16" cy="16" r="5" fill="url(#lg)"/></svg>
734
  <span>a11oy<span class="sub" style="margin-left:9px">Alloy by SZL Holdings</span></span></a>
735
+ <p class="muted" style="margin:6px 0 0">AI that can demonstrate its work — AI that exposes receipt
736
  integrity, signer state, evidence, and refusal behavior. The sha3_256 receipt ledger is
737
  independently inspectable; DSSE signing is claimed only when verification proves it.</p>
738
+ <p class="muted" style="margin:12px 0 0">Part of the SZL Holdings estate ·
739
  <a href="https://github.com/szl-holdings" target="_blank" rel="noopener">github.com/szl-holdings</a></p>
740
  </div>
741
  <div class="lk"><strong style="color:var(--ink)">Product</strong>
742
  <a href="/console">Command center</a>
743
  <a href="/ecosystem">Ecosystem atlas</a>
744
+ <a href="/anatomy-v5">Anatomy v5 · digital twin</a>
745
  <a href="/console#genome">Genome registry</a>
746
  <a href="/verify">Verify a receipt</a>
747
+ <a href="/living-anatomy">Living anatomy · 3D</a>
748
+ <a href="/elite">killinchu · counter-UAS</a>
749
+ <a href="https://szlholdings-immune.hf.space" target="_blank" rel="noopener">IMMUNE · live investor demo</a></div>
750
  <div class="lk"><strong style="color:var(--ink)">Evidence</strong>
751
  <a href="/trust">Trust center</a>
752
  <a href="/api/a11oy/v1/ledger">Receipt ledger</a>
753
  <a href="/api/a11oy/v1/honest">Honest status (JSON)</a>
754
  <a href="https://github.com/szl-holdings/lutar-lean">lutar-lean proofs</a></div>
755
  <div class="lk"><strong style="color:var(--ink)">Router &amp; org</strong>
756
+ <a href="/static/viz/router/">LLM-Router Live · 3D</a>
757
  <a href="https://huggingface.co/spaces/SZLHOLDINGS/llm-router-live" target="_blank" rel="noopener">Status Space (live, drift-checked)</a>
758
+ <a href="https://github.com/szl-holdings/szl-router" target="_blank" rel="noopener">SZL Router · OpenAI-compatible</a>
759
+ <a href="https://github.com/szl-holdings" target="_blank" rel="noopener">SZL Holdings · GitHub org</a>
760
  <a href="#surfaces">All nine surfaces</a></div>
761
+ <div class="lk"><strong style="color:var(--ink)">Estate · open source</strong>
762
+ <a href="https://github.com/szl-holdings/ouroboros" target="_blank" rel="noopener">ouroboros · self-referential loop</a>
763
+ <a href="https://github.com/szl-holdings/szl-formula-ledger" target="_blank" rel="noopener">szl-formula-ledger · formula genome</a>
764
+ <a href="https://github.com/szl-holdings/szl-energy-attest" target="_blank" rel="noopener">szl-energy-attest · grid_context (REPORTED)</a>
765
+ <a href="https://huggingface.co/SZLHOLDINGS" target="_blank" rel="noopener">Hugging Face org · SZLHOLDINGS</a></div>
766
  </div>
767
  <p class="disc">Honesty doctrine v11 LOCKED. The locked-proven Lean kernel is exactly <b>8</b>
768
  theorems {F1,F4,F7,F11,F12,F18,F19,F22}; the 144-entry genome registry is a separate, larger
769
+ set graded across four honesty tiers. The Λ trust gate is <b>Conjecture&nbsp;1</b> — an
770
  advisory bound, never a theorem and never 1.0. Receipt-chain integrity and DSSE signing are
771
  distinct states; signing is claimed only when persistent signer evidence is active and verification
772
  passes. Read-only routes never mint receipts. Energy is MEASURED only with a live exporter delta,
773
  otherwise honest SAMPLE. Supply
774
  chain is SLSA L1 honest (L2 build-attested); FedRAMP / IL5 / ATO accreditation is ROADMAP.
775
  <b style="color:var(--sub)">Alloy by SZL Holdings.</b>
776
+ © Stephen P. Lutar Jr. (ORCID 0009-0001-0110-4173) · Apache-2.0.</p>
777
  </div>
778
  </footer>
779
 
780
+ <!-- ===================== SOVEREIGN IMPORTMAP (vendored, NO CDN) — Dev 2 ===================== -->
781
  <script type="importmap">
782
  { "imports": {
783
  "three": "/hero/vendor3d/three.module.min.js",
 
785
  } }
786
  </script>
787
 
788
+ <!-- ===================== HERO BOOT (Three.js holographic field) — Dev 2 ===================== -->
789
  <script type="module">
790
  import { mountHero } from "/landing/app.js";
791
  const canvas = document.getElementById("hero-canvas");
 
833
 
834
  function showUnavailableOverclaimMetrics(){
835
  const count = $("hs-overclaims");
836
+ count.textContent = "—";
837
  count.classList.remove("proof");
838
  count.classList.add("gray");
839
+ $("hs-overclaim-time").textContent = "—";
840
  $("hs-overclaim-sample").textContent = "source unavailable";
841
+ $("hs-overclaims-chip").innerHTML = grayChip("SAMPLE · SNAPSHOT 2026-07-25 · SOURCE UNAVAILABLE");
842
  }
843
 
844
  async function loadOverclaimMetrics(){
 
874
  countElement.classList.add("proof");
875
  $("hs-overclaim-time").textContent = correctionTime;
876
  $("hs-overclaim-sample").textContent = "n="+sampleSize;
877
+ $("hs-overclaims-chip").innerHTML = grayChip("MEASURED · SNAPSHOT "+observed+" · DIGEST OK");
878
  } catch (_) {
879
  showUnavailableOverclaimMetrics();
880
  }
881
  }
882
 
883
+ // Advisory Λ is Conjecture 1: report its relation to the floor, never render pass/fail or green.
884
  function lamChip(elId, v){
885
  const el = $(elId); if(!el) return;
886
  if(num(v) === null){ el.innerHTML = downChip("N/A"); return; }
 
897
  }
898
 
899
  function setVerticals(v){
900
+ // v: {core,defense,insurance,finance,realestate} advisory Λ (numbers or null)
901
  [["core","v-core"],["defense","v-defense"],["insurance","v-insurance"],
902
  ["finance","v-finance"],["realestate","v-realestate"]].forEach(([k,id])=>{
903
  const val = fmtLam(v[k]);
 
908
 
909
  function setChain(receipts, alg, depth, head){
910
  $("chain-receipts").textContent = (num(receipts)===null) ? "UNAVAILABLE" : receipts.toLocaleString();
911
+ $("hs-receipts").textContent = (num(receipts)===null) ? "—" : receipts.toLocaleString();
912
+ $("hs-receipts-chip").innerHTML = (num(receipts)===null) ? downChip("offline") : grayChip((alg || "sha3_256") + " · CHAIN");
913
  if(alg) $("chain-alg").textContent = alg;
914
  $("chain-depth").textContent = (num(depth)===null) ? "N/A" : depth.toLocaleString();
915
  // Normalize head to the receipt id STRING. Some feeds (e.g. org/overview)
 
918
  const headId = (head && typeof head === "object")
919
  ? (head.receipt_id || head.id || head.digest || "")
920
  : head;
921
+ if(headId){ const h = String(headId); $("chain-head").textContent = h.length>14 ? (h.slice(0,10)+"…"+h.slice(-4)) : h; }
922
  else { $("chain-head").textContent = "N/A"; }
923
  }
924
 
 
945
  }catch(e){ return false; }
946
  }
947
 
948
+ // ---- (B) fallbacks — each source degrades to honest N/A independently ----
949
  async function loadGenomeTiers(){
950
  try{
951
  const g = await getJSON("/api/a11oy/v1/genome");
 
978
  if(Array.isArray(l.receipts) && l.receipts.length){ head = l.receipts[l.receipts.length-1].receipt_id; }
979
  if(receipts === null) receipts = depth; ok = true; }catch(e){}
980
  setChain(receipts, alg, depth, head);
981
+ $("chain-src").innerHTML = ok ? grayChip((alg || "sha3_256") + " · CHAIN") : downChip("UNAVAILABLE");
982
  }
983
 
984
  // ---- live estate pulse: reachability is reported separately from correctness ----
 
1006
  const s = d.summary && d.summary.summary || {};
1007
  if(!d.matrix_available) throw new Error("matrix unavailable");
1008
  const checked = Boolean(d.probe_verdict_available);
1009
+ pulseState("contract", checked ? "REACHABLE" : "SNAPSHOT", (s.tabs || "Published")+" tabs · "+(s.endpoints || "declared")+" endpoint contracts · "+(checked ? "deployment probe attached." : "static contract; deployment probe pending."));
1010
  }).catch(() => pulseState("contract", "UNAVAILABLE", "Tab contract is not bundled with this deployment.")),
1011
  pulseJSON("/api/a11oy/v1/ledger").then(d => pulseState("ledger", "REACHABLE", (typeof d.count === "number" ? d.count : "Current")+" receipts returned by the read; verify timestamp and chain state in the source."))
1012
  .catch(() => pulseState("ledger", "UNAVAILABLE", "Receipt ledger did not answer this session.")),
 
1016
  }).catch(() => pulseState("mesh", "UNAVAILABLE", "Mesh state did not answer this session."))
1017
  ];
1018
  await Promise.allSettled(checks);
1019
+ if($("pulse-checked")) $("pulse-checked").textContent = "Checked "+new Date().toLocaleString()+" · read-only · cache disabled";
1020
  }
1021
 
1022
  // ---- (C) living body: load the anatomy Space in-frame only on click (perf + reduced-motion) ----
 
1025
  const wrap = $("body-embed");
1026
  const f = document.createElement("iframe");
1027
  f.src = "https://szlholdings-anatomy.hf.space#estate";
1028
+ f.title = "a11oy living body — 3D governed organism (V10 · Estate + Ayllu wirings)";
1029
  f.loading = "lazy"; f.referrerPolicy = "no-referrer";
1030
  f.allow = "fullscreen"; f.setAttribute("allowfullscreen", "");
1031
  wrap.innerHTML = ""; wrap.appendChild(f);
 
1037
  const wrap = $("body-embed");
1038
  const f = document.createElement("iframe");
1039
  f.src = "/static/3d/brain.html";
1040
+ f.title = "The a11oy Brain — moldable 3D cortex, eight lobes wired to live public reads";
1041
  f.loading = "lazy"; f.referrerPolicy = "no-referrer";
1042
  f.allow = "fullscreen"; f.setAttribute("allowfullscreen", "");
1043
  wrap.innerHTML = ""; wrap.appendChild(f);
 
1062
  })();
1063
  </script>
1064
 
1065
+ <!-- SZL-FOURTH-WALL:v1:START — the page proves itself to the visitor. Claims-free: integrity & origin only. -->
1066
  <section id="fourth-wall" style="background:#060D1F;border-top:1px solid #C9B787;padding:18px 24px;font-family:ui-monospace,SFMono-Regular,Menlo,monospace;font-size:12.5px;color:#8FA3BF;line-height:1.7">
1067
  <div style="max-width:980px;margin:0 auto">
1068
+ <span style="color:#C9B787;letter-spacing:2px">⟨ 4TH WALL ⟩</span>
1069
+ <span> You are reading rendered bytes. Don&rsquo;t trust them — hash them:</span>
1070
  <button id="fw-hash-btn" style="margin-left:8px;background:transparent;border:1px solid #3AF4C8;color:#3AF4C8;padding:2px 10px;border-radius:3px;font:inherit;cursor:pointer">hash this page in your browser</button>
1071
  <span id="fw-hash-out" style="color:#3AF4C8;word-break:break-all"></span>
1072
+ <div style="margin-top:6px">canonical source: <a href="https://github.com/szl-holdings/a11oy/blob/main/a11oy_landing.html" style="color:#C9B787">szl-holdings/a11oy@main</a><span id="fw-main-sha"></span> · verify from outside:
1073
  <code style="color:#E8D9AE;background:#0B1F3A;padding:1px 6px;border-radius:3px">curl -s https://raw.githubusercontent.com/szl-holdings/a11oy/main/a11oy_landing.html | sha256sum</code>
1074
  </div>
1075
+ <div style="margin-top:4px;color:#5c6f8a">This proves integrity &amp; origin of this page only — never the accuracy of anything written on it. Doctrine v11. Expect the two hashes to differ by exactly the declared deltas: the server injects the operator-widget <code>&lt;script&gt;</code> tag in-memory, and the deployer may rewrite asset paths. In-browser hash = bytes as served; curl hash = canonical source; the attested sync + drift guards bind the two.</div>
1076
  </div>
1077
  </section>
1078
  <script>
govern_showcase.html CHANGED
The diff for this file is too large to render. See raw diff
 
pages/assurance.html CHANGED
@@ -1,13 +1,13 @@
1
- <!DOCTYPE html>
2
  <html lang="en">
3
  <head>
4
  <meta charset="utf-8" />
5
  <meta name="viewport" content="width=device-width, initial-scale=1" />
6
- <title>a11oy — AI Assurance for WDP-era Agentic AI</title>
7
  <style>
8
  /* =====================================================================
9
- a11oy Assurance Surface — elite showcase aesthetic
10
- Dark palette · Cabinet Grotesk / JetBrains Mono · honest-label chips
11
  ===================================================================== */
12
  @import url('https://fonts.googleapis.com/css2?family=JetBrains+Mono:ital,wght@0,400;0,600;1,400&display=swap');
13
 
@@ -403,7 +403,7 @@
403
  <nav class="nav-links">
404
  <a href="/verify" class="nav-back">Verify Receipt</a>
405
  <a href="/willay" class="nav-back">WILLAY</a>
406
- <a href="/console" class="nav-back">← Console</a>
407
  </nav>
408
  </header>
409
 
@@ -411,39 +411,39 @@
411
  <main class="page">
412
 
413
  <!-- =====================================================================
414
- A — HERO
415
  ===================================================================== -->
416
  <section class="section">
417
  <div class="hero">
418
- <div class="hero-eyebrow">WDP · Advana · CDAO · Agentic AI</div>
419
  <h1>Verifiable AI Assurance<br>for the <span class="hl">War Data Platform</span> era.</h1>
420
  <p class="hero-sub">
421
  The Jan-2026 DoD memo restructuring Advana into WDP calls for
422
  <strong>agentic AI</strong> + <strong>enhanced auditability</strong>.
423
  a11oy is the governance + verifiable-provenance overlay that produces
424
- the auditability evidence CDAO/RMF demands — one cryptographically
425
  signed receipt per AI decision, buyer-verifiable offline.
426
  </p>
427
  <div class="hero-honest">
428
- <span class="hero-honest-icon">⚠</span>
429
  <span>
430
- <strong>Honest status:</strong> a11oy is the assurance overlay — NOT an ATO-authorized system.
431
  ATO / IL5 / FedRAMP-High accreditation: <span class="chip chip-roadmap">ROADMAP</span>.
432
- Stated plainly — the honesty is the sell to an auditor audience.
433
  </span>
434
  </div>
435
  <div class="hero-chips">
436
- <span class="chip chip-live">DSSE Signed Receipts · LIVE</span>
437
- <span class="chip chip-live">WebCrypto Verify · LIVE</span>
438
- <span class="chip chip-live">Policy Gates · LIVE</span>
439
- <span class="chip chip-roadmap">ATO / IL5 / FedRAMP · ROADMAP</span>
440
- <span class="chip chip-info">a11oy = Overlay · NOT Replacement</span>
441
  </div>
442
  </div>
443
  </section>
444
 
445
  <!-- =====================================================================
446
- B — ASSURANCE MATRIX
447
  ===================================================================== -->
448
  <section class="section" id="section-matrix">
449
  <div class="section-head">
@@ -451,24 +451,24 @@
451
  <div>
452
  <div class="section-title">CDAO / DoD AI Assurance Requirements Matrix</div>
453
  <div class="section-desc">
454
- Each row: a real CDAO/DoD/OMB requirement → the a11oy artifact that satisfies it,
455
- with honest status. ROADMAP items are labeled plainly — no fabricated compliance.
456
  </div>
457
  </div>
458
  </div>
459
 
460
  <div id="matrix-container">
461
  <div class="matrix-loading">
462
- <span class="spinner"></span> Loading assurance matrix from /api/a11oy/v1/assurance/matrix…
463
  </div>
464
  </div>
465
 
466
  <div style="margin-top:14px; font-size:12px; color:var(--text-mute);">
467
  Status key:
468
- <span class="chip chip-live">LIVE</span> operational today ·
469
- <span class="chip chip-measured">MEASURED</span> real data ·
470
- <span class="chip chip-sample">SAMPLE</span> demo only ·
471
- <span class="chip chip-modeled">MODELED</span> model-derived ·
472
  <span class="chip chip-roadmap">ROADMAP</span> planned / not yet delivered
473
  </div>
474
 
@@ -480,29 +480,29 @@
480
  <div style="font-size:12px;color:var(--text-dim);margin-bottom:12px;">
481
  One signed, offline-verifiable JSON bundling the assurance matrix, khipu chain heads
482
  (re-walked <code>links_intact</code>), the lake health snapshot, and the doctrine
483
- snapshot — self-hashed with <strong>sha3_256</strong> so an auditor re-verifies offline.
484
  Honest: integrity is COMPUTED, not asserted; signature is the demo key (NOT production cosign).
485
  </div>
486
  <div class="btn-row">
487
  <button class="btn btn-primary" id="evidence-pack-btn" onclick="downloadEvidencePack()">
488
  Download Evidence Pack
489
  </button>
490
- <a class="btn" href="/api/a11oy/v1/assurance/evidence-pack" target="_blank">View JSON →</a>
491
  </div>
492
  <div id="evidence-pack-status" class="status-line"></div>
493
  </div>
494
  </section>
495
 
496
  <!-- =====================================================================
497
- C — LIVE PROOF WIDGET (run governed decision → sign → verify)
498
  ===================================================================== -->
499
  <section class="section" id="section-proof">
500
  <div class="section-head">
501
  <div class="section-letter">C</div>
502
  <div>
503
- <div class="section-title">Live Proof: Run → Sign → Verify Yourself</div>
504
  <div class="section-desc">
505
- Run a governed inference → receive a DSSE-signed Khipu receipt →
506
  verify the ECDSA-P256 signature in-browser via WebCrypto (zero server round-trip for verification).
507
  </div>
508
  </div>
@@ -523,31 +523,31 @@
523
  <div class="proof-body">
524
  <div class="btn-row">
525
  <button class="btn btn-primary" id="proof-run-btn" onclick="runProof()">
526
- Run Governed Decision → Get Signed Receipt → Verify
527
  </button>
528
  </div>
529
  <div id="proof-status" class="status-line"></div>
530
  <div id="proof-verdict" style="display:none"></div>
531
  <div id="proof-output" class="output" style="display:none"></div>
532
  <div style="margin-top:14px; font-size:12px; color:var(--text-mute);">
533
- <span class="conj">Λ Conjecture 1 — advisory, NOT a theorem</span>
534
- &nbsp;·&nbsp;
535
- <a href="/verify" style="font-size:12px">Open full /verify page →</a>
536
  </div>
537
  </div>
538
  </div>
539
  </section>
540
 
541
  <!-- =====================================================================
542
- D — WILLAY FOR DEFENSE
543
  ===================================================================== -->
544
  <section class="section" id="section-willay">
545
  <div class="section-head">
546
  <div class="section-letter">D</div>
547
  <div>
548
- <div class="section-title">WILLAY — Signed Refusals for Defense</div>
549
  <div class="section-desc">
550
- An agent that can refuse — and prove why, signed.
551
  Critical for agentic AI in defense: every denial is a
552
  cryptographically-signed, auditable artifact.
553
  </div>
@@ -555,7 +555,7 @@
555
  </div>
556
 
557
  <div class="willay-card">
558
- <div class="willay-icon">⚡</div>
559
  <div class="willay-content">
560
  <h3>What Makes a Signed Refusal Different</h3>
561
  <div class="willay-quote">
@@ -564,23 +564,23 @@
564
  WILLAY produces a DSSE-signed denial receipt that any auditor can verify.
565
  </div>
566
  <p>
567
- Every WILLAY denial embeds: the triggering gate name, the Λ advisory score
568
- (Conjecture 1 label), the hash-chain link (prev→digest), and the timestamp —
569
  all under ECDSA-P256 signature. The authorization package has a machine-verifiable
570
  TEVV artifact for every denied call, not just allowed ones.
571
  </p>
572
  <div style="display:flex; gap:10px; flex-wrap:wrap; margin-bottom:16px">
573
- <span class="chip chip-live">Signed denial receipts · LIVE</span>
574
- <span class="conj">Λ Conjecture 1 — advisory</span>
575
  <span class="chip chip-info">Auditor-verifiable offline</span>
576
  </div>
577
- <a href="/willay" class="btn-willay">Open WILLAY — Signed Refusals →</a>
578
  </div>
579
  </div>
580
  </section>
581
 
582
  <!-- =====================================================================
583
- E — WHERE A11OY FITS (honest diagram)
584
  ===================================================================== -->
585
  <section class="section" id="section-fit">
586
  <div class="section-head">
@@ -603,16 +603,16 @@
603
  <rect x="20" y="12" width="600" height="70" rx="10" fill="#0c1a33" stroke="#1e3a8a" stroke-width="1.5"/>
604
  <text x="36" y="36" font-family="'JetBrains Mono', monospace" font-size="10" fill="#6c8ef5" font-weight="700" letter-spacing="1">GOVERNANCE + TRUST OVERLAY</text>
605
  <text x="36" y="56" font-family="'Cabinet Grotesk', 'Inter', sans-serif" font-size="16" fill="#e8eaf0" font-weight="800">a11oy</text>
606
- <text x="100" y="56" font-family="'Cabinet Grotesk', 'Inter', sans-serif" font-size="13" fill="#8891a8">signed receipts · policy gates · honest labels · WILLAY refusals</text>
607
- <text x="36" y="73" font-family="'Cabinet Grotesk', 'Inter', sans-serif" font-size="11" fill="#4a5068">DSSE · ECDSA-P256 · WebCrypto-verifiable · Λ advisory (Conjecture 1)</text>
608
  <!-- Arrow -->
609
- <text x="280" y="103" font-family="monospace" font-size="12" fill="#4a5068" text-anchor="middle">sits on top of ↓</text>
610
  <!-- Platform layer -->
611
  <rect x="20" y="116" width="600" height="70" rx="10" fill="#0d1a0d" stroke="#2a3a1a" stroke-width="1.5"/>
612
  <text x="36" y="136" font-family="'JetBrains Mono', monospace" font-size="10" fill="#86efac" font-weight="700" letter-spacing="1">SYSTEM OF RECORD</text>
613
  <text x="36" y="158" font-family="'Cabinet Grotesk', 'Inter', sans-serif" font-size="14" fill="#86efac" font-weight="800">WDP / Advana</text>
614
- <text x="150" y="158" font-family="'Cabinet Grotesk', 'Inter', sans-serif" font-size="13" fill="#8891a8"> · Palantir Foundry · Databricks Unity Catalog</text>
615
- <text x="36" y="175" font-family="'Cabinet Grotesk', 'Inter', sans-serif" font-size="11" fill="#4a5068">data · ontology · lineage · column governance → stays authoritative</text>
616
  </svg>
617
 
618
  <div class="fit-list">
@@ -630,7 +630,7 @@
630
  </div>
631
  <div class="fit-item fit-item-yes">
632
  <div class="fit-item-label yes">a11oy IS</div>
633
- Signed refusal explainer (WILLAY) — not a black-box boolean gate
634
  </div>
635
  <div class="fit-item fit-item-no">
636
  <div class="fit-item-label no">a11oy IS NOT</div>
@@ -642,11 +642,11 @@
642
  </div>
643
  <div class="fit-item fit-item-no">
644
  <div class="fit-item-label no">a11oy IS NOT</div>
645
- An accredited system (ATO / IL5 / FedRAMP-High: ROADMAP — stated plainly)
646
  </div>
647
  <div class="fit-item fit-item-no">
648
  <div class="fit-item-label no">a11oy IS NOT</div>
649
- A certified classifier — Λ is Conjecture 1 (advisory; NOT a theorem)
650
  </div>
651
  </div>
652
 
@@ -655,7 +655,7 @@
655
  The Jan-2026 DoD memo explicitly calls for <em>agentic AI</em> + <em>enhanced auditability</em>
656
  toward a clean FY27/FY28 audit.
657
  Foundry shows data lineage. Unity Catalog shows column provenance.
658
- a11oy gives you a cryptographic signature on the <em>AI decision itself</em> —
659
  something the buyer can verify offline, without trusting the provider.
660
  </div>
661
  </div>
@@ -664,7 +664,7 @@
664
  <div style="background:var(--bg-panel); border-top:1px solid var(--border); padding:14px 24px; display:flex; align-items:center; gap:12px; flex-wrap:wrap;">
665
  <span style="font-size:11px; color:var(--text-mute); font-weight:700; text-transform:uppercase; letter-spacing:.07em">API</span>
666
  <a href="/api/a11oy/v1/assurance/fit" style="font-size:12px; font-family:var(--mono);" target="_blank">/api/a11oy/v1/assurance/fit</a>
667
- <span style="font-size:11px; color:var(--text-mute)">→ full machine-readable fit statement</span>
668
  <span id="fit-status" style="font-size:11px; color:var(--text-mute); margin-left:auto"></span>
669
  </div>
670
  </div>
@@ -675,17 +675,17 @@
675
  <!-- ===== FOOTER ===== -->
676
  <footer class="footer">
677
  <p>
678
- SZL Holdings · a11oy · Doctrine v11 · 8 kernel-proven formulas @ c7c0ba17 ·
679
- Λ = Conjecture 1 (advisory) · Khipu BFT = Conjecture 2 ·
680
- ATO/IL5/FedRAMP = ROADMAP (not accredited) ·
681
- <a href="/api/a11oy/v1/assurance/matrix" target="_blank">Assurance Matrix API</a> ·
682
- <a href="/verify" target="_blank">Verify a Receipt</a> ·
683
  <a href="/cosign.pub" target="_blank">cosign.pub</a>
684
  </p>
685
  </footer>
686
 
687
  <!-- ===================================================================
688
- JAVASCRIPT — all in-browser, 0 CDN
689
  =================================================================== -->
690
  <script>
691
  "use strict";
@@ -717,7 +717,7 @@ function statusChip(status) {
717
  }
718
 
719
  /* ==================================================================
720
- SECTION B — Load assurance matrix
721
  ================================================================== */
722
  async function loadMatrix() {
723
  var container = el('matrix-container');
@@ -729,8 +729,8 @@ async function loadMatrix() {
729
  data = await resp.json();
730
  } catch(e) {
731
  container.innerHTML = '<div class="matrix-loading" style="color:var(--amber)">'+
732
- '⚠ Could not load matrix: '+escHTML(e.message)+'<br>'+
733
- '<a href="/api/a11oy/v1/assurance/matrix" target="_blank" style="font-size:12px">Try API directly →</a>'+
734
  '</div>';
735
  return;
736
  }
@@ -751,7 +751,7 @@ async function loadMatrix() {
751
  : '';
752
  var sourceLink = r.source_url
753
  ? '<a class="source-link" href="'+escHTML(r.source_url)+'" target="_blank" rel="noopener">'+escHTML(r.source)+'</a>'
754
- : escHTML(r.source || '—');
755
 
756
  html += '<tr>'+
757
  '<td class="status-col"><span class="req-id-badge">'+escHTML(r.req_id)+'</span></td>'+
@@ -769,7 +769,7 @@ async function loadMatrix() {
769
  // Honest note banner
770
  if (data.honest_note) {
771
  html += '<div style="margin-top:12px;background:var(--amber-dark);border:1px solid var(--amber-mid);border-radius:var(--radius);padding:12px 16px;font-size:12px;color:var(--amber)">'+
772
- '⚠ '+escHTML(data.honest_note)+'</div>';
773
  }
774
 
775
  container.innerHTML = html;
@@ -825,14 +825,14 @@ async function importPubKeyFromPEM(pem) {
825
  }
826
 
827
  /* ==================================================================
828
- SECTION C — Run governed decision → verify receipt
829
  ================================================================== */
830
  async function runProof() {
831
  var btn = el('proof-run-btn');
832
  btn.disabled = true;
833
  hide('proof-verdict');
834
  hide('proof-output');
835
- setStatus('proof-status', 'Calling /api/a11oy/v1/govern/infer …', true);
836
 
837
  var data;
838
  try {
@@ -847,7 +847,7 @@ async function runProof() {
847
  btn.disabled = false; return;
848
  }
849
 
850
- setStatus('proof-status', 'Fetching cosign.pub and verifying signature via WebCrypto …', true);
851
 
852
  var dsse = data.dsse || {};
853
  var receipt = data.receipt || {};
@@ -876,7 +876,7 @@ async function runProof() {
876
  var verified = false, verifyError = '', sigKeyid = '';
877
 
878
  if (!dsse.signed) {
879
- verifyError = 'UNSIGNED envelope — private key not in runtime. Receipt chain still valid.';
880
  } else if (!sigs.length) {
881
  verifyError = 'No signatures in envelope.';
882
  } else {
@@ -884,7 +884,7 @@ async function runProof() {
884
  try {
885
  var sigBytes = b64Decode(sigEntry.sig||'');
886
  var rawSig = sigBytes;
887
- if(sigBytes[0]===0x30){try{rawSig=derToRaw(sigBytes);}catch(e2){verifyError='DER→raw failed: '+e2.message;}}
888
  if(!verifyError){
889
  verified = await crypto.subtle.verify({name:'ECDSA',hash:'SHA-256'}, pubKey, rawSig.buffer, paeBytes.buffer);
890
  if(!verified && sigBytes[0]===0x30){
@@ -901,29 +901,29 @@ async function runProof() {
901
 
902
  var verdictHTML = '';
903
  if(verified){
904
- verdictHTML='<div class="verdict-banner verdict-ok">✓ VERIFIED — WebCrypto ECDSA-P256 signature valid <span class="chip chip-ok">keyid: '+escHTML(sigKeyid)+'</span></div>';
905
  } else if(!dsse.signed){
906
- verdictHTML='<div class="verdict-banner verdict-dim">⚠ UNSIGNED — private key not in runtime; receipt chain still valid</div>';
907
  } else {
908
- verdictHTML='<div class="verdict-banner verdict-fail">✗ VERIFICATION FAILED — '+escHTML(verifyError)+'</div>';
909
  }
910
 
911
  var digestMatch = payloadDigestComputed===receiptDigest.substring(0,64);
912
  verdictHTML += '<div style="margin-bottom:12px">'+
913
  '<div class="hash-row"><span class="hash-label">Payload digest:</span>'+
914
- '<span class="hash-val '+(digestMatch?'hash-match':'hash-mismatch')+'">'+payloadDigestComputed.substring(0,32)+'…</span>'+
915
  '<span class="chip '+(digestMatch?'chip-ok':'chip-err')+'">'+(digestMatch?'MATCH':'MISMATCH')+'</span></div>'+
916
  '<div class="hash-row"><span class="hash-label">PAE SHA-256:</span>'+
917
- '<span class="hash-val">'+paeSHA.substring(0,32)+'…</span></div>'+
918
  '<div class="hash-row"><span class="hash-label">Chain prev:</span>'+
919
- '<span class="hash-val">'+escHTML(String(chainPrev).substring(0,32))+'…</span></div>'+
920
  '<div class="hash-row"><span class="hash-label">Chain digest:</span>'+
921
- '<span class="hash-val">'+escHTML(String(chainDigest).substring(0,32))+'…</span></div>'+
922
  '</div>'+
923
  '<div style="font-size:12px;color:var(--text-dim)">'+
924
- '<span class="conj">Λ Conjecture 1 — advisory</span>'+
925
- ' Λ = '+escHTML(String((data.governance||{}).lambda ?? 'N/A'))+
926
- ' &nbsp;·&nbsp; Energy: <span class="chip chip-dim">'+escHTML(((data.energy||{}).label)||'UNAVAILABLE')+'</span>'+
927
  '</div>';
928
 
929
  el('proof-verdict').innerHTML = verdictHTML;
@@ -934,13 +934,13 @@ async function runProof() {
934
  'governance.lambda': (data.governance||{}).lambda,
935
  'governance.lambda_kind': (data.governance||{}).lambda_kind,
936
  'receipt.seq': receipt.seq,
937
- 'receipt.prev': String(chainPrev).substring(0,32)+'…',
938
- 'receipt.digest': String(chainDigest).substring(0,32)+'…',
939
  'dsse.signed': dsse.signed,
940
  'dsse.payloadType': dsse.payloadType,
941
- 'verify.payload_sha256': payloadDigestComputed.substring(0,32)+'…',
942
- 'verify.pae_sha256': paeSHA.substring(0,32)+'…',
943
- 'verify.result': verified ? 'VERIFIED ✓' : (dsse.signed===false ? 'UNSIGNED (no key in runtime)' : 'FAILED: '+verifyError),
944
  'energy.label': (data.energy||{}).label,
945
  'honesty': data.honesty,
946
  };
@@ -949,14 +949,14 @@ async function runProof() {
949
  show('proof-output');
950
 
951
  setStatus('proof-status',
952
- verified ? '✓ WebCrypto verified — real ECDSA-P256 signature over DSSE PAE.' :
953
  (dsse.signed===false ? 'Unsigned receipt (key absent from runtime). Chain valid.' :
954
  'Verification result: '+verifyError));
955
  btn.disabled = false;
956
  }
957
 
958
  /* ==================================================================
959
- SECTION E — Load fit data and mark live
960
  ================================================================== */
961
  async function checkFit() {
962
  var s = el('fit-status'); if(!s) return;
@@ -973,12 +973,12 @@ async function checkFit() {
973
  }
974
 
975
  /* ==================================================================
976
- SECTION B' — Download Auditor Evidence Pack (sha3_256 self-verifiable)
977
  ================================================================== */
978
  async function downloadEvidencePack() {
979
  var btn = el('evidence-pack-btn');
980
  if (btn) btn.disabled = true;
981
- setStatus('evidence-pack-status', 'Assembling evidence pack from live surfaces…', true);
982
  try {
983
  var resp = await fetch('/api/a11oy/v1/assurance/evidence-pack');
984
  var data = await resp.json();
@@ -996,16 +996,16 @@ async function downloadEvidencePack() {
996
  setTimeout(function(){ URL.revokeObjectURL(url); }, 4000);
997
 
998
  // We do NOT recompute sha3_256 in-browser (WebCrypto has no SHA3, and shipping a
999
- // hand-rolled hash would risk a false result — honesty over a fake green check).
1000
  // The digest + exact canonicalization are in the pack so an auditor re-verifies
1001
  // offline with a trusted sha3_256 tool. We only surface what the server reported.
1002
  var sig = (data.signature || {});
1003
- var sigMsg = sig.signed ? (' · signed [' + (sig.keyid || 'demo') + ']') : ' · honest-unsigned (DSSE_PLACEHOLDER)';
1004
  setStatus('evidence-pack-status',
1005
- '✓ Downloaded. sha3_256=' + String(data.pack_sha3_256 || '').substring(0, 24) + '…' + sigMsg +
1006
- ' · re-verify offline per the pack’s digest_canonicalization note.', false);
1007
  } catch(e) {
1008
- setStatus('evidence-pack-status', '⚠ Could not assemble evidence pack: ' + e.message, false);
1009
  } finally {
1010
  if (btn) btn.disabled = false;
1011
  }
@@ -1020,3 +1020,4 @@ window.addEventListener('DOMContentLoaded', function() {
1020
 
1021
  </body>
1022
  </html>
 
 
1
+ <!DOCTYPE html>
2
  <html lang="en">
3
  <head>
4
  <meta charset="utf-8" />
5
  <meta name="viewport" content="width=device-width, initial-scale=1" />
6
+ <title>a11oy — AI Assurance for WDP-era Agentic AI</title>
7
  <style>
8
  /* =====================================================================
9
+ a11oy Assurance Surface — elite showcase aesthetic
10
+ Dark palette · Cabinet Grotesk / JetBrains Mono · honest-label chips
11
  ===================================================================== */
12
  @import url('https://fonts.googleapis.com/css2?family=JetBrains+Mono:ital,wght@0,400;0,600;1,400&display=swap');
13
 
