---
title: "a11oy โ Governance Substrate"
emoji: "๐ฌ"
colorFrom: indigo
colorTo: gray
sdk: docker
app_port: 7860
pinned: true
license: apache-2.0
short_description: "a11oy โ policy + receipt substrate"
tags:
- governance
- agentic-ai
- doctrine-v11
- a11oy
- execution-fabric
- apache-2.0
ecosystem-stage: "operational"
---
## Live
**HF Space (one-click, no login):** [](https://huggingface.co/spaces/SZLHOLDINGS/a11oy)
- **Primary face โ the full application:** https://szlholdings-a11oy.hf.space/ (also at `/console`)
- Space URL: https://szlholdings-a11oy.hf.space
- Health: `curl -s https://szlholdings-a11oy.hf.space/api/a11oy/v1/honest | jq .kernel_commit` โ `"c7c0ba17"`
- Docs: https://docs.szlholdings.com/flagships/a11oy
- Release: [v1.0.0](https://github.com/szl-holdings/a11oy/releases/tag/v1.0.0)
---
## The application
a11oy is a **full left-nav application** โ not a landing page or a single console panel. It opens directly to the Command Center and carries the unified SZL house style (dark ground, gold `#c9b787` + teal `#5fb3a3` accents, Space Grotesk + JetBrains Mono) with a **product switcher** in the top ribbon that jumps between the two live SZL products โ a11oy (command platform) and killinchu (drones & vessels) โ in one click.
**Primary app file:** [`pages/console.html`](pages/console.html) ยท **served at** `/` and `/console`.
**43 unique tabs** in the left navigation (plus **7 Warhacker live demos**). Representative views:
| View | What it does |
|---|---|
| **Command Center** | Live operational overview โ service health, recent verdicts, receipt stream |
| **Five Superpowers** | The five orchestrated capabilities a11oy coordinates internally |
| **Warhacker** | Maps the five Warhacker problems to the a11oy capability that solves each, with a live signed receipt |
| **Observability** | MELT + distributed tracing where every span is a signed Khipu receipt (vs New Relic / Datadog / OTel) |
| **Capabilities** | The built-in a11oy capability fabric โ reasoning, policy, and operator paths wired into the receipt substrate |
| **Services** | Live service reachability โ real probes, honest when a service is unreachable |
| **Formulas** | The PURIQ formula set โ **5 locked-proven in Lean 4 {F1, F11, F12, F18, F19}** + **~36 experimental** theorems CI-green on main `@7885fd9` (e.g. M2 hash-chain tamper-evidence, CP1 split-conformal coverage); remaining formulas are Roadmap |
| **Evidence** | Body-of-evidence export โ DSSE Khipu receipts, replayable and tamper-evident |
| **LLM Router** | The governed LLM routing surface |
---
## What it does
**a11oy is the audit-fiber continuity layer of the SZL command platform.** Every AI action routes through a11oy and leaves a DSSE-enveloped Khipu receipt on a SHA-256 hash-linked Merkle DAG. The invariant is `receipts.in โก receipts.out`: nothing is lost between the decision and the proof.
Key capabilities:
- **Policy + receipt substrate** โ `/v1/policy/evaluate`, `/v1/verify`, `/v1/ledger`: deny-by-default; every action signed
- **Built-in capability fabric** โ reasoning, policy, and operator paths are internal to a11oy (not external services); each emits signed receipts
- **Honest disclosure** โ `/v1/honest` reports live doctrine posture (749/14/163, ฮ = Conjecture 1)
- **8 TS workspace libs** โ `@szl-holdings/a11oy-knowledge`, `a11oy-policy`, `a11oy-qec-integrity`, `a11oy-receipt-substrate`, `perception-loop`, `rae1`, `sequence-pipeline`, `sparse-attention-kit`
- **DSSE Khipu receipts** โ ECDSA P-256-SHA256; multi-party-witnessed; BFT quorum-capable
---
## Verify it yourself
```bash
# 1. Confirm live doctrine posture
curl -s https://szlholdings-a11oy.hf.space/api/a11oy/v1/honest | jq .kernel_commit
