Spaces:
Running
Running
fix(sweep): reclaim dormant anatomy-3D pages + purge sunset-domain/purple (byte-aligned GitHub de9e538)
Browse filesWire szl_anatomy_3d (7 dormant 3D pages) into serve.py; fix company.html canonical/og a11oy.net->a-11-oy.com; purge banned purple in elite_console + READMEs. 4-dev audit. Doctrine v11; Lambda=Conjecture 1.
- README.md +1 -1
- data/genome.json +1 -1
- organs/amaru/README.md +154 -0
- organs/sentra/README.md +153 -0
- pages/company.html +4 -4
- serve.py +14 -0
- web/elite_console.html +5 -5
README.md
CHANGED
|
@@ -33,7 +33,7 @@ ecosystem-stage: "operational"
|
|
| 33 |
### Governed AI with a signed, verifiable receipt for every decision.
|
| 34 |
|
| 35 |
[](.compliance/SLSA_LEVEL.md)
|
| 36 |
-
[](https://github.com/szl-holdings/.github/tree/main/doctrine)
|
| 38 |
[](https://github.com/szl-holdings/a11oy/actions)
|
| 39 |
[](LICENSE)
|
|
|
|
| 33 |
### Governed AI with a signed, verifiable receipt for every decision.
|
| 34 |
|
| 35 |
[](.compliance/SLSA_LEVEL.md)
|
| 36 |
+
[](https://search.sigstore.dev/?logIndex=1710578865)
|
| 37 |
[](https://github.com/szl-holdings/.github/tree/main/doctrine)
|
| 38 |
[](https://github.com/szl-holdings/a11oy/actions)
|
| 39 |
[](LICENSE)
|
data/genome.json
CHANGED
|
@@ -580,7 +580,7 @@
|
|
| 580 |
],
|
| 581 |
"tag": "evidence-backed",
|
| 582 |
"lean_ref": "Scans/verifies lutar-lean but contains no proofs itself. reference-vectors.json formula='Λ_k(x)=(∏xᵢ)^(1/k)', k=9.",
|
| 583 |
-
"powers": "Public independent verification of the Lean kernel (
|
| 584 |
"notes": "scan (L43), summarize (L72), iter_lean_files (L29) in theorem_scan.py; also server.py, lean_numbers.py, index.html. README note (2026-06-30): HF entry is model SZLHOLDINGS/szl-kernels (an HF Space 'lean-kernel' was wrongly referenced and does not exist). SLSA L1 honest badge.",
|
| 585 |
"_quadrant": "Q1"
|
| 586 |
},
|
|
|
|
| 580 |
],
|
| 581 |
"tag": "evidence-backed",
|
| 582 |
"lean_ref": "Scans/verifies lutar-lean but contains no proofs itself. reference-vectors.json formula='Λ_k(x)=(∏xᵢ)^(1/k)', k=9.",
|
| 583 |
+
"powers": "Public independent verification of the Lean kernel (a-11-oy.com / docs-site)",
|
| 584 |
"notes": "scan (L43), summarize (L72), iter_lean_files (L29) in theorem_scan.py; also server.py, lean_numbers.py, index.html. README note (2026-06-30): HF entry is model SZLHOLDINGS/szl-kernels (an HF Space 'lean-kernel' was wrongly referenced and does not exist). SLSA L1 honest badge.",
|
| 585 |
"_quadrant": "Q1"
|
| 586 |
},
|
organs/amaru/README.md
ADDED
|
@@ -0,0 +1,154 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
---
|
| 2 |
+
title: "amaru — Memory Cortex"
|
| 3 |
+
emoji: "🐍"
|
| 4 |
+
colorFrom: green
|
| 5 |
+
colorTo: blue
|
| 6 |
+
sdk: docker
|
| 7 |
+
app_port: 7860
|
| 8 |
+
pinned: true
|
| 9 |
+
license: apache-2.0
|
| 10 |
+
short_description: "amaru — cited reasoning that refuses to fabricate; DSSE receipts"
|
| 11 |
+
tags:
|
| 12 |
+
- memory
|
| 13 |
+
- rag
|
| 14 |
+
- faiss
|
| 15 |
+
- doctrine-v11
|
| 16 |
+
- amaru
|
| 17 |
+
- slsa-l1
|
| 18 |
+
- apache-2.0
|
| 19 |
+
ecosystem-stage: "operational"
|
| 20 |
+
---
|
| 21 |
+
|
| 22 |
+
# amaru 🐍
|
| 23 |
+
|
| 24 |
+
> **⚠️ Archived — retired & consolidated into [szl-holdings/a11oy](https://github.com/szl-holdings/a11oy).** The `amaru` codename has been retired; its capabilities now ship as the **Memory** vertical inside the a11oy flagship. The standalone `szl-holdings/amaru` GitHub repository and the `szlholdings-amaru.hf.space` Hugging Face Space **no longer exist**. The clone URLs, Space links, badges, and deploy commands below are preserved for historical reference only and are **not live** — use [szl-holdings/a11oy](https://github.com/szl-holdings/a11oy) instead.
