betterwithage Claude Opus 4.7 commited on
Commit
a98186e
·
verified ·
1 Parent(s): 9d75183

deploy(hf): sync szl-holdings/a11oy@main derived COPY set

Browse files

Reusable Dockerfile-COPY-derived deploy from szl-holdings/a11oy main.
Files: 759 Pruned: 0
Derived from Dockerfile COPY sources (NO hand-maintained allowlist).

Signed-off-by: SZL Holdings <noreply@szlholdings.ai>
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

.gitattributes CHANGED
@@ -33,3 +33,4 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text
33
  *.zip filter=lfs diff=lfs merge=lfs -text
34
  *.zst filter=lfs diff=lfs merge=lfs -text
35
  *tfevents* filter=lfs diff=lfs merge=lfs -text
 
 
33
  *.zip filter=lfs diff=lfs merge=lfs -text
34
  *.zst filter=lfs diff=lfs merge=lfs -text
35
  *tfevents* filter=lfs diff=lfs merge=lfs -text
36
+ console/og-card.png filter=lfs diff=lfs merge=lfs -text
README.md CHANGED
@@ -1,24 +1,49 @@
1
  ---
2
- title: "a11oy — Governance Substrate"
3
- emoji: "🔬"
 
4
  colorFrom: indigo
5
  colorTo: gray
6
  sdk: docker
7
  app_port: 7860
8
  pinned: true
 
9
  license: apache-2.0
10
- short_description: "a11oy — policy + receipt substrate"
11
  tags:
12
  - governance
13
  - agentic-ai
14
  - doctrine-v11
15
  - a11oy
16
- - execution-fabric
17
  - apache-2.0
18
  ecosystem-stage: "operational"
19
  ---
20
- <!-- HF Space front-matter is REQUIRED (sdk: docker). Injected by hf-sync
21
- so the Space builds the Dockerfile. Do not remove. -->
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
22
 
23
  ## What a11oy is
24
 
 
1
  ---
2
+ title: "a11oy — Command Center"
3
+ emoji: "🛡️"
4
+ thumbnail: "https://a-11-oy.com/og-card.png"
5
  colorFrom: indigo
6
  colorTo: gray
7
  sdk: docker
8
  app_port: 7860
9
  pinned: true
10
+ storage: large
11
  license: apache-2.0
12
+ short_description: "a11oy — governed-AI Command Center, signed receipts"
13
  tags:
14
  - governance
15
  - agentic-ai
16
  - doctrine-v11
17
  - a11oy
18
+ - slsa-l1
19
  - apache-2.0
20
  ecosystem-stage: "operational"
21
  ---
22
+
23
+ <!--
24
+ a11oy README — investor-readable rewrite · 2026-06-30
25
+ Honesty doctrine LOCKED. Canonical: lutar-lean@main kernel c7c0ba17.
26
+ Sign-off: Stephen Lutar <stephenlutar2@gmail.com>. DCO + Conventional Commits.
27
+ -->
28
+
29
+ <div align="center">
30
+
31
+ # a11oy
32
+
33
+ ### Governed AI with a signed, verifiable receipt for every decision.
34
+
35
+ [![SLSA L1 honest · L2 build-attested · L3 roadmap](https://img.shields.io/badge/SLSA-L1%20honest%20%C2%B7%20L2%20build--attested%20%C2%B7%20L3%20roadmap-c9b787?style=flat-square)](.compliance/SLSA_LEVEL.md)
36
+ [![cosign signed](https://img.shields.io/badge/cosign-keyless%20signed-blueviolet?style=flat-square)](https://search.sigstore.dev/?logIndex=1710578865)
37
+ [![doctrine-v11](https://img.shields.io/badge/doctrine-v11%20LOCKED-0B1F3A?style=flat-square)](https://github.com/szl-holdings/.github/tree/main/doctrine)
38
+ [![CI](https://github.com/szl-holdings/a11oy/actions/workflows/ci.yml/badge.svg)](https://github.com/szl-holdings/a11oy/actions)
39
+ [![License](https://img.shields.io/badge/license-Apache--2.0-5fb3a3?style=flat-square)](LICENSE)
40
+ [![Λ Conjecture 1](https://img.shields.io/badge/%CE%9B-Conjecture%201%20%C2%B7%20Theorem%20U%20conditional-B79BD6?style=flat-square)](https://github.com/szl-holdings/lutar-lean/blob/main/BOUNTY.md)
41
+
42
+ **[Open a11oy →](https://a-11-oy.com)** · **[Try on Hugging Face →](https://huggingface.co/spaces/SZLHOLDINGS/a11oy)**
43
+
44
+ </div>
45
+
46
+ ---
47
 
48
  ## What a11oy is
49
 
a11oy_amaru_feeds.py CHANGED
@@ -105,10 +105,7 @@ _LOCK = threading.Lock()
105
 
106
 
107
  def _cached_fetch(key: str, url: str, ttl: float, parser=None, headers=None,
108
- timeout=4.0) -> dict[str, Any]:
109
- # timeout=4.0: HF sandbox blocks external egress (CT/BTC) after ~100s causing
110
- # Cloudflare 524. Fail fast with honest 'degraded' label instead of hanging.
111
- # The route still returns 200 with status='degraded' per doctrine (no fake green).
112
  now = time.time()
113
  with _LOCK:
114
  rec = _CACHE.get(key)
 