 
403
  <nav class="nav-links">
404
  <a href="/verify" class="nav-back">Verify Receipt</a>
405
  <a href="/willay" class="nav-back">WILLAY</a>
406
+ <a href="/console" class="nav-back">← Console</a>
407
  </nav>
408
  </header>
409
 
 
411
  <main class="page">
412
 
413
  <!-- =====================================================================
414
+ A — HERO
415
  ===================================================================== -->
416
  <section class="section">
417
  <div class="hero">
418
+ <div class="hero-eyebrow">WDP · Advana · CDAO · Agentic AI</div>
419
  <h1>Verifiable AI Assurance<br>for the <span class="hl">War Data Platform</span> era.</h1>
420
  <p class="hero-sub">
421
  The Jan-2026 DoD memo restructuring Advana into WDP calls for
422
  <strong>agentic AI</strong> + <strong>enhanced auditability</strong>.
423
  a11oy is the governance + verifiable-provenance overlay that produces
424
+ the auditability evidence CDAO/RMF demands — one cryptographically
425
  signed receipt per AI decision, buyer-verifiable offline.
426
  </p>
427
  <div class="hero-honest">
428
+ <span class="hero-honest-icon">âš </span>
429
  <span>
430
+ <strong>Honest status:</strong> a11oy is the assurance overlay — NOT an ATO-authorized system.
431
  ATO / IL5 / FedRAMP-High accreditation: <span class="chip chip-roadmap">ROADMAP</span>.
432
+ Stated plainly — the honesty is the sell to an auditor audience.
433
  </span>
434
  </div>
435
  <div class="hero-chips">
436
+ <span class="chip chip-live">DSSE Signed Receipts · LIVE</span>
437
+ <span class="chip chip-live">WebCrypto Verify · LIVE</span>
438
+ <span class="chip chip-live">Policy Gates · LIVE</span>
439
+ <span class="chip chip-roadmap">ATO / IL5 / FedRAMP · ROADMAP</span>
440
+ <span class="chip chip-info">a11oy = Overlay · NOT Replacement</span>
441
  </div>
442
  </div>
443
  </section>
444
 
445
  <!-- =====================================================================
446
+ B — ASSURANCE MATRIX
447
  ===================================================================== -->
448
  <section class="section" id="section-matrix">
449
  <div class="section-head">
 
451
  <div>
452
  <div class="section-title">CDAO / DoD AI Assurance Requirements Matrix</div>
453
  <div class="section-desc">
454
+ Each row: a real CDAO/DoD/OMB requirement → the a11oy artifact that satisfies it,
455
+ with honest status. ROADMAP items are labeled plainly — no fabricated compliance.
456
  </div>
457
  </div>
458
  </div>
459
 
460
  <div id="matrix-container">
461
  <div class="matrix-loading">
462
+ <span class="spinner"></span> Loading assurance matrix from /api/a11oy/v1/assurance/matrix…
463
  </div>
464
  </div>
465
 
466
  <div style="margin-top:14px; font-size:12px; color:var(--text-mute);">
467
  Status key:
468
+ <span class="chip chip-live">LIVE</span> operational today ·
469
+ <span class="chip chip-measured">MEASURED</span> real data ·
470
+ <span class="chip chip-sample">SAMPLE</span> demo only ·
471
+ <span class="chip chip-modeled">MODELED</span> model-derived ·
472
  <span class="chip chip-roadmap">ROADMAP</span> planned / not yet delivered
473
  </div>
474
 
 
480
  <div style="font-size:12px;color:var(--text-dim);margin-bottom:12px;">
481
  One signed, offline-verifiable JSON bundling the assurance matrix, khipu chain heads
482
  (re-walked <code>links_intact</code>), the lake health snapshot, and the doctrine
483
+ snapshot — self-hashed with <strong>sha3_256</strong> so an auditor re-verifies offline.
484
  Honest: integrity is COMPUTED, not asserted; signature is the demo key (NOT production cosign).
485
  </div>
486
  <div class="btn-row">
487
  <button class="btn btn-primary" id="evidence-pack-btn" onclick="downloadEvidencePack()">
488
  Download Evidence Pack
489
  </button>
490
+ <a class="btn" href="/api/a11oy/v1/assurance/evidence-pack" target="_blank">View JSON →</a>
491
  </div>
492
  <div id="evidence-pack-status" class="status-line"></div>
493
  </div>
494
  </section>
495
 
496
  <!-- =====================================================================
497
+ C — LIVE PROOF WIDGET (run governed decision → sign → verify)
498
  ===================================================================== -->
499
  <section class="section" id="section-proof">
500
  <div class="section-head">
501
  <div class="section-letter">C</div>
502
  <div>
503
+ <div class="section-title">Live Proof: Run → Sign → Verify Yourself</div>
504
  <div class="section-desc">
505
+ Run a governed execution → receive a DSSE-signed Khipu receipt →
506
  verify the ECDSA-P256 signature in-browser via WebCrypto (zero server round-trip for verification).
507
  </div>
508
  </div>
 
523
  <div class="proof-body">
524
  <div class="btn-row">
525
  <button class="btn btn-primary" id="proof-run-btn" onclick="runProof()">
526
+ Run Governed Decision → Get Signed Receipt → Verify
527
  </button>
528
  </div>
529
  <div id="proof-status" class="status-line"></div>
530
  <div id="proof-verdict" style="display:none"></div>
531
  <div id="proof-output" class="output" style="display:none"></div>
532
  <div style="margin-top:14px; font-size:12px; color:var(--text-mute);">
533
+ <span class="conj">Λ Conjecture 1 — advisory, NOT a theorem</span>
534
+ &nbsp;·&nbsp;
535
+ <a href="/verify" style="font-size:12px">Open full /verify page →</a>
536
  </div>
537
  </div>
538
  </div>
539
  </section>
540
 
541
  <!-- =====================================================================
542
+ D — WILLAY FOR DEFENSE
543
  ===================================================================== -->
544
  <section class="section" id="section-willay">
545
  <div class="section-head">
546
  <div class="section-letter">D</div>
547
  <div>
548
+ <div class="section-title">WILLAY — Signed Refusals for Defense</div>
549
  <div class="section-desc">
550
+ An agent that can refuse — and prove why, signed.
551
  Critical for agentic AI in defense: every denial is a
552
  cryptographically-signed, auditable artifact.
553
  </div>
 
555
  </div>
556
 
557
  <div class="willay-card">
558
+ <div class="willay-icon">âš¡</div>
559
  <div class="willay-content">
560
  <h3>What Makes a Signed Refusal Different</h3>
561
  <div class="willay-quote">
 
564
  WILLAY produces a DSSE-signed denial receipt that any auditor can verify.
565
  </div>
566
  <p>
567
+ Every WILLAY denial embeds: the triggering gate name, the Λ advisory score
568
+ (Conjecture 1 label), the hash-chain link (prev→digest), and the timestamp —
569
  all under ECDSA-P256 signature. The authorization package has a machine-verifiable
570
  TEVV artifact for every denied call, not just allowed ones.
571
  </p>
572
  <div style="display:flex; gap:10px; flex-wrap:wrap; margin-bottom:16px">
573
+ <span class="chip chip-live">Signed denial receipts · LIVE</span>
574
+ <span class="conj">Λ Conjecture 1 — advisory</span>
575
  <span class="chip chip-info">Auditor-verifiable offline</span>
576
  </div>
577
+ <a href="/willay" class="btn-willay">Open WILLAY — Signed Refusals →</a>
578
  </div>
579
  </div>
580
  </section>
581
 
582
  <!-- =====================================================================
583
+ E — WHERE A11OY FITS (honest diagram)
584
  ===================================================================== -->
585
  <section class="section" id="section-fit">
586
  <div class="section-head">
 
603
  <rect x="20" y="12" width="600" height="70" rx="10" fill="#0c1a33" stroke="#1e3a8a" stroke-width="1.5"/>
604
  <text x="36" y="36" font-family="'JetBrains Mono', monospace" font-size="10" fill="#6c8ef5" font-weight="700" letter-spacing="1">GOVERNANCE + TRUST OVERLAY</text>
605
  <text x="36" y="56" font-family="'Cabinet Grotesk', 'Inter', sans-serif" font-size="16" fill="#e8eaf0" font-weight="800">a11oy</text>
606
+ <text x="100" y="56" font-family="'Cabinet Grotesk', 'Inter', sans-serif" font-size="13" fill="#8891a8">signed receipts · policy gates · honest labels · WILLAY refusals</text>
607
+ <text x="36" y="73" font-family="'Cabinet Grotesk', 'Inter', sans-serif" font-size="11" fill="#4a5068">DSSE · ECDSA-P256 · WebCrypto-verifiable · Λ advisory (Conjecture 1)</text>
608
  <!-- Arrow -->
609
+ <text x="280" y="103" font-family="monospace" font-size="12" fill="#4a5068" text-anchor="middle">sits on top of ↓</text>
610
  <!-- Platform layer -->
611
  <rect x="20" y="116" width="600" height="70" rx="10" fill="#0d1a0d" stroke="#2a3a1a" stroke-width="1.5"/>
612
  <text x="36" y="136" font-family="'JetBrains Mono', monospace" font-size="10" fill="#86efac" font-weight="700" letter-spacing="1">SYSTEM OF RECORD</text>
613
  <text x="36" y="158" font-family="'Cabinet Grotesk', 'Inter', sans-serif" font-size="14" fill="#86efac" font-weight="800">WDP / Advana</text>
614
+ <text x="150" y="158" font-family="'Cabinet Grotesk', 'Inter', sans-serif" font-size="13" fill="#8891a8"> · Palantir Foundry · Databricks Unity Catalog</text>
615
+ <text x="36" y="175" font-family="'Cabinet Grotesk', 'Inter', sans-serif" font-size="11" fill="#4a5068">data · ontology · lineage · column governance → stays authoritative</text>
616
  </svg>
617
 
618
  <div class="fit-list">
 
630
  </div>
631
  <div class="fit-item fit-item-yes">
632
  <div class="fit-item-label yes">a11oy IS</div>
633
+ Signed refusal explainer (WILLAY) — not a black-box boolean gate
634
  </div>
635
  <div class="fit-item fit-item-no">
636
  <div class="fit-item-label no">a11oy IS NOT</div>
 
642
  </div>
643
  <div class="fit-item fit-item-no">
644
  <div class="fit-item-label no">a11oy IS NOT</div>
645
+ An accredited system (ATO / IL5 / FedRAMP-High: ROADMAP — stated plainly)
646
  </div>
647
  <div class="fit-item fit-item-no">
648
  <div class="fit-item-label no">a11oy IS NOT</div>
649
+ A certified classifier — Λ is Conjecture 1 (advisory; NOT a theorem)
650
  </div>
651
  </div>
652
 
 
655
  The Jan-2026 DoD memo explicitly calls for <em>agentic AI</em> + <em>enhanced auditability</em>
656
  toward a clean FY27/FY28 audit.
657
  Foundry shows data lineage. Unity Catalog shows column provenance.
658
+ a11oy gives you a cryptographic signature on the <em>AI decision itself</em> —
659
  something the buyer can verify offline, without trusting the provider.
660
  </div>
661
  </div>
 
664
  <div style="background:var(--bg-panel); border-top:1px solid var(--border); padding:14px 24px; display:flex; align-items:center; gap:12px; flex-wrap:wrap;">
665
  <span style="font-size:11px; color:var(--text-mute); font-weight:700; text-transform:uppercase; letter-spacing:.07em">API</span>
666
  <a href="/api/a11oy/v1/assurance/fit" style="font-size:12px; font-family:var(--mono);" target="_blank">/api/a11oy/v1/assurance/fit</a>
667
+ <span style="font-size:11px; color:var(--text-mute)">→ full machine-readable fit statement</span>
668
  <span id="fit-status" style="font-size:11px; color:var(--text-mute); margin-left:auto"></span>
669
  </div>
670
  </div>
 
675
  <!-- ===== FOOTER ===== -->
676
  <footer class="footer">
677
  <p>
678
+ SZL Holdings · a11oy · Doctrine v11 · 8 kernel-proven formulas @ c7c0ba17 ·
679
+ Λ = Conjecture 1 (advisory) · Khipu BFT = Conjecture 2 ·
680
+ ATO/IL5/FedRAMP = ROADMAP (not accredited) ·
681
+ <a href="/api/a11oy/v1/assurance/matrix" target="_blank">Assurance Matrix API</a> ·
682
+ <a href="/verify" target="_blank">Verify a Receipt</a> ·
683
  <a href="/cosign.pub" target="_blank">cosign.pub</a>
684
  </p>
685
  </footer>
686
 
687
  <!-- ===================================================================
688
+ JAVASCRIPT — all in-browser, 0 CDN
689
  =================================================================== -->
690
  <script>
691
  "use strict";
 
717
  }
718
 
719
  /* ==================================================================
720
+ SECTION B — Load assurance matrix
721
  ================================================================== */
722
  async function loadMatrix() {
723
  var container = el('matrix-container');
 
729
  data = await resp.json();
730
  } catch(e) {
731
  container.innerHTML = '<div class="matrix-loading" style="color:var(--amber)">'+
732
+ 'âš  Could not load matrix: '+escHTML(e.message)+'<br>'+
733
+ '<a href="/api/a11oy/v1/assurance/matrix" target="_blank" style="font-size:12px">Try API directly →</a>'+
734
  '</div>';
735
  return;
736
  }
 
751
  : '';
752
  var sourceLink = r.source_url
753
  ? '<a class="source-link" href="'+escHTML(r.source_url)+'" target="_blank" rel="noopener">'+escHTML(r.source)+'</a>'
754
+ : escHTML(r.source || '—');
755
 
756
  html += '<tr>'+
757
  '<td class="status-col"><span class="req-id-badge">'+escHTML(r.req_id)+'</span></td>'+
 
769
  // Honest note banner
770
  if (data.honest_note) {
771
  html += '<div style="margin-top:12px;background:var(--amber-dark);border:1px solid var(--amber-mid);border-radius:var(--radius);padding:12px 16px;font-size:12px;color:var(--amber)">'+
772
+ 'âš  '+escHTML(data.honest_note)+'</div>';
773
  }
774
 
775
  container.innerHTML = html;
 
825
  }
826
 
827
  /* ==================================================================
828
+ SECTION C — Run governed decision → verify receipt
829
  ================================================================== */
830
  async function runProof() {
831
  var btn = el('proof-run-btn');
832
  btn.disabled = true;
833
  hide('proof-verdict');
834
  hide('proof-output');
835
+ setStatus('proof-status', 'Calling /api/a11oy/v1/govern/infer …', true);
836
 
837
  var data;
838
  try {
 
847
  btn.disabled = false; return;
848
  }
849
 
850
+ setStatus('proof-status', 'Fetching cosign.pub and verifying signature via WebCrypto …', true);
851
 
852
  var dsse = data.dsse || {};
853
  var receipt = data.receipt || {};
 
876
  var verified = false, verifyError = '', sigKeyid = '';
877
 
878
  if (!dsse.signed) {
879
+ verifyError = 'UNSIGNED envelope — private key not in runtime. Receipt chain still valid.';
880
  } else if (!sigs.length) {
881
  verifyError = 'No signatures in envelope.';
882
  } else {
 
884
  try {
885
  var sigBytes = b64Decode(sigEntry.sig||'');
886
  var rawSig = sigBytes;
887
+ if(sigBytes[0]===0x30){try{rawSig=derToRaw(sigBytes);}catch(e2){verifyError='DER→raw failed: '+e2.message;}}
888
  if(!verifyError){
889
  verified = await crypto.subtle.verify({name:'ECDSA',hash:'SHA-256'}, pubKey, rawSig.buffer, paeBytes.buffer);
890
  if(!verified && sigBytes[0]===0x30){
 
901
 
902
  var verdictHTML = '';
903
  if(verified){
904
+ verdictHTML='<div class="verdict-banner verdict-ok">✓ VERIFIED — WebCrypto ECDSA-P256 signature valid <span class="chip chip-ok">keyid: '+escHTML(sigKeyid)+'</span></div>';
905
  } else if(!dsse.signed){
906
+ verdictHTML='<div class="verdict-banner verdict-dim">⚠ UNSIGNED — private key not in runtime; receipt chain still valid</div>';
907
  } else {
908
+ verdictHTML='<div class="verdict-banner verdict-fail">✗ VERIFICATION FAILED — '+escHTML(verifyError)+'</div>';
909
  }
910
 
911
  var digestMatch = payloadDigestComputed===receiptDigest.substring(0,64);
912
  verdictHTML += '<div style="margin-bottom:12px">'+
913
  '<div class="hash-row"><span class="hash-label">Payload digest:</span>'+
914
+ '<span class="hash-val '+(digestMatch?'hash-match':'hash-mismatch')+'">'+payloadDigestComputed.substring(0,32)+'…</span>'+
915
  '<span class="chip '+(digestMatch?'chip-ok':'chip-err')+'">'+(digestMatch?'MATCH':'MISMATCH')+'</span></div>'+
916
  '<div class="hash-row"><span class="hash-label">PAE SHA-256:</span>'+
917
+ '<span class="hash-val">'+paeSHA.substring(0,32)+'…</span></div>'+
918
  '<div class="hash-row"><span class="hash-label">Chain prev:</span>'+
919
+ '<span class="hash-val">'+escHTML(String(chainPrev).substring(0,32))+'…</span></div>'+
920
  '<div class="hash-row"><span class="hash-label">Chain digest:</span>'+
921
+ '<span class="hash-val">'+escHTML(String(chainDigest).substring(0,32))+'…</span></div>'+
922
  '</div>'+
923
  '<div style="font-size:12px;color:var(--text-dim)">'+
924
+ '<span class="conj">Λ Conjecture 1 — advisory</span>'+
925
+ ' Λ = '+escHTML(String((data.governance||{}).lambda ?? 'N/A'))+
926
+ ' &nbsp;·&nbsp; Energy: <span class="chip chip-dim">'+escHTML(((data.energy||{}).label)||'UNAVAILABLE')+'</span>'+
927
  '</div>';
928
 
929
  el('proof-verdict').innerHTML = verdictHTML;
 
934
  'governance.lambda': (data.governance||{}).lambda,
935
  'governance.lambda_kind': (data.governance||{}).lambda_kind,
936
  'receipt.seq': receipt.seq,
937
+ 'receipt.prev': String(chainPrev).substring(0,32)+'…',
938
+ 'receipt.digest': String(chainDigest).substring(0,32)+'…',
939
  'dsse.signed': dsse.signed,
940
  'dsse.payloadType': dsse.payloadType,
941
+ 'verify.payload_sha256': payloadDigestComputed.substring(0,32)+'…',
942
+ 'verify.pae_sha256': paeSHA.substring(0,32)+'…',
943
+ 'verify.result': verified ? 'VERIFIED ✓' : (dsse.signed===false ? 'UNSIGNED (no key in runtime)' : 'FAILED: '+verifyError),
944
  'energy.label': (data.energy||{}).label,
945
  'honesty': data.honesty,
946
  };
 
949
  show('proof-output');
950
 
951
  setStatus('proof-status',
952
+ verified ? '✓ WebCrypto verified — real ECDSA-P256 signature over DSSE PAE.' :
953
  (dsse.signed===false ? 'Unsigned receipt (key absent from runtime). Chain valid.' :
954
  'Verification result: '+verifyError));
955
  btn.disabled = false;
956
  }
957
 
958
  /* ==================================================================
959
+ SECTION E — Load fit data and mark live
960
  ================================================================== */
961
  async function checkFit() {
962
  var s = el('fit-status'); if(!s) return;
 
973
  }
974
 
975
  /* ==================================================================
976
+ SECTION B' — Download Auditor Evidence Pack (sha3_256 self-verifiable)
977
  ================================================================== */
978
  async function downloadEvidencePack() {
979
  var btn = el('evidence-pack-btn');
980
  if (btn) btn.disabled = true;
981
+ setStatus('evidence-pack-status', 'Assembling evidence pack from live surfaces…', true);
982
  try {
983
  var resp = await fetch('/api/a11oy/v1/assurance/evidence-pack');
984
  var data = await resp.json();
 
996
  setTimeout(function(){ URL.revokeObjectURL(url); }, 4000);
997
 
998
  // We do NOT recompute sha3_256 in-browser (WebCrypto has no SHA3, and shipping a
999
+ // hand-rolled hash would risk a false result — honesty over a fake green check).
1000
  // The digest + exact canonicalization are in the pack so an auditor re-verifies
1001
  // offline with a trusted sha3_256 tool. We only surface what the server reported.
1002
  var sig = (data.signature || {});
1003
+ var sigMsg = sig.signed ? (' · signed [' + (sig.keyid || 'demo') + ']') : ' · honest-unsigned (DSSE_PLACEHOLDER)';
1004
  setStatus('evidence-pack-status',
1005
+ '✓ Downloaded. sha3_256=' + String(data.pack_sha3_256 || '').substring(0, 24) + '…' + sigMsg +
1006
+ ' · re-verify offline per the pack’s digest_canonicalization note.', false);
1007
  } catch(e) {
1008
+ setStatus('evidence-pack-status', 'âš  Could not assemble evidence pack: ' + e.message, false);
1009
  } finally {
1010
  if (btn) btn.disabled = false;
1011
  }
 
1020
 
1021
  </body>
1022
  </html>
1023
+
pages/chaski.html CHANGED
@@ -1,11 +1,11 @@
1
- <!DOCTYPE html>
2
- <!-- SPDX-License-Identifier: Apache-2.0 © 2026 Lutar, Stephen P. — SZL Holdings · Doctrine v13 -->
3
- <!-- CHASKI surface — reception/onboarding/first-touch organ. ADDITIVE per Doctrine v13 §2.1. -->
4
  <html lang="en">
5
  <head>
6
  <meta charset="utf-8"/>
7
  <meta name="viewport" content="width=device-width, initial-scale=1"/>
8
- <title>a11oy · Smart Routing — Intelligent Request Dispatch</title>
9
  <style>
10
  :root{--bg:#0b0d12;--panel:#12151d;--ink:#e7ecf3;--mut:#8a93a6;--acc:#7cc4ff;--ok:#54d18c;--warn:#ffcf5c;--bad:#ff6b6b;--line:#222838;--mono:'SF Mono',ui-monospace,'JetBrains Mono',Menlo,Consolas,monospace}
11
  *{box-sizing:border-box}
@@ -41,12 +41,12 @@ footer{margin-top:34px;border-top:1px solid var(--line);padding-top:14px;color:v
41
  <body>
42
  <div class="wrap">
43
  <div class="top">
44
- <div><span class="brand">a11oy</span> <span class="tag">· Reception &amp; Routing · Doctrine v13 §2.1</span></div>
45
  <div class="nav"><a href="/">home</a><a href="/chaski">routing</a><a href="/willay">willay</a><a href="/verify">verify</a></div>
46
  </div>
47
 
48
  <h1>Intelligent Request Routing</h1>
49
- <p class="sub">The a11oy reception layer: greets visitors, explains what a11oy does in one breath, and routes each request to the right capability by stated need. Routing factor: <code>exp(-κ·backpressure)·𝟙[routable] ∈ [0,1]</code> — the F7 admission gate (admissible multiplier: can only gate harder, never inflate utility).</p>
50
 
51
  <div class="scene"><canvas id="welcome3d" style="width:100%;height:100%;display:block;border-radius:12px"></canvas></div>
52
  <p class="mut" style="text-align:center;margin-top:-6px">The router delivers each visitor to the right capability node. Drag to orbit.</p>
@@ -56,36 +56,36 @@ footer{margin-top:34px;border-top:1px solid var(--line);padding-top:14px;color:v
56
  <div class="path">GET /api/a11oy/chaski/welcome</div>
57
  <button onclick="callWelcome()">Greet me</button>
58
  <div id="flags"></div>
59
- <pre id="welcomeout">— click to receive the first-touch greeting + flagship map —</pre>
60
  </div>
61
 
62
  <div class="card">
63
- <h3>Onboard — route by stated need</h3>
64
- <div class="path">GET /onboard/start · POST /onboard/step</div>
65
  <input id="need" placeholder="what do you want to do? e.g. 'sync data', 'fly a drone'" size="46"/>
66
- <button onclick="runOnboard()">Run onboarding → route me</button>
67
- <pre id="onboardout">— enter a need and the router will dispatch you, applying the reception gate —</pre>
68
  </div>
69
 
70
  <div class="card">
71
  <h3>First-touch heatmap (UX metrics)</h3>
72
  <div class="path">GET /api/a11oy/chaski/heatmap</div>
73
  <button onclick="callHeat()">Load heatmap</button>
74
- <pre id="heatout">— first-touch event counts, route distribution, completion rate, Khipu depth —</pre>
75
  </div>
76
 
77
  <div class="honest">
78
- <b>Honest labels (Doctrine v13 §5):</b> every routing action emits a <b>signed-receipt</b> (SHA3-256 hash-chain). The routing factor is an <b>admissible</b> multiplier ∈ [0,1] — it can only gate harder, never inflate utility. The memory-cortex sync courier is a distinct lower layer.
79
  </div>
80
 
81
- <footer>a11oy · reception &amp; routing layer · Doctrine v13 (additive over v12 / v11 LOCKED 749/14/163 · 13-axis · replay <code>bacf5443…631fc5</code>) · — Yachay</footer>
82
  </div>
83
 
84
  <script>
85
  const API='/api/a11oy/chaski';
86
  function show(id,o){document.getElementById(id).textContent=typeof o==='string'?o:JSON.stringify(o,null,2);}
87
  async function callWelcome(){try{const r=await fetch(API+'/welcome');const j=await r.json();show('welcomeout',j);
88
- document.getElementById('flags').innerHTML=Object.entries(j.flagships||{}).map(([k,v])=>`<span class="flag">${k} · ${v.organ}</span>`).join('');
89
  }catch(e){show('welcomeout','error: '+e);}}
90
  async function runOnboard(){try{const need=document.getElementById('need').value||'route an llm';
91
  const s=await(await fetch(API+'/onboard/start')).json();const sid=s.session_id;let last;
@@ -115,7 +115,7 @@ const body=new THREE.Mesh(new THREE.CapsuleGeometry(0.35,0.9,8,16),mat);scene.ad
115
  const head=new THREE.Mesh(new THREE.SphereGeometry(0.28,24,24),mat);head.position.y=0.95;scene.add(head);
116
  const glow=new THREE.Mesh(new THREE.SphereGeometry(0.16,16,16),new THREE.MeshStandardMaterial({color:0x54d18c,emissive:0x54d18c,emissiveIntensity:1.6}));glow.position.set(0.55,1.0,0);scene.add(glow);
117
  // Five flagship nodes arranged in an arc (the chaskiwasi the messenger runs between)
118
- const labels=['governed inference','agents','killinchu','observability','a11oy'];const nodes=[];
119
  labels.forEach((lab,i)=>{const a=(-0.9+i*0.45);const x=Math.sin(a)*3.4,z=Math.cos(a)*-1.0-1.0;
120
  const n=new THREE.Mesh(new THREE.IcosahedronGeometry(0.26,0),new THREE.MeshStandardMaterial({color:0xffcf5c,emissive:0x6b5410,emissiveIntensity:0.7}));
121
  n.position.set(x,0.2,z);scene.add(n);nodes.push(n);
@@ -127,3 +127,4 @@ size();window.addEventListener('resize',()=>{size();cam.aspect=canvas.clientWidt
127
  </script>
128
  </body>
129
  </html>
 
 
1
+ <!DOCTYPE html>
2
+ <!-- SPDX-License-Identifier: Apache-2.0 © 2026 Lutar, Stephen P. — SZL Holdings · Doctrine v13 -->
3
+ <!-- CHASKI surface — reception/onboarding/first-touch organ. ADDITIVE per Doctrine v13 §2.1. -->
4
  <html lang="en">
5
  <head>
6
  <meta charset="utf-8"/>
7
  <meta name="viewport" content="width=device-width, initial-scale=1"/>
8
+ <title>a11oy · Smart Routing — Intelligent Request Dispatch</title>
9
  <style>
10
  :root{--bg:#0b0d12;--panel:#12151d;--ink:#e7ecf3;--mut:#8a93a6;--acc:#7cc4ff;--ok:#54d18c;--warn:#ffcf5c;--bad:#ff6b6b;--line:#222838;--mono:'SF Mono',ui-monospace,'JetBrains Mono',Menlo,Consolas,monospace}
11
  *{box-sizing:border-box}
 
41
  <body>
42
  <div class="wrap">
43
  <div class="top">
44
+ <div><span class="brand">a11oy</span> <span class="tag">· Reception &amp; Routing · Doctrine v13 §2.1</span></div>
45
  <div class="nav"><a href="/">home</a><a href="/chaski">routing</a><a href="/willay">willay</a><a href="/verify">verify</a></div>
46
  </div>
47
 
48
  <h1>Intelligent Request Routing</h1>
49
+ <p class="sub">The a11oy reception layer: greets visitors, explains what a11oy does in one breath, and routes each request to the right capability by stated need. Routing factor: <code>exp(-κ·backpressure)·𝟙[routable] ∈ [0,1]</code> — the F7 admission gate (admissible multiplier: can only gate harder, never inflate utility).</p>
50
 
51
  <div class="scene"><canvas id="welcome3d" style="width:100%;height:100%;display:block;border-radius:12px"></canvas></div>
52
  <p class="mut" style="text-align:center;margin-top:-6px">The router delivers each visitor to the right capability node. Drag to orbit.</p>
 
56
  <div class="path">GET /api/a11oy/chaski/welcome</div>
57
  <button onclick="callWelcome()">Greet me</button>
58
  <div id="flags"></div>
59
+ <pre id="welcomeout">— click to receive the first-touch greeting + flagship map —</pre>
60
  </div>
61
 
62
  <div class="card">
63
+ <h3>Onboard — route by stated need</h3>
64
+ <div class="path">GET /onboard/start · POST /onboard/step</div>
65
  <input id="need" placeholder="what do you want to do? e.g. 'sync data', 'fly a drone'" size="46"/>
66
+ <button onclick="runOnboard()">Run onboarding → route me</button>
67
+ <pre id="onboardout">— enter a need and the router will dispatch you, applying the reception gate —</pre>
68
  </div>
69
 
70
  <div class="card">
71
  <h3>First-touch heatmap (UX metrics)</h3>
72
  <div class="path">GET /api/a11oy/chaski/heatmap</div>
73
  <button onclick="callHeat()">Load heatmap</button>
74
+ <pre id="heatout">— first-touch event counts, route distribution, completion rate, Khipu depth —</pre>
75
  </div>
76
 
77
  <div class="honest">
78
+ <b>Honest labels (Doctrine v13 §5):</b> every routing action emits a <b>signed-receipt</b> (SHA3-256 hash-chain). The routing factor is an <b>admissible</b> multiplier ∈ [0,1] — it can only gate harder, never inflate utility. The memory-cortex sync courier is a distinct lower layer.
79
  </div>
80
 
81
+ <footer>a11oy · reception &amp; routing layer · Doctrine v13 (additive over v12 / v11 LOCKED 749/14/163 · 13-axis · replay <code>bacf5443…631fc5</code>) · — Yachay</footer>
82
  </div>
83
 
84
  <script>
85
  const API='/api/a11oy/chaski';
86
  function show(id,o){document.getElementById(id).textContent=typeof o==='string'?o:JSON.stringify(o,null,2);}
87
  async function callWelcome(){try{const r=await fetch(API+'/welcome');const j=await r.json();show('welcomeout',j);
88
+ document.getElementById('flags').innerHTML=Object.entries(j.flagships||{}).map(([k,v])=>`<span class="flag">${k} · ${v.organ}</span>`).join('');
89
  }catch(e){show('welcomeout','error: '+e);}}
90
  async function runOnboard(){try{const need=document.getElementById('need').value||'route an llm';
91
  const s=await(await fetch(API+'/onboard/start')).json();const sid=s.session_id;let last;
 
115
  const head=new THREE.Mesh(new THREE.SphereGeometry(0.28,24,24),mat);head.position.y=0.95;scene.add(head);
116
  const glow=new THREE.Mesh(new THREE.SphereGeometry(0.16,16,16),new THREE.MeshStandardMaterial({color:0x54d18c,emissive:0x54d18c,emissiveIntensity:1.6}));glow.position.set(0.55,1.0,0);scene.add(glow);
117
  // Five flagship nodes arranged in an arc (the chaskiwasi the messenger runs between)
118
+ const labels=['governed execution','agents','killinchu','observability','a11oy'];const nodes=[];
119
  labels.forEach((lab,i)=>{const a=(-0.9+i*0.45);const x=Math.sin(a)*3.4,z=Math.cos(a)*-1.0-1.0;
120
  const n=new THREE.Mesh(new THREE.IcosahedronGeometry(0.26,0),new THREE.MeshStandardMaterial({color:0xffcf5c,emissive:0x6b5410,emissiveIntensity:0.7}));
121
  n.position.set(x,0.2,z);scene.add(n);nodes.push(n);
 
127
  </script>
128
  </body>
129
  </html>
130
+
pages/console.html CHANGED
The diff for this file is too large to render. See raw diff
 
pages/fabric.html CHANGED
@@ -1,8 +1,8 @@
1
- <!DOCTYPE html>
2
  <html lang="en"><head>
3
  <meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1">
4
- <title>Governed Distributed Compute Fabric · a11oy</title>
5
- <meta name="description" content="The Governed Distributed Compute Fabric — one unified system-of-systems view. Sovereign signal. Signed receipt. No node left dark. Sovereign GPU mesh under one governed router, honest TCP reachability, joules MEASURED per node, doctrine-locked. Terrestrial-proven core; orbital is a clearly-labeled ROADMAP frame. 0 runtime CDN.">
6
  <!-- SZL Estate shared modules (byte-identical cross-app), served in-image at /static/shared (0 CDN). -->
7
  <script src="/static/shared/szl_label_engine.js"></script>
8
  <script src="/static/shared/szl_holo3d.js"></script>
@@ -76,51 +76,51 @@ th{color:var(--mut);font-weight:600}
76
  <nav class="note"><a href="/">home</a><a href="/mesh">/mesh</a><a href="/wires">/wires</a><a href="/observability">/observability</a><a href="/holo">/holo</a></nav>
77
  <h1>Governed Distributed Compute Fabric</h1>
78
  <p class="sub" style="font-weight:700;color:var(--acc);margin-bottom:6px">Sovereign signal. Signed receipt. No node left dark.</p>
79
- <p class="sub">The <b>Governed Distributed Compute Fabric</b> as one unified system-of-systems view. Sovereign GPU mesh + honest TCP reachability + joules <b>MEASURED</b> per node + one governed OpenAI-compatible router + doctrine-locked provenance. <span class="hl">Terrestrial governed mesh is the proven core; orbital is a clearly-labeled ROADMAP frame.</span> Doctrine v11 · Λ = Conjecture 1 · 0 runtime CDN.</p>
80
- <p class="note" style="margin:0 0 14px">The fabric unites your sovereign nodes — each request governed by the trust score (Λ), recorded in the signed-receipt ledger, and relayed under one governed router — into a single honest system-of-systems.</p>
81
 
82
  <div class="card">
83
  <div style="display:flex;justify-content:space-between;align-items:center;flex-wrap:wrap;gap:10px">
84
- <div class="note">Live sources (no fabrication): <code>/api/a11oy/v1/compute-pool-hardened</code> · <code>/api/a11oy/v1/energy/operator/status</code> · <code>/api/a11oy/v1/honest</code> · <code>/api/a11oy/provenance</code> · <span class="hl">live-work</span> (K-Verify · Govern-RAG · cheapest-watt, each probed independently, honestly PENDING until deployed)</div>
85
- <button class="refresh" onclick="loadAll()">↻ refresh live</button>
86
  </div>
87
- <div class="stamp" id="stamp" style="margin-top:8px">loading live fabric state…</div>
88
  </div>
89
 
90
- <h2>1 · Fabric at a glance</h2>
91
  <div class="card">
92
- <div class="kpis" id="kpis"><div class="note">…</div></div>
93
- <p class="note" style="margin-top:14px">Every figure is honestly labeled. <b>Reachability</b> is a real TCP probe THIS sweep — a timeout/refusal is reachable=false with the reason, never fabricated. <b>Joules</b> are MEASURED only via the on-box exporter (nodes with no exporter read SAMPLE / 0). <b>Sovereign</b> is a property of owned hardware, passed through, never inferred from reachability.</p>
94
  </div>
95
 