|
| 25 |
+
|
| 26 |
+
> **Reasoning that refuses to fabricate. Every answer cites a real source or declines. Every memory op wrapped in a DSSE Khipu receipt.**
|
| 27 |
+
|
| 28 |
+
[-555?style=flat-square)](.compliance/SLSA_LEVEL.md)
|
| 29 |
+
[](https://search.sigstore.dev/?logIndex=1723784350)
|
| 30 |
+
[](https://github.com/szl-holdings/.github/tree/main/doctrine)
|
| 31 |
+
|
| 32 |
+
[](LICENSE)
|
| 33 |
+
|
| 34 |
+
**749 declarations · 14 axioms · 163 sorries · Doctrine v11 LOCKED · kernel `c7c0ba17`**
|
| 35 |
+
|
| 36 |
+
[Live demo](#live) · [What it does](#what-it-does) · [Verify](#verify-it-yourself) · [Architecture](#architecture) · [Parity vs. leaders](#parity-vs-leaders) · [Honest status](#honest-status)
|
| 37 |
+
|
| 38 |
+
---
|
| 39 |
+
|
| 40 |
+
## Live
|
| 41 |
+
|
| 42 |
+
**HF Space (one-click, no login):** [](https://huggingface.co/spaces/SZLHOLDINGS/amaru)
|
| 43 |
+
|
| 44 |
+
- Space URL: https://szlholdings-amaru.hf.space
|
| 45 |
+
- Health: `curl -s https://szlholdings-amaru.hf.space/api/amaru/v1/honest | jq '{doctrine,declarations}'` → `{"doctrine":"v11","declarations":749}`
|
| 46 |
+
- Docs: https://docs.szlholdings.com/flagships/amaru
|
| 47 |
+
- Release: v1.0.0
|
| 48 |
+
|
| 49 |
+
---
|
| 50 |
+
|
| 51 |
+
## What it does
|
| 52 |
+
|
| 53 |
+
**amaru is the reasoning cortex.** It answers questions with citations and refuses when evidence is absent — it never invents a justification. This is the trust layer for any commander-facing readiness or assessment dashboard: automation bias kills trust; amaru produces reasoning an operator can act on.
|
| 54 |
+
|
| 55 |
+
Key capabilities:
|
| 56 |
+
- **Cited reasoning** — every answer tied to a chunk-level source; refuses to fabricate when evidence is absent
|
| 57 |
+
- **FAISS RAG memory** — provenance receipts on every memory read/write; COSE_Sign1-wrapped (RFC 9052) per op
|
| 58 |
+
- **7-Chakra scheduler** — ASCEND/DESCEND pipeline; each chakra emits a receipt trace entry
|
| 59 |
+
- **Cardano L1 anchor** — checkpoint hashes as transaction metadata (hash anchoring only — not a token)
|
| 60 |
+
- **Competitive parity** — Splunk-style analytics, Credo AI-style bias detection (live, HTTP 200)
|
| 61 |
+
|
| 62 |
+
**NATO Explainability/Traceability fit:** amaru produces the cited rationale doctrine requires. When an operator asks *why* the system flagged a track, amaru produces a cited answer or refuses — it never invents a justification.
|
| 63 |
+
|
| 64 |
+
---
|
| 65 |
+
|
| 66 |
+
## Verify it yourself
|
| 67 |
+
|
| 68 |
+
```bash
|
| 69 |
+
# 1. Confirm live doctrine numbers
|
| 70 |
+
curl -s https://szlholdings-amaru.hf.space/api/amaru/v1/honest \
|
| 71 |
+
| jq '{doctrine, declarations, axioms_unique, sorries_total}'
|
| 72 |
+
# => {"doctrine":"v11","declarations":749,"axioms_unique":14,"sorries_total":163}
|
| 73 |
+
|
| 74 |
+
# 2. Sign a Khipu receipt and verify the DSSE envelope
|
| 75 |
+
DSSE=$(curl -s -X POST https://szlholdings-amaru.hf.space/api/amaru/khipu/sign \
|
| 76 |
+
-H 'content-type: application/json' \
|
| 77 |
+
-d '{"receipt":{"action_id":"demo"}}' | jq .dsse)
|
| 78 |
+
curl -s -X POST https://szlholdings-amaru.hf.space/api/amaru/khipu/verify \
|
| 79 |
+
-H 'content-type: application/json' -d "{\"dsse\":$DSSE}" | jq '{verified, signatures}'
|
| 80 |
+
# => {"verified": true, "signatures": [{"keyid":"szlholdings-cosign","verified":true}]}
|
| 81 |
+
|
| 82 |
+
# 3. Verify cosign keyless signature on the published image (SLSA L1 honest)
|
| 83 |
+
cosign verify ghcr.io/szl-holdings/amaru:uds-v0.2.0 \
|
| 84 |
+
--certificate-identity-regexp="^https://github.com/szl-holdings/" \
|
| 85 |
+
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"