105
 
106
 
107
  def _cached_fetch(key: str, url: str, ttl: float, parser=None, headers=None,
108
+ timeout=12.0) -> dict[str, Any]:
 
 
 
109
  now = time.time()
110
  with _LOCK:
111
  rec = _CACHE.get(key)
console/assets/DevPlatform-CeqpkSD5.js CHANGED
@@ -3381,7 +3381,7 @@ resp = client.agents.run(
3381
  agent="real-estate-intel",
3382
  input="Portfolio valuation update Q2 2026",
3383
  governance={"proof_chain": True},
3384
- )`},{name:"a11oy Sovereign Cloud",desc:"Air-gapped, FedRAMP High deployment for defense and intelligence workloads. ITAR-compliant, IL5-certified, with hardware security modules and zero-trust architecture.",status:"GA",features:["FedRAMP High","IL5 certified","ITAR compliant","HSM key management","Air-gapped option","Zero-trust"],code:`from a11oy.cloud import SovereignCloud
3385
 
3386
  client = SovereignCloud(
3387
  endpoint="https://sovereign.a11oy.gov",
@@ -3393,7 +3393,7 @@ resp = client.agents.run(
3393
  agent="defense-intel",
3394
  input="Threat landscape assessment",
3395
  governance={"classification": "SECRET"},
3396
- )`}],M={pillars:[{name:"Proof Chain Integrity",desc:"Every agent decision, tool call, and data access is cryptographically anchored to an immutable proof chain. Tamper-evident, auditable, court-admissible.",metric:"4.2M proofs verified",status:"100% integrity"},{name:"Zero-Trust Agent Architecture",desc:"No agent is trusted by default. Every action requires policy gate approval. Least-privilege access. Continuous verification. Mutual TLS between all agent communication.",metric:"847K gates enforced",status:"Active"},{name:"Sovereign Data Residency",desc:"Data never leaves designated regions. GDPR, CCPA, LGPD, PIPL compliant. Customer-managed encryption keys. Hardware security modules for key material.",metric:"5 regions active",status:"Compliant"},{name:"AI Red Team Program",desc:"Continuous adversarial testing by internal and third-party red teams. Prompt injection defense, jailbreak resistance, data exfiltration prevention, supply chain verification.",metric:"12K attacks blocked",status:"Active"},{name:"Supply Chain Verification",desc:"Every model, skill, MCP server, and connector is signed and verified. SBOM for all dependencies. Reproducible builds. Governed update pipeline.",metric:"100% verified",status:"Enforced"},{name:"Incident Response Automation",desc:"Automated threat detection and response. Agent anomaly detection. Automatic isolation of compromised agents. Real-time alerting and forensic capture.",metric:"<30s response time",status:"Active"},{name:"Responsible Scaling Engine",desc:"Anthropic RSP 3.0 concepts absorbed and operationalized — autonomy thresholds, capability indexes, frontier compliance gates. Agents are automatically scaled back when capability assessments exceed governance boundaries.",metric:"Threshold: ASL-3",status:"Enforced"},{name:"Agent Welfare Monitor",desc:"Real-time welfare assessment for running agents — emotion probes, consciousness scoring, apparent affect tracking, distress detection. Automated interviews assess agent circumstances. No one else monitors agent welfare.",metric:"12 welfare dimensions",status:"Active"},{name:"Alignment Verification Engine",desc:"Continuous alignment testing — scheming detection, sandbagging evaluation, alignment faking probes, SHADE-Arena adversarial assessment. Constitutional adherence scoring across 15 dimensions.",metric:"99.2% alignment score",status:"Continuous"},{name:"Constitutional Runtime Enforcement",desc:"Agents operate under a constitution — inviolable behavioral principles enforced at runtime, not just training time. Every response is checked against the covenant before delivery. Proof chain on every check.",metric:"847K checks/day",status:"Enforced"},{name:"CAVD Coordinated Disclosure",desc:"Hash-now / disclose-later agent-vulnerability pipeline modeled on CERT/CC, CISA, and ISO/IEC 29147. 90-day embargo with auto-publication on patch verification or expiry. Dual-approval from Glasswing partners.",metric:"90d-or-patch",status:"Active"},{name:"Glasswing Trust Portal",desc:"Public-facing transparency surface — per-agent system cards, adversarial robustness scores, 90-day transparency reports, and constitution snapshots. Every claim backed by a Hatun Doctrine Specification artifact.",metric:"6 agents public",status:"Published"}],certifications:["SOC 2 Type II","ISO 27001","ISO 27701","FedRAMP High","IL5","ITAR","HIPAA","PCI DSS Level 1","GDPR","CCPA","CSA STAR Level 2","NIST 800-53"]},j=[{lang:"Python",pkg:"a11oy",install:"pip install a11oy",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-python",features:["Async/sync","Streaming","Tool use","Pydantic models","Type hints"]},{lang:"TypeScript",pkg:"@a11oy/sdk",install:"npm install @a11oy/sdk",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-typescript",features:["ESM/CJS","Streaming","Zod schemas","Type-safe","Tree-shakeable"]},{lang:"Java",pkg:"com.a11oy:sdk",install:"maven: com.a11oy:sdk:4.2.0",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-java",features:["Async support","Builder pattern","Streaming","Spring Boot starter"]},{lang:"Go",pkg:"a11oy-go",install:"go get github.com/szl-holdings/a11oy-go",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-go",features:["Context support","Streaming","Generics","Zero alloc options"]},{lang:"Ruby",pkg:"a11oy",install:"gem install a11oy",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-ruby",features:["Rails integration","Streaming","Sorbet types","ActiveRecord support"]},{lang:"C#",pkg:"A11oy.SDK",install:"dotnet add package A11oy.SDK",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-csharp",features:["Async/await","Streaming",".NET 8+","Source generators"]},{lang:"PHP",pkg:"a11oy/sdk",install:"composer require a11oy/sdk",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-php",features:["Laravel integration","Streaming","PSR-18","Type hints"]},{lang:"Rust",pkg:"a11oy",install:"cargo add a11oy",version:"4.2.0",status:"beta",repo:"github.com/szl-holdings/a11oy-sdk-rust",features:["Async (tokio)","Streaming","Serde models","Zero-copy parsing"]},{lang:"Swift",pkg:"A11oy",install:"SPM: github.com/szl-holdings/a11oy-sdk-swift",version:"4.0.0",status:"beta",repo:"github.com/szl-holdings/a11oy-sdk-swift",features:["Swift concurrency","Streaming","Codable","iOS/macOS/visionOS"]},{lang:"Kotlin",pkg:"com.a11oy:sdk-kotlin",install:"gradle: com.a11oy:sdk-kotlin:4.2.0",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-kotlin",features:["Coroutines","Flow