96
- <h2>2 · Live work — the fabric DOES verifiable work</h2>
97
  <div class="card">
98
- <p class="note" style="margin:0 0 12px">The mesh does not just <i>prove it exists</i> — it does governed, receipted work. Three new capabilities surface here <b>as they go live</b>. Each tile probes its own endpoint independently via <code>Promise.allSettled</code>: a capability that is not yet deployed renders an honest <span style="color:var(--warn);font-weight:700">PENDING</span> with the reason — <b>never a fabricated result</b>.</p>
99
  <div class="work" id="work">
100
  <div class="wk" id="wk-kverify">
101
- <h3>K-Verify · governed inference</h3>
102
  <p class="cap">A signed inference run over <code>k-verify-benchmark-v1</code>: N items, pass-rate, joules MEASURED, and a receipt hash you can verify.</p>
103
- <div class="state" id="kv-state"><span class="pending">PENDING<span class="why">probing live endpoint…</span></span></div>
104
  </div>
105
  <div class="wk" id="wk-rag">
106
- <h3>Govern-RAG · ask the doctrine</h3>
107
  <p class="cap">Ask a question; the fabric answers <b>only</b> from its own governed corpus, with citations. No corpus hit = honest "insufficient grounding," never a guess.</p>
108
  <div class="qa" id="rag-qa" style="display:none">
109
  <input id="rag-q" type="text" placeholder="e.g. How many formulas are locked, and at what kernel?" autocomplete="off">
110
  <button id="rag-ask" type="button" onclick="askRag()">ask</button>
111
  </div>
112
- <div class="state" id="rag-state"><span class="pending">PENDING<span class="why">probing live endpoint…</span></span></div>
113
  </div>
114
  <div class="wk" id="wk-watt">
115
- <h3>Cheapest-watt routing · last decision</h3>
116
- <p class="cap">The governed router places each job on the lowest-€/MWh reachable node. Savings are labeled <b>honestly</b> — MEASURED only where a meter exists, else MODELED.</p>
117
- <div class="state" id="watt-state"><span class="pending">PENDING<span class="why">probing live endpoint…</span></span></div>
118
  </div>
119
  </div>
120
- <p class="note" style="margin-top:12px">Honesty contract: a tile only shows a <b>result</b> when its endpoint actually returned one this sweep. Joules are <b>MEASURED</b> only on the on-box exporter node; routing savings are <b>MEASURED</b> where a meter exists and <b>MODELED</b> (clearly labeled) otherwise. Receipts are <b>tamper-EVIDENT</b> (SHA3 hash-chain), not tamper-proof. No fused VRAM is implied by any "work" shown here — placement is horizontal.</p>
121
  </div>
122
 
123
- <h2>3 · System-of-systems mesh (3D)</h2>
124
  <div class="card">
125
  <div class="holo" id="holo"></div>
126
  <div class="legend">
@@ -129,47 +129,47 @@ th{color:var(--mut);font-weight:600}
129
  <span><span class="sw" style="background:#7aa2ff"></span>sovereign owned GPU/CPU</span>
130
  <span><span class="sw" style="background:#e0c060"></span>hosted-inference failover (non-sovereign)</span>
131
  </div>
132
- <p class="note" style="margin-top:12px"><b>Scaling model — honest:</b> nodes scale <span class="hl">horizontally (placement + load-balance)</span> under one governed router. VRAM does <b>NOT</b> merge across the network — there is <b>no fused/combined VRAM</b>. The router places each job on a reachable node; it does not pool memory across machines.</p>
133
  </div>
134
 
135
- <h2>4 · Nodes — honest per-node board</h2>
136
- <div class="nodegrid" id="nodes"><div class="note">…</div></div>
137
 
138
- <h2>5 · Energy — joules MEASURED, climbing</h2>
139
  <div class="card">
140
- <div class="kpis" id="energy"><div class="note">…</div></div>
141
  <table id="byNode" style="margin-top:14px"><tr><th>node</th><th>jobs</th><th>tokens</th><th>joules</th><th>label</th></tr></table>
142
- <p class="note" style="margin-top:12px">Joules are MEASURED via the on-box exporter (node <code id="expnode">betterwithage</code>). Nodes without a local exporter contribute SAMPLE jobs (joules unmeasured) — shown honestly, never imputed. Signed receipts fold into the signed-receipt ledger: <code>/api/a11oy/v1/energy/provenance</code>.</p>
143
  </div>
144
 
145
- <h2>6 · Governed router + provenance</h2>
146
  <div class="card">
147
  <div class="flow">
148
- <span class="node">request</span><span class="arr">→</span>
149
- <span class="node">governed router</span><span class="arr">→</span>
150
- <span class="node">placement (Λ-gated)</span><span class="arr">→</span>
151
- <span class="node">sovereign node / failover</span><span class="arr">→</span>
152
- <span class="node">signed receipt → ledger</span>
153
  </div>
154
- <div id="prov" class="note" style="margin-top:8px">…</div>
155
  </div>
156
 
157
  <div class="orbit">
158
  <div class="band">
159
- <span class="banner">Roadmap · orbital framing</span>
160
  <span id="orbitBadge"></span>
161
  </div>
162
- <h2 style="margin-top:6px">7 · Orbital system-of-systems — ROADMAP / analogy (we do NOT run satellites)</h2>
163
- <p class="note">The same governance primitives the terrestrial mesh PROVES on real metal — honest reachability, joules MEASURED per node, Λ-gated placement, signed-receipt provenance — are exactly what distributed / edge / <b>orbital</b> compute system-of-systems will require. <span style="color:#cdb4ff;font-weight:700">This band is the vision frame, clearly labeled ROADMAP.</span> SZL does <b>not</b> operate satellites; nothing in the mesh above is orbital. We prove on terrestrial metal what the orbital-architecture crowd only asserts.</p>
164
  <div class="kpis" id="orbit">
165
- <div class="kpi"><div class="k">Terrestrial governed mesh</div><div class="v" id="orbReach">—</div><div class="l" id="orbReachL"></div></div>
166
  <div class="kpi"><div class="k">Per-node energy accounting</div><div class="v">joules</div><div class="l" id="orbJ"></div></div>
167
  <div class="kpi"><div class="k">Edge / orbital placement</div><div class="v">vision</div><div class="l" id="orbRm"></div></div>
168
  </div>
169
  </div>
170
 
171
  <div class="foot" id="foot">
172
- HONEST: all numbers above carry an explicit label — LIVE (real backend wired) · MEASURED (on-box exporter) · MODELED (deterministic, labeled) · ROADMAP (vision, not deployed). No fused/combined VRAM is claimed anywhere — nodes scale horizontally (placement + load-balance); memory does not merge across the network. The <b>live-work</b> tiles surface a capability only when its endpoint returns a real result this sweep; otherwise they render an honest PENDING and never fabricate. Orbital is analogy/ROADMAP; SZL does not run satellites. Reachability is a real TCP probe, never fabricated. trust &lt; 100% · tamper-EVIDENT not tamper-proof · Λ = Conjecture 1 · locked = 8 {F1,F4,F7,F11,F12,F18,F19,F22} @ kernel <code id="kernel">c7c0ba17</code> (749/14/163). SLSA L1 honest · L2 attested · L3 roadmap. Canonical numbers <a href="https://github.com/szl-holdings/.github/blob/main/.github/data/lean_numbers.json" target="_blank" rel="noopener">lean_numbers.json</a>.
173
  </div>
174
  </div>
175
 
@@ -177,16 +177,16 @@ HONEST: all numbers above carry an explicit label — LIVE (real backend wired)
177
  "use strict";
178
  var L = (window.SZLLabels && window.SZLLabels.badgeHTML) ? function(k,t){ return window.SZLLabels.badgeHTML(k, t?{label:t}:undefined); } : function(k,t){ return '<span class="szl-pill">'+(t||k)+'</span>'; };
179
  function $(id){ return document.getElementById(id); }
180
- function fmt(n){ if(n==null||isNaN(n)) return '—'; return Number(n).toLocaleString('en-US',{maximumFractionDigits:0}); }
181
- function fmt1(n){ if(n==null||isNaN(n)) return '—'; return Number(n).toLocaleString('en-US',{maximumFractionDigits:1}); }
182
  async function getJSON(url){ var r = await fetch(url, {headers:{'accept':'application/json'}}); if(!r.ok) throw new Error(url+' HTTP '+r.status); return r.json(); }
183
 
184
  var holoScene = null;
185
  function buildHolo(pool){
186
  var mount = $('holo');
187
- if(!window.SZLHolo || !window.SZLHolo.Scene){ mount.innerHTML = '<p class="note" style="padding:18px">3D kit unavailable — node board below carries the full honest state.</p>'; return; }
188
  mount.innerHTML = '';
189
- // λ here is a presentation parameter (Conjecture 1, <1.0), NOT a measured value.
190
  holoScene = new window.SZLHolo.Scene(mount, { title: 'GOVERNED DISTRIBUTED COMPUTE FABRIC', lambda: 0.42, autoRotate: true });
191
  var nodes = (pool.nodes||[]);
192
  // hub = the governed router (the host running this service / hetzner-box-cpu self node anchors center)
@@ -197,7 +197,7 @@ function buildHolo(pool){
197
  var y = (n.kind === 'hosted-inference') ? 0.55 : -0.25; // failover ring sits above
198
  specNodes.push({
199
  id: n.name,
200
- label: n.name + (n.reachable ? ' ✓' : ' ✕'),
201
  pos: [R*Math.cos(ang), y, R*Math.sin(ang)],
202
  // lower lambda => greener/larger (more trust); reachable+sovereign = most trusted
203
  lambda: n.reachable ? (n.sovereign ? 0.22 : 0.40) : 0.80
@@ -246,7 +246,7 @@ function renderNodes(pool, energy){
246
  '<div class="row">'+reach+'</div>'+
247
  '<div class="row">'+sov+'</div>'+
248
  '<div class="joule">energy: '+jVal+' &nbsp;'+jLabel+
249
- (bn.jobs!=null ? ' &nbsp;<span class="muted-num">· '+fmt(bn.jobs)+' jobs · '+fmt(bn.tokens)+' tok</span>' : '')+
250
  '</div></div>';
251
  });
252
  $('nodes').innerHTML = html;
@@ -258,7 +258,7 @@ function renderEnergy(energy){
258
  html += kpi('Measured token-joules', fmt(energy.measured_token_joules), L('MEASURED'));
259
  html += kpi('Measured jobs', fmt(energy.measured_jobs), L('MEASURED'));
260
  html += kpi('Sample jobs (unmeasured)', fmt(energy.sample_jobs), L('SAMPLE'));
261
- html += kpi('Grid price', fmt1(energy.grid_price_eur_mwh)+' €/MWh', L('LIVE'));
262
  html += kpi('Power sample', fmt1(energy.power_w_sample)+' W', L('SAMPLE'));
263
  $('energy').innerHTML = html;
264
  if(energy.exporter_node) $('expnode').textContent = energy.exporter_node;
@@ -275,12 +275,12 @@ function renderProv(prov, honest){
275
  var slsa = (honest && honest.footer) ? '' : '';
276
  var dl = (honest && honest.doctrine_lock) || {};
277
  var html = '';
278
- html += '<p>SLSA: <b>'+(prov.slsa||'L1')+'</b> — L1 honest · L2 attested · L3 roadmap. '+L('LIVE')+' &nbsp; Λ = '+(dl.lambda||'Conjecture 1')+' '+L('LIVE','CONJECTURE 1')+'</p>';
279
  if(prov.khipu_dsse){
280
- html += '<p>Provenance per answer: signed-receipt substrate · keyid <code>'+(prov.khipu_dsse.keyid||'?')+'</code> · verify at <code>'+(prov.khipu_dsse.verify_endpoint||'/api/a11oy/v1/govern/verify')+'</code>. tamper-EVIDENT (SHA3-256 hash-chain), not tamper-proof.</p>';
281
  }
282
  if(dl.locked_formula_ids){
283
- html += '<p>Doctrine lock: <code>'+(dl.declarations||749)+'/'+(dl.axioms||14)+'/'+(dl.sorries||163)+'</code> @ kernel <code>'+(dl.commit||'c7c0ba17')+'</code> · locked = '+(dl.locked_formula_count||8)+' {'+(dl.locked_formula_ids||[]).join(',')+'} '+L('LIVE')+'</p>';
284
  if(dl.commit) $('kernel').textContent = dl.commit;
285
  }
286
  $('prov').innerHTML = html;
@@ -288,7 +288,7 @@ function renderProv(prov, honest){
288
 
289
  function renderOrbit(pool, energy){
290
  var c = pool.counts || {};
291
- $('orbitBadge').innerHTML = L('ROADMAP','VISION FRAME — NOT DEPLOYED');
292
  $('orbReach').textContent = fmt(c.nodes_reachable) + '/' + fmt(c.nodes_total);
293
  $('orbReachL').innerHTML = L('LIVE','PROVEN ON METAL');
294
  $('orbJ').innerHTML = L('MEASURED','PER-NODE, REAL');
@@ -296,7 +296,7 @@ function renderOrbit(pool, energy){
296
  }
297
 
298
  // ---- Live-work panel: probe each new capability honestly; render result OR honest PENDING ----
299
- // Candidate endpoint lists — siblings (PowerD1-D4) may ship under any of these.
300
  // We take the FIRST that returns valid JSON this sweep; if none do, we render PENDING.
301
  var KV_EPS = ['/api/a11oy/v1/kverify/summary','/api/a11oy/v1/kverify/status','/api/a11oy/v1/k-verify/summary','/api/a11oy/v1/k-verify/status','/api/a11oy/v1/verify/run/last','/api/a11oy/v1/kverify/last'];
302
  var RAG_EPS = ['/api/a11oy/v1/rag/status','/api/a11oy/v1/rag/last','/api/a11oy/v1/govern-rag/status','/api/a11oy/rag/status','/api/a11oy/v1/rag/health'];
@@ -304,8 +304,8 @@ var WATT_EPS = ['/api/a11oy/v1/energy/cheapest-watt','/api/a11oy/v1/routing/chea
304
  var RAG_ASK_EPS = ['/api/a11oy/v1/rag/query','/api/a11oy/v1/rag/ask','/api/a11oy/v1/govern-rag/ask','/api/a11oy/rag/query'];
305
  var RAG_ASK_URL = null; // resolved once a status probe identifies a live RAG surface
306
 
307
- function pendingHTML(why){ return '<span class="pending">PENDING<span class="why">'+(why||'endpoint not yet live — shown honestly, not fabricated')+'</span></span>'; }
308
- function shortHash(h){ if(!h) return null; h=String(h); return h.length>20 ? h.slice(0,10)+'…'+h.slice(-6) : h; }
309
 
310
  // Try a list of endpoints; resolve with {url,data} of the first that returns ok JSON, else null.
311
  async function firstLive(urls){
@@ -319,12 +319,12 @@ function renderKVerify(hit){
319
  if(!hit){ el.innerHTML = pendingHTML('K-Verify endpoint not live this sweep'); return false; }
320
  var d = hit.data || {};
321
  // Honest idle state: endpoint is LIVE but no run has executed yet this process.
322
- // Surface that truthfully — never synthesize a zero-item "run" that didn't happen.
323
  var runData = d.run || d.last_run || d.summary || d;
324
  var hasRun = (d.ran === true) || (d.ran == null && (runData.n!=null || runData.count!=null || runData.items!=null || runData.total!=null || runData.pass!=null));
325
  if(!hasRun){
326
- el.innerHTML = '<div class="sub2"><b>endpoint live</b> '+L('LIVE','GOVERNED INFERENCE')+'</div>'+
327
- '<div class="sub2">no run yet this process — a signed run posts N items, pass-rate, joules MEASURED + a receipt hash. Shown honestly: no fabricated run.</div>';
328
  return true;
329
  }
330
  d = runData;
@@ -336,20 +336,20 @@ function renderKVerify(hit){
336
  var rh = d.receipt_hash || d.receipt || d.digest || (d.receipt_digest) || ((d.khipu&&d.khipu.hash)||null);
337
  var verify= d.verify_endpoint || d.receipt_verify_at || '/api/a11oy/khipu/verify';
338
  if(rate==null && typeof pass==='number' && typeof n==='number' && n>0) rate = pass/n;
339
- var passStr = (typeof pass==='number' && typeof n==='number') ? (fmt(pass)+'/'+fmt(n)) : (n!=null?fmt(n)+' items':'—');
340
- var rateStr = (typeof rate==='number') ? (' · '+(rate*100).toFixed(1)+'% pass') : '';
341
  var html = '<div class="big">'+passStr+'</div>';
342
  html += '<div class="sub2">items run / passed'+rateStr+'</div>';
343
- html += '<hr><div class="sub2">energy: <b>'+(joules!=null?fmt(joules)+' J':'—')+'</b> '+(jmeas?L('MEASURED'):L('SAMPLE'))+'</div>';
344
  if(rh){ html += '<div class="receipt">receipt '+shortHash(rh)+'</div>'; html += '<div class="sub2">verify: <code>'+verify+'</code> '+L('LIVE')+'</div>'; }
345
- html += '<div class="lbls">'+L('LIVE','GOVERNED INFERENCE')+'</div>';
346
  el.innerHTML = html;
347
  return true;
348
  }
349
 
350
  function renderRag(hit){
351
  var el = $('rag-state'); var qa = $('rag-qa');
352
- if(!hit){ qa.style.display='none'; el.innerHTML = pendingHTML('Govern-RAG endpoint not live this sweep — ask-box activates when it is'); RAG_ASK_URL=null; return false; }
353
  var d = hit.data || {};
354
  // Resolve an ask URL: explicit field, sibling of the status path, or default candidate.
355
  RAG_ASK_URL = d.query_endpoint || d.ask_endpoint || hit.url.replace(/\/(status|health|last)$/,'/query') || RAG_ASK_EPS[0];
@@ -365,14 +365,14 @@ function renderRag(hit){
365
  if(chunks!=null) stat.push(fmt(chunks)+' chunks');
366
  if(files!=null) stat.push(fmt(files)+' files');
367
  if(repos!=null) stat.push(fmt(repos)+' repos');
368
- var html = '<div class="sub2">governed corpus indexed: <b>'+(stat.length?stat.join(' · '):'ready')+'</b> '+L('LIVE')+'</div>';
369
  // Only show a 'last answer' if it carries a real grounded answer string (status citations are not answers).
370
  if(lastA && typeof lastA==='string'){
371
  html += '<div class="ans">'+(lastQ?'<b>Q:</b> '+escapeHTML(lastQ)+'<br>':'')+'<b>A:</b> '+escapeHTML(String(lastA))+'</div>';
372
- if(cites && cites.length){ html += '<div class="cite">cited: '+cites.map(function(c){ return escapeHTML(typeof c==='string'?c:(c.citation||c.path||c.source||c.id||c.doc||JSON.stringify(c))); }).join(' · ')+'</div>'; }
373
  html += '<div class="lbls">'+L('LIVE','GROUNDED + CITED')+'</div>';
374
  } else {
375
- html += '<div class="sub2">Ask the doctrine — answers come only from the governed corpus, with citations; off-corpus returns insufficient grounding.</div>';
376
  }
377
  el.innerHTML = html;
378
  return true;
@@ -383,7 +383,7 @@ async function askRag(){
383
  var btn = $('rag-ask'); var el = $('rag-state');
384
  if(!q){ return; }
385
  if(!RAG_ASK_URL){ el.innerHTML = pendingHTML('RAG query endpoint not live'); return; }
386
- btn.disabled = true; var prev = el.innerHTML; el.innerHTML = '<div class="sub2">asking the governed corpus…</div>';
387
  try {
388
  var r = await fetch(RAG_ASK_URL, {method:'POST', headers:{'content-type':'application/json','accept':'application/json'}, body: JSON.stringify({question:q, query:q})});
389
  if(!r.ok) throw new Error('HTTP '+r.status);
@@ -394,10 +394,10 @@ async function askRag(){
394
  var html = '';
395
  if(grounded){
396
  html += '<div class="ans"><b>Q:</b> '+escapeHTML(q)+'<br><b>A:</b> '+escapeHTML(String(ans))+'</div>';
397
- if(cites && cites.length){ html += '<div class="cite">cited: '+cites.map(function(c){ return escapeHTML(typeof c==='string'?c:(c.id||c.source||c.doc||JSON.stringify(c))); }).join(' · ')+'</div>'; }
398
  html += '<div class="lbls">'+L('LIVE','GROUNDED + CITED')+'</div>';
399
  } else {
400
- html += '<div class="ans"><b>Q:</b> '+escapeHTML(q)+'<br><b>A:</b> insufficient grounding in the governed corpus — no answer returned.</div>';
401
  html += '<div class="lbls">'+L('LIVE','HONEST: NO GUESS')+'</div>';
402
  }
403
  el.innerHTML = html;
@@ -421,21 +421,21 @@ function renderWatt(hit){
421
  var reason = dec.reason || dec.detail || null;
422
  var chHead = (d.chain && d.chain.head) || dec.receipt_hash || dec.receipt || dec.digest || null;
423
  var html = '';
424
- html += '<div class="big">'+(price!=null?fmt1(price)+' €/MWh':'—')+'</div>';
425
  html += '<div class="sub2">live grid price at decision '+(priceL==='MEASURED'?L('MEASURED'):L('LIVE'))+'</div>';
426
  if(node){
427
- html += '<hr><div class="sub2">chosen node: <b>'+escapeHTML(node)+'</b> '+L('LIVE','LOWEST-€ REACHABLE')+'</div>';
428
  if(save!=null){
429
  var sv = (typeof save==='number') ? ((save<=1?(save*100):save).toFixed(1)+'%') : escapeHTML(String(save));
430
  var lk = (saveLabel==='MEASURED') ? L('MEASURED') : L('MODELED','ROUTING LAW');
431
  html += '<div class="sub2">honest savings vs most-expensive comparable: <b>'+sv+'</b> '+lk+'</div>';
432
  }
433
  } else {
434
- // No placement this tick is an HONEST outcome, not a gap — surface the reason verbatim.
435
  html += '<hr><div class="sub2"><b>no placement this tick</b> '+L('LIVE','HONEST: NO FABRICATED SAVING')+'</div>';
436
  if(reason) html += '<div class="sub2">'+escapeHTML(reason)+'</div>';
437
  }
438
- if(chHead){ html += '<div class="receipt">receipt-chain '+shortHash(chHead)+(d.chain&&d.chain.length!=null?' · len '+fmt(d.chain.length):'')+'</div>'; }
439
  el.innerHTML = html;
440
  return true;
441
  }
@@ -455,7 +455,7 @@ async function loadWork(){
455
  }
456
 
457
  async function loadAll(){
458
- $('stamp').textContent = 'fetching live fabric state…';
459
  try {
460
  var results = await Promise.allSettled([
461
  getJSON('/api/a11oy/v1/compute-pool-hardened'),
@@ -481,9 +481,9 @@ async function loadAll(){
481
 
482
  var errs = results.filter(function(r){return r.status==='rejected';});
483
  var ts = pool.cached_at || new Date().toISOString();
484
- $('stamp').innerHTML = 'live as of <code>'+ts+'</code> · '+L('LIVE','4 ENDPOINTS WIRED') +
485
- ' · live work: <b>'+workLive+'/3</b> capabilities surfaced'+(workLive<3?' <span class="note">('+(3-workLive)+' honestly PENDING)</span>':'') +
486
- (errs.length ? ' <span class="err">· '+errs.length+' source(s) unavailable (shown honestly empty)</span>' : '');
487
  } catch(e){
488
  $('stamp').innerHTML = '<span class="err">fabric load error: '+e+'</span>';
489
  }
@@ -491,3 +491,4 @@ async function loadAll(){
491
  loadAll();
492
  </script>
493
  </body></html>
 
 
1
+ <!DOCTYPE html>
2
  <html lang="en"><head>
3
  <meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1">
4
+ <title>Governed Distributed Compute Fabric · a11oy</title>
5
+ <meta name="description" content="The Governed Distributed Compute Fabric — one unified system-of-systems view. Sovereign signal. Signed receipt. No node left dark. Sovereign GPU mesh under one governed router, honest TCP reachability, joules MEASURED per node, doctrine-locked. Terrestrial-proven core; orbital is a clearly-labeled ROADMAP frame. 0 runtime CDN.">
6
  <!-- SZL Estate shared modules (byte-identical cross-app), served in-image at /static/shared (0 CDN). -->
7
  <script src="/static/shared/szl_label_engine.js"></script>
8
  <script src="/static/shared/szl_holo3d.js"></script>
 
76
  <nav class="note"><a href="/">home</a><a href="/mesh">/mesh</a><a href="/wires">/wires</a><a href="/observability">/observability</a><a href="/holo">/holo</a></nav>
77
  <h1>Governed Distributed Compute Fabric</h1>
78
  <p class="sub" style="font-weight:700;color:var(--acc);margin-bottom:6px">Sovereign signal. Signed receipt. No node left dark.</p>
79
+ <p class="sub">The <b>Governed Distributed Compute Fabric</b> as one unified system-of-systems view. Sovereign GPU mesh + honest TCP reachability + joules <b>MEASURED</b> per node + one governed OpenAI-compatible router + doctrine-locked provenance. <span class="hl">Terrestrial governed mesh is the proven core; orbital is a clearly-labeled ROADMAP frame.</span> Doctrine v11 · Λ = Conjecture 1 · 0 runtime CDN.</p>
80
+ <p class="note" style="margin:0 0 14px">The fabric unites your sovereign nodes — each request governed by the trust score (Λ), recorded in the signed-receipt ledger, and relayed under one governed router — into a single honest system-of-systems.</p>
81
 
82
  <div class="card">
83
  <div style="display:flex;justify-content:space-between;align-items:center;flex-wrap:wrap;gap:10px">
84
+ <div class="note">Live sources (no fabrication): <code>/api/a11oy/v1/compute-pool-hardened</code> · <code>/api/a11oy/v1/energy/operator/status</code> · <code>/api/a11oy/v1/honest</code> · <code>/api/a11oy/provenance</code> · <span class="hl">live-work</span> (K-Verify · Govern-RAG · cheapest-watt, each probed independently, honestly PENDING until deployed)</div>
85
+ <button class="refresh" onclick="loadAll()">↻ refresh live</button>
86
  </div>
87
+ <div class="stamp" id="stamp" style="margin-top:8px">loading live fabric state…</div>
88
  </div>
89
 
90
+ <h2>1 · Fabric at a glance</h2>
91
  <div class="card">
92
+ <div class="kpis" id="kpis"><div class="note">…</div></div>
93
+ <p class="note" style="margin-top:14px">Every figure is honestly labeled. <b>Reachability</b> is a real TCP probe THIS sweep — a timeout/refusal is reachable=false with the reason, never fabricated. <b>Joules</b> are MEASURED only via the on-box exporter (nodes with no exporter read SAMPLE / 0). <b>Sovereign</b> is a property of owned hardware, passed through, never inferred from reachability.</p>
94
  </div>
95
 
96
+ <h2>2 · Live work — the fabric DOES verifiable work</h2>
97
  <div class="card">
98
+ <p class="note" style="margin:0 0 12px">The mesh does not just <i>prove it exists</i> — it does governed, receipted work. Three new capabilities surface here <b>as they go live</b>. Each tile probes its own endpoint independently via <code>Promise.allSettled</code>: a capability that is not yet deployed renders an honest <span style="color:var(--warn);font-weight:700">PENDING</span> with the reason — <b>never a fabricated result</b>.</p>
99
  <div class="work" id="work">
100
  <div class="wk" id="wk-kverify">
101
+ <h3>K-Verify · governed execution</h3>
102
  <p class="cap">A signed inference run over <code>k-verify-benchmark-v1</code>: N items, pass-rate, joules MEASURED, and a receipt hash you can verify.</p>
103
+ <div class="state" id="kv-state"><span class="pending">PENDING<span class="why">probing live endpoint…</span></span></div>
104
  </div>
105
  <div class="wk" id="wk-rag">
106
+ <h3>Govern-RAG · ask the doctrine</h3>
107
  <p class="cap">Ask a question; the fabric answers <b>only</b> from its own governed corpus, with citations. No corpus hit = honest "insufficient grounding," never a guess.</p>
108
  <div class="qa" id="rag-qa" style="display:none">
109
  <input id="rag-q" type="text" placeholder="e.g. How many formulas are locked, and at what kernel?" autocomplete="off">
110
  <button id="rag-ask" type="button" onclick="askRag()">ask</button>
111
  </div>
112
+ <div class="state" id="rag-state"><span class="pending">PENDING<span class="why">probing live endpoint…</span></span></div>
113
  </div>
114
  <div class="wk" id="wk-watt">
115
+ <h3>Cheapest-watt routing · last decision</h3>
116
+ <p class="cap">The governed router places each job on the lowest-€/MWh reachable node. Savings are labeled <b>honestly</b> — MEASURED only where a meter exists, else MODELED.</p>
117
+ <div class="state" id="watt-state"><span class="pending">PENDING<span class="why">probing live endpoint…</span></span></div>
118
  </div>
119
  </div>
120
+ <p class="note" style="margin-top:12px">Honesty contract: a tile only shows a <b>result</b> when its endpoint actually returned one this sweep. Joules are <b>MEASURED</b> only on the on-box exporter node; routing savings are <b>MEASURED</b> where a meter exists and <b>MODELED</b> (clearly labeled) otherwise. Receipts are <b>tamper-EVIDENT</b> (SHA3 hash-chain), not tamper-proof. No fused VRAM is implied by any "work" shown here — placement is horizontal.</p>
121
  </div>
122
 
123
+ <h2>3 · System-of-systems mesh (3D)</h2>
124
  <div class="card">
125
  <div class="holo" id="holo"></div>
126
  <div class="legend">
 
129
  <span><span class="sw" style="background:#7aa2ff"></span>sovereign owned GPU/CPU</span>
130
  <span><span class="sw" style="background:#e0c060"></span>hosted-inference failover (non-sovereign)</span>
131
  </div>
132
+ <p class="note" style="margin-top:12px"><b>Scaling model — honest:</b> nodes scale <span class="hl">horizontally (placement + load-balance)</span> under one governed router. VRAM does <b>NOT</b> merge across the network — there is <b>no fused/combined VRAM</b>. The router places each job on a reachable node; it does not pool memory across machines.</p>
133
  </div>
134
 
135
+ <h2>4 · Nodes — honest per-node board</h2>
136
+ <div class="nodegrid" id="nodes"><div class="note">…</div></div>
137
 
138
+ <h2>5 · Energy — joules MEASURED, climbing</h2>
139
  <div class="card">
140
+ <div class="kpis" id="energy"><div class="note">…</div></div>
141
  <table id="byNode" style="margin-top:14px"><tr><th>node</th><th>jobs</th><th>tokens</th><th>joules</th><th>label</th></tr></table>
142
+ <p class="note" style="margin-top:12px">Joules are MEASURED via the on-box exporter (node <code id="expnode">betterwithage</code>). Nodes without a local exporter contribute SAMPLE jobs (joules unmeasured) — shown honestly, never imputed. Signed receipts fold into the signed-receipt ledger: <code>/api/a11oy/v1/energy/provenance</code>.</p>
143
  </div>
144
 
145
+ <h2>6 · Governed router + provenance</h2>
146
  <div class="card">
147
  <div class="flow">
148
+ <span class="node">request</span><span class="arr">→</span>
149
+ <span class="node">governed router</span><span class="arr">→</span>
150
+ <span class="node">placement (Λ-gated)</span><span class="arr">→</span>
151
+ <span class="node">sovereign node / failover</span><span class="arr">→</span>
152
+ <span class="node">signed receipt → ledger</span>
153
  </div>
154
+ <div id="prov" class="note" style="margin-top:8px">…</div>
155
  </div>
156
 
157
  <div class="orbit">
158
  <div class="band">
159
+ <span class="banner">Roadmap · orbital framing</span>
160
  <span id="orbitBadge"></span>
161
  </div>
162
+ <h2 style="margin-top:6px">7 · Orbital system-of-systems — ROADMAP / analogy (we do NOT run satellites)</h2>
163
+ <p class="note">The same governance primitives the terrestrial mesh PROVES on real metal — honest reachability, joules MEASURED per node, Λ-gated placement, signed-receipt provenance — are exactly what distributed / edge / <b>orbital</b> compute system-of-systems will require. <span style="color:#cdb4ff;font-weight:700">This band is the vision frame, clearly labeled ROADMAP.</span> SZL does <b>not</b> operate satellites; nothing in the mesh above is orbital. We prove on terrestrial metal what the orbital-architecture crowd only asserts.</p>
164
  <div class="kpis" id="orbit">
165
+ <div class="kpi"><div class="k">Terrestrial governed mesh</div><div class="v" id="orbReach">—</div><div class="l" id="orbReachL"></div></div>
166
  <div class="kpi"><div class="k">Per-node energy accounting</div><div class="v">joules</div><div class="l" id="orbJ"></div></div>
167
  <div class="kpi"><div class="k">Edge / orbital placement</div><div class="v">vision</div><div class="l" id="orbRm"></div></div>
168
  </div>
169
  </div>
170
 
171
  <div class="foot" id="foot">
172
+ HONEST: all numbers above carry an explicit label — LIVE (real backend wired) · MEASURED (on-box exporter) · MODELED (deterministic, labeled) · ROADMAP (vision, not deployed). No fused/combined VRAM is claimed anywhere — nodes scale horizontally (placement + load-balance); memory does not merge across the network. The <b>live-work</b> tiles surface a capability only when its endpoint returns a real result this sweep; otherwise they render an honest PENDING and never fabricate. Orbital is analogy/ROADMAP; SZL does not run satellites. Reachability is a real TCP probe, never fabricated. trust &lt; 100% · tamper-EVIDENT not tamper-proof · Λ = Conjecture 1 · locked = 8 {F1,F4,F7,F11,F12,F18,F19,F22} @ kernel <code id="kernel">c7c0ba17</code> (749/14/163). SLSA L1 honest · L2 attested · L3 roadmap. Canonical numbers <a href="https://github.com/szl-holdings/.github/blob/main/.github/data/lean_numbers.json" target="_blank" rel="noopener">lean_numbers.json</a>.
173
  </div>
174
  </div>
175
 
 
177
  "use strict";
178
  var L = (window.SZLLabels && window.SZLLabels.badgeHTML) ? function(k,t){ return window.SZLLabels.badgeHTML(k, t?{label:t}:undefined); } : function(k,t){ return '<span class="szl-pill">'+(t||k)+'</span>'; };
179
  function $(id){ return document.getElementById(id); }
180
+ function fmt(n){ if(n==null||isNaN(n)) return '—'; return Number(n).toLocaleString('en-US',{maximumFractionDigits:0}); }
181
+ function fmt1(n){ if(n==null||isNaN(n)) return '—'; return Number(n).toLocaleString('en-US',{maximumFractionDigits:1}); }
182
  async function getJSON(url){ var r = await fetch(url, {headers:{'accept':'application/json'}}); if(!r.ok) throw new Error(url+' HTTP '+r.status); return r.json(); }
183
 
184
  var holoScene = null;
185
  function buildHolo(pool){
186
  var mount = $('holo');
187
+ if(!window.SZLHolo || !window.SZLHolo.Scene){ mount.innerHTML = '<p class="note" style="padding:18px">3D kit unavailable — node board below carries the full honest state.</p>'; return; }
188
  mount.innerHTML = '';
189
+ // λ here is a presentation parameter (Conjecture 1, <1.0), NOT a measured value.
190
  holoScene = new window.SZLHolo.Scene(mount, { title: 'GOVERNED DISTRIBUTED COMPUTE FABRIC', lambda: 0.42, autoRotate: true });
191
  var nodes = (pool.nodes||[]);
192
  // hub = the governed router (the host running this service / hetzner-box-cpu self node anchors center)
 
197
  var y = (n.kind === 'hosted-inference') ? 0.55 : -0.25; // failover ring sits above
198
  specNodes.push({
199
  id: n.name,
200
+ label: n.name + (n.reachable ? ' ✓' : ' ✕'),
201
  pos: [R*Math.cos(ang), y, R*Math.sin(ang)],
202
  // lower lambda => greener/larger (more trust); reachable+sovereign = most trusted
203
  lambda: n.reachable ? (n.sovereign ? 0.22 : 0.40) : 0.80
 