|
| 86 |
+
# => Verified OK (Rekor index 1723784350)
|
| 87 |
+
|
| 88 |
+
# 4. SLSA L2 provenance attestation is roadmap (Wire D), not yet earned.
|
| 89 |
+
# Currently returns "no matching attestations":
|
| 90 |
+
# cosign verify-attestation --type slsaprovenance ghcr.io/szl-holdings/amaru:uds-v0.2.0 \
|
| 91 |
+
# --certificate-identity-regexp="^https://github.com/szl-holdings/" \
|
| 92 |
+
# --certificate-oidc-issuer="https://token.actions.githubusercontent.com"
|
| 93 |
+
```
|
| 94 |
+
|
| 95 |
+
**Full guide:** [developers/VERIFY.md](https://github.com/szl-holdings/developers/blob/main/VERIFY.md)
|
| 96 |
+
|
| 97 |
+
---
|
| 98 |
+
|
| 99 |
+
## Architecture
|
| 100 |
+
|
| 101 |
+
```mermaid
|
| 102 |
+
graph TD
|
| 103 |
+
Q[Query] --> FAISS[FAISS RAG\nchunk-level retrieval\nprovenance hash per chunk]
|
| 104 |
+
FAISS --> CH[7-Chakra scheduler\nASCEND/DESCEND\neach chakra emits receipt]
|
| 105 |
+
CH --> ANS{Evidence found?}
|
| 106 |
+
ANS --> |Yes| CITE[Cited answer\nreceipt signed\nChakra trace entry]
|
| 107 |
+
ANS --> |No| REFUSE[Explicit refusal\nreceipt signed\nnever fabricates]
|
| 108 |
+
CITE & REFUSE --> KD[Khipu DAG\nDSSE P-256 signed\nCOSE_Sign1 per op]
|
| 109 |
+
KD --> CARD[Cardano anchor\ncheckpoint hash\ntx metadata only]
|
| 110 |
+
```
|
| 111 |
+
|
| 112 |
+
---
|
| 113 |
+
|
| 114 |
+
## Parity vs. leaders
|
| 115 |
+
|
| 116 |
+
| Capability | Palantir / Splunk | amaru | Differentiator |
|
| 117 |
+
|---|---|---|---|
|
| 118 |
+
| RAG / retrieval | ✅ | ✅ FAISS chunk-level | — |
|
| 119 |
+
| Citation of sources | partial | ✅ **chunk-level provenance** | Every claim tied to a verifiable source chunk |
|
| 120 |
+
| Refusal when no evidence | — | ✅ **explicit refusal** | Never fabricates; Palantir doesn't guarantee this |
|
| 121 |
+
| Receipt per reasoning op | — | ✅ **COSE_Sign1 per op** | — |
|
| 122 |
+
| Supply-chain provenance | — | ✅ **cosign-signed (SLSA L1 honest; L2 roadmap)** | Individually verifiable via `cosign verify` |
|
| 123 |
+
| Bias detection | ✅ (Credo AI) | ✅ parity endpoint | — |
|
| 124 |
+
|
| 125 |
+
---
|
| 126 |
+
|
| 127 |
+
## Quickstart
|
| 128 |
+
|
| 129 |
+
```bash
|
| 130 |
+
docker run --rm -p 7860:7860 ghcr.io/szl-holdings/amaru:uds-v0.2.0
|
| 131 |
+
```
|
| 132 |
+
|
| 133 |
+
> Note: in-Space Khipu DSSE receipts are signed with real ECDSA-P256 when `SZL_COSIGN_PRIVATE_PEM` runtime secret is present; otherwise receipts are emitted unsigned and labelled — never silently fabricated.
|
| 134 |
+
|
| 135 |
+
---
|
| 136 |
+
|
| 137 |
+
## Honest status
|
| 138 |
+
|
| 139 |
+
| Claim | Status |
|
| 140 |
+
|---|---|
|
| 141 |
+
| Live HF Space (HTTP 200) | ✅ |
|
| 142 |
+
| SLSA Build L1 honest (L2 roadmap via Wire D) | ✅ L1 — cosign-signed, Rekor [1723784350](https://search.sigstore.dev/?logIndex=1723784350). L2 attestation not yet earned (`cosign verify-attestation` returns "no matching attestations"). |
|
| 143 |
+
| cosign keyless signed | ✅ |
|
| 144 |
+
| DSSE Khipu receipts | ✅ — ECDSA P-256-SHA256 when secret present; labelled UNSIGNED otherwise |
|
| 145 |
+
| Cardano anchor | ⚠️ Demo-seeded; not on mainnet |
|
| 146 |
+
| Lean 749/14/163 @ `c7c0ba17` | ✅ |
|
| 147 |
+
| Λ-uniqueness | ⚠️ Conjecture 1 — not a theorem |
|
| 148 |
+
| SLSA L3 | ❌ Not claimed |
|
| 149 |
+
|
| 150 |
+
---
|
| 151 |
+
|
| 152 |
+
<sub>Doctrine v11 LOCKED · 749/14/163 · kernel `c7c0ba17` · SLSA L1 honest (L2 roadmap) · Λ = Conjecture 1 · Apache-2.0</sub>
|
| 153 |
+
|
| 154 |
+
Signed-off-by: stephenlutar2-hash <stephenlutar2@gmail.com>
|
organs/sentra/README.md
ADDED
|
@@ -0,0 +1,153 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