# => "c7c0ba17"
# 2. Verify the cosign keyless signature on the published image (SLSA L1).
# GHCR verification shows a cosign-signed image (L1); the SLSA provenance
# attestation (L2) verifies via `cosign verify-attestation --type slsaprovenance`
# with strict identity. See .compliance/SLSA_LEVEL.md.
cosign verify ghcr.io/szl-holdings/a11oy:uds-v0.2.0 \
--certificate-identity-regexp="^https://github.com/szl-holdings/" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"
# Public Rekor entry for the image signature: log index 1710578865
# 3. Verify the SLSA L2 provenance attestation (strict identity)
cosign verify-attestation --type slsaprovenance ghcr.io/szl-holdings/a11oy:uds-v0.2.0 \
--certificate-identity-regexp="https://github.com/szl-holdings/a11oy/" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"
# 4. Deploy as part of the signed mesh bundle
# (service images are L2-attested; the bundle artifact itself is not yet attested)
uds-cli bundle deploy oci://ghcr.io/szl-holdings/szl-uds-bundle:uds-v0.2.0 --confirm
```
**Full guide:** [developers/VERIFY.md](https://github.com/szl-holdings/developers/blob/main/VERIFY.md)
---
## Architecture
```mermaid
graph TD
A[Incoming action] --> PL[Policy layer\n/v1/policy/evaluate\ndeny-by-default]
PL --> KD[Khipu DAG\nDSSE P-256 signed\nSHA-256 hash-linked]
KD --> LDG[Ledger /v1/ledger\nreplayable, tamper-evident]
KD --> UDS[(GHCR\nSigned OCI\ncosign-signed ยท SLSA L2 attested)]
KD --> REKOR[(Rekor transparency log\nindex 1710578865)]
```
---
## Parity vs. leaders
| Capability | Palantir AIP | a11oy | Differentiator |
|---|---|---|---|
| Policy enforcement | โ
| โ
`/v1/policy/evaluate` | โ |
| Audit trail | โ
logs | โ
**signed receipts** | Palantir logs are not individually verifiable cryptographic artifacts |
| Supply-chain provenance | โ | โ
**cosign-signed + SLSA L2 attested** | `cosign verify` + `cosign verify-attestation --type slsaprovenance` on every image โ they don't offer this. |
| Formal math substrate | โ | โ
Lean 4 / 749 decl | Open, machine-checkable |
| Air-gap deployment | โ
(proprietary) | โ
**one UDS command** | Open-source, reproducible |
| Receipt multi-party witness | โ | โ
BFT quorum-capable | โ |
---
## Quickstart
```bash
docker run --rm -p 7860:7860 ghcr.io/szl-holdings/a11oy:uds-v0.2.0
```
---
## Honest status
| Claim | Status |
|---|---|
| Live HF Space (HTTP 200) | โ
|
| SLSA Build L1 + L2 | โ
โ cosign-signed image (L1), verifiable via `cosign verify`; Rekor [1710578865](https://search.sigstore.dev/?logIndex=1710578865). L2 SLSA provenance attestation verifies via `cosign verify-attestation --type slsaprovenance` (strict identity, keyless Fulcio+Rekor). See [.compliance/SLSA_LEVEL.md](.compliance/SLSA_LEVEL.md). |
| cosign keyless signed | โ
|
| UDS bundle (`szl-uds-bundle:uds-v0.2.0`) | โ
Real, deployable mesh bundle. **Note:** the bundle artifact itself is **not yet SLSA-attested** (owner-only GHCR package-write grant pending). The L2 build-provenance attestation that verifies is on the **service images**, not the bundle. |
| DSSE Khipu receipts | โ
โ ECDSA P-256-SHA256 |
| Lean 749/14/163 @ `c7c0ba17` | โ
|
| Locked-proven PURIQ formulas | โ
Exactly **5** โ F1, F11, F12, F18, F19 (Lean 4, depend on **no** axioms; machine-enforced `locked_count_five`). |
| Experimental theorems (main `@7885fd9`) | โ
**~36** CI-green, kernel-verified results (waves 5/6/7/8 + agentic P1โP6 + coder + the strengthened-axiom ฮ set, where ฮ-uniqueness remains **Conjecture 1**). **NOT** in the locked count. Key: M2 tamper-evidence (`#print axioms = [propext]` only), CP1 split-conformal coverage (not Hoeffding). |
| ฮ-uniqueness | โ ๏ธ **Conjecture 1** (F23 open bounty) โ never a theorem |
| SLSA L3 | โ Not claimed |
| FedRAMP / CMMC | โ Not claimed |
---
Doctrine v11 LOCKED ยท 749/14/163 ยท kernel `c7c0ba17` ยท SLSA L1 + L2 (provenance attestation verified; L3 not claimed) ยท ฮ = Conjecture 1 ยท Apache-2.0 ยท DOI [10.5281/zenodo.20434276](https://doi.org/10.5281/zenodo.20434276)
Signed-off-by: Stephen P. Lutar Jr.