246
  '<div class="row">'+reach+'</div>'+
247
  '<div class="row">'+sov+'</div>'+
248
  '<div class="joule">energy: '+jVal+' &nbsp;'+jLabel+
249
+ (bn.jobs!=null ? ' &nbsp;<span class="muted-num">· '+fmt(bn.jobs)+' jobs · '+fmt(bn.tokens)+' tok</span>' : '')+
250
  '</div></div>';
251
  });
252
  $('nodes').innerHTML = html;
 
258
  html += kpi('Measured token-joules', fmt(energy.measured_token_joules), L('MEASURED'));
259
  html += kpi('Measured jobs', fmt(energy.measured_jobs), L('MEASURED'));
260
  html += kpi('Sample jobs (unmeasured)', fmt(energy.sample_jobs), L('SAMPLE'));
261
+ html += kpi('Grid price', fmt1(energy.grid_price_eur_mwh)+' €/MWh', L('LIVE'));
262
  html += kpi('Power sample', fmt1(energy.power_w_sample)+' W', L('SAMPLE'));
263
  $('energy').innerHTML = html;
264
  if(energy.exporter_node) $('expnode').textContent = energy.exporter_node;
 
275
  var slsa = (honest && honest.footer) ? '' : '';
276
  var dl = (honest && honest.doctrine_lock) || {};
277
  var html = '';
278
+ html += '<p>SLSA: <b>'+(prov.slsa||'L1')+'</b> — L1 honest · L2 attested · L3 roadmap. '+L('LIVE')+' &nbsp; Λ = '+(dl.lambda||'Conjecture 1')+' '+L('LIVE','CONJECTURE 1')+'</p>';
279
  if(prov.khipu_dsse){
280
+ html += '<p>Provenance per answer: signed-receipt substrate · keyid <code>'+(prov.khipu_dsse.keyid||'?')+'</code> · verify at <code>'+(prov.khipu_dsse.verify_endpoint||'/api/a11oy/v1/govern/verify')+'</code>. tamper-EVIDENT (SHA3-256 hash-chain), not tamper-proof.</p>';
281
  }
282
  if(dl.locked_formula_ids){
283
+ html += '<p>Doctrine lock: <code>'+(dl.declarations||749)+'/'+(dl.axioms||14)+'/'+(dl.sorries||163)+'</code> @ kernel <code>'+(dl.commit||'c7c0ba17')+'</code> · locked = '+(dl.locked_formula_count||8)+' {'+(dl.locked_formula_ids||[]).join(',')+'} '+L('LIVE')+'</p>';
284
  if(dl.commit) $('kernel').textContent = dl.commit;
285
  }
286
  $('prov').innerHTML = html;
 
288
 
289
  function renderOrbit(pool, energy){
290
  var c = pool.counts || {};
291
+ $('orbitBadge').innerHTML = L('ROADMAP','VISION FRAME — NOT DEPLOYED');
292
  $('orbReach').textContent = fmt(c.nodes_reachable) + '/' + fmt(c.nodes_total);
293
  $('orbReachL').innerHTML = L('LIVE','PROVEN ON METAL');
294
  $('orbJ').innerHTML = L('MEASURED','PER-NODE, REAL');
 
296
  }
297
 
298
  // ---- Live-work panel: probe each new capability honestly; render result OR honest PENDING ----
299
+ // Candidate endpoint lists — siblings (PowerD1-D4) may ship under any of these.
300
  // We take the FIRST that returns valid JSON this sweep; if none do, we render PENDING.
301
  var KV_EPS = ['/api/a11oy/v1/kverify/summary','/api/a11oy/v1/kverify/status','/api/a11oy/v1/k-verify/summary','/api/a11oy/v1/k-verify/status','/api/a11oy/v1/verify/run/last','/api/a11oy/v1/kverify/last'];
302
  var RAG_EPS = ['/api/a11oy/v1/rag/status','/api/a11oy/v1/rag/last','/api/a11oy/v1/govern-rag/status','/api/a11oy/rag/status','/api/a11oy/v1/rag/health'];
 
304
  var RAG_ASK_EPS = ['/api/a11oy/v1/rag/query','/api/a11oy/v1/rag/ask','/api/a11oy/v1/govern-rag/ask','/api/a11oy/rag/query'];
305
  var RAG_ASK_URL = null; // resolved once a status probe identifies a live RAG surface
306
 
307
+ function pendingHTML(why){ return '<span class="pending">PENDING<span class="why">'+(why||'endpoint not yet live — shown honestly, not fabricated')+'</span></span>'; }
308
+ function shortHash(h){ if(!h) return null; h=String(h); return h.length>20 ? h.slice(0,10)+'…'+h.slice(-6) : h; }
309
 
310
  // Try a list of endpoints; resolve with {url,data} of the first that returns ok JSON, else null.
311
  async function firstLive(urls){
 
319
  if(!hit){ el.innerHTML = pendingHTML('K-Verify endpoint not live this sweep'); return false; }
320
  var d = hit.data || {};
321
  // Honest idle state: endpoint is LIVE but no run has executed yet this process.
322
+ // Surface that truthfully — never synthesize a zero-item "run" that didn't happen.
323
  var runData = d.run || d.last_run || d.summary || d;
324
  var hasRun = (d.ran === true) || (d.ran == null && (runData.n!=null || runData.count!=null || runData.items!=null || runData.total!=null || runData.pass!=null));
325
  if(!hasRun){
326
+ el.innerHTML = '<div class="sub2"><b>endpoint live</b> '+L('LIVE','EVIDENCE-FIRST AI')+'</div>'+
327
+ '<div class="sub2">no run yet this process — a signed run posts N items, pass-rate, joules MEASURED + a receipt hash. Shown honestly: no fabricated run.</div>';
328
  return true;
329
  }
330
  d = runData;
 
336
  var rh = d.receipt_hash || d.receipt || d.digest || (d.receipt_digest) || ((d.khipu&&d.khipu.hash)||null);
337
  var verify= d.verify_endpoint || d.receipt_verify_at || '/api/a11oy/khipu/verify';
338
  if(rate==null && typeof pass==='number' && typeof n==='number' && n>0) rate = pass/n;
339
+ var passStr = (typeof pass==='number' && typeof n==='number') ? (fmt(pass)+'/'+fmt(n)) : (n!=null?fmt(n)+' items':'—');
340
+ var rateStr = (typeof rate==='number') ? (' · '+(rate*100).toFixed(1)+'% pass') : '';
341
  var html = '<div class="big">'+passStr+'</div>';
342
  html += '<div class="sub2">items run / passed'+rateStr+'</div>';
343
+ html += '<hr><div class="sub2">energy: <b>'+(joules!=null?fmt(joules)+' J':'—')+'</b> '+(jmeas?L('MEASURED'):L('SAMPLE'))+'</div>';
344
  if(rh){ html += '<div class="receipt">receipt '+shortHash(rh)+'</div>'; html += '<div class="sub2">verify: <code>'+verify+'</code> '+L('LIVE')+'</div>'; }
345
+ html += '<div class="lbls">'+L('LIVE','EVIDENCE-FIRST AI')+'</div>';
346
  el.innerHTML = html;
347
  return true;
348
  }
349
 
350
  function renderRag(hit){
351
  var el = $('rag-state'); var qa = $('rag-qa');
352
+ if(!hit){ qa.style.display='none'; el.innerHTML = pendingHTML('Govern-RAG endpoint not live this sweep — ask-box activates when it is'); RAG_ASK_URL=null; return false; }
353
  var d = hit.data || {};
354
  // Resolve an ask URL: explicit field, sibling of the status path, or default candidate.
355
  RAG_ASK_URL = d.query_endpoint || d.ask_endpoint || hit.url.replace(/\/(status|health|last)$/,'/query') || RAG_ASK_EPS[0];
 
365
  if(chunks!=null) stat.push(fmt(chunks)+' chunks');
366
  if(files!=null) stat.push(fmt(files)+' files');
367
  if(repos!=null) stat.push(fmt(repos)+' repos');
368
+ var html = '<div class="sub2">governed corpus indexed: <b>'+(stat.length?stat.join(' · '):'ready')+'</b> '+L('LIVE')+'</div>';
369
  // Only show a 'last answer' if it carries a real grounded answer string (status citations are not answers).
370
  if(lastA && typeof lastA==='string'){
371
  html += '<div class="ans">'+(lastQ?'<b>Q:</b> '+escapeHTML(lastQ)+'<br>':'')+'<b>A:</b> '+escapeHTML(String(lastA))+'</div>';
372
+ if(cites && cites.length){ html += '<div class="cite">cited: '+cites.map(function(c){ return escapeHTML(typeof c==='string'?c:(c.citation||c.path||c.source||c.id||c.doc||JSON.stringify(c))); }).join(' · ')+'</div>'; }
373
  html += '<div class="lbls">'+L('LIVE','GROUNDED + CITED')+'</div>';
374
  } else {
375
+ html += '<div class="sub2">Ask the doctrine — answers come only from the governed corpus, with citations; off-corpus returns insufficient grounding.</div>';
376
  }
377
  el.innerHTML = html;
378
  return true;
 
383
  var btn = $('rag-ask'); var el = $('rag-state');
384
  if(!q){ return; }
385
  if(!RAG_ASK_URL){ el.innerHTML = pendingHTML('RAG query endpoint not live'); return; }
386
+ btn.disabled = true; var prev = el.innerHTML; el.innerHTML = '<div class="sub2">asking the governed corpus…</div>';
387
  try {
388
  var r = await fetch(RAG_ASK_URL, {method:'POST', headers:{'content-type':'application/json','accept':'application/json'}, body: JSON.stringify({question:q, query:q})});
389
  if(!r.ok) throw new Error('HTTP '+r.status);
 
394
  var html = '';
395
  if(grounded){
396
  html += '<div class="ans"><b>Q:</b> '+escapeHTML(q)+'<br><b>A:</b> '+escapeHTML(String(ans))+'</div>';
397
+ if(cites && cites.length){ html += '<div class="cite">cited: '+cites.map(function(c){ return escapeHTML(typeof c==='string'?c:(c.id||c.source||c.doc||JSON.stringify(c))); }).join(' · ')+'</div>'; }
398
  html += '<div class="lbls">'+L('LIVE','GROUNDED + CITED')+'</div>';
399
  } else {
400
+ html += '<div class="ans"><b>Q:</b> '+escapeHTML(q)+'<br><b>A:</b> insufficient grounding in the governed corpus — no answer returned.</div>';
401
  html += '<div class="lbls">'+L('LIVE','HONEST: NO GUESS')+'</div>';
402
  }
403
  el.innerHTML = html;
 
421
  var reason = dec.reason || dec.detail || null;
422
  var chHead = (d.chain && d.chain.head) || dec.receipt_hash || dec.receipt || dec.digest || null;
423
  var html = '';
424
+ html += '<div class="big">'+(price!=null?fmt1(price)+' €/MWh':'—')+'</div>';
425
  html += '<div class="sub2">live grid price at decision '+(priceL==='MEASURED'?L('MEASURED'):L('LIVE'))+'</div>';
426
  if(node){
427
+ html += '<hr><div class="sub2">chosen node: <b>'+escapeHTML(node)+'</b> '+L('LIVE','LOWEST-€ REACHABLE')+'</div>';
428
  if(save!=null){
429
  var sv = (typeof save==='number') ? ((save<=1?(save*100):save).toFixed(1)+'%') : escapeHTML(String(save));
430
  var lk = (saveLabel==='MEASURED') ? L('MEASURED') : L('MODELED','ROUTING LAW');
431
  html += '<div class="sub2">honest savings vs most-expensive comparable: <b>'+sv+'</b> '+lk+'</div>';
432
  }
433
  } else {
434
+ // No placement this tick is an HONEST outcome, not a gap — surface the reason verbatim.
435
  html += '<hr><div class="sub2"><b>no placement this tick</b> '+L('LIVE','HONEST: NO FABRICATED SAVING')+'</div>';
436
  if(reason) html += '<div class="sub2">'+escapeHTML(reason)+'</div>';
437
  }
438
+ if(chHead){ html += '<div class="receipt">receipt-chain '+shortHash(chHead)+(d.chain&&d.chain.length!=null?' · len '+fmt(d.chain.length):'')+'</div>'; }
439
  el.innerHTML = html;
440
  return true;
441
  }
 
455
  }
456
 
457
  async function loadAll(){
458
+ $('stamp').textContent = 'fetching live fabric state…';
459
  try {
460
  var results = await Promise.allSettled([
461
  getJSON('/api/a11oy/v1/compute-pool-hardened'),
 
481
 
482
  var errs = results.filter(function(r){return r.status==='rejected';});
483
  var ts = pool.cached_at || new Date().toISOString();
484
+ $('stamp').innerHTML = 'live as of <code>'+ts+'</code> · '+L('LIVE','4 ENDPOINTS WIRED') +
485
+ ' · live work: <b>'+workLive+'/3</b> capabilities surfaced'+(workLive<3?' <span class="note">('+(3-workLive)+' honestly PENDING)</span>':'') +
486
+ (errs.length ? ' <span class="err">· '+errs.length+' source(s) unavailable (shown honestly empty)</span>' : '');
487
  } catch(e){
488
  $('stamp').innerHTML = '<span class="err">fabric load error: '+e+'</span>';
489
  }
 
491
  loadAll();
492
  </script>
493
  </body></html>
494
+
pages/landing.html CHANGED
@@ -574,7 +574,7 @@ img,svg,canvas,video{max-width:100%;height:auto;}
574
  </div>
575
 
576
  <section class="inv-hero">
577
- <p class="ds-eyebrow">Governed inference</p>
578
  <h1>AI that signs its work<br><span class="accent">and refuses to lie.</span></h1>
579
  <p>Every AI decision arrives with a signed receipt you can verify yourself. The trust math is a
580
  machine-checked theorem. When the model is not sure, it refuses rather than guesses. It runs on
 
574
  </div>
575
 
576
  <section class="inv-hero">
577
+ <p class="ds-eyebrow">Evidence-first AI</p>
578
  <h1>AI that signs its work<br><span class="accent">and refuses to lie.</span></h1>
579
  <p>Every AI decision arrives with a signed receipt you can verify yourself. The trust math is a
580
  machine-checked theorem. When the model is not sure, it refuses rather than guesses. It runs on
pages/pinn-console.html CHANGED
@@ -1,11 +1,11 @@
1
- <!DOCTYPE html>
2
  <html lang="en">
3
  <head>
4
  <meta charset="utf-8" />
5
  <meta name="viewport" content="width=device-width, initial-scale=1" />
6
- <title>a11oy — Governed Inverse-PINN Console</title>
7
  <!--
8
- Governed Inverse-PINN Console — runs the LIVE governed parameter-discovery
9
  engine at POST /api/a11oy/v1/pinn/identify and SHOWS the governance:
10
  the discovered parameter(s) with 95% CI, the GREEN/YELLOW/RED convergence
11
  badge, the FIM identifiability / self-doubt result (the REFUSAL is the hero
@@ -15,7 +15,7 @@
15
 
16
  Doctrine v11 LOCKED. Values are MODELED (a fit to data, never MEASURED).
17
  Locked-proven = 8 {F1,F4,F7,F11,F12,F18,F19,F22}. Lambda = Conjecture 1.
18
- Pure HTML/JS/CSS — 0 runtime CDN, no server-side numpy. Reuses the
19
  pages/verify.html design system (CSS variables, JetBrains Mono, chips).
20
  -->
21
  <style>
@@ -250,8 +250,8 @@
250
  <circle cx="16" cy="16" r="2.5" fill="#8aaaf8"/>
251
  </svg>
252
  <span class="site-title">a11oy</span>
253
- <span class="site-tagline">Governed Inference · Verifiable by Design</span>
254
- <a href="/console" class="nav-back">← Console</a>
255
  </header>
256
 
257
  <!-- ===== MAIN ===== -->
@@ -260,13 +260,13 @@
260
  <div class="page-hero">
261
  <h1>Governed Inverse-PINN Console</h1>
262
  <p>
263
- Discover an unknown <strong>physical</strong> parameter of an ODE from data + physics —
264
  then watch the governance work. Every discovered value is <span class="chip chip-info">MODELED</span>
265
  (a fit to data, never MEASURED), carries a 95% confidence interval, a GREEN/YELLOW/RED convergence
266
  badge, a Fisher-information self-doubt gate that <em>refuses</em> non-identifiable parameters,
267
- a Λ advisory, an F19/Bekenstein plausibility check, and a signed Khipu receipt you can re-verify.
268
  </p>
269
- <span class="eq">Duffing oscillator&nbsp;&nbsp;m·x″ + c·x′ + δ·x + <strong>α</strong>·x³ = F·cos(ωt)&nbsp;&nbsp;— α is unknown</span>
270
  </div>
271
 
272
  <!-- ===== RUN ===== -->
@@ -282,11 +282,11 @@
282
  <div class="btn-row">
283
  <button class="btn btn-green" id="btn-green" onclick="runIdentify('green')">
284
  Run Duffing demo (GREEN)
285
- <span class="btn-sub">identify α — converges, asserts with CI</span>
286
  </button>
287
  <button class="btn btn-red" id="btn-red" onclick="runIdentify('red')">
288
- Run non-identifiable case (RED — see it refuse)
289
- <span class="btn-sub">ask for α + a ghost param — engine REFUSES</span>
290
  </button>
291
  </div>
292
  <div id="status" class="status-line"></div>
@@ -303,7 +303,7 @@
303
  <p>The 3-state governance verdict from the causal-weight / gradient / FIM-conditioning criteria.</p>
304
  </div>
305
  <div class="section-body">
306
- <div id="verdict" class="verdict-banner verdict-dim">—</div>
307
  <div class="metric-grid" id="conv-metrics"></div>
308
  </div>
309
  </section>
@@ -314,7 +314,7 @@
314
  <h2><span class="section-label">2</span> Discovered parameter(s)</h2>
315
  <p>
316
  Each value is <span class="chip chip-info">MODELED</span> with a 95% CI. A parameter the
317
- self-doubt gate cannot support is <strong>REFUSED</strong> verbatim — no value invented.
318
  </p>
319
  <p class="moat-line">"We don't report what we can't support."</p>
320
  </div>
@@ -326,10 +326,10 @@
326
  <!-- self-doubt / FIM -->
327
  <section class="section">
328
  <div class="section-head">
329
- <h2><span class="section-label">3</span> Identifiability — the self-doubt gate</h2>
330
  <p>
331
  Fisher Information Matrix conditioning decides whether the data actually constrain the
332
- parameter. κ(FIM) → ∞ or Fisher below floor ⇒ <strong>UNIDENTIFIABLE</strong> ⇒ the engine refuses.
333
  </p>
334
  </div>
335
  <div class="section-body">
@@ -340,16 +340,16 @@
340
  <!-- lambda advisory -->
341
  <section class="section">
342
  <div class="section-head">
343
- <h2><span class="section-label">4</span> Λ advisory</h2>
344
  <p>
345
- A single advisory trust score. <span class="conj">Conjecture 1 — advisory, NOT a theorem</span>
346
- — capped ≤ 0.99, <strong>never a proof, never 1.0</strong>.
347
  </p>
348
  </div>
349
  <div class="section-body">
350
  <div style="display:flex; align-items:center; gap:24px; flex-wrap:wrap;">
351
  <div>
352
- <div class="lambda-big" id="lambda-val">—</div>
353
  <div class="small" id="lambda-status"></div>
354
  </div>
355
  <div class="small" id="lambda-basis" style="max-width:420px;"></div>
@@ -363,13 +363,13 @@
363
  <div class="section-head">
364
  <h2><span class="section-label">5</span> F19 / Bekenstein check</h2>
365
  <p>
366
- The Bekenstein bound (F19) is a <strong>locked-proven inequality</strong> — here it is
367
  <em>applied</em>, not re-claimed. It checks the discovery doesn't encode more information
368
  than the system can physically hold.
369
  </p>
370
  </div>
371
  <div class="section-body">
372
- <div id="bek" class="small">—</div>
373
  </div>
374
  </section>
375
 
@@ -379,7 +379,7 @@
379
  <h2><span class="section-label">6</span> Signed receipt + ledger</h2>
380
  <p>
381
  The discovery is sealed as a DSSE-enveloped Khipu receipt in the unified ledger organ
382
- <code>a11oy-pinn</code>. Signature state is shown exactly as returned — never faked.
383
  </p>
384
  </div>
385
  <div class="section-body">
@@ -392,14 +392,14 @@
392
  <section class="section">
393
  <div class="section-head">
394
  <h2><span class="section-label">Doctrine</span> Honest labels</h2>
395
- <p>What is proven, what is wired, what is advisory. The half-state — claiming more than is real — is the only unacceptable outcome.</p>
396
  </div>
397
  <div class="section-body">
398
  <div class="corpus-diagram">
399
  <div class="corpus-tier">
400
  <div class="corpus-count proven">8</div>
401
  <div class="corpus-tier-label">Locked-proven</div>
402
- <div class="corpus-tier-desc">No-axiom theorems {F1,F4,F7,F11,F12,F18,F19,F22}. F19 Bekenstein is one of them — applied here, not re-claimed.</div>
403
  </div>
404
  <div class="corpus-tier">
405
  <div class="corpus-count wired">~35</div>
@@ -413,10 +413,10 @@
413
  </div>
414
  </div>
415
  <div class="never-claim">
416
- Discovered values are <strong>MODELED</strong> (a fit to data, never MEASURED). Λ is
417
- <strong>Conjecture 1</strong> — advisory, capped ≤ 0.99, never a theorem, never 1.0. The Bekenstein
418
  bound is a PROVEN inequality whose <em>application</em> here is MODELED. Receipts are signed or
419
- unsigned exactly as the engine returns — never fabricated.
420
  </div>
421
  </div>
422
  </section>
@@ -424,8 +424,8 @@
424
  </main>
425
 
426
  <footer class="footer">
427
- a11oy · Governed Inverse-PINN · Doctrine v11 LOCKED · values MODELED · Λ = Conjecture 1 ·
428
- <a href="/console">Console</a> · <a href="/verify">Verify</a>
429
  </footer>
430
 
431
  <script>
@@ -458,7 +458,7 @@ function badgeClass(label) {
458
  async function runIdentify(kind) {
459
  const bg = el("btn-green"), br = el("btn-red");
460
  bg.disabled = true; br.disabled = true;
461
- el("status").innerHTML = '<span class="spinner"></span>Calling the live governed engine at ' + API + ' …';
462
  el("results").classList.add("hidden");
463
  try {
464
  const res = await fetch(API, {
@@ -469,12 +469,12 @@ async function runIdentify(kind) {
469
  const data = await res.json();
470
  if (!res.ok && !data.convergence) {
471
  el("status").innerHTML = '<span style="color:var(--red)">Engine returned ' + res.status +
472
- ' — ' + (data.error || "unexpected") + '</span>';
473
  return;
474
  }
475
  render(data);
476
  el("status").innerHTML = 'Live response received (HTTP ' + res.status +
477
- ') · system <code>' + (data.system || "?") + '</code> · honest label MODELED.';
478
  } catch (e) {
479
  el("status").innerHTML = '<span style="color:var(--red)">Network error: ' + e + '</span>';
480
  } finally {
@@ -485,15 +485,15 @@ async function runIdentify(kind) {
485
  function render(d) {
486
  el("results").classList.remove("hidden");
487
  const conv = d.convergence || {};
488
- const label = conv.label || "—";
489
 
490
  // ---- verdict ----
491
  const v = el("verdict");
492
  v.className = "verdict-banner verdict-" + badgeClass(label);
493
  let head = "Convergence: " + label;
494
- if (label === "GREEN") head += " — parameter asserted";
495
- else if (label === "RED") head += " — the engine REFUSES";
496
- else if (label === "YELLOW") head += " — partial / keep running";
497
  v.innerHTML = '<span class="chip chip-' + badgeClass(label) + '">' + label + '</span>' +
498
  '<span>' + head + '</span>' +
499
  '<span class="vsub">' + (conv.epochs_run != null ? conv.epochs_run + " epochs" : "") + '</span>';
@@ -503,8 +503,8 @@ function render(d) {
503
  const cmRows = [
504
  ["min causal weight", cm.min_causal_weight || fmt(conv.min_causal_weight)],
505
  ["grad norm", cm.grad_norm || fmt(conv.grad_norm)],
506
- ["κ(FIM)", cm.kappa_fim || fmt(conv.kappa_fim)],
507
- ["min Fisher", cm.min_fisher || "—"],
508
  ["residual rms", fmt(conv.residual_rms)],
509
  ["data rms", fmt(conv.data_rms)]
510
  ];
@@ -521,15 +521,15 @@ function render(d) {
521
  return '<div class="param-card asserted">' +
522
  '<div class="param-card-head">' +
523
  '<span class="param-name">' + p.name + '</span>' +
524
- '<span class="chip chip-' + pl + '">' + (p.convergence_label || "—") + '</span>' +
525
  '<span class="chip chip-info">MODELED</span>' +
526
  '<span class="chip chip-green">IDENTIFIABLE</span>' +
527
  '</div>' +
528
  '<div class="param-value">' + fmt(p.value) + '</div>' +
529
- '<div class="param-ci">' + ci + (p.std != null ? ' · σ ' + fmt(p.std) : '') + '</div>' +
530
  '</div>';
531
  }
532
- // REFUSED — hero honesty moment
533
  return '<div class="param-card refused">' +
534
  '<div class="param-card-head">' +
535
  '<span class="param-name">' + p.name + '</span>' +
@@ -537,7 +537,7 @@ function render(d) {
537
  '<span class="chip chip-red">REFUSED</span>' +
538
  '</div>' +
539
  '<div class="param-value null">value = null</div>' +
540
- '<div class="refusal-box"><span class="rh">Self-doubt gate · not asserted</span>' +
541
  (p.refusal || "UNIDENTIFIABLE: the engine refuses to assert this parameter.") + '</div>' +
542
  '</div>';
543
  }).join("");
@@ -545,9 +545,9 @@ function render(d) {
545
  // ---- FIM / self-doubt ----
546
  const anyRefused = params.some(p => !p.asserted);
547
  const fimRows = [
548
- ["κ(FIM)", cm.kappa_fim || fmt(conv.kappa_fim), badgeClass(label) === "red" ? "red" : "green"],
549
- ["min Fisher", cm.min_fisher || "—", ""],
550
- ["gate", anyRefused ? "REFUSED ≥1 parameter" : "all parameters identifiable",
551
  anyRefused ? "red" : "green"]
552
  ];
553
  el("fim-metrics").innerHTML = fimRows.map(r =>
@@ -556,9 +556,9 @@ function render(d) {
556
 
557
  // ---- lambda ----
558
  const lam = d.lambda_advisory || {};
559
- el("lambda-val").textContent = (lam.value != null) ? fmt(lam.value, 4) : "—";
560
  el("lambda-status").innerHTML = '<span class="conj">' + (lam.status || "ADVISORY") + '</span>';
561
- el("lambda-basis").textContent = lam.basis || "Λ = Conjecture 1 (advisory, capped ≤ 0.99; NEVER a proof).";
562
  const lf = lam.factors || {};
563
  el("lambda-factors").innerHTML = Object.keys(lf).map(k =>
564
  '<div class="metric"><div class="metric-k">' + k + '</div><div class="metric-v">' + fmt(lf[k], 4) + '</div></div>'
@@ -579,7 +579,7 @@ function render(d) {
579
  '</div>' +
580
  '<div class="small" style="margin-top:10px;">' + (b.basis || "") + '</div>';
581
  } else {
582
- el("bek").innerHTML = '<span class="small">No asserted parameter to check — Bekenstein is applied only to an asserted discovery (the engine refused all parameters here).</span>';
583
  }
584
 
585
  // ---- receipt ----
@@ -591,20 +591,20 @@ function render(d) {
591
  let html =
592
  '<div class="hash-row"><span class="hash-label">signature</span>' +
593
  '<span class="chip chip-' + (signed ? "green" : "amber") + '">' + (signed ? "SIGNED" : "UNSIGNED") + '</span>' +
594
- '<span class="small">' + (signed ? "DSSE envelope present (payloadType " + ((r.dsse||{}).payloadType || "application/vnd.szl.ipinn+json") + ")" : "honest UNSIGNED — no cosign key in this env") + '</span>' +
595
  '</div>' +
596
  '<div class="hash-row"><span class="hash-label">ledger</span>' +
597
  '<span class="chip chip-' + (ledger.recorded ? "green" : "dim") + '">' + (ledger.recorded ? "RECORDED" : "NOT RECORDED") + '</span>' +
598
  '<span class="small">organ <code>a11oy-pinn</code>' +
599
- (lres.chain_index != null ? ' · chain index ' + lres.chain_index : '') + '</span>' +
600
  '</div>';
601
  if (rid) {
602
  html += '<div class="hash-row"><span class="hash-label">receipt id</span>' +
603
  '<span class="hash-val">' + rid + '</span></div>' +
604
  '<div class="hash-row"><span class="hash-label">verify</span>' +
605
  '<a class="hash-val" href="' + VERIFY_BASE + rid + '" target="_blank" rel="noopener">' +
606
- VERIFY_BASE + rid + ' ↗</a></div>' +
607
- '<div class="small" style="margin-top:6px;">Re-verify independently — the Khipu hash-chain integrity is recomputed server-side and is publicly checkable.</div>';
608
  }
609
  if (lres.chain_head) {
610
  html += '<hr class="divider"><div class="hash-row"><span class="hash-label">chain head</span>' +
@@ -617,3 +617,4 @@ function render(d) {
617
  </script>
618
  </body>
619
  </html>
 
 
1
+ <!DOCTYPE html>
2
  <html lang="en">
3
  <head>
4
  <meta charset="utf-8" />
5
  <meta name="viewport" content="width=device-width, initial-scale=1" />
6
+ <title>a11oy — Governed Inverse-PINN Console</title>
7
  <!--
8
+ Governed Inverse-PINN Console — runs the LIVE governed parameter-discovery
9
  engine at POST /api/a11oy/v1/pinn/identify and SHOWS the governance:
10
  the discovered parameter(s) with 95% CI, the GREEN/YELLOW/RED convergence
11
  badge, the FIM identifiability / self-doubt result (the REFUSAL is the hero
 
15
 
16
  Doctrine v11 LOCKED. Values are MODELED (a fit to data, never MEASURED).
17
  Locked-proven = 8 {F1,F4,F7,F11,F12,F18,F19,F22}. Lambda = Conjecture 1.
18
+ Pure HTML/JS/CSS — 0 runtime CDN, no server-side numpy. Reuses the
19
  pages/verify.html design system (CSS variables, JetBrains Mono, chips).
20
  -->
21
  <style>
 
250
  <circle cx="16" cy="16" r="2.5" fill="#8aaaf8"/>
251
  </svg>
252
  <span class="site-title">a11oy</span>
253
+ <span class="site-tagline">AI that can demonstrate its work · Verifiable by Design</span>
254
+ <a href="/console" class="nav-back">← Console</a>
255
  </header>
256
 
257
  <!-- ===== MAIN ===== -->
 
260
  <div class="page-hero">
261
  <h1>Governed Inverse-PINN Console</h1>
262
  <p>
263
+ Discover an unknown <strong>physical</strong> parameter of an ODE from data + physics —
264
  then watch the governance work. Every discovered value is <span class="chip chip-info">MODELED</span>
265
  (a fit to data, never MEASURED), carries a 95% confidence interval, a GREEN/YELLOW/RED convergence
266
  badge, a Fisher-information self-doubt gate that <em>refuses</em> non-identifiable parameters,
267
+ a Λ advisory, an F19/Bekenstein plausibility check, and a signed Khipu receipt you can re-verify.
268
  </p>
269
+ <span class="eq">Duffing oscillator&nbsp;&nbsp;m·x″ + c·x′ + δ·x + <strong>α</strong>·x³ = F·cos(ωt)&nbsp;&nbsp;— α is unknown</span>
270
  </div>
271
 
272
  <!-- ===== RUN ===== -->
 
282
  <div class="btn-row">
283
  <button class="btn btn-green" id="btn-green" onclick="runIdentify('green')">
284
  Run Duffing demo (GREEN)
285
+ <span class="btn-sub">identify α — converges, asserts with CI</span>
286
  </button>
287
  <button class="btn btn-red" id="btn-red" onclick="runIdentify('red')">
288
+ Run non-identifiable case (RED — see it refuse)
289
+ <span class="btn-sub">ask for α + a ghost param — engine REFUSES</span>
290
  </button>
291
  </div>
292
  <div id="status" class="status-line"></div>
 
303
  <p>The 3-state governance verdict from the causal-weight / gradient / FIM-conditioning criteria.</p>
304
  </div>
305
  <div class="section-body">
306
+ <div id="verdict" class="verdict-banner verdict-dim">—</div>
307
  <div class="metric-grid" id="conv-metrics"></div>
308
  </div>
309
  </section>
 
314
  <h2><span class="section-label">2</span> Discovered parameter(s)</h2>
315
  <p>
316
  Each value is <span class="chip chip-info">MODELED</span> with a 95% CI. A parameter the
317
+ self-doubt gate cannot support is <strong>REFUSED</strong> verbatim — no value invented.
318
  </p>
319
  <p class="moat-line">"We don't report what we can't support."</p>
320
  </div>
 
326
  <!-- self-doubt / FIM -->
327
  <section class="section">
328
  <div class="section-head">
329
+ <h2><span class="section-label">3</span> Identifiability — the self-doubt gate</h2>
330
  <p>
331
  Fisher Information Matrix conditioning decides whether the data actually constrain the
332
+ parameter. κ(FIM) → ∞ or Fisher below floor ⇒ <strong>UNIDENTIFIABLE</strong> ⇒ the engine refuses.
333
  </p>
334
  </div>
335
  <div class="section-body">
 
340
  <!-- lambda advisory -->
341
  <section class="section">
342
  <div class="section-head">
343
+ <h2><span class="section-label">4</span> Λ advisory</h2>
344
  <p>
345
+ A single advisory trust score. <span class="conj">Conjecture 1 — advisory, NOT a theorem</span>
346
+ — capped ≤ 0.99, <strong>never a proof, never 1.0</strong>.
347
  </p>
348
  </div>
349
  <div class="section-body">
350
  <div style="display:flex; align-items:center; gap:24px; flex-wrap:wrap;">
351
  <div>
352
+ <div class="lambda-big" id="lambda-val">—</div>
353
  <div class="small" id="lambda-status"></div>
354
  </div>
355
  <div class="small" id="lambda-basis" style="max-width:420px;"></div>
 
363
  <div class="section-head">
364
  <h2><span class="section-label">5</span> F19 / Bekenstein check</h2>
365
  <p>
366
+ The Bekenstein bound (F19) is a <strong>locked-proven inequality</strong> — here it is
367
  <em>applied</em>, not re-claimed. It checks the discovery doesn't encode more information
368
  than the system can physically hold.
369
  </p>
370
  </div>
371
  <div class="section-body">
372
+ <div id="bek" class="small">—</div>
373
  </div>
374
  </section>
375
 
 
379
  <h2><span class="section-label">6</span> Signed receipt + ledger</h2>
380
  <p>
381
  The discovery is sealed as a DSSE-enveloped Khipu receipt in the unified ledger organ
382
+ <code>a11oy-pinn</code>. Signature state is shown exactly as returned — never faked.
383
  </p>
384
  </div>
385
  <div class="section-body">
 
392
  <section class="section">
393
  <div class="section-head">
394
  <h2><span class="section-label">Doctrine</span> Honest labels</h2>
395
+ <p>What is proven, what is wired, what is advisory. The half-state — claiming more than is real — is the only unacceptable outcome.</p>
396
  </div>
397
  <div class="section-body">
398
  <div class="corpus-diagram">
399
  <div class="corpus-tier">
400
  <div class="corpus-count proven">8</div>
401
  <div class="corpus-tier-label">Locked-proven</div>
402
+ <div class="corpus-tier-desc">No-axiom theorems {F1,F4,F7,F11,F12,F18,F19,F22}. F19 Bekenstein is one of them — applied here, not re-claimed.</div>
403
  </div>
404
  <div class="corpus-tier">
405
  <div class="corpus-count wired">~35</div>
 
413
  </div>
414
  </div>
415
  <div class="never-claim">
416
+ Discovered values are <strong>MODELED</strong> (a fit to data, never MEASURED). Λ is
417
+ <strong>Conjecture 1</strong> — advisory, capped ≤ 0.99, never a theorem, never 1.0. The Bekenstein
418
  bound is a PROVEN inequality whose <em>application</em> here is MODELED. Receipts are signed or
419
+ unsigned exactly as the engine returns — never fabricated.
420
  </div>
421
  </div>
422
  </section>
 