---
|
| 2 |
+
title: "sentra — Immune System Gateway"
|
| 3 |
+
emoji: "🛡️"
|
| 4 |
+
colorFrom: red
|
| 5 |
+
colorTo: gray
|
| 6 |
+
sdk: docker
|
| 7 |
+
app_port: 7860
|
| 8 |
+
pinned: true
|
| 9 |
+
license: apache-2.0
|
| 10 |
+
short_description: "sentra — deny-by-default policy immune system; signed verdicts"
|
| 11 |
+
tags:
|
| 12 |
+
- governance
|
| 13 |
+
- agentic-ai
|
| 14 |
+
- doctrine-v11
|
| 15 |
+
- sentra
|
| 16 |
+
- immune-system
|
| 17 |
+
- slsa-l1
|
| 18 |
+
- apache-2.0
|
| 19 |
+
ecosystem-stage: "operational"
|
| 20 |
+
---
|
| 21 |
+
|
| 22 |
+
# sentra 🛡️
|
| 23 |
+
|
| 24 |
+
> **⚠️ Archived — retired & consolidated into [szl-holdings/a11oy](https://github.com/szl-holdings/a11oy).** The `sentra` codename has been retired; its capabilities now ship as the **Sentinel** vertical inside the a11oy flagship. The standalone `szl-holdings/sentra` GitHub repository and the `szlholdings-sentra.hf.space` Hugging Face Space **no longer exist**. The clone URLs, Space links, badges, and deploy commands below are preserved for historical reference only and are **not live** — use [szl-holdings/a11oy](https://github.com/szl-holdings/a11oy) instead.
|
| 25 |
+
|
| 26 |
+
> **Deny-by-default policy immune system. 8 gates. Every verdict signed, traced, and chained.**
|
| 27 |
+
|
| 28 |
+
[-555?style=flat-square)](.compliance/SLSA_LEVEL.md)
|
| 29 |
+
[](https://search.sigstore.dev/?logIndex=1723794608)
|
| 30 |
+
[](https://github.com/szl-holdings/.github/tree/main/doctrine)
|
| 31 |
+
|
| 32 |
+
[](LICENSE)
|
| 33 |
+
|
| 34 |
+
**749 declarations · 14 axioms · 163 sorries · Doctrine v11 LOCKED · kernel `c7c0ba17`**
|
| 35 |
+
|
| 36 |
+
[Live demo](#live) · [What it does](#what-it-does) · [Verify](#verify-it-yourself) · [Architecture](#architecture) · [Parity vs. leaders](#parity-vs-leaders) · [Honest status](#honest-status)
|
| 37 |
+
|
| 38 |
+
---
|
| 39 |
+
|
| 40 |
+
## Live
|
| 41 |
+
|
| 42 |
+
**HF Space (one-click, no login):** [](https://huggingface.co/spaces/SZLHOLDINGS/sentra)
|
| 43 |
+
|
| 44 |
+
- Space URL: https://szlholdings-sentra.hf.space
|
| 45 |
+
- Health: `curl -s https://szlholdings-sentra.hf.space/api/sentra/v1/honest | jq .doctrine` → `"v11"`
|
| 46 |
+
- Docs: https://docs.szlholdings.com/flagships/sentra
|
| 47 |
+
- Release: v1.0.0
|
| 48 |
+
|
| 49 |
+
---
|
| 50 |
+
|
| 51 |
+
## What it does
|
| 52 |
+
|
| 53 |
+
**sentra is the policy immune system for the SZL mesh.** It evaluates every incoming action against eight security and policy gates, issues a signed allow/deny verdict, and chains the verdict into the a11oy Khipu receipt DAG. Deny-by-default: an action must pass all eight gates before it is allowed to proceed.
|
| 54 |
+
|
| 55 |
+
Key capabilities:
|
| 56 |
+
- **8 immune gates** — signature-scan, size-guard, Λ-threshold, dual-use, STIX/TAXII, traceparent, Wire-B contract, receipt-hash
|
| 57 |
+
- **Deny by default** — every action evaluated; verdict signed and chained (`/v1/verdict`, `/v1/inspect`)
|
| 58 |
+
- **Signed verdicts** — DSSE ECDSA P-256-SHA256; each verdict is a verifiable artifact, not a log line
|
| 59 |
+
- **Threat-intel cross-reference** — STIX/TAXII corpus; honest Mādhava error envelope
|
| 60 |
+
- **Competitive parity endpoints** — OPA/policy, New Relic/metrics, Wiz/security surface (live, HTTP 200)
|
| 61 |
+
|
| 62 |
+
**Warhacker / DoDD 3000.09 fit:** sentra is the "catch the moment a line gets crossed" organ. Deny-by-default operationalizes "appropriate human judgment over use of force" — actions outside authorized parameters are blocked, and the block itself is a signed, auditable event.
