The Running System
The Storefront Is the Evidence.
Most vendors show you a demo. This page is a tour of a working institution — with its receipts, its claim ledger, and its known limits printed together.
What Sovereignty Means Here.
Sovereign is a word being colonized from above — hyperscalers now sell "sovereign tiers" that are data-residency checkboxes with a premium invoice. So before we use the word, we define it. Operationally. In five points you can verify with your own hands.
- You own the relationship. No platform's terms of service sit between you and your AI. Nobody re-prices, rate-limits, or retires what you depend on.
- The server is in your building. Not "your region." Your building. You can put your hand on it.
- Your data never leaves your network. There is no central store on our side. Nothing syncs out. Nothing phones home.
- There is nothing of yours to breach. When an AI vendor gets breached, their customers' data is the casualty. We hold none of yours. The security posture is structural, not contractual.
- The kill switch is in your hand. You can shut the whole thing off — physically — without asking anyone's permission. Including ours.
| Dimension | Public AI Stack | Sovereign Stack |
|---|---|---|
| Data ownership | Platform terms govern retention and use | You own it. No central store exists. |
| Pricing power | Theirs — prices rise once you depend on it | Yours — the hardware is bought, not rented |
| Breach exposure | Your data sits in their blast radius | Nothing of yours sits on anyone else's side |
| Who can turn it off | The vendor, a policy change, an acquisition | You. The kill switch is physical and yours. |
| Who it improves for | The platform's growth metrics | Your business. Learning stays in your walls. |
The Machine That Backs the Promise.
Most vendors show you a demo. This is a tour of an institution — the governed, self-measuring system we run on ourselves, every day, before any of it is offered to you. Every mechanism below ends the same way: what it means for you.
The constitution's spine
The whole system runs under a written constitution. Its spine — quoted, not paraphrased — is five lines:
- Proof is authority. Nothing holds reach it hasn't earned by verified proof.
- Development is the reach; only value-positions are gated. Building and testing run free; touching anything real requires passed exams.
- Governance is invitation, not cage. The rules exist so every member can play its fullest game.
- No gate may block what doctrine invites; don't fund the broken. A rule that contradicts the mission gets fixed, never paid off.
- The record is the system. Only validated, recorded work counts. What isn't captured evaporates.
"Agents propose, humans decide" is the house rule that sits under line one — human authority at every irreversible edge, by architecture rather than policy.
The governing principle: reach — authority, scope, trust — is earned by verified proof, never claimed. It widens on proof and tightens on failure. An agent that hasn't proven a capability doesn't get to exercise it, no matter how confidently it asks.
What it means for youNothing in your deployment runs on reputation. If a capability is on, it's on because it passed. If it failed, its reach shrank — automatically.
Every tool and capability earns its place through a staged pipeline: NOMINATE→SHADOW→EXAM→PROMOTE→EXIT Candidates run in shadow — observed, not trusted — before they're examined. Only what passes gets promoted. What degrades gets exited.
What it means for youYour stack doesn't accumulate junk. New capability arrives tested; failing capability gets removed instead of quietly rotting.
Multiple AI models — local and frontier — work under the same written contract, with authorship and custody recorded as separate facts. A model may draft; a human holds custody. Custody is not authorship, and the record never confuses the two.
What it means for youYou're never locked to one model or one vendor. Models are staff under a contract you own — swappable, auditable, replaceable.
Recurring scheduled checks run on local models against the system's own state — integrity, drift, staleness — and their findings are written back into the record. The institution measures itself on a cadence, not when someone remembers to look.
What it means for youThe same discipline is what a stewarded care plan buys: a system checked on a schedule, by design, so problems are found before they're fires.
This tour is deliberately sanitized: no hostnames, no addresses, no internal paths, no workflow identifiers. The record is public; the plumbing is not. That boundary is itself one of the disciplines on display.
The Claim Ledger.
Every claim this site makes is entered here at its actual maturity — measured, candidate, pre-registered, or not yet claimable. Marketing pages don't usually audit themselves. That's rather the point.
| Claim | Maturity | What it rests on |
|---|---|---|
| RVS v2.3 release-test suite | Green at last check | Full pass/fail history lives in the repository's own test runner, not printed here as a headline count |
| Subjects under the governed manifest | Live | Tracked under a governed subject manifest; the running count lives in the system of record, not on this marketing page |
| Governed research plates (RVS 1.x) | Live | Plates run under the same governed-manifest discipline as the rest of the record |
| Doctrine corpus: 5 papers on governed multi-agent institutions | Pre-registered | Claims and falsification paths published before results; results unresolved. See the research shelf. |
| Client-side audit trail & kill switch | Live | Delivered as named handover artifacts, labeled by what the shipped client stack verifiably does — the internal institution's proofs are not borrowed |
| Client-side earned-authority ledger | In Build | Ships when it passes, not before |
| Governed decision gateway (Mission Control v2) | Live | Human GO/NO-GO required on every consequential action; hash-chained, externally anchored ledgers; least-privilege and fail-closed; an instant kill switch. GO itself stays gated — no capital moves travel any agent path. |
| Fully autonomous self-actuation | Shadow | Agents propose, humans decide. The decision gateway that adjudicates GO/NO-GO is live; agents acting on anything consequential without a human in the loop stays shadow-only until its own sentinel exists and it passes. |
Known Limits.
Internally, we call the known-issues section the most valuable section of any document. This page keeps the discipline. Here is what this system is not — today, in public, printed next to the things it's for sale with.
- Fully autonomous self-actuation is still shadow-only. The governed decision gateway — human GO/NO-GO, hash-chained and externally anchored ledgers, fail-closed, instant kill switch — is live today. What stays gated is agents acting on anything consequential without a human in the loop; that stays labeled Shadow until its own sentinel exists and it passes.
- The doctrine corpus is pre-registered, not proven. Five papers on governed multi-agent institutions have published claims and falsification paths — and unresolved results. Pre-registration is a promise about honesty, not a result.
- Local models are not frontier models. For the deepest reasoning tasks, the big labs' newest models are better. Full stop. What a sovereign stack gives you is routing on your terms: local for the private and the routine — most of a business's actual day — and a frontier call, under your data rules, when a task genuinely warrants it. Anyone who tells you a local box beats the frontier at everything is selling you something. We're telling you what we route where.
- Capacity is one steward deep. Stewarded seats are capped at what one person can verifiably serve, and we don't sign response-time promises we can't keep. The cap is public because the promise has to stay smaller than the capacity — that's Proof-of-Reach applied to ourselves.
The permanent version of this section lives at /limits, and the research it disciplines lives at /research. Neither page will ever be softer than this one.