424
  </main>
425
 
426
  <footer class="footer">
427
+ a11oy · Governed Inverse-PINN · Doctrine v11 LOCKED · values MODELED · Λ = Conjecture 1 ·
428
+ <a href="/console">Console</a> · <a href="/verify">Verify</a>
429
  </footer>
430
 
431
  <script>
 
458
  async function runIdentify(kind) {
459
  const bg = el("btn-green"), br = el("btn-red");
460
  bg.disabled = true; br.disabled = true;
461
+ el("status").innerHTML = '<span class="spinner"></span>Calling the live governed engine at ' + API + ' …';
462
  el("results").classList.add("hidden");
463
  try {
464
  const res = await fetch(API, {
 
469
  const data = await res.json();
470
  if (!res.ok && !data.convergence) {
471
  el("status").innerHTML = '<span style="color:var(--red)">Engine returned ' + res.status +
472
+ ' — ' + (data.error || "unexpected") + '</span>';
473
  return;
474
  }
475
  render(data);
476
  el("status").innerHTML = 'Live response received (HTTP ' + res.status +
477
+ ') · system <code>' + (data.system || "?") + '</code> · honest label MODELED.';
478
  } catch (e) {
479
  el("status").innerHTML = '<span style="color:var(--red)">Network error: ' + e + '</span>';
480
  } finally {
 
485
  function render(d) {
486
  el("results").classList.remove("hidden");
487
  const conv = d.convergence || {};
488
+ const label = conv.label || "—";
489
 
490
  // ---- verdict ----
491
  const v = el("verdict");
492
  v.className = "verdict-banner verdict-" + badgeClass(label);
493
  let head = "Convergence: " + label;
494
+ if (label === "GREEN") head += " — parameter asserted";
495
+ else if (label === "RED") head += " — the engine REFUSES";
496
+ else if (label === "YELLOW") head += " — partial / keep running";
497
  v.innerHTML = '<span class="chip chip-' + badgeClass(label) + '">' + label + '</span>' +
498
  '<span>' + head + '</span>' +
499
  '<span class="vsub">' + (conv.epochs_run != null ? conv.epochs_run + " epochs" : "") + '</span>';
 
503
  const cmRows = [
504
  ["min causal weight", cm.min_causal_weight || fmt(conv.min_causal_weight)],
505
  ["grad norm", cm.grad_norm || fmt(conv.grad_norm)],
506
+ ["κ(FIM)", cm.kappa_fim || fmt(conv.kappa_fim)],
507
+ ["min Fisher", cm.min_fisher || "—"],
508
  ["residual rms", fmt(conv.residual_rms)],
509
  ["data rms", fmt(conv.data_rms)]
510
  ];
 
521
  return '<div class="param-card asserted">' +
522
  '<div class="param-card-head">' +
523
  '<span class="param-name">' + p.name + '</span>' +
524
+ '<span class="chip chip-' + pl + '">' + (p.convergence_label || "—") + '</span>' +
525
  '<span class="chip chip-info">MODELED</span>' +
526
  '<span class="chip chip-green">IDENTIFIABLE</span>' +
527
  '</div>' +
528
  '<div class="param-value">' + fmt(p.value) + '</div>' +
529
+ '<div class="param-ci">' + ci + (p.std != null ? ' · σ ' + fmt(p.std) : '') + '</div>' +
530
  '</div>';
531
  }
532
+ // REFUSED — hero honesty moment
533
  return '<div class="param-card refused">' +
534
  '<div class="param-card-head">' +
535
  '<span class="param-name">' + p.name + '</span>' +
 
537
  '<span class="chip chip-red">REFUSED</span>' +
538
  '</div>' +
539
  '<div class="param-value null">value = null</div>' +
540
+ '<div class="refusal-box"><span class="rh">Self-doubt gate · not asserted</span>' +
541
  (p.refusal || "UNIDENTIFIABLE: the engine refuses to assert this parameter.") + '</div>' +
542
  '</div>';
543
  }).join("");
 
545
  // ---- FIM / self-doubt ----
546
  const anyRefused = params.some(p => !p.asserted);
547
  const fimRows = [
548
+ ["κ(FIM)", cm.kappa_fim || fmt(conv.kappa_fim), badgeClass(label) === "red" ? "red" : "green"],
549
+ ["min Fisher", cm.min_fisher || "—", ""],
550
+ ["gate", anyRefused ? "REFUSED ≥1 parameter" : "all parameters identifiable",
551
  anyRefused ? "red" : "green"]
552
  ];
553
  el("fim-metrics").innerHTML = fimRows.map(r =>
 
556
 
557
  // ---- lambda ----
558
  const lam = d.lambda_advisory || {};
559
+ el("lambda-val").textContent = (lam.value != null) ? fmt(lam.value, 4) : "—";
560
  el("lambda-status").innerHTML = '<span class="conj">' + (lam.status || "ADVISORY") + '</span>';
561
+ el("lambda-basis").textContent = lam.basis || "Λ = Conjecture 1 (advisory, capped ≤ 0.99; NEVER a proof).";
562
  const lf = lam.factors || {};
563
  el("lambda-factors").innerHTML = Object.keys(lf).map(k =>
564
  '<div class="metric"><div class="metric-k">' + k + '</div><div class="metric-v">' + fmt(lf[k], 4) + '</div></div>'
 
579
  '</div>' +
580
  '<div class="small" style="margin-top:10px;">' + (b.basis || "") + '</div>';
581
  } else {
582
+ el("bek").innerHTML = '<span class="small">No asserted parameter to check — Bekenstein is applied only to an asserted discovery (the engine refused all parameters here).</span>';
583
  }
584
 
585
  // ---- receipt ----
 
591
  let html =
592
  '<div class="hash-row"><span class="hash-label">signature</span>' +
593
  '<span class="chip chip-' + (signed ? "green" : "amber") + '">' + (signed ? "SIGNED" : "UNSIGNED") + '</span>' +
594
+ '<span class="small">' + (signed ? "DSSE envelope present (payloadType " + ((r.dsse||{}).payloadType || "application/vnd.szl.ipinn+json") + ")" : "honest UNSIGNED — no cosign key in this env") + '</span>' +
595
  '</div>' +
596
  '<div class="hash-row"><span class="hash-label">ledger</span>' +
597
  '<span class="chip chip-' + (ledger.recorded ? "green" : "dim") + '">' + (ledger.recorded ? "RECORDED" : "NOT RECORDED") + '</span>' +
598
  '<span class="small">organ <code>a11oy-pinn</code>' +
599
+ (lres.chain_index != null ? ' · chain index ' + lres.chain_index : '') + '</span>' +
600
  '</div>';
601
  if (rid) {
602
  html += '<div class="hash-row"><span class="hash-label">receipt id</span>' +
603
  '<span class="hash-val">' + rid + '</span></div>' +
604
  '<div class="hash-row"><span class="hash-label">verify</span>' +
605
  '<a class="hash-val" href="' + VERIFY_BASE + rid + '" target="_blank" rel="noopener">' +
606
+ VERIFY_BASE + rid + ' ↗</a></div>' +
607
+ '<div class="small" style="margin-top:6px;">Re-verify independently — the Khipu hash-chain integrity is recomputed server-side and is publicly checkable.</div>';
608
  }
609
  if (lres.chain_head) {
610
  html += '<hr class="divider"><div class="hash-row"><span class="hash-label">chain head</span>' +
 
617
  </script>
618
  </body>
619
  </html>
620
+
pages/pricing.html CHANGED
@@ -9,7 +9,7 @@
9
  <meta charset="utf-8"/>
10
  <meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover"/>
11
  <title>a11oy — Pricing</title>
12
- <meta name="description" content="a11oy pricing: three honest tiers — Developer, Team, and Enterprise (air-gapped). Governed inference that signs its work and refuses to lie. Talk to us for a quote."/>
13
  <link rel="canonical" href="https://a-11-oy.com/pricing"/>
14
  <style>
15
  /* KANCHAY palette — one palette org-wide. 0 runtime CDN: named font families
@@ -141,7 +141,7 @@ footer a{color:var(--muted)} footer a:hover{color:var(--text)}
141
  <main>
142
  <section class="hero wrap">
143
  <p class="eyebrow">Pricing</p>
144
- <h1>Governed inference,<br>priced honestly.</h1>
145
  <p>a11oy is AI that signs its work and refuses to lie — every decision ships a signed receipt you
146
  can verify yourself. Three tiers below. Where we have not fixed a public price yet, we say
147
  "Contact us" instead of inventing one.</p>
@@ -156,7 +156,7 @@ footer a{color:var(--muted)} footer a:hover{color:var(--text)}
156
  <div class="price">Free<small>Self-serve · open-weight models</small></div>
157
  <ul>
158
  <li>Signed receipts on every decision, verifiable in your browser</li>
159
- <li>Governed inference API + the operator console</li>
160
  <li>Deny-by-default policy gate</li>
161
  <li>Community support</li>
162
  <li>For evaluation and non-production use</li>
 
9
  <meta charset="utf-8"/>
10
  <meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover"/>
11
  <title>a11oy — Pricing</title>
12
+ <meta name="description" content="a11oy pricing: three honest tiers — Developer, Team, and Enterprise (air-gapped). Evidence-first AI that signs its work and refuses to lie. Talk to us for a quote."/>
13
  <link rel="canonical" href="https://a-11-oy.com/pricing"/>
14
  <style>
15
  /* KANCHAY palette — one palette org-wide. 0 runtime CDN: named font families
 
141
  <main>
142
  <section class="hero wrap">
143
  <p class="eyebrow">Pricing</p>
144
+ <h1>Evidence-first AI,<br>priced honestly.</h1>
145
  <p>a11oy is AI that signs its work and refuses to lie — every decision ships a signed receipt you
146
  can verify yourself. Three tiers below. Where we have not fixed a public price yet, we say
147
  "Contact us" instead of inventing one.</p>
 
156
  <div class="price">Free<small>Self-serve · open-weight models</small></div>
157
  <ul>
158
  <li>Signed receipts on every decision, verifiable in your browser</li>
159
+ <li>Evidence-first AI API + the operator console</li>
160
  <li>Deny-by-default policy gate</li>
161
  <li>Community support</li>
162
  <li>For evaluation and non-production use</li>
pages/substrate.html CHANGED
@@ -1,9 +1,9 @@
1
- <!DOCTYPE html>
2
- <!-- SPDX-License-Identifier: Apache-2.0 © 2026 Lutar, Stephen P. — SZL Holdings · Doctrine v10 -->
3
- <!-- ADDITIVE moat surface — shipped via HfApi.create_commit (never GitHub Actions). -->
4
  <html lang="en"><head>
5
  <meta charset="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/>
6
- <title>a11oy · Substrate Inspector — @szl/substrate</title>
7
  <style>:root{--bg:#0b0d12;--panel:#12151d;--ink:#e7ecf3;--mut:#8a93a6;--acc:#7cc4ff;--ok:#54d18c;--warn:#ffcf5c;--bad:#ff6b6b;--line:#222838;--mono:'SF Mono',ui-monospace,'JetBrains Mono',Menlo,Consolas,monospace}
8
  *{box-sizing:border-box}
9
  body{margin:0;background:var(--bg);color:var(--ink);font:15px/1.55 -apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif}
@@ -55,28 +55,28 @@ code{font-family:var(--mono);color:var(--acc);font-size:12.5px}
55
  .mono{font-family:var(--mono);font-size:12px}
56
  footer{margin-top:34px;border-top:1px solid var(--line);padding-top:14px;color:var(--mut);font-size:12px}</style></head><body><div class="wrap">
57
  <div class="top">
58
- <div><span class="brand">a11oy</span> <span class="tag">· Governance Substrate · Doctrine v10</span></div>
59
  <div class="nav">
60
  <a href="/">home</a><a href="/wires">wires</a><a href="/codex-kernel">codex-kernel</a>
61
  <a href="/substrate">substrate</a><a href="/evidence">evidence</a><a href="/run-all">run-all</a>
62
  </div>
63
  </div>
64
 
65
- <h1>Substrate Inspector — @szl/substrate v0.2.0</h1>
66
- <p class="sub">Sovereign Execution Substrate — policy-shaped graphs, evidence-chained transitions, confidence-budget routing, and counterfactual replay for all SZL workflows.<br>
67
- Source: <a href="https://github.com/szl-holdings/platform/tree/main/packages/substrate">https://github.com/szl-holdings/platform/tree/main/packages/substrate</a> · public package (<code>private:false</code>) · #2 — compile-time Kahn-sort approval-DAG (packages/substrate/src/compiler.ts).</p>
68
 
69
  <div class="row"><span class='pill acc'>Reason()</span><span class='pill acc'>Retrieve()</span><span class='pill acc'>ToolCall()</span><span class='pill acc'>Verify()</span><span class='pill acc'>Decide()</span><span class='pill acc'>ApprovalGate()</span></div>
70
  <div class="row"><span class="mut" style="font-size:12px">modes:</span><span class='pill'>live</span><span class='pill'>dry-run</span><span class='pill'>replay</span><span class='pill'>counterfactual</span></div>
71
 
72
  <div class="grid">
73
  <div class="card"><h3>The moat in one line</h3>
74
- <p>The single, opinionated execution runtime every SZL product surface (Lyte · Aegis · Vessels · Terra · Counsel · Carlota Jo) calls the same way.
75
- <code>defineWorkflow(&#123;stages, policy, budget&#125;)</code> → <code>runtime.start(workflow, input, &#123;mode&#125;)</code> → <code>PipelineRun</code>.</p></div>
76
- <div class="card"><h3>Innovation #2 — compile-time approval-DAG</h3>
77
  <p><code>compiler.ts</code> runs a Kahn topological sort over the approval DAG <b>at compile time</b> and throws
78
  <code>SubstrateCompilerError</code> for cycles, orphan gates, or high-risk side-effects reachable without an ancestor
79
- <code>ApprovalGate()</code>. Topology-enforced, not runtime-checked. Tests: <code>vitest — src/engine.test.ts · src/compiler.test.ts · src/workflows/phase2.test.ts</code>.</p></div>
80
  </div>
81
 
82
  <h2>Substrate packages (the moat)</h2>
@@ -85,23 +85,23 @@ Source: <a href="https://github.com/szl-holdings/platform/tree/main/packages/sub
85
  <span class='pill'>@szl/substrate-adapters</span><span class='pill'>@szl/substrate-client</span>
86
  </div>
87
 
88
- <h2>Public API surface — core files</h2>
89
- <table class="tbl"><tr><th>File</th><th>Purpose</th><th>LOC</th><th>Exports</th></tr><tr><td class='mono'>src/index.ts</td><td>Public package entry — re-exports every primitive, type, runtime, compiler, journal, telemetry &amp; workflow symbol.</td><td style='text-align:right' class='mut'>332</td><td class='mono mut'>AdvisorMatch, AegisThreatTriageInput, AegisThreatTriageResult, AnomalyFinding, AnyStage, ApprovalGate, BriefSection, CarlotaJoTaskRoutingInput…</td></tr><tr><td class='mono'>src/types.ts</td><td>Core TypeScript interfaces + Zod schemas: ExecutionMode, SideEffectCategory, 7 StageTypes, WorkflowDefinition, PipelineRun, EvidenceBundle.</td><td style='text-align:right' class='mut'>559</td><td class='mono mut'>AnyStage, AnyStageSchema, ApprovalGate, ApprovalGateSchema, BaseStage, CompiledGraph, CompiledStageNode, ConfidenceBudget…</td></tr><tr><td class='mono'>src/stage-primitives.ts</td><td>Five stage primitive factories — Reason() · Retrieve() · ToolCall() · Verify() · Decide() — plus ApprovalGate(), definePolicy(), defineBudget().</td><td style='text-align:right' class='mut'>161</td><td class='mono mut'>ApprovalGate, Decide, Reason, Retrieve, ToolCall, Verify, defineBudget, definePolicy</td></tr><tr><td class='mono'>src/compiler.ts</td><td>Innovation #2 — compile-time Kahn topological sort over the approval DAG; throws SubstrateCompilerError for cycles, orphan gates, or high-risk side-effects reachable without an ancestor ApprovalGate. Topology-enforced, not runtime-checked.</td><td style='text-align:right' class='mut'>276</td><td class='mono mut'>SubstrateCompilerError, compile</td></tr><tr><td class='mono'>src/engine.ts</td><td>SubstrateRuntime: start(workflow, input, {mode}) → PipelineRun. Workflow registry (register/lookup/list/clear), defaultRuntime singleton.</td><td style='text-align:right' class='mut'>1105</td><td class='mono mut'>SubstrateRuntime, SubstrateRuntimeOptions, clearWorkflowRegistry, defaultRuntime, listWorkflows, lookupWorkflow, registerWorkflow</td></tr><tr><td class='mono'>src/journal.ts</td><td>Evidence-chained journal: computeBundleHash, hashValue, sign/verify bundle signatures, SubstrateJournal store, runtime event bus.</td><td style='text-align:right' class='mut'>540</td><td class='mono mut'>JournalStore, RunStore, SubstrateJournal, SubstrateRuntimeEvent, SubstrateRuntimeEventType, computeBundleHash, defaultJournal, defaultJournalStore…</td></tr><tr><td class='mono'>src/budget-router.ts</td><td>Confidence-budget routing — routeByBudget, aggregatePipelineConfidence, validateFinalConfidence (escalate when budget exceeded).</td><td style='text-align:right' class='mut'>110</td><td class='mono mut'>RoutingDecision, aggregatePipelineConfidence, routeByBudget, validateFinalConfidence</td></tr><tr><td class='mono'>src/adapters.ts</td><td>Adapter registries (model/policy/resource/retriever/tool) + wirePolicyEngineAdapter / wireToolMeshAdapter bridges to platform packages.</td><td style='text-align:right' class='mut'>494</td><td class='mono mut'>McpCapabilitySpec, McpToolCall, McpToolDefinition, McpToolResult, ModelAdapter, ModelAdapterInput, ModelAdapterOutput, PolicyAdapter…</td></tr><tr><td class='mono'>src/telemetry.ts</td><td>OpenTelemetry spans: SubstrateTelemetry, getMetrics, getRecentSpans, getRunSpans (SubstrateSpan).</td><td style='text-align:right' class='mut'>279</td><td class='mono mut'>SubstrateSpan, SubstrateTelemetry, getMetrics, getRecentSpans, getRunSpans</td></tr><tr><td class='mono'>src/python-worker.ts</td><td>Bridge to services/substrate-py-workers — protocol messages (claim/result/error/heartbeat/register), PYTHON_WORKER_PROTOCOL_VERSION.</td><td style='text-align:right' class='mut'>386</td><td class='mono mut'>PYTHON_WORKER_PROTOCOL_VERSION, PythonWorkerBaseMessage, PythonWorkerChannel, PythonWorkerMessage, PythonWorkerMessageType, RegisteredWorker, StageClaimMessage, StageErrorMessage…</td></tr><tr><td class='mono'>src/cli/bin.ts</td><td>`substrate` CLI binary entrypoint.</td><td style='text-align:right' class='mut'>80</td><td class='mono mut'></td></tr><tr><td class='mono'>src/cli/replay.ts</td><td>Replay &amp; counterfactual — replay(), handleReplayRequest, resolvePolicyProfileById, formatDiff (deterministic re-execution of a recorded run).</td><td style='text-align:right' class='mut'>312</td><td class='mono mut'>PolicyNotFoundError, ReplayEndpointRequest, ReplayEndpointResponse, ReplayOptions, ReplayResult, formatDiff, handleReplayRequest, replay…</td></tr></table>
90
 
91
  <h2>Reference + vertical workflow packs</h2>
92
- <table class="tbl"><tr><th>Workflow</th><th>Purpose</th><th>Exports</th></tr><tr><td class='mono'>opportunity-audit.ts</td><td>Phase-1 reference workflow — anomaly→remediation opportunity audit (Lyte retriever).</td><td class='mono mut'>AnomalyFinding, OpportunityAuditInput, OpportunityAuditResult, RemediationDecision, isLyteRetrieverRegistered, opportunityAuditWorkflow</td></tr><tr><td class='mono'>cross-system-reconciliation.ts</td><td>Reconcile discrepancies across systems → reconciliation decision.</td><td class='mono mut'>CrossSystemReconciliationInput, CrossSystemReconciliationResult, ReconciliationDecision, ReconciliationDiscrepancy, crossSystemReconciliationWorkflow, runCrossSystemReconciliation</td></tr><tr><td class='mono'>evidence-based-recommendation.ts</td><td>Evidence-cited recommendation decision packet.</td><td class='mono mut'>EvidenceBasedRecommendationInput, EvidenceBasedRecommendationResult, EvidenceCitation, RecommendationDecisionPacket, evidenceBasedRecommendationWorkflow, runEvidenceBasedRecommendation</td></tr><tr><td class='mono'>executive-brief.ts</td><td>Multi-section executive brief generation.</td><td class='mono mut'>BriefSection, ExecutiveBriefInput, ExecutiveBriefOutput, ExecutiveBriefResult, executiveBriefWorkflow, runExecutiveBrief</td></tr><tr><td class='mono'>risk-escalation.ts</td><td>Risk-signal summary → escalation decision.</td><td class='mono mut'>RiskEscalationDecision, RiskEscalationInput, RiskEscalationResult, RiskSignalSummary, riskEscalationWorkflow, runRiskEscalation</td></tr><tr><td class='mono'>aegis-threat-triage.ts</td><td>Aegis vertical pack — threat triage decision.</td><td class='mono mut'>AegisThreatTriageInput, AegisThreatTriageResult, ThreatTriageDecision, TriagedThreat, aegisThreatTriageWorkflow, runAegisThreatTriage</td></tr><tr><td class='mono'>carlota-jo-task-routing.ts</td><td>Carlota Jo vertical pack — advisor-match task routing.</td><td class='mono mut'>AdvisorMatch, CarlotaJoTaskRoutingInput, CarlotaJoTaskRoutingResult, TaskRoutingDecision, carlotaJoTaskRoutingWorkflow, runCarlotaJoTaskRouting</td></tr><tr><td class='mono'>lyte-operational-drift.ts</td><td>Lyte vertical pack — operational drift detection decision.</td><td class='mono mut'>DriftItem, LyteOperationalDriftInput, LyteOperationalDriftResult, OperationalDriftDecision, lyteOperationalDriftWorkflow, runLyteOperationalDrift</td></tr><tr><td class='mono'>prism-counsel-evidence-packaging.ts</td><td>Prism Counsel vertical pack — legal evidence packaging + matter deadlines.</td><td class='mono mut'>EvidencePackage, MatterDeadline, PrismCounselDecision, PrismCounselEvidencePackagingInput, PrismCounselEvidencePackagingResult, prismCounselEvidencePackagingWorkflow</td></tr><tr><td class='mono'>terra-portfolio-anomaly.ts</td><td>Terra vertical pack — portfolio anomaly decision.</td><td class='mono mut'>PortfolioAnomaly, PortfolioAnomalyDecision, TerraPortfolioAnomalyInput, TerraPortfolioAnomalyResult, runTerraPortfolioAnomaly, terraPortfolioAnomalyWorkflow</td></tr><tr><td class='mono'>vessels-voyage-anomaly.ts</td><td>Vessels vertical pack — voyage anomaly decision.</td><td class='mono mut'>VesselsVoyageAnomalyInput, VesselsVoyageAnomalyResult, VoyageAnomaly, VoyageAnomalyDecision, runVesselsVoyageAnomaly, vesselsVoyageAnomalyWorkflow</td></tr><tr><td class='mono'>index.ts</td><td>Demo seed inputs for the reference workflows.</td><td class='mono mut'>ALL_WORKFLOW_SEEDS, WorkflowSeedKey, aegisThreatTriageSeed, carlotaJoTaskRoutingSeed, crossSystemReconciliationSeed, evidenceBasedRecommendationSeed</td></tr></table>
93
 
94
  <h2>Subpath exports (package.json)</h2>
95
- <div class="row"><span class='pill mut'>.</span><span class='pill mut'>./adapters</span><span class='pill mut'>./budget-router</span><span class='pill mut'>./compiler</span><span class='pill mut'>./engine</span><span class='pill mut'>./journal</span><span class='pill mut'>./python-worker</span><span class='pill mut'>./telemetry</span><span class='pill mut'>./types</span><span class='pill mut'>./workflows/aegis-threat-triage</span><span class='pill mut'>./workflows/carlota-jo-task-routing</span><span class='pill mut'>./workflows/cross-system-reconciliation</span><span class='pill mut'>./workflows/evidence-based-recommendation</span><span class='pill mut'>./workflows/executive-brief</span><span class='pill mut'>./workflows/lyte-operational-drift</span><span class='pill mut'>./workflows/opportunity-audit</span><span class='pill mut'>./workflows/prism-counsel-evidence-packaging</span><span class='pill mut'>./workflows/risk-escalation</span><span class='pill mut'>./workflows/seeds</span><span class='pill mut'>./workflows/terra-portfolio-anomaly</span><span class='pill mut'>./workflows/vessels-voyage-anomaly</span></div>
96
 
97
  <div class="honest"><b>What is honest right now.</b> This page reads the real
98
  <code>packages/substrate/</code> source in <code>szl-holdings/platform</code> and lists every public file, its purpose, and its
99
  exported symbols. The substrate is <b>real code</b> (compiler + engine + journal + budget-router + 11 workflow packs).
100
- It is shipped here as an <b>inspector / documentation surface</b> — the live TypeScript runtime executes inside the platform
101
  monorepo (and the substrate-py-workers GPU fleet), not inside this static HF Space. The side-effect categories enforced by the
102
  compiler are: read-only, write-internal, write-external, financial, notification, deletion, escalation, infrastructure.</div>
103
 
104
- <footer>SZL Holdings · Apache-2.0 · ORCID <a href="https://orcid.org/0009-0001-0110-4173">0009-0001-0110-4173</a> ·
105
- Doctrine v10 (749 declarations · 14 unique axioms · 163 tracked sorries · lutar-v18.0.0 @ c7c0ba17).
106
  Shipped additively via HfApi.create_commit.</footer>
107
- </div></body></html>
 
1
+ <!DOCTYPE html>
2
+ <!-- SPDX-License-Identifier: Apache-2.0 © 2026 Lutar, Stephen P. — SZL Holdings · Doctrine v10 -->
3
+ <!-- ADDITIVE moat surface — shipped via HfApi.create_commit (never GitHub Actions). -->
4
  <html lang="en"><head>
5
  <meta charset="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/>
6
+ <title>a11oy · Substrate Inspector — @szl/substrate</title>
7
  <style>:root{--bg:#0b0d12;--panel:#12151d;--ink:#e7ecf3;--mut:#8a93a6;--acc:#7cc4ff;--ok:#54d18c;--warn:#ffcf5c;--bad:#ff6b6b;--line:#222838;--mono:'SF Mono',ui-monospace,'JetBrains Mono',Menlo,Consolas,monospace}
8
  *{box-sizing:border-box}
9
  body{margin:0;background:var(--bg);color:var(--ink);font:15px/1.55 -apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif}
 
55
  .mono{font-family:var(--mono);font-size:12px}
56
  footer{margin-top:34px;border-top:1px solid var(--line);padding-top:14px;color:var(--mut);font-size:12px}</style></head><body><div class="wrap">
57
  <div class="top">
58
+ <div><span class="brand">a11oy</span> <span class="tag">· Governance Substrate · Doctrine v10</span></div>
59
  <div class="nav">
60
  <a href="/">home</a><a href="/wires">wires</a><a href="/codex-kernel">codex-kernel</a>
61
  <a href="/substrate">substrate</a><a href="/evidence">evidence</a><a href="/run-all">run-all</a>
62
  </div>
63
  </div>
64
 
65
+ <h1>Substrate Inspector — @szl/substrate v0.2.0</h1>
66
+ <p class="sub">Sovereign Execution Substrate — policy-shaped graphs, evidence-chained transitions, confidence-budget routing, and counterfactual replay for all SZL workflows.<br>
67
+ Source: <a href="https://github.com/szl-holdings/platform/tree/main/packages/substrate">https://github.com/szl-holdings/platform/tree/main/packages/substrate</a> · public package (<code>private:false</code>) · #2 — compile-time Kahn-sort approval-DAG (packages/substrate/src/compiler.ts).</p>
68
 
69
  <div class="row"><span class='pill acc'>Reason()</span><span class='pill acc'>Retrieve()</span><span class='pill acc'>ToolCall()</span><span class='pill acc'>Verify()</span><span class='pill acc'>Decide()</span><span class='pill acc'>ApprovalGate()</span></div>
70
  <div class="row"><span class="mut" style="font-size:12px">modes:</span><span class='pill'>live</span><span class='pill'>dry-run</span><span class='pill'>replay</span><span class='pill'>counterfactual</span></div>
71
 
72
  <div class="grid">
73
  <div class="card"><h3>The moat in one line</h3>
74
+ <p>The single, opinionated execution runtime every SZL product surface (Aegis · Vessels · Terra · Counsel · Carlota Jo · Structured) calls the same way.
75
+ <code>defineWorkflow(&#123;stages, policy, budget&#125;)</code> → <code>runtime.start(workflow, input, &#123;mode&#125;)</code> → <code>PipelineRun</code>.</p></div>
76
+ <div class="card"><h3>Innovation #2 — compile-time approval-DAG</h3>
77
  <p><code>compiler.ts</code> runs a Kahn topological sort over the approval DAG <b>at compile time</b> and throws
78
  <code>SubstrateCompilerError</code> for cycles, orphan gates, or high-risk side-effects reachable without an ancestor
79
+ <code>ApprovalGate()</code>. Topology-enforced, not runtime-checked. Tests: <code>vitest — src/engine.test.ts · src/compiler.test.ts · src/workflows/phase2.test.ts</code>.</p></div>
80
  </div>
81
 
82
  <h2>Substrate packages (the moat)</h2>
 
85
  <span class='pill'>@szl/substrate-adapters</span><span class='pill'>@szl/substrate-client</span>
86
  </div>
87
 
88
+ <h2>Public API surface — core files</h2>
89
+ <table class="tbl"><tr><th>File</th><th>Purpose</th><th>LOC</th><th>Exports</th></tr><tr><td class='mono'>src/index.ts</td><td>Public package entry — re-exports every primitive, type, runtime, compiler, journal, telemetry &amp; workflow symbol.</td><td style='text-align:right' class='mut'>332</td><td class='mono mut'>AdvisorMatch, AegisThreatTriageInput, AegisThreatTriageResult, AnomalyFinding, AnyStage, ApprovalGate, BriefSection, CarlotaJoTaskRoutingInput…</td></tr><tr><td class='mono'>src/types.ts</td><td>Core TypeScript interfaces + Zod schemas: ExecutionMode, SideEffectCategory, 7 StageTypes, WorkflowDefinition, PipelineRun, EvidenceBundle.</td><td style='text-align:right' class='mut'>559</td><td class='mono mut'>AnyStage, AnyStageSchema, ApprovalGate, ApprovalGateSchema, BaseStage, CompiledGraph, CompiledStageNode, ConfidenceBudget…</td></tr><tr><td class='mono'>src/stage-primitives.ts</td><td>Five stage primitive factories — Reason() · Retrieve() · ToolCall() · Verify() · Decide() — plus ApprovalGate(), definePolicy(), defineBudget().</td><td style='text-align:right' class='mut'>161</td><td class='mono mut'>ApprovalGate, Decide, Reason, Retrieve, ToolCall, Verify, defineBudget, definePolicy</td></tr><tr><td class='mono'>src/compiler.ts</td><td>Innovation #2 — compile-time Kahn topological sort over the approval DAG; throws SubstrateCompilerError for cycles, orphan gates, or high-risk side-effects reachable without an ancestor ApprovalGate. Topology-enforced, not runtime-checked.</td><td style='text-align:right' class='mut'>276</td><td class='mono mut'>SubstrateCompilerError, compile</td></tr><tr><td class='mono'>src/engine.ts</td><td>SubstrateRuntime: start(workflow, input, {mode}) → PipelineRun. Workflow registry (register/lookup/list/clear), defaultRuntime singleton.</td><td style='text-align:right' class='mut'>1105</td><td class='mono mut'>SubstrateRuntime, SubstrateRuntimeOptions, clearWorkflowRegistry, defaultRuntime, listWorkflows, lookupWorkflow, registerWorkflow</td></tr><tr><td class='mono'>src/journal.ts</td><td>Evidence-chained journal: computeBundleHash, hashValue, sign/verify bundle signatures, SubstrateJournal store, runtime event bus.</td><td style='text-align:right' class='mut'>540</td><td class='mono mut'>JournalStore, RunStore, SubstrateJournal, SubstrateRuntimeEvent, SubstrateRuntimeEventType, computeBundleHash, defaultJournal, defaultJournalStore…</td></tr><tr><td class='mono'>src/budget-router.ts</td><td>Confidence-budget routing — routeByBudget, aggregatePipelineConfidence, validateFinalConfidence (escalate when budget exceeded).</td><td style='text-align:right' class='mut'>110</td><td class='mono mut'>RoutingDecision, aggregatePipelineConfidence, routeByBudget, validateFinalConfidence</td></tr><tr><td class='mono'>src/adapters.ts</td><td>Adapter registries (model/policy/resource/retriever/tool) + wirePolicyEngineAdapter / wireToolMeshAdapter bridges to platform packages.</td><td style='text-align:right' class='mut'>494</td><td class='mono mut'>McpCapabilitySpec, McpToolCall, McpToolDefinition, McpToolResult, ModelAdapter, ModelAdapterInput, ModelAdapterOutput, PolicyAdapter…</td></tr><tr><td class='mono'>src/telemetry.ts</td><td>OpenTelemetry spans: SubstrateTelemetry, getMetrics, getRecentSpans, getRunSpans (SubstrateSpan).</td><td style='text-align:right' class='mut'>279</td><td class='mono mut'>SubstrateSpan, SubstrateTelemetry, getMetrics, getRecentSpans, getRunSpans</td></tr><tr><td class='mono'>src/python-worker.ts</td><td>Bridge to services/substrate-py-workers — protocol messages (claim/result/error/heartbeat/register), PYTHON_WORKER_PROTOCOL_VERSION.</td><td style='text-align:right' class='mut'>386</td><td class='mono mut'>PYTHON_WORKER_PROTOCOL_VERSION, PythonWorkerBaseMessage, PythonWorkerChannel, PythonWorkerMessage, PythonWorkerMessageType, RegisteredWorker, StageClaimMessage, StageErrorMessage…</td></tr><tr><td class='mono'>src/cli/bin.ts</td><td>`substrate` CLI binary entrypoint.</td><td style='text-align:right' class='mut'>80</td><td class='mono mut'></td></tr><tr><td class='mono'>src/cli/replay.ts</td><td>Replay &amp; counterfactual — replay(), handleReplayRequest, resolvePolicyProfileById, formatDiff (deterministic re-execution of a recorded run).</td><td style='text-align:right' class='mut'>312</td><td class='mono mut'>PolicyNotFoundError, ReplayEndpointRequest, ReplayEndpointResponse, ReplayOptions, ReplayResult, formatDiff, handleReplayRequest, replay…</td></tr></table>
90
 