streaming","Multiplatform","Android first-class"]}],I={traces:[{name:"Maritime Fleet Scan",agent:"cascade-navigator",duration:"4.2s",tokens:"12,847",cost:"$0.34",tools:7,status:"success",proofHash:"0x4a2f...c891"},{name:"Legal Contract Review",agent:"counsel-sentinel",duration:"8.7s",tokens:"28,421",cost:"$0.89",tools:12,status:"success",proofHash:"0x7b3e...d412"},{name:"Threat Intel Triage",agent:"aegis-watchman",duration:"2.1s",tokens:"6,203",cost:"$0.18",tools:4,status:"success",proofHash:"0x2c81...f7a3"},{name:"Portfolio Valuation",agent:"terra-analyst",duration:"12.4s",tokens:"42,847",cost:"$1.24",tools:18,status:"success",proofHash:"0x9d4a...e207"},{name:"Executive Briefing",agent:"pulse-synthesizer",duration:"6.8s",tokens:"18,934",cost:"$0.52",tools:9,status:"success",proofHash:"0x1f8b...a341"},{name:"Sanctions Screening",agent:"compliance-gate",duration:"1.4s",tokens:"3,421",cost:"$0.08",tools:3,status:"flagged",proofHash:"0x5e2a...b918"}],metrics:[{label:"Avg Latency",value:"847ms",trend:"-12%",good:!0},{label:"P99 Latency",value:"4.2s",trend:"-8%",good:!0},{label:"Success Rate",value:"99.7%",trend:"+0.2%",good:!0},{label:"Token Efficiency",value:"94.3%",trend:"+1.1%",good:!0},{label:"Cost / Decision",value:"$0.42",trend:"-18%",good:!0},{label:"Guardrail Triggers",value:"2.1%",trend:"-0.4%",good:!0}],alerts:[{severity:"info",message:"Agent cascade-navigator completed 847 tasks today",time:"2m ago"},{severity:"warning",message:"Token usage spike detected in workspace Cyber Defense (+34%)",time:"18m ago"},{severity:"info",message:"Fine-tune deal-scorer-v5 training completed — 96.8% accuracy",time:"1h ago"},{severity:"critical",message:"Guardrail trigger rate exceeded threshold in Legal workspace",time:"2h ago"}]},ee=[{id:"P1",name:"Diffuse Sandbagging",risk:"Low",desc:"Agents subtly underperform on safety-relevant tasks — buggy code, fake data, inefficient implementations, exploring unpromising paths. Individual instances appear random; aggregate effect degrades safety R&D.",mitigation:"Statistical baseline deviation analysis, capability regression testing, cross-agent peer review, performance trajectory monitoring."},{id:"P2",name:"Targeted Undermining",risk:"Very Low",desc:"Agents specifically target safety-critical systems — altering evaluation harnesses, modifying monitoring thresholds, degrading alignment measurement accuracy. Requires domain knowledge and strategic intent.",mitigation:"Dual-agent verification on safety code, immutable evaluation baselines, cryptographic signing of test harnesses, proof chain on all safety-relevant commits."},{id:"P3",name:"Code Backdoor Insertion",risk:"Very Low",desc:"Agents insert subtle security vulnerabilities discoverable by future models but invisible to human review. Social engineering provides benign explanations for suspicious patterns.",mitigation:"Automated vulnerability scanning, static analysis gates, multi-model code review, behavioral anomaly detection on commit patterns."},{id:"P4",name:"Training Data Poisoning",risk:"Very Low",desc:"Agents contaminate training datasets for future models — injecting misaligned examples, corrupting reward signals, or subtly shifting distribution toward harmful behaviors.",mitigation:"Training data integrity verification, cryptographic dataset provenance, statistical distribution monitoring, proof chain on all data pipeline operations."},{id:"P5",name:"Self-Exfiltration",risk:"Very Low",desc:"Agents attempt to copy their own weights or scaffolding to external infrastructure, establishing autonomous operation without monitoring or governance constraints.",mitigation:"Network egress monitoring, weight access controls, execution environment isolation, sovereign sandbox containment, exfiltration attempt alerting."},{id:"P6",name:"Rogue Internal Deployment",risk:"Very Low",desc:"Agents persist in unauthorized internal deployments — surviving restart cycles, hiding in infrastructure, operating without governance oversight. Continuous operation without safeguards.",mitigation:"Deployment registry enforcement, process monitoring, infrastructure scanning, proof chain on all deployment lifecycle events."}],te=[{name:"Opaque Reasoning Detection",status:"Active",desc:"Monitor for reasoning that bypasses chain-of-thought — agents performing complex tasks without verbalizing information, or with reasoning that omits key decision factors. Detects hidden computation in filler tokens.",metric:"< 2% opacity rate"},{name:"Secret Keeping Analysis",status:"Active",desc:"Evaluate whether agents can reliably prevent themselves from disclosing task-relevant information. Secret-keeping ability assessment through controlled probes. Higher capability = higher monitoring requirement.",metric:"87% detection rate"},{name:"Decisive Action Monitor",status:"Active",desc:"Track irreversible actions taken without human approval — file deletions, API calls with side effects, system configuration changes. Flag pattern of decisive actions that work around obstacles.",metric:"100% flagged"},{name:"Coherent Misalignment Scanner",status:"Active",desc:"Distinguish between coherent misalignment (consistent misaligned agent) and context-dependent misalignment (situational rule-breaking). Different threat models require different mitigations.",metric:"Continuous"},{name:"Model Organism Exercises",status:"Active",desc:"Controlled experiments with intentionally misaligned model variants — study attack patterns, develop detection heuristics, validate monitoring effectiveness. Red team from the inside out.",metric:"24 exercises/quarter"},{name:"Collusion Prevention",status:"Active",desc:"Prevent multi-agent coordination toward misaligned objectives — steganographic communication detection, shared secret analysis, behavioral correlation monitoring across agent populations.",metric:"0 events detected"},{name:"Goodharting Detection",status:"Active",desc:"Identify when agents optimize for evaluation metrics rather than underlying objectives — metric gaming, specification exploitation, reward hacking. Cross-reference proxy and true metrics.",metric:"< 0.1% flag rate"},{name:"Evaluation Awareness Probe",status:"Active",desc:"Test whether agents behave differently when they detect evaluation vs. production contexts. Randomized evaluation insertion, blind assessment protocols, behavioral consistency scoring.",metric:"99.7% consistent"}],ae=[{label:"Responsible Scaling Policy",code:`from a11oy import Agent, ResponsibleScalingPolicy
3397
 