|
| 63 |
+
|
| 64 |
+
---
|
| 65 |
+
|
| 66 |
+
## Verify it yourself
|
| 67 |
+
|
| 68 |
+
```bash
|
| 69 |
+
# 1. Confirm live doctrine posture
|
| 70 |
+
curl -s https://szlholdings-sentra.hf.space/api/sentra/v1/honest | jq .doctrine
|
| 71 |
+
# => "v11"
|
| 72 |
+
|
| 73 |
+
# 2. Verify cosign keyless signature on the published image (SLSA L1 honest)
|
| 74 |
+
cosign verify ghcr.io/szl-holdings/sentra:uds-v0.2.0 \
|
| 75 |
+
--certificate-identity-regexp="^https://github.com/szl-holdings/" \
|
| 76 |
+
--certificate-oidc-issuer="https://token.actions.githubusercontent.com"
|
| 77 |
+
# => Verified OK (Rekor index 1723794608)
|
| 78 |
+
|
| 79 |
+
# 3. SLSA L2 provenance attestation is roadmap (Wire D), not yet earned.
|
| 80 |
+
# Currently returns "no matching attestations":
|
| 81 |
+
# cosign verify-attestation --type slsaprovenance ghcr.io/szl-holdings/sentra:uds-v0.2.0 \
|
| 82 |
+
# --certificate-identity-regexp="^https://github.com/szl-holdings/" \
|
| 83 |
+
# --certificate-oidc-issuer="https://token.actions.githubusercontent.com"
|
| 84 |
+
|
| 85 |
+
# 4. Exercise a live deny
|
| 86 |
+
curl -s -X POST https://szlholdings-sentra.hf.space/api/sentra/v1/verdict \
|
| 87 |
+
-H 'content-type: application/json' \
|
| 88 |
+
-d '{"action":{"type":"out_of_policy_action"}}'
|
| 89 |
+
# => {"verdict":"DENY","signed":true,"gate":"lambda_threshold"}
|
| 90 |
+
```
|
| 91 |
+
|
| 92 |
+
**Full guide:** [developers/VERIFY.md](https://github.com/szl-holdings/developers/blob/main/VERIFY.md)
|
| 93 |
+
|
| 94 |
+
---
|
| 95 |
+
|
| 96 |
+
## Architecture
|
| 97 |
+
|
| 98 |
+
```mermaid
|
| 99 |
+
graph LR
|
| 100 |
+
A[Incoming action] --> G1[signature-scan]
|
| 101 |
+
G1 --> G2[size-guard]
|
| 102 |
+
G2 --> G3[Λ-threshold]
|
| 103 |
+
G3 --> G4[dual-use]
|
| 104 |
+
G4 --> G5[STIX/TAXII]
|
| 105 |
+
G5 --> G6[traceparent]
|
| 106 |
+
G6 --> G7[Wire-B contract]
|
| 107 |
+
G7 --> G8[receipt-hash]
|
| 108 |
+
G8 --> |ALLOW| OUT[Signed verdict\nDSSE P-256\nchained to Khipu DAG]
|
| 109 |
+
G1 & G2 & G3 & G4 & G5 & G6 & G7 & G8 --> |DENY| DENY[Signed DENY receipt\naudit fiber preserved]
|
| 110 |
+
```
|
| 111 |
+
|
| 112 |
+
---
|
| 113 |
+
|
| 114 |
+
## Parity vs. leaders
|
| 115 |
+
|
| 116 |
+
| Capability | OPA / Wiz | sentra | Differentiator |
|
| 117 |
+
|---|---|---|---|
|
| 118 |
+
| Policy enforcement | ✅ | ✅ 8 gates, deny-by-default | — |
|
| 119 |
+
| Threat intel (STIX/TAXII) | ✅ | ✅ | — |
|
| 120 |
+
| Signed verdicts | — | ✅ **DSSE-signed per decision** | Each deny is a cryptographic artifact, not a log |
|
| 121 |
+
| Supply-chain provenance | — | ✅ **cosign-signed (SLSA L1 honest; L2 roadmap)** | Individually verifiable via `cosign verify` |
|
| 122 |
+
| Air-gap deployment | ✅ (proprietary) | ✅ **UDS bundle** | Open-source |
|
| 123 |
+
| Receipt chaining | — | ✅ Khipu DAG | — |
|
| 124 |
+
|
| 125 |
+
---
|
| 126 |
+
|
| 127 |
+
## Quickstart
|
| 128 |
+
|
| 129 |
+
```bash
|
| 130 |
+
docker run --rm -p 7860:7860 ghcr.io/szl-holdings/sentra:uds-v0.2.0
|
| 131 |
+
```
|
| 132 |
+
|
| 133 |
+
---
|
| 134 |
+
|
| 135 |
+
## Honest status
|
| 136 |
+
|
| 137 |
+
| Claim | Status |
|
| 138 |
+
|---|---|
|
| 139 |
+
| Live HF Space (HTTP 200) | ✅ |
|
| 140 |
+
| SLSA Build L1 honest (L2 roadmap via Wire D) | ✅ L1 — cosign-signed, Rekor [1723794608](https://search.sigstore.dev/?logIndex=1723794608). L2 attestation not yet earned (`cosign verify-attestation` returns "no matching attestations"). |
|