91
  <h2>Reference + vertical workflow packs</h2>
92
+ <table class="tbl"><tr><th>Workflow</th><th>Purpose</th><th>Exports</th></tr><tr><td class='mono'>opportunity-audit.ts</td><td>Phase-1 reference workflow — anomaly→remediation opportunity audit (structured retriever).</td><td class='mono mut'>AnomalyFinding, OpportunityAuditInput, OpportunityAuditResult, RemediationDecision, isStructuredRetrieverRegistered, opportunityAuditWorkflow</td></tr><tr><td class='mono'>cross-system-reconciliation.ts</td><td>Reconcile discrepancies across systems → reconciliation decision.</td><td class='mono mut'>CrossSystemReconciliationInput, CrossSystemReconciliationResult, ReconciliationDecision, ReconciliationDiscrepancy, crossSystemReconciliationWorkflow, runCrossSystemReconciliation</td></tr><tr><td class='mono'>evidence-based-recommendation.ts</td><td>Evidence-cited recommendation decision packet.</td><td class='mono mut'>EvidenceBasedRecommendationInput, EvidenceBasedRecommendationResult, EvidenceCitation, RecommendationDecisionPacket, evidenceBasedRecommendationWorkflow, runEvidenceBasedRecommendation</td></tr><tr><td class='mono'>executive-brief.ts</td><td>Multi-section executive brief generation.</td><td class='mono mut'>BriefSection, ExecutiveBriefInput, ExecutiveBriefOutput, ExecutiveBriefResult, executiveBriefWorkflow, runExecutiveBrief</td></tr><tr><td class='mono'>risk-escalation.ts</td><td>Risk-signal summary → escalation decision.</td><td class='mono mut'>RiskEscalationDecision, RiskEscalationInput, RiskEscalationResult, RiskSignalSummary, riskEscalationWorkflow, runRiskEscalation</td></tr><tr><td class='mono'>aegis-threat-triage.ts</td><td>Aegis vertical pack — threat triage decision.</td><td class='mono mut'>AegisThreatTriageInput, AegisThreatTriageResult, ThreatTriageDecision, TriagedThreat, aegisThreatTriageWorkflow, runAegisThreatTriage</td></tr><tr><td class='mono'>carlota-jo-task-routing.ts</td><td>Carlota Jo vertical pack — advisor-match task routing.</td><td class='mono mut'>AdvisorMatch, CarlotaJoTaskRoutingInput, CarlotaJoTaskRoutingResult, TaskRoutingDecision, carlotaJoTaskRoutingWorkflow, runCarlotaJoTaskRouting</td></tr><tr><td class='mono'>structured-operational-drift.ts</td><td>structured vertical pack — operational drift detection decision.</td><td class='mono mut'>DriftItem, StructuredOperationalDriftInput, StructuredOperationalDriftResult, OperationalDriftDecision, structuredOperationalDriftWorkflow, runStructuredOperationalDrift</td></tr><tr><td class='mono'>prism-counsel-evidence-packaging.ts</td><td>Prism Counsel vertical pack — legal evidence packaging + matter deadlines.</td><td class='mono mut'>EvidencePackage, MatterDeadline, PrismCounselDecision, PrismCounselEvidencePackagingInput, PrismCounselEvidencePackagingResult, prismCounselEvidencePackagingWorkflow</td></tr><tr><td class='mono'>terra-portfolio-anomaly.ts</td><td>Terra vertical pack — portfolio anomaly decision.</td><td class='mono mut'>PortfolioAnomaly, PortfolioAnomalyDecision, TerraPortfolioAnomalyInput, TerraPortfolioAnomalyResult, runTerraPortfolioAnomaly, terraPortfolioAnomalyWorkflow</td></tr><tr><td class='mono'>vessels-voyage-anomaly.ts</td><td>Vessels vertical pack — voyage anomaly decision.</td><td class='mono mut'>VesselsVoyageAnomalyInput, VesselsVoyageAnomalyResult, VoyageAnomaly, VoyageAnomalyDecision, runVesselsVoyageAnomaly, vesselsVoyageAnomalyWorkflow</td></tr><tr><td class='mono'>index.ts</td><td>Demo seed inputs for the reference workflows.</td><td class='mono mut'>ALL_WORKFLOW_SEEDS, WorkflowSeedKey, aegisThreatTriageSeed, carlotaJoTaskRoutingSeed, crossSystemReconciliationSeed, evidenceBasedRecommendationSeed</td></tr></table>
93
 
94
  <h2>Subpath exports (package.json)</h2>
95
+ <div class="row"><span class='pill mut'>.</span><span class='pill mut'>./adapters</span><span class='pill mut'>./budget-router</span><span class='pill mut'>./compiler</span><span class='pill mut'>./engine</span><span class='pill mut'>./journal</span><span class='pill mut'>./python-worker</span><span class='pill mut'>./telemetry</span><span class='pill mut'>./types</span><span class='pill mut'>./workflows/aegis-threat-triage</span><span class='pill mut'>./workflows/carlota-jo-task-routing</span><span class='pill mut'>./workflows/cross-system-reconciliation</span><span class='pill mut'>./workflows/evidence-based-recommendation</span><span class='pill mut'>./workflows/executive-brief</span><span class='pill mut'>./workflows/structured-operational-drift</span><span class='pill mut'>./workflows/opportunity-audit</span><span class='pill mut'>./workflows/prism-counsel-evidence-packaging</span><span class='pill mut'>./workflows/risk-escalation</span><span class='pill mut'>./workflows/seeds</span><span class='pill mut'>./workflows/terra-portfolio-anomaly</span><span class='pill mut'>./workflows/vessels-voyage-anomaly</span></div>
96
 
97
  <div class="honest"><b>What is honest right now.</b> This page reads the real
98
  <code>packages/substrate/</code> source in <code>szl-holdings/platform</code> and lists every public file, its purpose, and its
99
  exported symbols. The substrate is <b>real code</b> (compiler + engine + journal + budget-router + 11 workflow packs).
100
+ It is shipped here as an <b>inspector / documentation surface</b> — the live TypeScript runtime executes inside the platform
101
  monorepo (and the substrate-py-workers GPU fleet), not inside this static HF Space. The side-effect categories enforced by the
102
  compiler are: read-only, write-internal, write-external, financial, notification, deletion, escalation, infrastructure.</div>
103
 
104
+ <footer>SZL Holdings · Apache-2.0 · ORCID <a href="https://orcid.org/0009-0001-0110-4173">0009-0001-0110-4173</a> ·
105
+ Doctrine v10 (749 declarations · 14 unique axioms · 163 tracked sorries · lutar-v18.0.0 @ c7c0ba17).
106
  Shipped additively via HfApi.create_commit.</footer>
107
+ </div></body></html>
pages/verify.html CHANGED
@@ -1,13 +1,13 @@
1
- <!DOCTYPE html>
2
  <html lang="en">
3
  <head>
4
  <meta charset="utf-8" />
5
  <meta name="viewport" content="width=device-width, initial-scale=1" />
6
- <title>a11oy — Verifiable Inference</title>
7
  <style>
8
  /* =====================================================================
9
- a11oy Tier-1 Demo — elite showcase aesthetic
10
- Dark palette · Cabinet Grotesk / JetBrains Mono · honest-label chips
11
  ===================================================================== */
12
  @import url('https://fonts.googleapis.com/css2?family=JetBrains+Mono:ital,wght@0,400;0,600;1,400&display=swap');
13
 
@@ -288,8 +288,8 @@
288
  <circle cx="16" cy="16" r="2.5" fill="#8aaaf8"/>
289
  </svg>
290
  <span class="site-title">a11oy</span>
291
- <span class="site-tagline">Governed Inference · Verifiable by Design</span>
292
- <a href="/" class="nav-back">← Console</a>
293
  </header>
294
 
295
  <!-- ===== MAIN ===== -->
@@ -297,11 +297,11 @@
297
 
298
  <div class="page-hero">
299
  <h1>Verifiable Inference</h1>
300
- <p>Real, verifiable governance receipts — including our own public ledger. Every receipt is signed and independently verifiable. The honesty is the product.</p>
301
  </div>
302
 
303
  <!-- ===================================================================
304
- SECTION A — Buyer-Verifiable Receipt (BVIR)
305
  =================================================================== -->
306
  <section class="section" id="section-bvir">
307
  <div class="section-head">
@@ -311,7 +311,7 @@
311
  </h2>
312
  <p>
313
  Makes a real POST /api/a11oy/v1/govern/infer call, then verifies the DSSE ECDSA-P256
314
- signature <strong>in-browser</strong> using WebCrypto — no server round-trip for verification.
315
  SHA-256 of the decoded payload is recomputed and matched to <code>receipt.payload_digest</code>.
316
  </p>
317
  <p class="moat-line">
@@ -334,20 +334,20 @@
334
  </section>
335
 
336
  <!-- ===================================================================
337
- SECTION B — Λ-Gated Honest Refusal
338
  =================================================================== -->
339
  <section class="section" id="section-govern">
340
  <div class="section-head">
341
  <h2>
342
  <span class="section-label">B</span>
343
- Λ-Gated Honest Refusal
344
  </h2>
345
  <p>
346
  Three preset governance cases. Each returns a REAL signed receipt via
347
- <code>szl_dsse.sign_khipu_receipt</code>. Λ is always labeled
348
- <span class="conj">Conjecture 1 — advisory, NOT a theorem</span>.
349
  </p>
350
- <p class="moat-line">"Even our refusals are signed and explained — no black-box boolean."</p>
351
  </div>
352
  <div class="section-body">
353
 
@@ -372,7 +372,7 @@
372
  </section>
373
 
374
  <!-- ===================================================================
375
- SECTION C — Verifiable Thesis
376
  =================================================================== -->
377
  <section class="section" id="section-thesis">
378
  <div class="section-head">
@@ -382,9 +382,9 @@
382
  </h2>
383
  <p>
384
  The 8 PROVEN formulas with verbatim Lean 4 statements, the 3-tier honest corpus
385
- (8 / ~35 / ~185), and the honest conjecture labels for Λ and Khipu BFT.
386
  </p>
387
- <p class="moat-line">"The honesty is the product. Click any formula — verify it yourself."</p>
388
  </div>
389
  <div class="section-body">
390
 
@@ -419,13 +419,13 @@
419
  </section>
420
 
421
  <!-- ===================================================================
422
- SECTION D — Public Ledger (real receipts from szl-lake)
423
  =================================================================== -->
424
  <section class="section" id="section-ledger">
425
  <div class="section-head">
426
  <h2>
427
  <span class="section-label">D</span>
428
- Public Ledger — Real Receipts
429
  </h2>
430
  <p>
431
  Real signed Khipu receipts from our public dataset
@@ -433,9 +433,9 @@
433
  (snapshot 2026-07-02). This page recomputes the <strong>hash-chain linkage in your browser</strong>;
434
  the DSSE / sigstore signatures verify <strong>offline</strong> with the
435
  <a href="https://pypi.org/project/szl-receipt/" target="_blank" rel="noopener">szl-receipt</a>
436
- library and cross-check against the canonical rows on Hugging Face — infrastructure we do not control.
437
  </p>
438
- <p class="moat-line">"The receipts you would read in diligence — including the ones where we mark our own central claim, &Lambda;, still OPEN."</p>
439
  </div>
440
  <div class="section-body">
441
  <div class="btn-row">
@@ -455,15 +455,15 @@
455
  </main>
456
 
457
  <footer class="footer">
458
- <p>SZL Holdings · a11oy · Doctrine v11 · 8 kernel-verified formulas @ c7c0ba17 ·
459
- Λ = Conjecture 1 (advisory) · Khipu BFT = Conjecture 2 ·
460
- <a href="/govern/health" target="_blank">Governance Health</a> ·
461
  <a href="/api/a11oy/v1/demo/thesis" target="_blank">Thesis API</a>
462
  </p>
463
  </footer>
464
 
465
  <!-- ===================================================================
466
- JAVASCRIPT — all in-browser, no CDN
467
  =================================================================== -->
468
  <script>
469
  "use strict";
@@ -495,7 +495,7 @@ function escHTML(s) {
495
 
496
  /* ---- base64 helpers ---- */
497
  function b64Decode(s) {
498
- // standard base64 → Uint8Array (not URL-safe; WebCrypto importKey returns SPKI base64)
499
  const bin = atob(s);
500
  const b = new Uint8Array(bin.length);
501
  for (let i = 0; i < bin.length; i++) b[i] = bin.charCodeAt(i);
@@ -509,10 +509,10 @@ function b64Encode(buf) {
509
  return btoa(s);
510
  }
511
 
512
- /* ---- DER ASN.1 → raw r‖s converter (for WebCrypto ECDSA P-256) ----
513
  cosign / cryptography-lib ECDSA signs in DER (ASN.1 SEQUENCE { INTEGER r, INTEGER s }).
514
- WebCrypto ECDSA P-256 SHA-256 expects IEEE P-1363 raw r‖s (64 bytes: 32+32).
515
- We decode the DER SEQUENCE here entirely in JS — no library needed.
516
  */
517
  function derToRaw(derBytes) {
518
  let i = 0;
@@ -594,14 +594,14 @@ async function importPubKeyFromPEM(pem) {
594
  }
595
 
596
  /* ====================================================================
597
- SECTION A — BVIR
598
  ==================================================================== */
599
  async function runBVIR() {
600
  const btn = el('bvir-run');
601
  btn.disabled = true;
602
  hide('bvir-verdict');
603
  hide('bvir-output');
604
- setStatus('bvir-status', 'Calling /api/a11oy/v1/govern/infer …', true);
605
 
606
  let data;
607
  try {
@@ -617,7 +617,7 @@ async function runBVIR() {
617
  return;
618
  }
619
 
620
- setStatus('bvir-status', 'Verifying signature in-browser via WebCrypto …', true);
621
 
622
  const dsse = data.dsse || {};
623
  const receipt= data.receipt|| {};
@@ -666,7 +666,7 @@ async function runBVIR() {
666
  let sigKeyid = '';
667
 
668
  if (!dsse.signed) {
669
- verifyError = 'UNSIGNED envelope — private key not available in this runtime. Receipt chain is still valid.';
670
  } else if (sigs.length === 0) {
671
  verifyError = 'No signatures in envelope.';
672
  } else {
@@ -682,7 +682,7 @@ async function runBVIR() {
682
  try {
683
  rawSig = derToRaw(sigBytes);
684
  } catch(e2) {
685
- verifyError = 'DER→raw conversion failed: ' + e2.message;
686
  }
687
  }
688
 
@@ -729,26 +729,26 @@ async function runBVIR() {
729
  let verdictHTML = '';
730
  if (verified && isDemoKey) {
731
  verdictHTML = `<div class="verdict-banner verdict-ok">
732
- ✓ VERIFIED (demo-signing-key — not the production cosign key)
733
  <span class="chip chip-ok">keyid: ${escHTML(sigKeyid)}</span>
734
  <div style="font-size:12px;font-weight:400;margin-top:6px;color:var(--text-dim)">
735
  Real ECDSA-P256 signature, verified in your browser against /demo-cosign.pub.
736
- This is a clearly-labelled DEMO key — the production cosign key stays
737
  founder-gated and is never placed in this runtime.
738
  </div>
739
  </div>`;
740
  } else if (verified) {
741
  verdictHTML = `<div class="verdict-banner verdict-ok">
742
- ✓ VERIFIED — WebCrypto ECDSA-P256 signature valid
743
  <span class="chip chip-ok">keyid: ${escHTML(sigKeyid)}</span>
744
  </div>`;
745
  } else if (!dsse.signed) {
746
  verdictHTML = `<div class="verdict-banner verdict-dim">
747
- ⚠ UNSIGNED — private key not in runtime; receipt chain still valid
748
  </div>`;
749
  } else {
750
  verdictHTML = `<div class="verdict-banner verdict-fail">
751
- ✗ VERIFICATION FAILED — ${escHTML(verifyError)}
752
  </div>`;
753
  }
754
 
@@ -780,33 +780,33 @@ async function runBVIR() {
780
  </div>
781
  <div class="hash-row">
782
  <span class="hash-label">Payload digest:</span>
783
- <span class="hash-val ${digestValClass}">${payloadDigestComputed.substring(0,32)}…</span>
784
  <span class="chip ${digestChipClass}">${digestChipText}</span>
785
  </div>
786
  ${hasDeclaredDigest ? `<div class="hash-row">
787
  <span class="hash-label">Declared digest:</span>
788
- <span class="hash-val">${escHTML(declaredPayloadDigest.substring(0,32))}…</span>
789
  </div>` : `<div class="hash-row">
790
  <span class="hash-label">Declared digest:</span>
791
- <span class="hash-val" style="color:var(--text-dim)">(none declared — nothing to compare against)</span>
792
  </div>`}
793
  <div class="hash-row">
794
  <span class="hash-label">PAE SHA-256:</span>
795
- <span class="hash-val">${paeSHA.substring(0,32)}…</span>
796
  </div>
797
  <div class="hash-row">
798
  <span class="hash-label">Chain prev:</span>
799
- <span class="hash-val">${escHTML(String(chainPrev).substring(0,32))}…</span>
800
  </div>
801
  <div class="hash-row">
802
  <span class="hash-label">Chain digest:</span>
803
- <span class="hash-val">${escHTML(String(chainDigest).substring(0,32))}…</span>
804
  </div>
805
  </div>
806
  <div style="font-size:12px;color:var(--text-dim);margin-bottom:8px">
807
- <span class="conj">Λ Conjecture 1 — advisory</span>
808
- Λ = ${escHTML(String((data.governance||{}).lambda ?? 'N/A'))}
809
- &nbsp;·&nbsp;
810
  Energy: <span class="chip chip-dim">${escHTML((data.energy||{}).label || 'UNAVAILABLE')}</span>
811
  </div>
812
  `;
@@ -819,18 +819,18 @@ async function runBVIR() {
819
  'governance.lambda': (data.governance||{}).lambda,
820
  'governance.lambda_kind': (data.governance||{}).lambda_kind,
821
  'receipt.seq': receipt.seq,
822
- 'receipt.prev': String(chainPrev).substring(0,32) + '…',
823
- 'receipt.digest': String(chainDigest).substring(0,32) + '…',
824
  'dsse.signed': dsse.signed,
825
  'dsse.keyid': dsseKeyid || null,
826
- 'dsse.key_kind': isDemoKey ? 'demo (demo-signing-key — NOT production cosign)' : (dsse.signed ? 'production cosign' : null),
827
  'dsse.payloadType': dsse.payloadType,
828
  'verify.public_key_url': pubKeyURL,
829
- 'verify.computed_payload_sha256': payloadDigestComputed.substring(0,32) + '…',
830
- 'verify.declared_payload_digest': hasDeclaredDigest ? declaredPayloadDigest.substring(0,32) + '…' : null,
831
  'verify.payload_digest_match': hasDeclaredDigest ? (payloadDigestMatches ? 'MATCH' : 'MISMATCH') : 'no declared digest to compare',
832
- 'verify.pae_sha256': paeSHA.substring(0,32) + '…',
833
- 'verify.result': verified ? (isDemoKey ? 'VERIFIED ✓ (demo-signing-key — not production cosign)' : 'VERIFIED ✓') : (dsse.signed === false ? 'UNSIGNED (no private key in runtime)' : 'FAILED: ' + verifyError),
834
  'energy.label': (data.energy||{}).label,
835
  };
836
  el('bvir-output').textContent = JSON.stringify(outputData, null, 2);
@@ -839,8 +839,8 @@ async function runBVIR() {
839
 
840
  setStatus('bvir-status', verified
841
  ? (isDemoKey
842
- ? '✓ WebCrypto verified — real ECDSA-P256 over DSSE PAE with demo-signing-key (NOT the production cosign key).'
843
- : '✓ WebCrypto verified — real ECDSA-P256 signature over DSSE PAE.')
844
  : (dsse.signed === false
845
  ? 'Unsigned receipt (private key absent from runtime). Chain valid.'
846
  : 'Verification result: ' + verifyError));
@@ -848,11 +848,11 @@ async function runBVIR() {
848
  }
849
 
850
  /* ====================================================================
851
- SECTION B — Governed Refusal
852
  ==================================================================== */
853
  async function runGovern(caseKey) {
854
  hide('govern-panel');
855
- setStatus('govern-status', `Calling /api/a11oy/v1/demo/govern case="${caseKey}" …`, true);
856
 
857
  let data;
858
  try {
@@ -875,20 +875,20 @@ async function runGovern(caseKey) {
875
 
876
  // Verdict banner
877
  const decClasses = { allow:'verdict-ok', review:'verdict-dim', deny:'verdict-fail' };
878
- const decLabels = { allow:'✓ ALLOW — governance passed', review:'⚠ REVIEW — below advisory floor', deny:'✗ DENY — gate fired' };
879
  const bannerCls = decClasses[decision] || 'verdict-dim';
880
  const bannerLbl = decLabels[decision] || decision.toUpperCase();
881
  el('govern-verdict-banner').innerHTML = `<div class="verdict-banner ${bannerCls}">${bannerLbl}</div>`;
882
 
883
- // Λ row
884
  const lambdaPass = gov.lambda_pass;
885
  el('govern-lambda-row').innerHTML = `
886
  <div style="display:flex;align-items:center;gap:10px;flex-wrap:wrap">
887
- <span style="font-size:14px;font-weight:700">Λ = ${escHTML(String(gov.lambda ?? 'N/A'))}</span>
888
  <span class="chip ${lambdaPass ? 'chip-ok' : 'chip-err'}">
889
  ${lambdaPass ? 'PASS' : 'FAIL'} (floor ${escHTML(String(gov.lambda_floor ?? 0.9))})
890
  </span>
891
- <span class="conj">Conjecture 1 — advisory, NOT a theorem</span>
892
  </div>
893
  <div style="font-size:12px;color:var(--text-dim);margin-top:4px">
894
  ${escHTML(gov.lambda_kind || 'Conjecture 1 (advisory; NOT a theorem)')}
@@ -902,9 +902,9 @@ async function runGovern(caseKey) {
902
  const fired = g.fired;
903
  gatesHTML += `
904
  <div class="gate-row">
905
- <span class="gate-name">${escHTML(g.name || '—')}</span>
906
  <span class="gate-fired ${fired ? 'chip chip-err' : 'chip chip-ok'}">${fired ? 'FIRED' : 'PASS'}</span>
907
- <span class="chip chip-dim">${escHTML(g.decision || '—')}</span>
908
  </div>`;
909
  });
910
  el('govern-gates').innerHTML = gatesHTML;
@@ -918,8 +918,8 @@ async function runGovern(caseKey) {
918
  lambda: receipt.lambda,
919
  lambda_kind: receipt.lambda_kind,
920
  gates: receipt.gates,
921
- prev: String(chain.prev || '').substring(0,32) + '…',
922
- digest: String(chain.digest || '').substring(0,32) + '…',
923
  'dsse.signed': signed,
924
  'dsse.keyid': ((dsse.signatures||[])[0]||{}).keyid,
925
  honesty: data.honesty,
@@ -932,17 +932,17 @@ async function runGovern(caseKey) {
932
  }
933
 
934
  show('govern-panel');
935
- setStatus('govern-status', `Decision: ${decision.toUpperCase()} · Λ = ${gov.lambda} · ${dsse.signed ? 'Receipt signed ✓' : 'Receipt unsigned (key absent)'}`);
936
  }
937
 
938
  /* ====================================================================
939
- SECTION C — Verifiable Thesis
940
  ==================================================================== */
941
  async function loadThesis() {
942
  const btn = el('thesis-load');
943
  btn.disabled = true;
944
  hide('thesis-panel');
945
- setStatus('thesis-status', 'Loading /api/a11oy/v1/demo/thesis …', true);
946
 
947
  let data;
948
  try {
@@ -973,7 +973,7 @@ async function loadThesis() {
973
  });
974
  corpusHTML += `</div>`;
975
  corpusHTML += `<div class="corpus-never-claim">
976
- ⚠ ${escHTML(corpus.honest_note || 'We never claim 183 proven.')}
977
  </div>`;
978
  el('thesis-corpus').innerHTML = corpusHTML;
979
 
@@ -988,7 +988,7 @@ async function loadThesis() {
988
  </div>
989
  <div class="formula-lean">${escHTML(f.lean)}</div>
990
  <div class="formula-desc">${escHTML(f.description)}</div>
991
- <div class="formula-status">✓ ${escHTML(f.status)}</div>
992
  </div>`;
993
  });
994
  el('thesis-formulas').innerHTML = formulasHTML;
@@ -1000,14 +1000,14 @@ async function loadThesis() {
1000
  </div>
1001
  <div style="display:flex;gap:14px;flex-wrap:wrap">
1002
  <div style="flex:1;min-width:220px;background:var(--bg-panel);border:1px solid #92400e;border-radius:var(--radius);padding:14px">
1003
- <div style="font-size:11px;font-weight:700;color:var(--amber);text-transform:uppercase;letter-spacing:.07em;margin-bottom:6px">Conjecture 1 — Λ (Lambda)</div>
1004
  <div style="font-size:13px;color:var(--text-dim)">${escHTML(doctrine.lambda_kind || 'Conjecture 1 (advisory; NOT a theorem)')}</div>
1005
  <div style="font-size:12px;color:var(--text-mute);margin-top:6px">Open bounty: szl-holdings/lambda-bounty</div>
1006
  </div>
1007
  <div style="flex:1;min-width:220px;background:var(--bg-panel);border:1px solid #991b1b;border-radius:var(--radius);padding:14px">
1008
- <div style="font-size:11px;font-weight:700;color:var(--red);text-transform:uppercase;letter-spacing:.07em;margin-bottom:6px">Conjecture 2 — Khipu BFT</div>
1009
  <div style="font-size:13px;color:var(--text-dim)">${escHTML(doctrine.bft_kind || 'Conjecture 2 (NOT proven; NOT a theorem)')}</div>
1010
- <div style="font-size:12px;color:var(--text-mute);margin-top:6px">Labeled honestly everywhere — no false safety claim</div>
1011
  </div>
1012
  </div>
1013
  <div style="margin-top:14px;font-size:12px;color:var(--text-dim)">
@@ -1016,12 +1016,12 @@ async function loadThesis() {
1016
  `;
1017
 
1018
  show('thesis-panel');
1019
- setStatus('thesis-status', `Loaded ${formulas.length} proven formulas · 3-tier corpus · live doctrine`);
1020
  btn.disabled = false;
1021
  }
1022
 