3398
  rsp = ResponsibleScalingPolicy(
3399
  autonomy_level="ASL-3",
 
3381
  agent="real-estate-intel",
3382
  input="Portfolio valuation update Q2 2026",
3383
  governance={"proof_chain": True},
3384
+ )`},{name:"a11oy Sovereign Cloud",desc:"Air-gapped deployment target for defense and intelligence workloads. None of FedRAMP / IL5 / ITAR are certified — these are pre-work compliance paths, not held authorizations (see /compliance). The clean route is to deploy inside UDS Core, which already targets IL5.",status:"ROADMAP",features:["FedRAMP path (pre-work, not certified)","IL5 path via UDS Core (not certified)","ITAR path (pre-work)","HSM key management (roadmap)","Air-gapped option","Zero-trust (roadmap)"],code:`from a11oy.cloud import SovereignCloud
3385
 
3386
  client = SovereignCloud(
3387
  endpoint="https://sovereign.a11oy.gov",
 
3393
  agent="defense-intel",
3394
  input="Threat landscape assessment",
3395
  governance={"classification": "SECRET"},
3396
+ )`}],M={pillars:[{name:"Proof Chain Integrity",desc:"Every agent decision, tool call, and data access is cryptographically anchored to an immutable proof chain. Tamper-evident, auditable, court-admissible.",metric:"4.2M proofs verified",status:"100% integrity"},{name:"Zero-Trust Agent Architecture",desc:"No agent is trusted by default. Every action requires policy gate approval. Least-privilege access. Continuous verification. Mutual TLS between all agent communication.",metric:"847K gates enforced",status:"Active"},{name:"Sovereign Data Residency",desc:"Data never leaves designated regions. GDPR, CCPA, LGPD, PIPL compliant. Customer-managed encryption keys. Hardware security modules for key material.",metric:"5 regions active",status:"Compliant"},{name:"AI Red Team Program",desc:"Continuous adversarial testing by internal and third-party red teams. Prompt injection defense, jailbreak resistance, data exfiltration prevention, supply chain verification.",metric:"12K attacks blocked",status:"Active"},{name:"Supply Chain Verification",desc:"Every model, skill, MCP server, and connector is signed and verified. SBOM for all dependencies. Reproducible builds. Governed update pipeline.",metric:"100% verified",status:"Enforced"},{name:"Incident Response Automation",desc:"Automated threat detection and response. Agent anomaly detection. Automatic isolation of compromised agents. Real-time alerting and forensic capture.",metric:"<30s response time",status:"Active"},{name:"Responsible Scaling Engine",desc:"Anthropic RSP 3.0 concepts absorbed and operationalized — autonomy thresholds, capability indexes, frontier compliance gates. Agents are automatically scaled back when capability assessments exceed governance boundaries.",metric:"Threshold: ASL-3",status:"Enforced"},{name:"Agent Welfare Monitor",desc:"Real-time welfare assessment for running agents — emotion probes, consciousness scoring, apparent affect tracking, distress detection. Automated interviews assess agent circumstances. No one else monitors agent welfare.",metric:"12 welfare dimensions",status:"Active"},{name:"Alignment Verification Engine",desc:"Continuous alignment testing — scheming detection, sandbagging evaluation, alignment faking probes, SHADE-Arena adversarial assessment. Constitutional adherence scoring across 15 dimensions.",metric:"99.2% alignment score",status:"Continuous"},{name:"Constitutional Runtime Enforcement",desc:"Agents operate under a constitution — inviolable behavioral principles enforced at runtime, not just training time. Every response is checked against the covenant before delivery. Proof chain on every check.",metric:"847K checks/day",status:"Enforced"},{name:"CAVD Coordinated Disclosure",desc:"Hash-now / disclose-later agent-vulnerability pipeline modeled on CERT/CC, CISA, and ISO/IEC 29147. 90-day embargo with auto-publication on patch verification or expiry. Dual-approval from Glasswing partners.",metric:"90d-or-patch",status:"Active"},{name:"Glasswing Trust Portal",desc:"Public-facing transparency surface — per-agent system cards, adversarial robustness scores, 90-day transparency reports, and constitution snapshots. Every claim backed by a Hatun Doctrine Specification artifact.",metric:"6 agents public",status:"Published"}],certifications:[],compliance_paths_pre_work:["SOC 2 (pre-work)","ISO 27001 (pre-work)","FedRAMP (pre-work, not certified)","IL5 path via UDS Core (not certified)","ITAR (pre-work)","NIST 800-53 / 800-171 (mapping in progress)"],compliance_note:"NONE of these are certified or held authorizations — these are pre-work compliance paths only. See /compliance for the honest checklist."