| 141 |
+
| cosign keyless signed | ✅ |
|
| 142 |
+
| UDS bundle (`szl-mesh:v0.4.0`) | ✅ |
|
| 143 |
+
| DSSE Khipu receipts | ✅ |
|
| 144 |
+
| Lean 749/14/163 @ `c7c0ba17` | ✅ |
|
| 145 |
+
| Λ-uniqueness | ⚠️ Conjecture 1 — not a theorem |
|
| 146 |
+
| SLSA L3 | ❌ Not claimed |
|
| 147 |
+
| FedRAMP / CMMC | ❌ Not claimed |
|
| 148 |
+
|
| 149 |
+
---
|
| 150 |
+
|
| 151 |
+
<sub>Doctrine v11 LOCKED · 749/14/163 · kernel `c7c0ba17` · SLSA L1 honest (L2 roadmap) · Λ = Conjecture 1 · Apache-2.0</sub>
|
| 152 |
+
|
| 153 |
+
Signed-off-by: stephenlutar2-hash <stephenlutar2@gmail.com>
|
pages/company.html
CHANGED
|
@@ -6,12 +6,12 @@
|
|
| 6 |
<title>Company · SZL Holdings — Governed AI, proven in Lean | a11oy</title>
|
| 7 |
<meta name="description" content="SZL Holdings builds governed agentic AI. Consequential decisions are recorded as cryptographically signed, tamper-evident receipts — verifiable offline. Proven receipt core, honestly staged roadmap. Sovereign, air-gapped capable, defense-grade.">
|
| 8 |
<meta name="theme-color" content="#05060f">
|
| 9 |
-
<link rel="canonical" href="https://
|
| 10 |
<meta property="og:type" content="website">
|
| 11 |
<meta property="og:site_name" content="a11oy · SZL Holdings">
|
| 12 |
<meta property="og:title" content="SZL Holdings — Governed AI, with a proven receipt core.">
|
| 13 |
<meta property="og:description" content="Governed agentic systems. Decisions recorded as cryptographically signed, tamper-evident receipts — verifiable offline. Proven core, honest roadmap.">
|
| 14 |
-
<meta property="og:url" content="https://
|
| 15 |
<style>
|
| 16 |
:root{
|
| 17 |
--hatun-300:#e6c875; --hatun-400:#d7b96b; --hatun-500:#c08f2f;
|
|
@@ -225,13 +225,13 @@ footer{border-top:1px solid var(--line);padding:54px 0 40px}
|
|
| 225 |
<div class="tag-row"><span class="code">02 // a11oy</span><span class="pill pill-live">Live</span></div>
|
| 226 |
<h3>Execution Fabric</h3>
|
| 227 |
<p>The governed agentic substrate — policy, measurement, and a knowledge graph — wired to the receipt layer. A live, public demonstration runs today with real backend APIs and live data feeds: a system you can open and operate, not a screenshot.</p>
|
| 228 |
-
<div class="meta">
|
| 229 |
</div>
|
| 230 |
<div class="card proven">
|
| 231 |
<div class="tag-row"><span class="code">03 // killinchu</span><span class="pill pill-live">Live console</span></div>
|
| 232 |
<h3>Drone Intelligence — Counter-UAS</h3>
|
| 233 |
<p>A counter-drone command surface: an autonomous craft crosses a restricted-airspace line, the system denies it, and a signed receipt of that decision is written and chained. The console is live; the receipt of every verdict is provable and tamper-evident.</p>
|
| 234 |
-
<div class="meta">
|
| 235 |
</div>
|
| 236 |
</div>
|
| 237 |
<div class="honest">
|
|
|
|
| 6 |
<title>Company · SZL Holdings — Governed AI, proven in Lean | a11oy</title>
|
| 7 |
<meta name="description" content="SZL Holdings builds governed agentic AI. Consequential decisions are recorded as cryptographically signed, tamper-evident receipts — verifiable offline. Proven receipt core, honestly staged roadmap. Sovereign, air-gapped capable, defense-grade.">
|
| 8 |
<meta name="theme-color" content="#05060f">
|
| 9 |
+
<link rel="canonical" href="https://a-11-oy.com/company">
|
| 10 |
<meta property="og:type" content="website">
|
| 11 |
<meta property="og:site_name" content="a11oy · SZL Holdings">
|
| 12 |