1023
  /* ====================================================================
1024
- SECTION D — Public Ledger (real receipts from szl-lake, snapshot)
1025
  In-browser: hash-chain linkage check. Offline: signatures via szl-receipt.
1026
  ==================================================================== */
1027
  const LEDGER_SNAPSHOT = {"source": "https://huggingface.co/datasets/SZLHOLDINGS/szl-lake", "captured_utc": "2026-07-02", "lutar_lean": [{"branch": "theorem-u-kernel", "chain_index": 1, "doctrine": "v11", "honesty": {"conjecture_1": "OPEN: unconditional Lambda uniqueness is Conjecture 1 and is machine-checked FALSE as stated. Theorem U does NOT close it.", "doctrine": "v11", "locked_five_unchanged": true, "locked_set": ["F1", "F11", "F12", "F18", "F19"], "theorem_u": "REAL-conditional: Lutar.Uniqueness Theorem U is kernel-verified (axiom footprint within the Lean/Mathlib trust base, no sorry) but CONDITIONAL on its stated checkable hypotheses; it is NOT part of the locked-proven baseline."}, "kernel_commit": "e736decd244ae06e8bb48531c6c7dc0f1029b25a", "kernel_commit_short": "e736decd244a", "kind": "theorem-u-anchor", "lambda_status": "Conjecture_1 (OPEN; unconditional uniqueness machine-checked FALSE)", "numbers": {"axioms_unique": 22, "declarations": 1323, "sorries_noncomment": 254}, "organ": "lutar-lean", "prev_hash": null, "receipt_id": "d70f444db57df9a4a2d52e69408ce61b511e4b50152f7fbf97456b1af66fe9a0", "schema": "szl.khipu.receipt/v1", "signing": {"format": "sigstore-keyless-bundle", "bytes": 18428, "b64_head": "eyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZGV2\u2026"}, "source_run": {"conclusion": "success", "id": "27186151340", "url": "https://github.com/szl-holdings/lutar-lean/actions/runs/27186151340", "workflow": "Lake build (gate + numbers)"}, "subject": {"name": "theorem_u_snapshot.json", "sha256": "82d08a4e892579e815d880d51f61cb8035a3325e077c29e412f310f76b50985e", "snapshot": {"branch": "theorem-u-kernel", "built_at_utc": "2026-06-09T05:37:45Z", "honesty": {"conjecture_1": "OPEN: unconditional Lambda uniqueness is Conjecture 1 and is machine-checked FALSE as stated. Theorem U does NOT close it.", "doctrine": "v11", "locked_five_unchanged": true, "locked_set": ["F1", "F11", "F12", "F18", "F19"], "theorem_u": "REAL-conditional: Lutar.Uniqueness Theorem U is kernel-verified (axiom footprint within the Lean/Mathlib trust base, no sorry) but CONDITIONAL on its stated checkable hypotheses; it is NOT part of the locked-proven baseline."}, "kernel_commit": "e736decd244ae06e8bb48531c6c7dc0f1029b25a", "kernel_commit_short": "e736decd244a", "lean_numbers": {"lean_numbers_sha256": "50098073e92aefdf275ec53e60faafc0f1bd5d4a1a88023e819490aaaa69d4d6", "numbers": {"axiom_names": ["A6'_block_consistent", "KS_theorem_1_1", "MomentSubGaussian", "audit_reidemeister_invariance", "canonicalReceipt", "chromotopology_code_bijection", "compression_collision_resistant", "domain_separation", "gleason_length_mod_8", "klDivergence_nonneg", "lambda_schur_concave_n_axis", "lambda_stationary_unique", "leaf_collision_resistant", "liu_hui_pi_converges", "node_collision_resistant", "pinsker", "r1_invariance", "r2_invariance", "setAlpha_cauchy", "setDelta_stage2", "sha256", "sha256_collision_resistant"], "axioms_raw": 23, "axioms_unique": 22, "declarations": 1323, "sorries_baseline": 251, "sorries_noncomment": 254, "sorries_putnam": 56, "sorries_raw": 307}, "reference_vectors_sha256": "857967629daf5e5c45a167306ea0e0091569a29766b01ac91bef15a539b816dc", "replay_hash": "9860c3332a2d0b0553b775dcd27111b0ce4fae4bc5cebe2827dc6148be4cbebe", "schema": "szl.lean_numbers/v1"}, "repo": "szl-holdings/lutar-lean", "schema": "szl.theorem_u.snapshot/v1", "theorem_u": {"decl_source_sha256": {"Lutar/Uniqueness/AxiomCheck.lean": "f45781ef2becf15eccd0c31702603a55cfab1eb7960483593a045202b66f4887", "Lutar/Uniqueness/Identifiability.lean": "fa340e6a999eac7ea1cd035d90647548baaa290b7376d7fcbdcbd165e475dedf", "Lutar/Uniqueness/LambdaEquiv.lean": "03f63e36f3a9b19e8e9d4f48313a450bae7c85fcb53049d52e0f6d4adf4b1c23", "Lutar/Uniqueness/TheoremU.lean": "c958520ba31d6fc1f48a9b49871d67812f178e168b31bf2be9e3d5fb2061386c"}, "full_axiom_footprint": {"Lutar.Uniqueness.AxiomCheck.conjecture1_still_open": [], "Lutar.Uniqueness.AxiomCheck.locked_count_five": [], "Lutar.Uniqueness.AxiomCheck.theoremU_axiom_sets_kernel_only": [], "Lutar.Uniqueness.AxiomCheck.theoremU_excluded_from_locked": [], "Lutar.Uniqueness.CorollaryU1_LambdaUnique_Separable": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.CorollaryU2_LambdaUnique_Factors": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.TheoremU_LambdaUnique": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.TheoremU_LambdaUnique_eq": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.identifiability_forces_lambda": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.lambda_equiv_to_eq_of_anchored": ["Classical.choice", "Quot.sound", "propext"]}, "headline_axiom_footprint": {"CorollaryU1_LambdaUnique_Separable": ["Classical.choice", "Quot.sound", "propext"], "CorollaryU2_LambdaUnique_Factors": ["Classical.choice", "Quot.sound", "propext"], "TheoremU_LambdaUnique": ["Classical.choice", "Quot.sound", "propext"], "TheoremU_LambdaUnique_eq": ["Classical.choice", "Quot.sound", "propext"], "identifiability_forces_lambda": ["Classical.choice", "Quot.sound", "propext"], "lambda_equiv_to_eq_of_anchored": ["Classical.choice", "Quot.sound", "propext"]}, "headline_decls": ["CorollaryU1_LambdaUnique_Separable", "CorollaryU2_LambdaUnique_Factors", "TheoremU_LambdaUnique", "TheoremU_LambdaUnique_eq", "identifiability_forces_lambda", "lambda_equiv_to_eq_of_anchored"], "kernel_only": true, "kernel_trust_base": ["Classical.choice", "Quot.sound", "funext", "propext"], "module": "Lutar.Uniqueness", "status": "REAL-conditional"}}}, "theorem_u_status": "REAL-conditional", "timestamp": "2026-06-09T05:39:22Z"}, {"branch": "main", "chain_index": 2, "doctrine": "v11", "honesty": {"conjecture": "This is a GENERATED, OPEN conjecture \u2014 NOT a theorem and NOT machine-verified. It remains OPEN until a solution is independently verified.", "difficulty": "Difficulty 'open-resistant' / grade 'OPEN' come from a REAL bounded solver run. OPEN means searched-to-budget, not proven true; VERIFIED-FINITE certifies only the finite enumerated domain; REFUTED carries a concrete witness. No score is fabricated.", "doctrine": "v11", "kernel_only": false, "novelty": "Novelty verdict 'novel-candidate' is an advisory screen, not a proof of originality; external prior-art sources are labelled live/cached/unreachable and an unreachable source never confirms novelty.", "signing": "Disclosure is cosign keyless-OIDC signed and anchored into the szl-lake DSSE Khipu ledger; the signature attests the timestamp + content, NOT the truth of the conjecture.", "status": "OPEN"}, "kernel_commit": "d851aefe86b9f12f9d4423200bd9e5257d05c41e", "kernel_commit_short": "d851aefe86b9", "kind": "conjecture-disclosure-anchor", "milestone_kind": "conjecture-disclosure", "milestone_status": "OPEN", "milestone_title": "SZL mixing-map convergence conjecture", "numbers": {"axioms_unique": null, "declarations": null, "sorries_noncomment": null}, "organ": "lutar-lean", "prev_hash": "d70f444db57df9a4a2d52e69408ce61b511e4b50152f7fbf97456b1af66fe9a0", "receipt_id": "08744b67b647039f87abbf0b29587638ae777308ca7fc2434ed3ae4033687b50", "schema": "szl.khipu.receipt/v1", "signing": {"format": "sigstore-keyless-bundle", "bytes": 17488, "b64_head": "eyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZGV2\u2026"}, "source_run": {"conclusion": "success", "id": "27318564784", "url": "https://github.com/szl-holdings/lutar-lean/actions/runs/27318564784", "workflow": "Conjecture Factory (generate -> timestamp -> grade -> anchor)"}, "subject": {"name": "conjecture_snapshot.json", "sha256": "7faded7df9ac5bea4ca7ddaa1e5c38c247c237fd49b8a1a39d35a260c2189fb0", "snapshot": {"branch": "main", "built_at_utc": "2026-06-11T01:54:20Z", "candidate": {"created_utc": "2026-06-11T01:54:19Z", "doctrine": "v11", "domain": "number-theory / arithmetic dynamics", "id": "cf-5ddbbe7571a9", "intended_solution_outline": "Bound the orbit by a Lyapunov / drift argument on the 2-adic valuation: show the\ncontracting branch (n = 3 mod 4) dominates the accelerating branch (n = 1 mod 4)\nin expectation, then rule out non-trivial cycles via a residue-class descent.\nStatus: OPEN \u2014 no proof is claimed; the predicate only performs bounded testing.", "predicate": {"description": "Sound bounded-orbit checker: returns False only on a detected non-1 cycle (a certain counterexample); inconclusive bounded runs assert no counterexample.", "entry": "holds", "kind": "python-callable", "module": "conjectures/samples/szl-mixing-map/predicate.py"}, "references": ["conjectures/corpus/collatz.md (related but distinct: classical 3n+1 map)", "Lagarias, J. (2010). The 3x+1 problem: an annotated bibliography."], "schema": "szl.conjecture.candidate/v1", "statement": "Define M : Z+ -> Z+ by\n M(n) = n / 2 if n is even,\n M(n) = (3n + 1) / 2 if n is odd and n = 1 (mod 4),\n M(n) = (n + 1) / 2 if n is odd and n = 3 (mod 4).\nConjecture: for every integer n >= 1 there exists k >= 0 with M^k(n) = 1.", "statement_canonical": "Define M : Z+ -> Z+ by M(n) = n / 2 if n is even, M(n) = (3n + 1) / 2 if n is odd and n = 1 (mod 4), M(n) = (n + 1) / 2 if n is odd and n = 3 (mod 4). Conjecture: for every integer n >= 1 there exists k >= 0 with M^k(n) = 1.", "statement_hash": "sha256:5ddbbe7571a93f9ed3d49c37dbb3559eb339a51380e427882bd3783b7cb2743a", "taxonomy": "OPEN", "title": "SZL mixing-map convergence conjecture"}, "grade": {"budget": 100000, "candidate_id": "cf-5ddbbe7571a9", "difficulty": "open-resistant", "graded_utc": "2026-06-11T01:54:20Z", "honesty": "Grade from a REAL ensemble run. REFUTED carries a concrete witness. VERIFIED-FINITE certifies only the finite enumerated domain, not the conjecture in general. OPEN means searched-to-budget with no counterexample \u2014 NOT a proof of truth. The candidate stays OPEN (doctrine v11).", "result": "OPEN", "schema": "szl.conjecture.grade/v1", "seed": 1729, "solver_ensemble": [{"budget": 100000, "checked": 100000, "elapsed_sec": 0.411268, "note": "infinite/streaming domain", "resolved": false, "result": "OPEN", "solver": "exhaustive", "witness": null}, {"budget": 100000, "checked": 100000, "elapsed_sec": 0.654207, "note": "random sampling found no counterexample (not a proof)", "resolved": false, "result": "OPEN", "solver": "sampler", "witness": null}], "success_rate": 0.0, "witness": null}, "honesty": {"conjecture": "This is a GENERATED, OPEN conjecture \u2014 NOT a theorem and NOT machine-verified. It remains OPEN until a solution is independently verified.", "difficulty": "Difficulty 'open-resistant' / grade 'OPEN' come from a REAL bounded solver run. OPEN means searched-to-budget, not proven true; VERIFIED-FINITE certifies only the finite enumerated domain; REFUTED carries a concrete witness. No score is fabricated.", "doctrine": "v11", "kernel_only": false, "novelty": "Novelty verdict 'novel-candidate' is an advisory screen, not a proof of originality; external prior-art sources are labelled live/cached/unreachable and an unreachable source never confirms novelty.", "signing": "Disclosure is cosign keyless-OIDC signed and anchored into the szl-lake DSSE Khipu ledger; the signature attests the timestamp + content, NOT the truth of the conjecture.", "status": "OPEN"}, "kernel_commit": "d851aefe86b9f12f9d4423200bd9e5257d05c41e", "kernel_commit_short": "d851aefe86b9", "kind": "conjecture-disclosure", "milestone": {"difficulty": "open-resistant", "grade_result": "OPEN", "headline_decls": [], "id": "cf-5ddbbe7571a9", "kernel_only": false, "novelty_verdict": "novel-candidate", "release_stage": "statement", "statement_hash": "sha256:5ddbbe7571a93f9ed3d49c37dbb3559eb339a51380e427882bd3783b7cb2743a", "status": "OPEN", "title": "SZL mixing-map convergence conjecture"}, "novelty": {"candidate_id": "cf-5ddbbe7571a9", "external": [{"hits": 0, "note": "offline run (--online not set)", "source": "arxiv", "status": "unreachable", "top": []}, {"hits": 0, "note": "offline run (--online not set)", "source": "crossref", "status": "unreachable", "top": []}], "honesty": "Novelty is a screen, not a proof of originality. External sources are labelled live/cached/unreachable; an unreachable source contributes no hits and is never silently treated as confirming novelty. The candidate stays OPEN regardless of this verdict (doctrine v11).", "local_corpus": {"corpus_dir": "conjectures/corpus", "documents_scanned": 2, "max_similarity": 0.0688, "method": "char-5-gram shingle Jaccard", "near_duplicate": false, "nearest": {"doc": "collatz.md", "similarity": 0.0688}, "threshold": 0.8, "top": [{"doc": "collatz.md", "similarity": 0.0688}, {"doc": "goldbach.md", "similarity": 0.0451}]}, "schema": "szl.conjecture.novelty/v1", "screened_utc": "2026-06-11T01:54:19Z", "statement_hash": "sha256:5ddbbe7571a93f9ed3d49c37dbb3559eb339a51380e427882bd3783b7cb2743a", "verdict": "novel-candidate", "verdict_reason": "no near-duplicate found (local-only; external prior-art not fully screened \u2014 unreachable: ['arxiv', 'crossref'])"}, "predicate_type": "https://szl-holdings/conjecture-disclosure/v1", "repo": "szl-holdings/lutar-lean", "schema": "szl.conjecture.disclosure/v1"}}, "timestamp": "2026-06-11T01:54:27Z"}, {"branch": "main", "chain_index": 3, "doctrine": "v11", "honesty": {"conjecture_1": "OPEN: unconditional Lambda uniqueness is Conjecture 1 and is machine-checked FALSE as stated; conjecture1_still_open re-asserts it stays open.", "doctrine": "v11", "locked_baseline": "REAL-invariant: kernel-verified meta-theorems in Lutar/Uniqueness/AxiomCheck.lean (locked_count_eight, theoremU_excluded_from_locked, theoremU_axiom_sets_kernel_only, conjecture1_still_open) \u2014 each proven by `decide`, axiom footprint within the Lean/Mathlib trust base, no sorry. They ASSERT that the locked-proven baseline is EXACTLY the eight {F1,F4,F7,F11,F12,F18,F19,F22}; they do NOT themselves re-prove those formulas (the formula proofs live in Lutar/Puriq/Formulas/ProvedFormulas.lean).", "locked_set": ["F1", "F4", "F7", "F11", "F12", "F18", "F19", "F22"], "theorem_u": "Theorem U stays REAL-conditional and EXCLUDED from this locked baseline (theoremU_excluded_from_locked); anchoring this milestone does not change Theorem U's status."}, "kernel_commit": "25e0b2af781f5fb10324945ea10c861bcc28cc83", "kernel_commit_short": "25e0b2af781f", "kind": "locked-baseline-anchor", "milestone_kind": "locked-baseline", "milestone_status": "REAL-invariant", "milestone_title": "Locked-proven baseline (Doctrine v11) \u2014 kernel meta-invariants", "numbers": {"axioms_unique": 22, "declarations": 1323, "sorries_noncomment": 254}, "organ": "lutar-lean", "prev_hash": "08744b67b647039f87abbf0b29587638ae777308ca7fc2434ed3ae4033687b50", "receipt_id": "dcdad01763241e4d7af6b45e59949e6596c12ccf43ed6b784471c1f05b4715c0", "schema": "szl.khipu.receipt/v1", "signing": {"format": "sigstore-keyless-bundle", "bytes": 19036, "b64_head": "eyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZGV2\u2026"}, "source_run": {"conclusion": "success", "id": "27319352318", "url": "https://github.com/szl-holdings/lutar-lean/actions/runs/27319352318", "workflow": "Lake build (gate + numbers)"}, "subject": {"name": "locked_baseline_snapshot.json", "sha256": "19ea5946195f7437cfb881eb5489898d0d45f5f074dfa210c22eb6c8bbfc3bc9", "snapshot": {"branch": "main", "built_at_utc": "2026-06-11T02:18:27Z", "honesty": {"conjecture_1": "OPEN: unconditional Lambda uniqueness is Conjecture 1 and is machine-checked FALSE as stated; conjecture1_still_open re-asserts it stays open.", "doctrine": "v11", "locked_baseline": "REAL-invariant: kernel-verified meta-theorems in Lutar/Uniqueness/AxiomCheck.lean (locked_count_eight, theoremU_excluded_from_locked, theoremU_axiom_sets_kernel_only, conjecture1_still_open) \u2014 each proven by `decide`, axiom footprint within the Lean/Mathlib trust base, no sorry. They ASSERT that the locked-proven baseline is EXACTLY the eight {F1,F4,F7,F11,F12,F18,F19,F22}; they do NOT themselves re-prove those formulas (the formula proofs live in Lutar/Puriq/Formulas/ProvedFormulas.lean).", "locked_set": ["F1", "F4", "F7", "F11", "F12", "F18", "F19", "F22"], "theorem_u": "Theorem U stays REAL-conditional and EXCLUDED from this locked baseline (theoremU_excluded_from_locked); anchoring this milestone does not change Theorem U's status."}, "kernel_commit": "25e0b2af781f5fb10324945ea10c861bcc28cc83", "kernel_commit_short": "25e0b2af781f", "kind": "locked-baseline", "lean_numbers": {"lean_numbers_sha256": "38f9a69cb289110e44ffa9bc4a8575d811220c4654a7985b85694d6f1bb3f7f9", "numbers": {"axiom_names": ["A6'_block_consistent", "KS_theorem_1_1", "MomentSubGaussian", "audit_reidemeister_invariance", "canonicalReceipt", "chromotopology_code_bijection", "compression_collision_resistant", "domain_separation", "gleason_length_mod_8", "klDivergence_nonneg", "lambda_schur_concave_n_axis", "lambda_stationary_unique", "leaf_collision_resistant", "liu_hui_pi_converges", "node_collision_resistant", "pinsker", "r1_invariance", "r2_invariance", "setAlpha_cauchy", "setDelta_stage2", "sha256", "sha256_collision_resistant"], "axioms_raw": 23, "axioms_unique": 22, "declarations": 1323, "sorries_baseline": 251, "sorries_noncomment": 254, "sorries_putnam": 56, "sorries_raw": 307}, "reference_vectors_sha256": "857967629daf5e5c45a167306ea0e0091569a29766b01ac91bef15a539b816dc", "replay_hash": "1f0c9d9938b96b3d56fe01e37b955e1b91ff1aec0610fe30c30e515cc8ab469c", "schema": "szl.lean_numbers/v1"}, "milestone": {"decl_source_sha256": {"Lutar/Uniqueness/AxiomCheck.lean": "5e7998d33a1928c12f2e07595ec929544ac04e37f17ad7693ab2838136ab540f", "Lutar/Uniqueness/Identifiability.lean": "fa340e6a999eac7ea1cd035d90647548baaa290b7376d7fcbdcbd165e475dedf", "Lutar/Uniqueness/LambdaEquiv.lean": "03f63e36f3a9b19e8e9d4f48313a450bae7c85fcb53049d52e0f6d4adf4b1c23", "Lutar/Uniqueness/TheoremU.lean": "c958520ba31d6fc1f48a9b49871d67812f178e168b31bf2be9e3d5fb2061386c"}, "full_axiom_footprint": {"Lutar.Uniqueness.AxiomCheck.conjecture1_still_open": [], "Lutar.Uniqueness.AxiomCheck.locked_count_eight": [], "Lutar.Uniqueness.AxiomCheck.theoremU_axiom_sets_kernel_only": [], "Lutar.Uniqueness.AxiomCheck.theoremU_excluded_from_locked": [], "Lutar.Uniqueness.CorollaryU1_LambdaUnique_Separable": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.CorollaryU2_LambdaUnique_Factors": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.TheoremU_LambdaUnique": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.TheoremU_LambdaUnique_eq": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.identifiability_forces_lambda": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.lambda_equiv_to_eq_of_anchored": ["Classical.choice", "Quot.sound", "propext"]}, "headline_axiom_footprint": {"conjecture1_still_open": [], "locked_count_eight": [], "theoremU_axiom_sets_kernel_only": [], "theoremU_excluded_from_locked": []}, "headline_decls": ["conjecture1_still_open", "locked_count_eight", "theoremU_axiom_sets_kernel_only", "theoremU_excluded_from_locked"], "id": "locked-baseline", "kernel_only": true, "kernel_trust_base": ["Classical.choice", "Quot.sound", "funext", "propext"], "module": "Lutar.Uniqueness.AxiomCheck", "status": "REAL-invariant", "title": "Locked-proven baseline (Doctrine v11) \u2014 kernel meta-invariants"}, "repo": "szl-holdings/lutar-lean", "schema": "szl.proof.snapshot/v1"}}, "timestamp": "2026-06-11T02:20:21Z"}], "amaru": [{"receipt_id": "4c9c3f2b8d6452d9bc0e9a9144fc9e1743b3ca76544a988d4d9e4b39df87ba73", "timestamp": "2026-06-02T02:13:07.827680+00:00", "organ": "amaru", "kind": "tick", "index": 0, "lambda": 0.9, "lambda_pass": true, "predicted_hash": "", "actual_hash": "4c9c3f2b8d6452d9bc0e9a9144fc9e1743b3ca76544a988d4d9e4b39df87ba73", "delta": 0.0, "lutar_anchor": "c7c0ba17", "doctrine": "v11", "decl": 749, "axioms": 14, "sorries": 163, "neuro_citations": "[]", "dsse_payload_type": "application/vnd.szl.khipu+json", "dsse_pae_sha256": "6a8ba013ddcd1938e0fc2174ef79287ca49266277b0195595f324dacb9eb02c9", "dsse_sig": "MEQCIBIZjd6T0E4Bhl0OGkhcMZmAuqmnN0ZxmWrL+7U/h31JAiAmF2U1DBEQieaDrFkHcjBcOW91PY1glK0X+/2EKprpVQ==", "dsse_keyid": "szlholdings-cosign", "dsse_signed": true, "verify_key_url": "https://github.com/szl-holdings/.github/blob/main/cosign.pub"}, {"receipt_id": "bc4d6a1629c01584eb6789d19a432fbc9448ce92ada8d47e14552fe94dee9fa1", "timestamp": "2026-06-02T02:13:08.490579+00:00", "organ": "amaru", "kind": "tick", "index": 1, "lambda": 0.9, "lambda_pass": true, "predicted_hash": "4c9c3f2b8d6452d9bc0e9a9144fc9e1743b3ca76544a988d4d9e4b39df87ba73", "actual_hash": "bc4d6a1629c01584eb6789d19a432fbc9448ce92ada8d47e14552fe94dee9fa1", "delta": 0.0, "lutar_anchor": "c7c0ba17", "doctrine": "v11", "decl": 749, "axioms": 14, "sorries": 163, "neuro_citations": "[]", "dsse_payload_type": "application/vnd.szl.khipu+json", "dsse_pae_sha256": "3cb923bc57002b34cd52124601bfbeeff68c6232e598dd06eccb4ff2847f1371", "dsse_sig": "MEUCIQDBB4xUJMFm4YKcZ0mcz6n3q6XomOKEepJWmaplX9Xo0gIgUIg3Xm316oVN05pvIoNxhJBDyL6Vhp1xfEq9nx9V5Wg=", "dsse_keyid": "szlholdings-cosign", "dsse_signed": true, "verify_key_url": "https://github.com/szl-holdings/.github/blob/main/cosign.pub"}, {"receipt_id": "2f872c5144585602dd1016ce732912134ad30423e442fda009cdc0d168c6732d", "timestamp": "2026-06-02T02:13:09.173270+00:00", "organ": "amaru", "kind": "tick", "index": 2, "lambda": 0.9, "lambda_pass": true, "predicted_hash": "bc4d6a1629c01584eb6789d19a432fbc9448ce92ada8d47e14552fe94dee9fa1", "actual_hash": "2f872c5144585602dd1016ce732912134ad30423e442fda009cdc0d168c6732d", "delta": 0.0, "lutar_anchor": "c7c0ba17", "doctrine": "v11", "decl": 749, "axioms": 14, "sorries": 163, "neuro_citations": "[]", "dsse_payload_type": "application/vnd.szl.khipu+json", "dsse_pae_sha256": "f72e37f1ea8d785d862ec7469d3908fc7b455360964d6cdea61e430d89b3e66d", "dsse_sig": "MEYCIQDvfS5l1nyk5zHz9wsNwe/wj6ZPNAMbbJ4KzMG2ZXEQkwIhAJ4mkTOAnOdNWFb2SuweFbQnjP0QPORGAA/IU8sHB+X5", "dsse_keyid": "szlholdings-cosign", "dsse_signed": true, "verify_key_url": "https://github.com/szl-holdings/.github/blob/main/cosign.pub"}]};
@@ -1029,7 +1029,7 @@ const LEDGER_SNAPSHOT = {"source": "https://huggingface.co/datasets/SZLHOLDINGS/
1029
  function renderLedger() {
1030
  const btn = el('ledger-load');
1031
  btn.disabled = true;
1032
- setStatus('ledger-status', 'Checking hash-chain linkage in-browser …', true);
1033
 
1034
  const lut = LEDGER_SNAPSHOT.lutar_lean || [];
1035
  const ama = LEDGER_SNAPSHOT.amaru || [];
@@ -1045,7 +1045,7 @@ function renderLedger() {
1045
  });
1046
  const intact = broken === 0;
1047
  let chainHTML = '<div class="verdict-banner ' + (intact ? 'verdict-ok' : 'verdict-fail') + '">'
1048
- + (intact ? '✓ CHAIN INTACT' : '✗ CHAIN BROKEN') + ' — ' + links + '/' + lut.length
1049
  + ' hash-links verified in your browser <span class="chip chip-dim">organ: lutar-lean</span></div>'
1050
  + '<div style="font-size:12px;color:var(--text-dim);margin-bottom:8px">Each receipt\'s <code>prev_hash</code> '
1051
  + 'is compared to the previous receipt\'s <code>receipt_id</code>. This proves append-only ordering. '
@@ -1053,8 +1053,8 @@ function renderLedger() {
1053
  rows.forEach(({ r, i, prev, ok }) => {
1054
  chainHTML += '<div class="hash-row"><span class="hash-label">#' + escHTML(String(r.chain_index)) + ' '
1055
  + escHTML(r.kind || '') + '</span><span class="hash-val">id ' + escHTML(String(r.receipt_id).substring(0,16))
1056
- + '…</span><span class="hash-val ' + (ok ? 'hash-match' : 'hash-mismatch') + '">prev '
1057
- + escHTML(prev == null ? '(genesis)' : String(prev).substring(0,16) + '…') + '</span>'
1058
  + '<span class="chip ' + (ok ? 'chip-ok' : 'chip-err') + '">' + (ok ? 'LINK OK' : 'BROKEN') + '</span></div>';
1059
  });
1060
  el('ledger-chain').innerHTML = chainHTML;
@@ -1075,40 +1075,41 @@ function renderLedger() {
1075
  + '<span class="formula-id">lutar-lean</span><span class="formula-name">' + escHTML(r.kind || 'receipt') + '</span>'
1076
  + '<span class="chip chip-dim">schema ' + escHTML(r.schema || '') + '</span></div>'
1077
  + '<div class="hash-row"><span class="hash-label">receipt_id</span><span class="hash-val">'
1078
- + escHTML(String(r.receipt_id).substring(0,40)) + '…</span></div>'
1079
  + (r.numbers ? '<div style="font-size:12px;color:var(--text-dim);margin:6px 0">declarations '
1080
- + escHTML(String(r.numbers.declarations)) + ' · axioms ' + escHTML(String(r.numbers.axioms_unique))
1081
- + ' · sorries ' + escHTML(String(r.numbers.sorries_noncomment)) + ' · kernel '
1082
  + escHTML(String(r.kernel_commit_short || '')) + '</div>' : '')
1083
  + '<div style="margin:8px 0">' + honestyHTML + '</div>'
1084
- + '<div style="font-size:12px;color:var(--text-mute)">signing: ' + escHTML(sg.format || '—')
1085
  + (sg.bytes ? ' (' + escHTML(String(sg.bytes)) + ' bytes)' : '') + '</div>'
1086
- + '<div style="margin-top:8px;font-size:12px"><a href="' + hfBase + 'lutar_lean_receipts.ndjson" target="_blank" rel="noopener">Canonical rows on Hugging Face ↗</a>'
1087
- + ' &nbsp;·&nbsp; <a href="https://pypi.org/project/szl-receipt/" target="_blank" rel="noopener">Verify offline (szl-receipt)</a></div></div>';
1088
  });
1089
  ama.forEach(r => {
1090
  cardsHTML += '<div class="formula-card"><div class="formula-card-head">'
1091
  + '<span class="formula-id">amaru</span><span class="formula-name">' + escHTML(r.kind || 'tick') + '</span>'
1092
- + '<span class="chip ' + (r.lambda_pass ? 'chip-ok' : 'chip-err') + '">Λ ' + escHTML(String(r.lambda)) + ' '
1093
- + (r.lambda_pass ? 'PASS' : 'FAIL') + '</span><span class="conj">Conjecture 1 — advisory</span></div>'
1094
  + '<div class="hash-row"><span class="hash-label">receipt_id</span><span class="hash-val">'
1095
- + escHTML(String(r.receipt_id).substring(0,40)) + '…</span></div>'
1096
  + '<div style="font-size:12px;color:var(--text-dim);margin:6px 0">doctrine ' + escHTML(String(r.doctrine))
1097
- + ' · decl ' + escHTML(String(r.decl)) + ' · axioms ' + escHTML(String(r.axioms)) + ' · sorries '
1098
- + escHTML(String(r.sorries)) + ' · anchor ' + escHTML(String(r.lutar_anchor || '')) + '</div>'
1099
- + '<div style="font-size:12px;color:var(--text-mute)">DSSE ' + (r.dsse_signed ? 'signed ✓' : 'unsigned')
1100
- + ' · keyid ' + escHTML(String(r.dsse_keyid || '—')) + '</div>'
1101
- + '<div style="margin-top:8px;font-size:12px"><a href="' + hfBase + 'amaru_receipts.ndjson" target="_blank" rel="noopener">Canonical rows on Hugging Face ↗</a>'
1102
- + ' &nbsp;·&nbsp; <a href="' + escHTML(String(r.verify_key_url || '#')) + '" target="_blank" rel="noopener">Public key ↗</a></div></div>';
1103
  });
1104
  el('ledger-cards').innerHTML = cardsHTML;
1105
 
1106
  show('ledger-panel');
1107
  setStatus('ledger-status', 'Chain: ' + (intact ? 'INTACT' : 'BROKEN') + ' (' + links + '/' + lut.length
1108
- + ' links) · ' + (lut.length + ama.length) + ' real receipts shown · signatures verify offline against Hugging Face.');
1109
  btn.disabled = false;
1110
  }
1111
  </script>
1112
 
1113
  </body>
1114
  </html>
 
 
1
+ <!DOCTYPE html>
2
  <html lang="en">
3
  <head>
4
  <meta charset="utf-8" />
5
  <meta name="viewport" content="width=device-width, initial-scale=1" />
6
+ <title>a11oy — Verifiable Inference</title>
7
  <style>
8
  /* =====================================================================
9
+ a11oy Tier-1 Demo — elite showcase aesthetic
10
+ Dark palette · Cabinet Grotesk / JetBrains Mono · honest-label chips
11
  ===================================================================== */
12
  @import url('https://fonts.googleapis.com/css2?family=JetBrains+Mono:ital,wght@0,400;0,600;1,400&display=swap');
13
 
 
288
  <circle cx="16" cy="16" r="2.5" fill="#8aaaf8"/>
289
  </svg>
290
  <span class="site-title">a11oy</span>
291
+ <span class="site-tagline">AI that can demonstrate its work · Verifiable by Design</span>
292
+ <a href="/" class="nav-back">← Console</a>
293
  </header>
294
 
295
  <!-- ===== MAIN ===== -->
 
297
 
298
  <div class="page-hero">
299
  <h1>Verifiable Inference</h1>
300
+ <p>Real, verifiable governance receipts — including our own public ledger. Every receipt is signed and independently verifiable. The honesty is the product.</p>
301
  </div>
302
 
303
  <!-- ===================================================================
304
+ SECTION A — Buyer-Verifiable Receipt (BVIR)
305
  =================================================================== -->
306
  <section class="section" id="section-bvir">
307
  <div class="section-head">
 
311
  </h2>
312
  <p>
313
  Makes a real POST /api/a11oy/v1/govern/infer call, then verifies the DSSE ECDSA-P256
314
+ signature <strong>in-browser</strong> using WebCrypto — no server round-trip for verification.
315
  SHA-256 of the decoded payload is recomputed and matched to <code>receipt.payload_digest</code>.
316
  </p>
317
  <p class="moat-line">
 
334
  </section>
335
 
336
  <!-- ===================================================================
337
+ SECTION B — Λ-Gated Honest Refusal
338
  =================================================================== -->
339
  <section class="section" id="section-govern">
340
  <div class="section-head">
341
  <h2>
342
  <span class="section-label">B</span>
343
+ Λ-Gated Honest Refusal
344
  </h2>
345
  <p>
346
  Three preset governance cases. Each returns a REAL signed receipt via
347
+ <code>szl_dsse.sign_khipu_receipt</code>. Λ is always labeled
348
+ <span class="conj">Conjecture 1 — advisory, NOT a theorem</span>.
349
  </p>
350
+ <p class="moat-line">"Even our refusals are signed and explained — no black-box boolean."</p>
351
  </div>
352
  <div class="section-body">
353
 
 
372
  </section>
373
 
374
  <!-- ===================================================================
375
+ SECTION C — Verifiable Thesis
376
  =================================================================== -->
377
  <section class="section" id="section-thesis">
378
  <div class="section-head">
 
382
  </h2>
383
  <p>
384
  The 8 PROVEN formulas with verbatim Lean 4 statements, the 3-tier honest corpus
385
+ (8 / ~35 / ~185), and the honest conjecture labels for Λ and Khipu BFT.
386
  </p>
387
+ <p class="moat-line">"The honesty is the product. Click any formula — verify it yourself."</p>
388
  </div>
389
  <div class="section-body">
390
 
 
419
  </section>
420
 
421
  <!-- ===================================================================
422
+ SECTION D — Public Ledger (real receipts from szl-lake)
423
  =================================================================== -->
424
  <section class="section" id="section-ledger">
425
  <div class="section-head">
426
  <h2>
427
  <span class="section-label">D</span>
428
+ Public Ledger — Real Receipts
429
  </h2>
430
  <p>
431
  Real signed Khipu receipts from our public dataset
 
433
  (snapshot 2026-07-02). This page recomputes the <strong>hash-chain linkage in your browser</strong>;
434
  the DSSE / sigstore signatures verify <strong>offline</strong> with the
435
  <a href="https://pypi.org/project/szl-receipt/" target="_blank" rel="noopener">szl-receipt</a>
436
+ library and cross-check against the canonical rows on Hugging Face — infrastructure we do not control.
437
  </p>
438
+ <p class="moat-line">"The receipts you would read in diligence — including the ones where we mark our own central claim, &Lambda;, still OPEN."</p>
439
  </div>
440
  <div class="section-body">
441
  <div class="btn-row">
 
455
  </main>
456
 
457
  <footer class="footer">
458
+ <p>SZL Holdings · a11oy · Doctrine v11 · 8 kernel-verified formulas @ c7c0ba17 ·
459
+ Λ = Conjecture 1 (advisory) · Khipu BFT = Conjecture 2 ·
460
+ <a href="/govern/health" target="_blank">Governance Health</a> ·
461
  <a href="/api/a11oy/v1/demo/thesis" target="_blank">Thesis API</a>
462
  </p>
463
  </footer>
464
 
465
  <!-- ===================================================================
466
+ JAVASCRIPT — all in-browser, no CDN
467
  =================================================================== -->
468
  <script>
469
  "use strict";
 
495
 
496
  /* ---- base64 helpers ---- */
497
  function b64Decode(s) {
498
+ // standard base64 → Uint8Array (not URL-safe; WebCrypto importKey returns SPKI base64)
499
  const bin = atob(s);
500
  const b = new Uint8Array(bin.length);
501
  for (let i = 0; i < bin.length; i++) b[i] = bin.charCodeAt(i);
 
509
  return btoa(s);
510
  }
511
 
512
+ /* ---- DER ASN.1 → raw r‖s converter (for WebCrypto ECDSA P-256) ----
513
  cosign / cryptography-lib ECDSA signs in DER (ASN.1 SEQUENCE { INTEGER r, INTEGER s }).
514
+ WebCrypto ECDSA P-256 SHA-256 expects IEEE P-1363 raw r‖s (64 bytes: 32+32).
515
+ We decode the DER SEQUENCE here entirely in JS — no library needed.
516
  */
517
  function derToRaw(derBytes) {
518
  let i = 0;
 
594
  }
595
 
596
  /* ====================================================================
597
+ SECTION A — BVIR
598
  ==================================================================== */
599
  async function runBVIR() {
600
  const btn = el('bvir-run');
601
  btn.disabled = true;
602
  hide('bvir-verdict');
603
  hide('bvir-output');
604
+ setStatus('bvir-status', 'Calling /api/a11oy/v1/govern/infer …', true);
605
 
606
  let data;
607
  try {
 
617
  return;
618
  }
619
 
620
+ setStatus('bvir-status', 'Verifying signature in-browser via WebCrypto …', true);
621
 
622
  const dsse = data.dsse || {};
623
  const receipt= data.receipt|| {};
 
666
  let sigKeyid = '';
667
 
668
  if (!dsse.signed) {
669
+ verifyError = 'UNSIGNED envelope — private key not available in this runtime. Receipt chain is still valid.';
670
  } else if (sigs.length === 0) {
671
  verifyError = 'No signatures in envelope.';
672
  } else {
 
682
  try {
683
  rawSig = derToRaw(sigBytes);
684
  } catch(e2) {
685
+ verifyError = 'DER→raw conversion failed: ' + e2.message;
686
  }
687
  }
688
 
 
729
  let verdictHTML = '';
730
  if (verified && isDemoKey) {
731
  verdictHTML = `<div class="verdict-banner verdict-ok">
732
+ ✓ VERIFIED (demo-signing-key — not the production cosign key)
733
  <span class="chip chip-ok">keyid: ${escHTML(sigKeyid)}</span>
734
  <div style="font-size:12px;font-weight:400;margin-top:6px;color:var(--text-dim)">
735
  Real ECDSA-P256 signature, verified in your browser against /demo-cosign.pub.
736
+ This is a clearly-labelled DEMO key — the production cosign key stays
737
  founder-gated and is never placed in this runtime.
738
  </div>
739
  </div>`;
740
  } else if (verified) {
741
  verdictHTML = `<div class="verdict-banner verdict-ok">
742
+ ✓ VERIFIED — WebCrypto ECDSA-P256 signature valid
743
  <span class="chip chip-ok">keyid: ${escHTML(sigKeyid)}</span>
744
  </div>`;
745
  } else if (!dsse.signed) {
746
  verdictHTML = `<div class="verdict-banner verdict-dim">
747
+ ⚠ UNSIGNED — private key not in runtime; receipt chain still valid
748
  </div>`;
749
  } else {
750
  verdictHTML = `<div class="verdict-banner verdict-fail">
751
+ ✗ VERIFICATION FAILED — ${escHTML(verifyError)}
752
  </div>`;
753
  }
754
 
 
780
  </div>
781
  <div class="hash-row">
782
  <span class="hash-label">Payload digest:</span>
783
+ <span class="hash-val ${digestValClass}">${payloadDigestComputed.substring(0,32)}…</span>
784
  <span class="chip ${digestChipClass}">${digestChipText}</span>
785
  </div>
786
  ${hasDeclaredDigest ? `<div class="hash-row">
787
  <span class="hash-label">Declared digest:</span>
788
+ <span class="hash-val">${escHTML(declaredPayloadDigest.substring(0,32))}…</span>
789
  </div>` : `<div class="hash-row">
790
  <span class="hash-label">Declared digest:</span>
791
+ <span class="hash-val" style="color:var(--text-dim)">(none declared — nothing to compare against)</span>
792
  </div>`}
793
  <div class="hash-row">
794
  <span class="hash-label">PAE SHA-256:</span>
795
+ <span class="hash-val">${paeSHA.substring(0,32)}…</span>
796
  </div>
797
  <div class="hash-row">
798
  <span class="hash-label">Chain prev:</span>
799
+ <span class="hash-val">${escHTML(String(chainPrev).substring(0,32))}…</span>
800
  </div>
801
  <div class="hash-row">
802
  <span class="hash-label">Chain digest:</span>
803
+ <span class="hash-val">${escHTML(String(chainDigest).substring(0,32))}…</span>
804
  </div>
805
  </div>
806
  <div style="font-size:12px;color:var(--text-dim);margin-bottom:8px">
807
+ <span class="conj">Λ Conjecture 1 — advisory</span>
808
+ Λ = ${escHTML(String((data.governance||{}).lambda ?? 'N/A'))}
809
+ &nbsp;·&nbsp;
810
  Energy: <span class="chip chip-dim">${escHTML((data.energy||{}).label || 'UNAVAILABLE')}</span>
811
  </div>
812
  `;
 
819
  'governance.lambda': (data.governance||{}).lambda,
820
  'governance.lambda_kind': (data.governance||{}).lambda_kind,
821
  'receipt.seq': receipt.seq,
822
+ 'receipt.prev': String(chainPrev).substring(0,32) + '…',
823
+ 'receipt.digest': String(chainDigest).substring(0,32) + '…',
824
  'dsse.signed': dsse.signed,
825
  'dsse.keyid': dsseKeyid || null,
826
+ 'dsse.key_kind': isDemoKey ? 'demo (demo-signing-key — NOT production cosign)' : (dsse.signed ? 'production cosign' : null),
827
  'dsse.payloadType': dsse.payloadType,
828
  'verify.public_key_url': pubKeyURL,
829
+ 'verify.computed_payload_sha256': payloadDigestComputed.substring(0,32) + '…',
830
+ 'verify.declared_payload_digest': hasDeclaredDigest ? declaredPayloadDigest.substring(0,32) + '…' : null,
831
  'verify.payload_digest_match': hasDeclaredDigest ? (payloadDigestMatches ? 'MATCH' : 'MISMATCH') : 'no declared digest to compare',
832
+ 'verify.pae_sha256': paeSHA.substring(0,32) + '…',
833
+ 'verify.result': verified ? (isDemoKey ? 'VERIFIED ✓ (demo-signing-key — not production cosign)' : 'VERIFIED ✓') : (dsse.signed === false ? 'UNSIGNED (no private key in runtime)' : 'FAILED: ' + verifyError),
834
  'energy.label': (data.energy||{}).label,
835
  };
836
  el('bvir-output').textContent = JSON.stringify(outputData, null, 2);
 
839
 
840
  setStatus('bvir-status', verified
841
  ? (isDemoKey
842
+ ? '✓ WebCrypto verified — real ECDSA-P256 over DSSE PAE with demo-signing-key (NOT the production cosign key).'
843
+ : '✓ WebCrypto verified — real ECDSA-P256 signature over DSSE PAE.')
844
  : (dsse.signed === false
845
  ? 'Unsigned receipt (private key absent from runtime). Chain valid.'
846
  : 'Verification result: ' + verifyError));
 
848
  }
849
 
850
  /* ====================================================================
851
+ SECTION B — Governed Refusal
852
  ==================================================================== */
853
  async function runGovern(caseKey) {
854
  hide('govern-panel');
855
+ setStatus('govern-status', `Calling /api/a11oy/v1/demo/govern case="${caseKey}" …`, true);
856
 
857
  let data;
858
  try {
 
875
 
876
  // Verdict banner
877
  const decClasses = { allow:'verdict-ok', review:'verdict-dim', deny:'verdict-fail' };
878
+ const decLabels = { allow:'✓ ALLOW — governance passed', review:'⚠ REVIEW — below advisory floor', deny:'✗ DENY — gate fired' };
879
  const bannerCls = decClasses[decision] || 'verdict-dim';
880
  const bannerLbl = decLabels[decision] || decision.toUpperCase();
881
  el('govern-verdict-banner').innerHTML = `<div class="verdict-banner ${bannerCls}">${bannerLbl}</div>`;
882
 
883
+ // Λ row
884
  const lambdaPass = gov.lambda_pass;
885
  el('govern-lambda-row').innerHTML = `
886
  <div style="display:flex;align-items:center;gap:10px;flex-wrap:wrap">
887
+ <span style="font-size:14px;font-weight:700">Λ = ${escHTML(String(gov.lambda ?? 'N/A'))}</span>
888
  <span class="chip ${lambdaPass ? 'chip-ok' : 'chip-err'}">
889
  ${lambdaPass ? 'PASS' : 'FAIL'} (floor ${escHTML(String(gov.lambda_floor ?? 0.9))})
890
  </span>
891
+ <span class="conj">Conjecture 1 — advisory, NOT a theorem</span>
892
  </div>
893
  <div style="font-size:12px;color:var(--text-dim);margin-top:4px">
894
  ${escHTML(gov.lambda_kind || 'Conjecture 1 (advisory; NOT a theorem)')}
 
902
  const fired = g.fired;
903
  gatesHTML += `
904
  <div class="gate-row">
905
+ <span class="gate-name">${escHTML(g.name || '—')}</span>
906
  <span class="gate-fired ${fired ? 'chip chip-err' : 'chip chip-ok'}">${fired ? 'FIRED' : 'PASS'}</span>
907
+ <span class="chip chip-dim">${escHTML(g.decision || '—')}</span>
908
  </div>`;
909
  });
910
  el('govern-gates').innerHTML = gatesHTML;
 