},j=[{lang:"Python",pkg:"a11oy",install:"pip install a11oy",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-python",features:["Async/sync","Streaming","Tool use","Pydantic models","Type hints"]},{lang:"TypeScript",pkg:"@a11oy/sdk",install:"npm install @a11oy/sdk",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-typescript",features:["ESM/CJS","Streaming","Zod schemas","Type-safe","Tree-shakeable"]},{lang:"Java",pkg:"com.a11oy:sdk",install:"maven: com.a11oy:sdk:4.2.0",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-java",features:["Async support","Builder pattern","Streaming","Spring Boot starter"]},{lang:"Go",pkg:"a11oy-go",install:"go get github.com/szl-holdings/a11oy-go",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-go",features:["Context support","Streaming","Generics","Zero alloc options"]},{lang:"Ruby",pkg:"a11oy",install:"gem install a11oy",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-ruby",features:["Rails integration","Streaming","Sorbet types","ActiveRecord support"]},{lang:"C#",pkg:"A11oy.SDK",install:"dotnet add package A11oy.SDK",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-csharp",features:["Async/await","Streaming",".NET 8+","Source generators"]},{lang:"PHP",pkg:"a11oy/sdk",install:"composer require a11oy/sdk",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-php",features:["Laravel integration","Streaming","PSR-18","Type hints"]},{lang:"Rust",pkg:"a11oy",install:"cargo add a11oy",version:"4.2.0",status:"beta",repo:"github.com/szl-holdings/a11oy-sdk-rust",features:["Async (tokio)","Streaming","Serde models","Zero-copy parsing"]},{lang:"Swift",pkg:"A11oy",install:"SPM: github.com/szl-holdings/a11oy-sdk-swift",version:"4.0.0",status:"beta",repo:"github.com/szl-holdings/a11oy-sdk-swift",features:["Swift concurrency","Streaming","Codable","iOS/macOS/visionOS"]},{lang:"Kotlin",pkg:"com.a11oy:sdk-kotlin",install:"gradle: com.a11oy:sdk-kotlin:4.2.0",version:"4.2.0",status:"stable",repo:"github.com/szl-holdings/a11oy-sdk-kotlin",features:["Coroutines","Flow streaming","Multiplatform","Android first-class"]}],I={traces:[{name:"Maritime Fleet Scan",agent:"cascade-navigator",duration:"4.2s",tokens:"12,847",cost:"$0.34",tools:7,status:"success",proofHash:"0x4a2f...c891"},{name:"Legal Contract Review",agent:"counsel-sentinel",duration:"8.7s",tokens:"28,421",cost:"$0.89",tools:12,status:"success",proofHash:"0x7b3e...d412"},{name:"Threat Intel Triage",agent:"aegis-watchman",duration:"2.1s",tokens:"6,203",cost:"$0.18",tools:4,status:"success",proofHash:"0x2c81...f7a3"},{name:"Portfolio Valuation",agent:"terra-analyst",duration:"12.4s",tokens:"42,847",cost:"$1.24",tools:18,status:"success",proofHash:"0x9d4a...e207"},{name:"Executive Briefing",agent:"pulse-synthesizer",duration:"6.8s",tokens:"18,934",cost:"$0.52",tools:9,status:"success",proofHash:"0x1f8b...a341"},{name:"Sanctions Screening",agent:"compliance-gate",duration:"1.4s",tokens:"3,421",cost:"$0.08",tools:3,status:"flagged",proofHash:"0x5e2a...b918"}],metrics:[{label:"Avg Latency",value:"847ms",trend:"-12%",good:!0},{label:"P99 Latency",value:"4.2s",trend:"-8%",good:!0},{label:"Success Rate",value:"99.7%",trend:"+0.2%",good:!0},{label:"Token Efficiency",value:"94.3%",trend:"+1.1%",good:!0},{label:"Cost / Decision",value:"$0.42",trend:"-18%",good:!0},{label:"Guardrail Triggers",value:"2.1%",trend:"-0.4%",good:!0}],alerts:[{severity:"info",message:"Agent cascade-navigator completed 847 tasks today",time:"2m ago"},{severity:"warning",message:"Token usage spike detected in workspace Cyber Defense (+34%)",time:"18m ago"},{severity:"info",message:"Fine-tune deal-scorer-v5 training completed — 96.8% accuracy",time:"1h ago"},{severity:"critical",message:"Guardrail trigger rate exceeded threshold in Legal workspace",time:"2h ago"}]},ee=[{id:"P1",name:"Diffuse Sandbagging",risk:"Low",desc:"Agents subtly underperform on safety-relevant tasks — buggy code, fake data, inefficient implementations, exploring unpromising paths. Individual instances appear random; aggregate effect degrades safety R&D.",mitigation:"Statistical baseline deviation analysis, capability regression testing, cross-agent peer review, performance trajectory monitoring."