<meta property="og:title" content="SZL Holdings — Governed AI, with a proven receipt core.">
|
| 13 |
<meta property="og:description" content="Governed agentic systems. Decisions recorded as cryptographically signed, tamper-evident receipts — verifiable offline. Proven core, honest roadmap.">
|
| 14 |
+
<meta property="og:url" content="https://a-11-oy.com/company">
|
| 15 |
<style>
|
| 16 |
:root{
|
| 17 |
--hatun-300:#e6c875; --hatun-400:#d7b96b; --hatun-500:#c08f2f;
|
|
|
|
| 225 |
<div class="tag-row"><span class="code">02 // a11oy</span><span class="pill pill-live">Live</span></div>
|
| 226 |
<h3>Execution Fabric</h3>
|
| 227 |
<p>The governed agentic substrate — policy, measurement, and a knowledge graph — wired to the receipt layer. A live, public demonstration runs today with real backend APIs and live data feeds: a system you can open and operate, not a screenshot.</p>
|
| 228 |
+
<div class="meta">a-11-oy.com/console · live /healthz + trust score Λ</div>
|
| 229 |
</div>
|
| 230 |
<div class="card proven">
|
| 231 |
<div class="tag-row"><span class="code">03 // killinchu</span><span class="pill pill-live">Live console</span></div>
|
| 232 |
<h3>Drone Intelligence — Counter-UAS</h3>
|
| 233 |
<p>A counter-drone command surface: an autonomous craft crosses a restricted-airspace line, the system denies it, and a signed receipt of that decision is written and chained. The console is live; the receipt of every verdict is provable and tamper-evident.</p>
|
| 234 |
+
<div class="meta">a-11-oy.com/elite · signed verdict chain</div>
|
| 235 |
</div>
|
| 236 |
</div>
|
| 237 |
<div class="honest">
|
serve.py
CHANGED
|
@@ -701,6 +701,20 @@ except Exception as _szl3d_e: # pragma: no cover
|
|
| 701 |
print(f"[a11oy] szl3d holographic estate NOT registered: {_szl3d_e!r}; SPA + API unaffected", file=__import__("sys").stderr)
|
| 702 |
|
| 703 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 704 |
# -- RESTRAINT (descend-the-ladder code-restraint ladder + info) -- REGRESSION RESTORE.
|
| 705 |
# Route /api/a11oy/v1/restraint/info (+ evaluate, bench) is the restraint surface. Its
|
| 706 |
# registration was dropped during a serve.py mesh refactor while szl_restraint.py
|
|
|
|
| 701 |
print(f"[a11oy] szl3d holographic estate NOT registered: {_szl3d_e!r}; SPA + API unaffected", file=__import__("sys").stderr)
|
| 702 |
|
| 703 |
|
| 704 |
+
# -- szl_anatomy_3d LIVING-ANATOMY 3D PAGES (Dev0 sweep: was DORMANT — shipped but unwired).
|
| 705 |
+
# Reclaims 7 finished, self-contained 3D pages (/body-3d, /immune-3d, /nervous-3d,
|
| 706 |
+
# /khipu-chain-3d, /lambda-spine-3d, /wires-3d, /yuyay-13) + their live JSON endpoints, each
|
| 707 |
+
# wired to real evaluators / Khipu DAG / DSSE. Self-serves sovereign Three.js r128 at
|
| 708 |
+
# /anatomy-three.min.js (0 runtime CDN). No path collision with szl_anatomy_routes (mounted
|
| 709 |
+
# elsewhere). Registered BEFORE the SPA catch-all; try/except-guarded. Λ = Conjecture 1.
|
| 710 |
+
try:
|
| 711 |
+
import szl_anatomy_3d as _szl_anatomy_3d
|
| 712 |
+
_anat3d_status = _szl_anatomy_3d.register(app, ns="a11oy")
|
| 713 |
+
print(f"[a11oy] Living-anatomy 3D pages registered: {_anat3d_status.get('paths') if isinstance(_anat3d_status, dict) else _anat3d_status}", file=__import__("sys").stderr)
|
| 714 |
+
except Exception as _anat3d_e: # pragma: no cover
|
| 715 |
+
print(f"[a11oy] Living-anatomy 3D pages NOT registered: {_anat3d_e!r}; SPA + API unaffected", file=__import__("sys").stderr)
