Mode A · Software tier · Flagship
Released, repaired, or blocked. Three physically distinct devices, each separately attested to a private enclave, no single device ever sees both the AI output and the rule set.
Separation of knowledge
Device 1
Holds and vectorises the output. Never sees the library.
Device 2
Holds and vectorises your rule set. Never sees the output.
The private enclave
It binds its verdict to the exact inputs and library version it saw. Nothing else can produce a valid verdict.
Never exposed in plaintext to the AI side.
A swapped input, library, or verdict fails verification.
No data leaves the boundary for the check.
Re-vectorised and re-attested, not re-fabricated.
Dispositions
In envelope. The action proceeds.
Governed convergence pulls the output back toward compliance rather than merely refusing.
Outside the envelope, refused. Nothing proceeds.
Every verdict is bound to the named library version in a compliance token.
Grounded, not speculative
The governed-reasoning lifecycle behind Attested Semantic Compare is the engine already running pinpole in production, at scale.
Detection configurations
Residual-energy lanes asking: is this state within the approved distribution at all? Measurable now; makes no claim awaiting the experiment.
Loaded separately, gated by the experiment. Named here, not buried.
Three-machine on-prem topology.
AWS Nitro Enclaves reference build.
Control-plane tooling that compiles a validated configuration into an attested deployment.
The honest boundary
Rules 1, 2, 4, 5 and 6 within the software boundary, the three-machine separation is Rule 1 made physical. Rules 3 and 7 in full arrive in hardware. The eight rules →