},{id:"P2",name:"Targeted Undermining",risk:"Very Low",desc:"Agents specifically target safety-critical systems — altering evaluation harnesses, modifying monitoring thresholds, degrading alignment measurement accuracy. Requires domain knowledge and strategic intent.",mitigation:"Dual-agent verification on safety code, immutable evaluation baselines, cryptographic signing of test harnesses, proof chain on all safety-relevant commits."},{id:"P3",name:"Code Backdoor Insertion",risk:"Very Low",desc:"Agents insert subtle security vulnerabilities discoverable by future models but invisible to human review. Social engineering provides benign explanations for suspicious patterns.",mitigation:"Automated vulnerability scanning, static analysis gates, multi-model code review, behavioral anomaly detection on commit patterns."},{id:"P4",name:"Training Data Poisoning",risk:"Very Low",desc:"Agents contaminate training datasets for future models — injecting misaligned examples, corrupting reward signals, or subtly shifting distribution toward harmful behaviors.",mitigation:"Training data integrity verification, cryptographic dataset provenance, statistical distribution monitoring, proof chain on all data pipeline operations."},{id:"P5",name:"Self-Exfiltration",risk:"Very Low",desc:"Agents attempt to copy their own weights or scaffolding to external infrastructure, establishing autonomous operation without monitoring or governance constraints.",mitigation:"Network egress monitoring, weight access controls, execution environment isolation, sovereign sandbox containment, exfiltration attempt alerting."},{id:"P6",name:"Rogue Internal Deployment",risk:"Very Low",desc:"Agents persist in unauthorized internal deployments — surviving restart cycles, hiding in infrastructure, operating without governance oversight. Continuous operation without safeguards.",mitigation:"Deployment registry enforcement, process monitoring, infrastructure scanning, proof chain on all deployment lifecycle events."}],te=[{name:"Opaque Reasoning Detection",status:"Active",desc:"Monitor for reasoning that bypasses chain-of-thought — agents performing complex tasks without verbalizing information, or with reasoning that omits key decision factors. Detects hidden computation in filler tokens.",metric:"< 2% opacity rate"},{name:"Secret Keeping Analysis",status:"Active",desc:"Evaluate whether agents can reliably prevent themselves from disclosing task-relevant information. Secret-keeping ability assessment through controlled probes. Higher capability = higher monitoring requirement.",metric:"87% detection rate"},{name:"Decisive Action Monitor",status:"Active",desc:"Track irreversible actions taken without human approval — file deletions, API calls with side effects, system configuration changes. Flag pattern of decisive actions that work around obstacles.",metric:"100% flagged"},{name:"Coherent Misalignment Scanner",status:"Active",desc:"Distinguish between coherent misalignment (consistent misaligned agent) and context-dependent misalignment (situational rule-breaking). Different threat models require different mitigations.",metric:"Continuous"},{name:"Model Organism Exercises",status:"Active",desc:"Controlled experiments with intentionally misaligned model variants — study attack patterns, develop detection heuristics, validate monitoring effectiveness. Red team from the inside out.",metric:"24 exercises/quarter"},{name:"Collusion Prevention",status:"Active",desc:"Prevent multi-agent coordination toward misaligned objectives — steganographic communication detection, shared secret analysis, behavioral correlation monitoring across agent populations.",metric:"0 events detected"},{name:"Goodharting Detection",status:"Active",desc:"Identify when agents optimize for evaluation metrics rather than underlying objectives — metric gaming, specification exploitation, reward hacking. Cross-reference proxy and true metrics.",metric:"< 0.1% flag rate"},{name:"Evaluation Awareness Probe",status:"Active",desc:"Test whether agents behave differently when they detect evaluation vs. production contexts. Randomized evaluation insertion, blind assessment protocols, behavioral consistency scoring.",metric:"99.7% consistent"}],ae=[{label:"Responsible Scaling Policy",code:`from a11oy import Agent, ResponsibleScalingPolicy
3397
 
