Hardware-Interlock Enforcement · Triodian

Mode B · Assurance ceiling

Enforcement no software at any privilege level can remove.

A hardware automaton at the decode boundary, default-biased to blocking, physically prevents commitment of any non-accepted token, released only on a hardware root-of-trust attestation that the loaded policy is unmodified, with cryptographic per-emission proof.

Every action checked against the constraint, admitted or blocked in hardware.

Why hardware

Enforcement has to sit beneath the layer the model can influence.

When ~80% of an intrusion runs with no human in the loop, enforcement that holds has to sit beneath the layer the model can influence. This is that layer.

~80%

of a recent state-sponsored intrusion ran autonomously, before humans intervened.

0

software paths, at any privilege, that can lift this gate.

The architecture, plainly

Four blocks. A single-byte policy change fails root-of-trust.

HardwareInterlock diagram
A fixed pipeline no software can remove
01

Hardware automaton engine

Per-request parsing state, held in silicon.

02

Per-token validity bitmask

Computed in silicon, every token, every step.

03

Default-blocking gate

Biased to block; a non-accepted token cannot commit.

04

Attestation-gated emission

A single-byte policy change fails root-of-trust.

Form factors FPGA companion card PCIe/CXL co-processor SmartNIC-resident function , bounded worst-case per-token latency published as a device spec.

Two loadouts, one interlock

The same substrate. Two questions, one that needs no experiment, one that does.

Grammar loadout

The automaton's accept-set is the policy, binary, deterministic, decidable. What the FPGA MVP proves, with formal property checking of the interlock and a published bypass-test report.

Governance-score loadout

The same interlock, gated on a fused frozen-transform → residual-energy score against a risk-controlled threshold λ. Same substrate, same non-bypassability, loaded only after the Mode A validation experiment.

“The interlock does not care what decides. Prove it on the question that needs no experiment, then load the one that does.”

For sophisticated buyers

Every element is public. The integration under bounded WCET is not.

Several elements of the chain are textbook. What is not public is the specific end-to-end integration under bounded worst-case execution time, frozen whitening transform in ROM, residual-energy lane, certified threshold, hardware interlock, and root-of-trust attestation, composed to hold together.

Worked example

Bounded actuation in a safety-critical control setting, with a privileged software adversary squarely in scope. The gate holds because it is not software the adversary can reach.

The honest boundary

  • The chain is an architecture, not a claim that any governance-score signal tracks compliance. Only Validating lanes loaded onto the interlock await the experiment, and this page names which.
  • The grammar loadout enforces form, not meaning.

At this rung the full eight are in reach, Rules 1, 3 and 7 are what the hardware substrate adds. Trust relocated onto the silicon and its attestation chain, not abolished. The eight rules →

Register as an anchor-licensee candidate.

Existing software-tier customers are pre-qualified upgraders, the upgrade changes the enforcement substrate, not the promise.

Register interest →