|
| 716 |
+
|
| 717 |
+
|
| 718 |
# -- RESTRAINT (descend-the-ladder code-restraint ladder + info) -- REGRESSION RESTORE.
|
| 719 |
# Route /api/a11oy/v1/restraint/info (+ evaluate, bench) is the restraint surface. Its
|
| 720 |
# registration was dropped during a serve.py mesh refactor while szl_restraint.py
|
web/elite_console.html
CHANGED
|
@@ -36,7 +36,7 @@
|
|
| 36 |
--red:#e05050; --red-dim:rgba(224,80,80,.15);
|
| 37 |
--amber:#e8b030; --amber-dim:rgba(232,176,48,.12);
|
| 38 |
--blue:#4090f0; --blue-dim:rgba(64,144,240,.12);
|
| 39 |
-
--purple:#
|
| 40 |
--cyan:#30d8e0; --cyan-dim:rgba(48,216,224,.12);
|
| 41 |
/* Type */
|
| 42 |
--sans:'Inter',system-ui,sans-serif;
|
|
@@ -60,7 +60,7 @@ body {
|
|
| 60 |
font:14px/1.55 var(--sans); color:var(--text); background:var(--bg);
|
| 61 |
overflow-x:hidden; min-height:100vh;
|
| 62 |
background-image:
|
| 63 |
-
radial-gradient(ellipse 80% 40% at 70% -5%, rgba(
|
| 64 |
radial-gradient(ellipse 60% 30% at 0% 90%, rgba(212,165,116,.08) 0%, transparent 55%);
|
| 65 |
}
|
| 66 |
a { color:var(--gold); text-decoration:none }
|
|
@@ -2077,7 +2077,7 @@ function init3DOrganMap(organs, edges) {
|
|
| 2077 |
const { scene, camera } = makeScene();
|
| 2078 |
camera.aspect = W / H; camera.updateProjectionMatrix();
|
| 2079 |
|
| 2080 |
-
const COLORS = [0xd4a574, 0x4090f0,
|
| 2081 |
const nodes = organs.map((o, i) => {
|
| 2082 |
const angle = (i / organs.length) * Math.PI * 2;
|
| 2083 |
const x = 2.8 * Math.cos(angle), y = 2.8 * Math.sin(angle);
|
|
@@ -2181,7 +2181,7 @@ function init3DQuorum(organList) {
|
|
| 2181 |
camera.position.set(0, 0, 6);
|
| 2182 |
|
| 2183 |
const orgNames = organList.map(o => o.organ || o);
|
| 2184 |
-
const colors = [0xd4a574, 0x4090f0,
|
| 2185 |
const orgNodes = orgNames.map((name, i) => {
|
| 2186 |
const angle = (i / orgNames.length) * Math.PI * 2;
|
| 2187 |
const geo = new THREE.OctahedronGeometry(0.32, 0);
|
|
@@ -2244,7 +2244,7 @@ function init3DAnatomy(organs, edges) {
|
|
| 2244 |
new THREE.TetrahedronGeometry(0.35, 0),
|
| 2245 |
new THREE.DodecahedronGeometry(0.35, 0),
|
| 2246 |
];
|
| 2247 |
-
const COLORS = [0xd4a574, 0x4090f0,
|
| 2248 |
const positions = [
|
| 2249 |
[0, 0, 0], [-2.5, 1.5, -0.5], [2.5, 1.5, -0.5],
|
| 2250 |
[-2.5, -1.5, 0.5], [2.5, -1.5, 0.5]
|
|
|
|
| 36 |
--red:#e05050; --red-dim:rgba(224,80,80,.15);
|
| 37 |
--amber:#e8b030; --amber-dim:rgba(232,176,48,.12);
|
| 38 |
--blue:#4090f0; --blue-dim:rgba(64,144,240,.12);
|
| 39 |
+
--purple:#5b8dee; --purple-dim:rgba(91,141,238,.12);
|
| 40 |
--cyan:#30d8e0; --cyan-dim:rgba(48,216,224,.12);
|
| 41 |
/* Type */
|
| 42 |
--sans:'Inter',system-ui,sans-serif;
|
|
|
|
| 60 |
font:14px/1.55 var(--sans); color:var(--text); background:var(--bg);
|
| 61 |
overflow-x:hidden; min-height:100vh;
|
| 62 |
background-image:
|
| 63 |
+
radial-gradient(ellipse 80% 40% at 70% -5%, rgba(91,141,238,.12) 0%, transparent 60%),
|
| 64 |
radial-gradient(ellipse 60% 30% at 0% 90%, rgba(212,165,116,.08) 0%, transparent 55%);
|
| 65 |
}
|
| 66 |
a { color:var(--gold); text-decoration:none }
|
|
|
|
| 2077 |
const { scene, camera } = makeScene();
|
| 2078 |
camera.aspect = W / H; camera.updateProjectionMatrix();
|
| 2079 |
|
| 2080 |
+
const COLORS = [0xd4a574, 0x4090f0, 0x5b8dee, 0x3ecf7a, 0x30d8e0];
|
| 2081 |
const nodes = organs.map((o, i) => {
|
| 2082 |
const angle = (i / organs.length) * Math.PI * 2;
|
| 2083 |
const x = 2.8 * Math.cos(angle), y = 2.8 * Math.sin(angle);
|
|
|
|
| 2181 |
camera.position.set(0, 0, 6);
|
| 2182 |
|
| 2183 |
const orgNames = organList.map(o => o.organ || o);
|
| 2184 |
+
const colors = [0xd4a574, 0x4090f0, 0x5b8dee, 0x3ecf7a];
|
| 2185 |
const orgNodes = orgNames.map((name, i) => {
|
| 2186 |
const angle = (i / orgNames.length) * Math.PI * 2;
|
| 2187 |
const geo = new THREE.OctahedronGeometry(0.32, 0);
|
|
|
|
| 2244 |
new THREE.TetrahedronGeometry(0.35, 0),
|
| 2245 |
new THREE.DodecahedronGeometry(0.35, 0),
|
| 2246 |
];
|
| 2247 |
+
const COLORS = [0xd4a574, 0x4090f0, 0x5b8dee, 0x3ecf7a, 0x30d8e0];
|
| 2248 |
const positions = [
|
| 2249 |
[0, 0, 0], [-2.5, 1.5, -0.5], [2.5, 1.5, -0.5],
|
| 2250 |
[-2.5, -1.5, 0.5], [2.5, -1.5, 0.5]
|