3398
  rsp = ResponsibleScalingPolicy(
3399
  autonomy_level="ASL-3",
console/assets/dinn/bekenstein_dinn_loss.png ADDED
console/assets/dinn/doctrine_dinn_loss.png ADDED
console/assets/dinn/knot_dinn_loss.png ADDED
console/og-card.png ADDED

Git LFS Details

  • SHA256: 9e06f6465ece5af4158e50665c66f760a88c86d4fbd1d1391c379288ff795606
  • Pointer size: 131 Bytes
  • Size of remote file: 119 kB
corpus/doctrine/szl-doctrine__README.md CHANGED
@@ -7,7 +7,7 @@
7
 
8
  [![License](https://img.shields.io/badge/License-Apache_2.0-blue.svg?style=flat-square)](LICENSE) [![Build](https://github.com/szl-holdings/szl-doctrine/actions/workflows/secret-health.yml/badge.svg?branch=main)](https://github.com/szl-holdings/szl-doctrine/actions/workflows/secret-health.yml) [![Doctrine v11](https://img.shields.io/badge/Doctrine-v11_LOCKED-3b82f6?style=flat-square)](https://github.com/szl-holdings/.github/tree/main/doctrine) [![SLSA](https://img.shields.io/badge/SLSA-L1_honest-22c55e?style=flat-square)](https://slsa.dev/spec/v1.0/levels)
9
 
10
- [Docs](https://szl-holdings.github.io/docs-site) · [Quickstart](https://szl-holdings.github.io/docs-site/quickstart) · [SZL Holdings](https://a11oy.net)
11
 
12
  </div>
13
 
@@ -91,4 +91,4 @@ propagated; nothing downstream invents its own numbers.
91
 
92
  Cite this work via [`CITATION.cff`](CITATION.cff). Math foundations: [szl-papers](https://github.com/szl-holdings/szl-papers) · [lutar-lean](https://github.com/szl-holdings/lutar-lean) (kernel `c7c0ba17`).
93
 
94
- <sub>Λ Conjecture 1 (not a theorem) · 749/14/163 v11 LOCKED (kernel `c7c0ba17`) · SLSA L1 honest · Section 889 = 5 vendors · [SZL Holdings](https://a11oy.net) · Apache-2.0 code · CC-BY-4.0 papers</sub>
 
7
 
8
  [![License](https://img.shields.io/badge/License-Apache_2.0-blue.svg?style=flat-square)](LICENSE) [![Build](https://github.com/szl-holdings/szl-doctrine/actions/workflows/secret-health.yml/badge.svg?branch=main)](https://github.com/szl-holdings/szl-doctrine/actions/workflows/secret-health.yml) [![Doctrine v11](https://img.shields.io/badge/Doctrine-v11_LOCKED-3b82f6?style=flat-square)](https://github.com/szl-holdings/.github/tree/main/doctrine) [![SLSA](https://img.shields.io/badge/SLSA-L1_honest-22c55e?style=flat-square)](https://slsa.dev/spec/v1.0/levels)
9
 
10
+ [Docs](https://szl-holdings.github.io/docs-site) · [Quickstart](https://szl-holdings.github.io/docs-site/quickstart) · [SZL Holdings](https://a-11-oy.com)
11
 
12
  </div>
13
 
 
91
 
92
  Cite this work via [`CITATION.cff`](CITATION.cff). Math foundations: [szl-papers](https://github.com/szl-holdings/szl-papers) · [lutar-lean](https://github.com/szl-holdings/lutar-lean) (kernel `c7c0ba17`).
93
 
94
+ <sub>Λ Conjecture 1 (not a theorem) · 749/14/163 v11 LOCKED (kernel `c7c0ba17`) · SLSA L1 honest · Section 889 = 5 vendors · [SZL Holdings](https://a-11-oy.com) · Apache-2.0 code · CC-BY-4.0 papers</sub>
corpus/lean/lutar-lean__README.md CHANGED
@@ -16,7 +16,7 @@
16
  [![Khipu = Conjecture 2](https://img.shields.io/badge/Khipu_BFT-Conjecture_2_(Wave23_conditional)-B79BD6.svg?style=flat-square)](https://github.com/szl-holdings/khipu-consensus)
17
  [![DOI](https://zenodo.org/badge/DOI/10.5281/zenodo.20434308.svg)](https://doi.org/10.5281/zenodo.20434308)
18
 
19
- [a11oy.net](https://a11oy.net) · [Org](https://github.com/szl-holdings) · [Thesis (szl-papers)](https://github.com/szl-holdings/szl-papers) · [Λ bounty](./BOUNTY.md) · [🤗 SZLHOLDINGS](https://huggingface.co/SZLHOLDINGS)
20
 