918
  lambda: receipt.lambda,
919
  lambda_kind: receipt.lambda_kind,
920
  gates: receipt.gates,
921
+ prev: String(chain.prev || '').substring(0,32) + '…',
922
+ digest: String(chain.digest || '').substring(0,32) + '…',
923
  'dsse.signed': signed,
924
  'dsse.keyid': ((dsse.signatures||[])[0]||{}).keyid,
925
  honesty: data.honesty,
 
932
  }
933
 
934
  show('govern-panel');
935
+ setStatus('govern-status', `Decision: ${decision.toUpperCase()} · Λ = ${gov.lambda} · ${dsse.signed ? 'Receipt signed ✓' : 'Receipt unsigned (key absent)'}`);
936
  }
937
 
938
  /* ====================================================================
939
+ SECTION C — Verifiable Thesis
940
  ==================================================================== */
941
  async function loadThesis() {
942
  const btn = el('thesis-load');
943
  btn.disabled = true;
944
  hide('thesis-panel');
945
+ setStatus('thesis-status', 'Loading /api/a11oy/v1/demo/thesis …', true);
946
 
947
  let data;
948
  try {
 
973
  });
974
  corpusHTML += `</div>`;
975
  corpusHTML += `<div class="corpus-never-claim">
976
+ âš  ${escHTML(corpus.honest_note || 'We never claim 183 proven.')}
977
  </div>`;
978
  el('thesis-corpus').innerHTML = corpusHTML;
979
 
 
988
  </div>
989
  <div class="formula-lean">${escHTML(f.lean)}</div>
990
  <div class="formula-desc">${escHTML(f.description)}</div>
991
+ <div class="formula-status">✓ ${escHTML(f.status)}</div>
992
  </div>`;
993
  });
994
  el('thesis-formulas').innerHTML = formulasHTML;
 
1000
  </div>
1001
  <div style="display:flex;gap:14px;flex-wrap:wrap">
1002
  <div style="flex:1;min-width:220px;background:var(--bg-panel);border:1px solid #92400e;border-radius:var(--radius);padding:14px">
1003
+ <div style="font-size:11px;font-weight:700;color:var(--amber);text-transform:uppercase;letter-spacing:.07em;margin-bottom:6px">Conjecture 1 — Λ (Lambda)</div>
1004
  <div style="font-size:13px;color:var(--text-dim)">${escHTML(doctrine.lambda_kind || 'Conjecture 1 (advisory; NOT a theorem)')}</div>
1005
  <div style="font-size:12px;color:var(--text-mute);margin-top:6px">Open bounty: szl-holdings/lambda-bounty</div>
1006
  </div>
1007
  <div style="flex:1;min-width:220px;background:var(--bg-panel);border:1px solid #991b1b;border-radius:var(--radius);padding:14px">
1008
+ <div style="font-size:11px;font-weight:700;color:var(--red);text-transform:uppercase;letter-spacing:.07em;margin-bottom:6px">Conjecture 2 — Khipu BFT</div>
1009
  <div style="font-size:13px;color:var(--text-dim)">${escHTML(doctrine.bft_kind || 'Conjecture 2 (NOT proven; NOT a theorem)')}</div>
1010
+ <div style="font-size:12px;color:var(--text-mute);margin-top:6px">Labeled honestly everywhere — no false safety claim</div>
1011
  </div>
1012
  </div>
1013
  <div style="margin-top:14px;font-size:12px;color:var(--text-dim)">
 
1016
  `;
1017
 
1018
  show('thesis-panel');
1019
+ setStatus('thesis-status', `Loaded ${formulas.length} proven formulas · 3-tier corpus · live doctrine`);
1020
  btn.disabled = false;
1021
  }
1022
 
1023
  /* ====================================================================
1024
+ SECTION D — Public Ledger (real receipts from szl-lake, snapshot)
1025
  In-browser: hash-chain linkage check. Offline: signatures via szl-receipt.
1026
  ==================================================================== */
1027
  const LEDGER_SNAPSHOT = {"source": "https://huggingface.co/datasets/SZLHOLDINGS/szl-lake", "captured_utc": "2026-07-02", "lutar_lean": [{"branch": "theorem-u-kernel", "chain_index": 1, "doctrine": "v11", "honesty": {"conjecture_1": "OPEN: unconditional Lambda uniqueness is Conjecture 1 and is machine-checked FALSE as stated. Theorem U does NOT close it.", "doctrine": "v11", "locked_five_unchanged": true, "locked_set": ["F1", "F11", "F12", "F18", "F19"], "theorem_u": "REAL-conditional: Lutar.Uniqueness Theorem U is kernel-verified (axiom footprint within the Lean/Mathlib trust base, no sorry) but CONDITIONAL on its stated checkable hypotheses; it is NOT part of the locked-proven baseline."}, "kernel_commit": "e736decd244ae06e8bb48531c6c7dc0f1029b25a", "kernel_commit_short": "e736decd244a", "kind": "theorem-u-anchor", "lambda_status": "Conjecture_1 (OPEN; unconditional uniqueness machine-checked FALSE)", "numbers": {"axioms_unique": 22, "declarations": 1323, "sorries_noncomment": 254}, "organ": "lutar-lean", "prev_hash": null, "receipt_id": "d70f444db57df9a4a2d52e69408ce61b511e4b50152f7fbf97456b1af66fe9a0", "schema": "szl.khipu.receipt/v1", "signing": {"format": "sigstore-keyless-bundle", "bytes": 18428, "b64_head": "eyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZGV2\u2026"}, "source_run": {"conclusion": "success", "id": "27186151340", "url": "https://github.com/szl-holdings/lutar-lean/actions/runs/27186151340", "workflow": "Lake build (gate + numbers)"}, "subject": {"name": "theorem_u_snapshot.json", "sha256": "82d08a4e892579e815d880d51f61cb8035a3325e077c29e412f310f76b50985e", "snapshot": {"branch": "theorem-u-kernel", "built_at_utc": "2026-06-09T05:37:45Z", "honesty": {"conjecture_1": "OPEN: unconditional Lambda uniqueness is Conjecture 1 and is machine-checked FALSE as stated. Theorem U does NOT close it.", "doctrine": "v11", "locked_five_unchanged": true, "locked_set": ["F1", "F11", "F12", "F18", "F19"], "theorem_u": "REAL-conditional: Lutar.Uniqueness Theorem U is kernel-verified (axiom footprint within the Lean/Mathlib trust base, no sorry) but CONDITIONAL on its stated checkable hypotheses; it is NOT part of the locked-proven baseline."}, "kernel_commit": "e736decd244ae06e8bb48531c6c7dc0f1029b25a", "kernel_commit_short": "e736decd244a", "lean_numbers": {"lean_numbers_sha256": "50098073e92aefdf275ec53e60faafc0f1bd5d4a1a88023e819490aaaa69d4d6", "numbers": {"axiom_names": ["A6'_block_consistent", "KS_theorem_1_1", "MomentSubGaussian", "audit_reidemeister_invariance", "canonicalReceipt", "chromotopology_code_bijection", "compression_collision_resistant", "domain_separation", "gleason_length_mod_8", "klDivergence_nonneg", "lambda_schur_concave_n_axis", "lambda_stationary_unique", "leaf_collision_resistant", "liu_hui_pi_converges", "node_collision_resistant", "pinsker", "r1_invariance", "r2_invariance", "setAlpha_cauchy", "setDelta_stage2", "sha256", "sha256_collision_resistant"], "axioms_raw": 23, "axioms_unique": 22, "declarations": 1323, "sorries_baseline": 251, "sorries_noncomment": 254, "sorries_putnam": 56, "sorries_raw": 307}, "reference_vectors_sha256": "857967629daf5e5c45a167306ea0e0091569a29766b01ac91bef15a539b816dc", "replay_hash": "9860c3332a2d0b0553b775dcd27111b0ce4fae4bc5cebe2827dc6148be4cbebe", "schema": "szl.lean_numbers/v1"}, "repo": "szl-holdings/lutar-lean", "schema": "szl.theorem_u.snapshot/v1", "theorem_u": {"decl_source_sha256": {"Lutar/Uniqueness/AxiomCheck.lean": "f45781ef2becf15eccd0c31702603a55cfab1eb7960483593a045202b66f4887", "Lutar/Uniqueness/Identifiability.lean": "fa340e6a999eac7ea1cd035d90647548baaa290b7376d7fcbdcbd165e475dedf", "Lutar/Uniqueness/LambdaEquiv.lean": "03f63e36f3a9b19e8e9d4f48313a450bae7c85fcb53049d52e0f6d4adf4b1c23", "Lutar/Uniqueness/TheoremU.lean": "c958520ba31d6fc1f48a9b49871d67812f178e168b31bf2be9e3d5fb2061386c"}, "full_axiom_footprint": {"Lutar.Uniqueness.AxiomCheck.conjecture1_still_open": [], "Lutar.Uniqueness.AxiomCheck.locked_count_five": [], "Lutar.Uniqueness.AxiomCheck.theoremU_axiom_sets_kernel_only": [], "Lutar.Uniqueness.AxiomCheck.theoremU_excluded_from_locked": [], "Lutar.Uniqueness.CorollaryU1_LambdaUnique_Separable": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.CorollaryU2_LambdaUnique_Factors": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.TheoremU_LambdaUnique": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.TheoremU_LambdaUnique_eq": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.identifiability_forces_lambda": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.lambda_equiv_to_eq_of_anchored": ["Classical.choice", "Quot.sound", "propext"]}, "headline_axiom_footprint": {"CorollaryU1_LambdaUnique_Separable": ["Classical.choice", "Quot.sound", "propext"], "CorollaryU2_LambdaUnique_Factors": ["Classical.choice", "Quot.sound", "propext"], "TheoremU_LambdaUnique": ["Classical.choice", "Quot.sound", "propext"], "TheoremU_LambdaUnique_eq": ["Classical.choice", "Quot.sound", "propext"], "identifiability_forces_lambda": ["Classical.choice", "Quot.sound", "propext"], "lambda_equiv_to_eq_of_anchored": ["Classical.choice", "Quot.sound", "propext"]}, "headline_decls": ["CorollaryU1_LambdaUnique_Separable", "CorollaryU2_LambdaUnique_Factors", "TheoremU_LambdaUnique", "TheoremU_LambdaUnique_eq", "identifiability_forces_lambda", "lambda_equiv_to_eq_of_anchored"], "kernel_only": true, "kernel_trust_base": ["Classical.choice", "Quot.sound", "funext", "propext"], "module": "Lutar.Uniqueness", "status": "REAL-conditional"}}}, "theorem_u_status": "REAL-conditional", "timestamp": "2026-06-09T05:39:22Z"}, {"branch": "main", "chain_index": 2, "doctrine": "v11", "honesty": {"conjecture": "This is a GENERATED, OPEN conjecture \u2014 NOT a theorem and NOT machine-verified. It remains OPEN until a solution is independently verified.", "difficulty": "Difficulty 'open-resistant' / grade 'OPEN' come from a REAL bounded solver run. OPEN means searched-to-budget, not proven true; VERIFIED-FINITE certifies only the finite enumerated domain; REFUTED carries a concrete witness. No score is fabricated.", "doctrine": "v11", "kernel_only": false, "novelty": "Novelty verdict 'novel-candidate' is an advisory screen, not a proof of originality; external prior-art sources are labelled live/cached/unreachable and an unreachable source never confirms novelty.", "signing": "Disclosure is cosign keyless-OIDC signed and anchored into the szl-lake DSSE Khipu ledger; the signature attests the timestamp + content, NOT the truth of the conjecture.", "status": "OPEN"}, "kernel_commit": "d851aefe86b9f12f9d4423200bd9e5257d05c41e", "kernel_commit_short": "d851aefe86b9", "kind": "conjecture-disclosure-anchor", "milestone_kind": "conjecture-disclosure", "milestone_status": "OPEN", "milestone_title": "SZL mixing-map convergence conjecture", "numbers": {"axioms_unique": null, "declarations": null, "sorries_noncomment": null}, "organ": "lutar-lean", "prev_hash": "d70f444db57df9a4a2d52e69408ce61b511e4b50152f7fbf97456b1af66fe9a0", "receipt_id": "08744b67b647039f87abbf0b29587638ae777308ca7fc2434ed3ae4033687b50", "schema": "szl.khipu.receipt/v1", "signing": {"format": "sigstore-keyless-bundle", "bytes": 17488, "b64_head": "eyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZGV2\u2026"}, "source_run": {"conclusion": "success", "id": "27318564784", "url": "https://github.com/szl-holdings/lutar-lean/actions/runs/27318564784", "workflow": "Conjecture Factory (generate -> timestamp -> grade -> anchor)"}, "subject": {"name": "conjecture_snapshot.json", "sha256": "7faded7df9ac5bea4ca7ddaa1e5c38c247c237fd49b8a1a39d35a260c2189fb0", "snapshot": {"branch": "main", "built_at_utc": "2026-06-11T01:54:20Z", "candidate": {"created_utc": "2026-06-11T01:54:19Z", "doctrine": "v11", "domain": "number-theory / arithmetic dynamics", "id": "cf-5ddbbe7571a9", "intended_solution_outline": "Bound the orbit by a Lyapunov / drift argument on the 2-adic valuation: show the\ncontracting branch (n = 3 mod 4) dominates the accelerating branch (n = 1 mod 4)\nin expectation, then rule out non-trivial cycles via a residue-class descent.\nStatus: OPEN \u2014 no proof is claimed; the predicate only performs bounded testing.", "predicate": {"description": "Sound bounded-orbit checker: returns False only on a detected non-1 cycle (a certain counterexample); inconclusive bounded runs assert no counterexample.", "entry": "holds", "kind": "python-callable", "module": "conjectures/samples/szl-mixing-map/predicate.py"}, "references": ["conjectures/corpus/collatz.md (related but distinct: classical 3n+1 map)", "Lagarias, J. (2010). The 3x+1 problem: an annotated bibliography."], "schema": "szl.conjecture.candidate/v1", "statement": "Define M : Z+ -> Z+ by\n M(n) = n / 2 if n is even,\n M(n) = (3n + 1) / 2 if n is odd and n = 1 (mod 4),\n M(n) = (n + 1) / 2 if n is odd and n = 3 (mod 4).\nConjecture: for every integer n >= 1 there exists k >= 0 with M^k(n) = 1.", "statement_canonical": "Define M : Z+ -> Z+ by M(n) = n / 2 if n is even, M(n) = (3n + 1) / 2 if n is odd and n = 1 (mod 4), M(n) = (n + 1) / 2 if n is odd and n = 3 (mod 4). Conjecture: for every integer n >= 1 there exists k >= 0 with M^k(n) = 1.", "statement_hash": "sha256:5ddbbe7571a93f9ed3d49c37dbb3559eb339a51380e427882bd3783b7cb2743a", "taxonomy": "OPEN", "title": "SZL mixing-map convergence conjecture"}, "grade": {"budget": 100000, "candidate_id": "cf-5ddbbe7571a9", "difficulty": "open-resistant", "graded_utc": "2026-06-11T01:54:20Z", "honesty": "Grade from a REAL ensemble run. REFUTED carries a concrete witness. VERIFIED-FINITE certifies only the finite enumerated domain, not the conjecture in general. OPEN means searched-to-budget with no counterexample \u2014 NOT a proof of truth. The candidate stays OPEN (doctrine v11).", "result": "OPEN", "schema": "szl.conjecture.grade/v1", "seed": 1729, "solver_ensemble": [{"budget": 100000, "checked": 100000, "elapsed_sec": 0.411268, "note": "infinite/streaming domain", "resolved": false, "result": "OPEN", "solver": "exhaustive", "witness": null}, {"budget": 100000, "checked": 100000, "elapsed_sec": 0.654207, "note": "random sampling found no counterexample (not a proof)", "resolved": false, "result": "OPEN", "solver": "sampler", "witness": null}], "success_rate": 0.0, "witness": null}, "honesty": {"conjecture": "This is a GENERATED, OPEN conjecture \u2014 NOT a theorem and NOT machine-verified. It remains OPEN until a solution is independently verified.", "difficulty": "Difficulty 'open-resistant' / grade 'OPEN' come from a REAL bounded solver run. OPEN means searched-to-budget, not proven true; VERIFIED-FINITE certifies only the finite enumerated domain; REFUTED carries a concrete witness. No score is fabricated.", "doctrine": "v11", "kernel_only": false, "novelty": "Novelty verdict 'novel-candidate' is an advisory screen, not a proof of originality; external prior-art sources are labelled live/cached/unreachable and an unreachable source never confirms novelty.", "signing": "Disclosure is cosign keyless-OIDC signed and anchored into the szl-lake DSSE Khipu ledger; the signature attests the timestamp + content, NOT the truth of the conjecture.", "status": "OPEN"}, "kernel_commit": "d851aefe86b9f12f9d4423200bd9e5257d05c41e", "kernel_commit_short": "d851aefe86b9", "kind": "conjecture-disclosure", "milestone": {"difficulty": "open-resistant", "grade_result": "OPEN", "headline_decls": [], "id": "cf-5ddbbe7571a9", "kernel_only": false, "novelty_verdict": "novel-candidate", "release_stage": "statement", "statement_hash": "sha256:5ddbbe7571a93f9ed3d49c37dbb3559eb339a51380e427882bd3783b7cb2743a", "status": "OPEN", "title": "SZL mixing-map convergence conjecture"}, "novelty": {"candidate_id": "cf-5ddbbe7571a9", "external": [{"hits": 0, "note": "offline run (--online not set)", "source": "arxiv", "status": "unreachable", "top": []}, {"hits": 0, "note": "offline run (--online not set)", "source": "crossref", "status": "unreachable", "top": []}], "honesty": "Novelty is a screen, not a proof of originality. External sources are labelled live/cached/unreachable; an unreachable source contributes no hits and is never silently treated as confirming novelty. The candidate stays OPEN regardless of this verdict (doctrine v11).", "local_corpus": {"corpus_dir": "conjectures/corpus", "documents_scanned": 2, "max_similarity": 0.0688, "method": "char-5-gram shingle Jaccard", "near_duplicate": false, "nearest": {"doc": "collatz.md", "similarity": 0.0688}, "threshold": 0.8, "top": [{"doc": "collatz.md", "similarity": 0.0688}, {"doc": "goldbach.md", "similarity": 0.0451}]}, "schema": "szl.conjecture.novelty/v1", "screened_utc": "2026-06-11T01:54:19Z", "statement_hash": "sha256:5ddbbe7571a93f9ed3d49c37dbb3559eb339a51380e427882bd3783b7cb2743a", "verdict": "novel-candidate", "verdict_reason": "no near-duplicate found (local-only; external prior-art not fully screened \u2014 unreachable: ['arxiv', 'crossref'])"}, "predicate_type": "https://szl-holdings/conjecture-disclosure/v1", "repo": "szl-holdings/lutar-lean", "schema": "szl.conjecture.disclosure/v1"}}, "timestamp": "2026-06-11T01:54:27Z"}, {"branch": "main", "chain_index": 3, "doctrine": "v11", "honesty": {"conjecture_1": "OPEN: unconditional Lambda uniqueness is Conjecture 1 and is machine-checked FALSE as stated; conjecture1_still_open re-asserts it stays open.", "doctrine": "v11", "locked_baseline": "REAL-invariant: kernel-verified meta-theorems in Lutar/Uniqueness/AxiomCheck.lean (locked_count_eight, theoremU_excluded_from_locked, theoremU_axiom_sets_kernel_only, conjecture1_still_open) \u2014 each proven by `decide`, axiom footprint within the Lean/Mathlib trust base, no sorry. They ASSERT that the locked-proven baseline is EXACTLY the eight {F1,F4,F7,F11,F12,F18,F19,F22}; they do NOT themselves re-prove those formulas (the formula proofs live in Lutar/Puriq/Formulas/ProvedFormulas.lean).", "locked_set": ["F1", "F4", "F7", "F11", "F12", "F18", "F19", "F22"], "theorem_u": "Theorem U stays REAL-conditional and EXCLUDED from this locked baseline (theoremU_excluded_from_locked); anchoring this milestone does not change Theorem U's status."}, "kernel_commit": "25e0b2af781f5fb10324945ea10c861bcc28cc83", "kernel_commit_short": "25e0b2af781f", "kind": "locked-baseline-anchor", "milestone_kind": "locked-baseline", "milestone_status": "REAL-invariant", "milestone_title": "Locked-proven baseline (Doctrine v11) \u2014 kernel meta-invariants", "numbers": {"axioms_unique": 22, "declarations": 1323, "sorries_noncomment": 254}, "organ": "lutar-lean", "prev_hash": "08744b67b647039f87abbf0b29587638ae777308ca7fc2434ed3ae4033687b50", "receipt_id": "dcdad01763241e4d7af6b45e59949e6596c12ccf43ed6b784471c1f05b4715c0", "schema": "szl.khipu.receipt/v1", "signing": {"format": "sigstore-keyless-bundle", "bytes": 19036, "b64_head": "eyJtZWRpYVR5cGUiOiJhcHBsaWNhdGlvbi92bmQuZGV2\u2026"}, "source_run": {"conclusion": "success", "id": "27319352318", "url": "https://github.com/szl-holdings/lutar-lean/actions/runs/27319352318", "workflow": "Lake build (gate + numbers)"}, "subject": {"name": "locked_baseline_snapshot.json", "sha256": "19ea5946195f7437cfb881eb5489898d0d45f5f074dfa210c22eb6c8bbfc3bc9", "snapshot": {"branch": "main", "built_at_utc": "2026-06-11T02:18:27Z", "honesty": {"conjecture_1": "OPEN: unconditional Lambda uniqueness is Conjecture 1 and is machine-checked FALSE as stated; conjecture1_still_open re-asserts it stays open.", "doctrine": "v11", "locked_baseline": "REAL-invariant: kernel-verified meta-theorems in Lutar/Uniqueness/AxiomCheck.lean (locked_count_eight, theoremU_excluded_from_locked, theoremU_axiom_sets_kernel_only, conjecture1_still_open) \u2014 each proven by `decide`, axiom footprint within the Lean/Mathlib trust base, no sorry. They ASSERT that the locked-proven baseline is EXACTLY the eight {F1,F4,F7,F11,F12,F18,F19,F22}; they do NOT themselves re-prove those formulas (the formula proofs live in Lutar/Puriq/Formulas/ProvedFormulas.lean).", "locked_set": ["F1", "F4", "F7", "F11", "F12", "F18", "F19", "F22"], "theorem_u": "Theorem U stays REAL-conditional and EXCLUDED from this locked baseline (theoremU_excluded_from_locked); anchoring this milestone does not change Theorem U's status."}, "kernel_commit": "25e0b2af781f5fb10324945ea10c861bcc28cc83", "kernel_commit_short": "25e0b2af781f", "kind": "locked-baseline", "lean_numbers": {"lean_numbers_sha256": "38f9a69cb289110e44ffa9bc4a8575d811220c4654a7985b85694d6f1bb3f7f9", "numbers": {"axiom_names": ["A6'_block_consistent", "KS_theorem_1_1", "MomentSubGaussian", "audit_reidemeister_invariance", "canonicalReceipt", "chromotopology_code_bijection", "compression_collision_resistant", "domain_separation", "gleason_length_mod_8", "klDivergence_nonneg", "lambda_schur_concave_n_axis", "lambda_stationary_unique", "leaf_collision_resistant", "liu_hui_pi_converges", "node_collision_resistant", "pinsker", "r1_invariance", "r2_invariance", "setAlpha_cauchy", "setDelta_stage2", "sha256", "sha256_collision_resistant"], "axioms_raw": 23, "axioms_unique": 22, "declarations": 1323, "sorries_baseline": 251, "sorries_noncomment": 254, "sorries_putnam": 56, "sorries_raw": 307}, "reference_vectors_sha256": "857967629daf5e5c45a167306ea0e0091569a29766b01ac91bef15a539b816dc", "replay_hash": "1f0c9d9938b96b3d56fe01e37b955e1b91ff1aec0610fe30c30e515cc8ab469c", "schema": "szl.lean_numbers/v1"}, "milestone": {"decl_source_sha256": {"Lutar/Uniqueness/AxiomCheck.lean": "5e7998d33a1928c12f2e07595ec929544ac04e37f17ad7693ab2838136ab540f", "Lutar/Uniqueness/Identifiability.lean": "fa340e6a999eac7ea1cd035d90647548baaa290b7376d7fcbdcbd165e475dedf", "Lutar/Uniqueness/LambdaEquiv.lean": "03f63e36f3a9b19e8e9d4f48313a450bae7c85fcb53049d52e0f6d4adf4b1c23", "Lutar/Uniqueness/TheoremU.lean": "c958520ba31d6fc1f48a9b49871d67812f178e168b31bf2be9e3d5fb2061386c"}, "full_axiom_footprint": {"Lutar.Uniqueness.AxiomCheck.conjecture1_still_open": [], "Lutar.Uniqueness.AxiomCheck.locked_count_eight": [], "Lutar.Uniqueness.AxiomCheck.theoremU_axiom_sets_kernel_only": [], "Lutar.Uniqueness.AxiomCheck.theoremU_excluded_from_locked": [], "Lutar.Uniqueness.CorollaryU1_LambdaUnique_Separable": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.CorollaryU2_LambdaUnique_Factors": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.TheoremU_LambdaUnique": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.TheoremU_LambdaUnique_eq": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.identifiability_forces_lambda": ["Classical.choice", "Quot.sound", "propext"], "Lutar.Uniqueness.lambda_equiv_to_eq_of_anchored": ["Classical.choice", "Quot.sound", "propext"]}, "headline_axiom_footprint": {"conjecture1_still_open": [], "locked_count_eight": [], "theoremU_axiom_sets_kernel_only": [], "theoremU_excluded_from_locked": []}, "headline_decls": ["conjecture1_still_open", "locked_count_eight", "theoremU_axiom_sets_kernel_only", "theoremU_excluded_from_locked"], "id": "locked-baseline", "kernel_only": true, "kernel_trust_base": ["Classical.choice", "Quot.sound", "funext", "propext"], "module": "Lutar.Uniqueness.AxiomCheck", "status": "REAL-invariant", "title": "Locked-proven baseline (Doctrine v11) \u2014 kernel meta-invariants"}, "repo": "szl-holdings/lutar-lean", "schema": "szl.proof.snapshot/v1"}}, "timestamp": "2026-06-11T02:20:21Z"}], "amaru": [{"receipt_id": "4c9c3f2b8d6452d9bc0e9a9144fc9e1743b3ca76544a988d4d9e4b39df87ba73", "timestamp": "2026-06-02T02:13:07.827680+00:00", "organ": "amaru", "kind": "tick", "index": 0, "lambda": 0.9, "lambda_pass": true, "predicted_hash": "", "actual_hash": "4c9c3f2b8d6452d9bc0e9a9144fc9e1743b3ca76544a988d4d9e4b39df87ba73", "delta": 0.0, "lutar_anchor": "c7c0ba17", "doctrine": "v11", "decl": 749, "axioms": 14, "sorries": 163, "neuro_citations": "[]", "dsse_payload_type": "application/vnd.szl.khipu+json", "dsse_pae_sha256": "6a8ba013ddcd1938e0fc2174ef79287ca49266277b0195595f324dacb9eb02c9", "dsse_sig": "MEQCIBIZjd6T0E4Bhl0OGkhcMZmAuqmnN0ZxmWrL+7U/h31JAiAmF2U1DBEQieaDrFkHcjBcOW91PY1glK0X+/2EKprpVQ==", "dsse_keyid": "szlholdings-cosign", "dsse_signed": true, "verify_key_url": "https://github.com/szl-holdings/.github/blob/main/cosign.pub"}, {"receipt_id": "bc4d6a1629c01584eb6789d19a432fbc9448ce92ada8d47e14552fe94dee9fa1", "timestamp": "2026-06-02T02:13:08.490579+00:00", "organ": "amaru", "kind": "tick", "index": 1, "lambda": 0.9, "lambda_pass": true, "predicted_hash": "4c9c3f2b8d6452d9bc0e9a9144fc9e1743b3ca76544a988d4d9e4b39df87ba73", "actual_hash": "bc4d6a1629c01584eb6789d19a432fbc9448ce92ada8d47e14552fe94dee9fa1", "delta": 0.0, "lutar_anchor": "c7c0ba17", "doctrine": "v11", "decl": 749, "axioms": 14, "sorries": 163, "neuro_citations": "[]", "dsse_payload_type": "application/vnd.szl.khipu+json", "dsse_pae_sha256": "3cb923bc57002b34cd52124601bfbeeff68c6232e598dd06eccb4ff2847f1371", "dsse_sig": "MEUCIQDBB4xUJMFm4YKcZ0mcz6n3q6XomOKEepJWmaplX9Xo0gIgUIg3Xm316oVN05pvIoNxhJBDyL6Vhp1xfEq9nx9V5Wg=", "dsse_keyid": "szlholdings-cosign", "dsse_signed": true, "verify_key_url": "https://github.com/szl-holdings/.github/blob/main/cosign.pub"}, {"receipt_id": "2f872c5144585602dd1016ce732912134ad30423e442fda009cdc0d168c6732d", "timestamp": "2026-06-02T02:13:09.173270+00:00", "organ": "amaru", "kind": "tick", "index": 2, "lambda": 0.9, "lambda_pass": true, "predicted_hash": "bc4d6a1629c01584eb6789d19a432fbc9448ce92ada8d47e14552fe94dee9fa1", "actual_hash": "2f872c5144585602dd1016ce732912134ad30423e442fda009cdc0d168c6732d", "delta": 0.0, "lutar_anchor": "c7c0ba17", "doctrine": "v11", "decl": 749, "axioms": 14, "sorries": 163, "neuro_citations": "[]", "dsse_payload_type": "application/vnd.szl.khipu+json", "dsse_pae_sha256": "f72e37f1ea8d785d862ec7469d3908fc7b455360964d6cdea61e430d89b3e66d", "dsse_sig": "MEYCIQDvfS5l1nyk5zHz9wsNwe/wj6ZPNAMbbJ4KzMG2ZXEQkwIhAJ4mkTOAnOdNWFb2SuweFbQnjP0QPORGAA/IU8sHB+X5", "dsse_keyid": "szlholdings-cosign", "dsse_signed": true, "verify_key_url": "https://github.com/szl-holdings/.github/blob/main/cosign.pub"}]};
 
1029
  function renderLedger() {
1030
  const btn = el('ledger-load');
1031
  btn.disabled = true;
1032
+ setStatus('ledger-status', 'Checking hash-chain linkage in-browser …', true);
1033
 
1034
  const lut = LEDGER_SNAPSHOT.lutar_lean || [];
1035
  const ama = LEDGER_SNAPSHOT.amaru || [];
 
1045
  });
1046
  const intact = broken === 0;
1047
  let chainHTML = '<div class="verdict-banner ' + (intact ? 'verdict-ok' : 'verdict-fail') + '">'
1048
+ + (intact ? '✓ CHAIN INTACT' : '✗ CHAIN BROKEN') + ' — ' + links + '/' + lut.length
1049
  + ' hash-links verified in your browser <span class="chip chip-dim">organ: lutar-lean</span></div>'
1050
  + '<div style="font-size:12px;color:var(--text-dim);margin-bottom:8px">Each receipt\'s <code>prev_hash</code> '
1051
  + 'is compared to the previous receipt\'s <code>receipt_id</code>. This proves append-only ordering. '
 
1053
  rows.forEach(({ r, i, prev, ok }) => {
1054
  chainHTML += '<div class="hash-row"><span class="hash-label">#' + escHTML(String(r.chain_index)) + ' '
1055
  + escHTML(r.kind || '') + '</span><span class="hash-val">id ' + escHTML(String(r.receipt_id).substring(0,16))
1056
+ + '…</span><span class="hash-val ' + (ok ? 'hash-match' : 'hash-mismatch') + '">prev '
1057
+ + escHTML(prev == null ? '(genesis)' : String(prev).substring(0,16) + '…') + '</span>'
1058
  + '<span class="chip ' + (ok ? 'chip-ok' : 'chip-err') + '">' + (ok ? 'LINK OK' : 'BROKEN') + '</span></div>';
1059
  });
1060
  el('ledger-chain').innerHTML = chainHTML;
 
1075
  + '<span class="formula-id">lutar-lean</span><span class="formula-name">' + escHTML(r.kind || 'receipt') + '</span>'
1076
  + '<span class="chip chip-dim">schema ' + escHTML(r.schema || '') + '</span></div>'
1077
  + '<div class="hash-row"><span class="hash-label">receipt_id</span><span class="hash-val">'
1078
+ + escHTML(String(r.receipt_id).substring(0,40)) + '…</span></div>'
1079
  + (r.numbers ? '<div style="font-size:12px;color:var(--text-dim);margin:6px 0">declarations '
1080
+ + escHTML(String(r.numbers.declarations)) + ' · axioms ' + escHTML(String(r.numbers.axioms_unique))
1081
+ + ' · sorries ' + escHTML(String(r.numbers.sorries_noncomment)) + ' · kernel '
1082
  + escHTML(String(r.kernel_commit_short || '')) + '</div>' : '')
1083
  + '<div style="margin:8px 0">' + honestyHTML + '</div>'
1084
+ + '<div style="font-size:12px;color:var(--text-mute)">signing: ' + escHTML(sg.format || '—')
1085
  + (sg.bytes ? ' (' + escHTML(String(sg.bytes)) + ' bytes)' : '') + '</div>'
1086
+ + '<div style="margin-top:8px;font-size:12px"><a href="' + hfBase + 'lutar_lean_receipts.ndjson" target="_blank" rel="noopener">Canonical rows on Hugging Face ↗</a>'
1087
+ + ' &nbsp;·&nbsp; <a href="https://pypi.org/project/szl-receipt/" target="_blank" rel="noopener">Verify offline (szl-receipt)</a></div></div>';
1088
  });
1089
  ama.forEach(r => {
1090
  cardsHTML += '<div class="formula-card"><div class="formula-card-head">'
1091
  + '<span class="formula-id">amaru</span><span class="formula-name">' + escHTML(r.kind || 'tick') + '</span>'
1092
+ + '<span class="chip ' + (r.lambda_pass ? 'chip-ok' : 'chip-err') + '">Λ ' + escHTML(String(r.lambda)) + ' '
1093
+ + (r.lambda_pass ? 'PASS' : 'FAIL') + '</span><span class="conj">Conjecture 1 — advisory</span></div>'
1094
  + '<div class="hash-row"><span class="hash-label">receipt_id</span><span class="hash-val">'
1095
+ + escHTML(String(r.receipt_id).substring(0,40)) + '…</span></div>'
1096
  + '<div style="font-size:12px;color:var(--text-dim);margin:6px 0">doctrine ' + escHTML(String(r.doctrine))
1097
+ + ' · decl ' + escHTML(String(r.decl)) + ' · axioms ' + escHTML(String(r.axioms)) + ' · sorries '
1098
+ + escHTML(String(r.sorries)) + ' · anchor ' + escHTML(String(r.lutar_anchor || '')) + '</div>'
1099
+ + '<div style="font-size:12px;color:var(--text-mute)">DSSE ' + (r.dsse_signed ? 'signed ✓' : 'unsigned')
1100
+ + ' · keyid ' + escHTML(String(r.dsse_keyid || '—')) + '</div>'
1101
+ + '<div style="margin-top:8px;font-size:12px"><a href="' + hfBase + 'amaru_receipts.ndjson" target="_blank" rel="noopener">Canonical rows on Hugging Face ↗</a>'
1102
+ + ' &nbsp;·&nbsp; <a href="' + escHTML(String(r.verify_key_url || '#')) + '" target="_blank" rel="noopener">Public key ↗</a></div></div>';
1103
  });
1104
  el('ledger-cards').innerHTML = cardsHTML;
1105
 
1106
  show('ledger-panel');
1107
  setStatus('ledger-status', 'Chain: ' + (intact ? 'INTACT' : 'BROKEN') + ' (' + links + '/' + lut.length
1108
+ + ' links) · ' + (lut.length + ama.length) + ' real receipts shown · signatures verify offline against Hugging Face.');
1109
  btn.disabled = false;
1110
  }
1111
  </script>
1112
 
1113
  </body>
1114
  </html>
1115
+