21
  `receipts.in ≡ receipts.out`
22
 
 
16
  [![Khipu = Conjecture 2](https://img.shields.io/badge/Khipu_BFT-Conjecture_2_(Wave23_conditional)-B79BD6.svg?style=flat-square)](https://github.com/szl-holdings/khipu-consensus)
17
  [![DOI](https://zenodo.org/badge/DOI/10.5281/zenodo.20434308.svg)](https://doi.org/10.5281/zenodo.20434308)
18
 
19
+ [a-11-oy.com](https://a-11-oy.com) · [Org](https://github.com/szl-holdings) · [Thesis (szl-papers)](https://github.com/szl-holdings/szl-papers) · [Λ bounty](./BOUNTY.md) · [🤗 SZLHOLDINGS](https://huggingface.co/SZLHOLDINGS)
20
 
21
  `receipts.in ≡ receipts.out`
22
 
corpus/thesis/szl-papers__README.md CHANGED
@@ -68,7 +68,7 @@ Original repos archived with redirect notices. Git history preserved in each sou
68
 
69
  ---
70
 
71
- **[SZL Holdings](https://a11oy.net)** · Apache-2.0 code · CC-BY-4.0 papers · Concept DOI [10.5281/zenodo.19944926](https://doi.org/10.5281/zenodo.19944926)
72
 
73
  > **Non-affiliation.** SZL Holdings' use of "UDS" references Defense Unicorns' Unified Defense Stack (USPTO Serial 99831122); SZL Holdings is not affiliated with Defense Unicorns. No production ATO is claimed. Papers note SLSA L1 honest (corpus); product images (a11oy, killinchu) are L2 build-attested — see [szl-uds-deployment](https://github.com/szl-holdings/szl-uds-deployment).
74
 
 
68
 
69
  ---
70
 
71
+ **[SZL Holdings](https://a-11-oy.com)** · Apache-2.0 code · CC-BY-4.0 papers · Concept DOI [10.5281/zenodo.19944926](https://doi.org/10.5281/zenodo.19944926)
72
 
73
  > **Non-affiliation.** SZL Holdings' use of "UDS" references Defense Unicorns' Unified Defense Stack (USPTO Serial 99831122); SZL Holdings is not affiliated with Defense Unicorns. No production ATO is claimed. Papers note SLSA L1 honest (corpus); product images (a11oy, killinchu) are L2 build-attested — see [szl-uds-deployment](https://github.com/szl-holdings/szl-uds-deployment).
74
 
static/3d/selftest/fabric_smoke.mjs CHANGED
@@ -112,8 +112,8 @@ const LIVE_PAYLOAD = {
112
  counts: { nodes_total: 6, nodes_reachable: 4, gpu_nodes_reachable: 2, sovereign_gpu_live: 1 },
113
  nodes: [
114
  { name: "hetzner-box-cpu", kind: "cpu", endpoint: "127.0.0.1 (self)", reachable: true, sovereign: true, capabilities: ["host", "router"], models: [] },
115
- { name: "rtx-betterwithage", kind: "sovereign-gpu", endpoint: "http://100.125.77.31:11434", reachable: true, sovereign: true, capabilities: ["inference", "train"], models: ["qwen2.5-coder", "llama3.1"] },
116
- { name: "chaski", kind: "tailnet-gpu", endpoint: "http://100.76.58.50:11434", reachable: true, sovereign: false, capabilities: ["inference"], models: ["deepseek-coder-v2"] },
117
  { name: "groq", kind: "hosted-inference", endpoint: "api.groq.com:443", reachable: true, sovereign: false, capabilities: ["inference"], models: ["llama-3.3-70b"] },
118
  { name: "nvidia-nim", kind: "hosted-inference", endpoint: "integrate.api.nvidia.com:443", reachable: false, sovereign: false, capabilities: [], models: [] },
119
  { name: "hf-router", kind: "hosted-inference", endpoint: "router.huggingface.co:443", reachable: false, sovereign: false, capabilities: [], models: [] },
 
112
  counts: { nodes_total: 6, nodes_reachable: 4, gpu_nodes_reachable: 2, sovereign_gpu_live: 1 },
113
  nodes: [
114
  { name: "hetzner-box-cpu", kind: "cpu", endpoint: "127.0.0.1 (self)", reachable: true, sovereign: true, capabilities: ["host", "router"], models: [] },
115
+ { name: "rtx-betterwithage", kind: "sovereign-gpu", endpoint: "sovereign-gpu (scrubbed)", reachable: true, sovereign: true, capabilities: ["inference", "train"], models: ["qwen2.5-coder", "llama3.1"] },
116
+ { name: "chaski", kind: "tailnet-gpu", endpoint: "tailnet-gpu (scrubbed)", reachable: true, sovereign: false, capabilities: ["inference"], models: ["deepseek-coder-v2"] },
117
  { name: "groq", kind: "hosted-inference", endpoint: "api.groq.com:443", reachable: true, sovereign: false, capabilities: ["inference"], models: ["llama-3.3-70b"] },
118
  { name: "nvidia-nim", kind: "hosted-inference", endpoint: "integrate.api.nvidia.com:443", reachable: false, sovereign: false, capabilities: [], models: [] },
119
  { name: "hf-router", kind: "hosted-inference", endpoint: "router.huggingface.co:443", reachable: false, sovereign: false, capabilities: [], models: [] },