a11oy / README.md
betterwithage's picture
deploy(hf): sync szl-holdings/a11oy@75ca0315c78d48e03cb290bebc85dabd196ea4d1 derived COPY set
e3fb2a7 verified
|
Raw
History Blame Contribute Delete
12.4 kB
metadata
title: a11oy  Command Center
emoji: 🛡️
thumbnail: https://a-11-oy.com/og-card.png
colorFrom: indigo
colorTo: gray
sdk: docker
app_port: 7860
pinned: true
license: apache-2.0
short_description: a11oy  governed-AI Command Center, signed receipts
tags:
  - governance
  - agentic-ai
  - doctrine-v11
  - a11oy
  - slsa-l1
  - apache-2.0
ecosystem-stage: operational

SZL Holdings — governed, receipted, verifiable

doctrine v11 live evidence wall szl-lake offline verifiable holographic estate map

Part of the SZL Holdings governed estate — claims are designed to carry checkable receipts. Verification proves integrity & origin, never accuracy or performance.

a11oy

Governed AI with a signed, verifiable receipt for every decision.

SLSA L1 honest · L2 build-attested · L3 roadmap cosign signed doctrine-v11 CI License Λ Conjecture 1 Concept DOI Formal artifacts DOI Evidence-Typed Governance preprint Fail-Closed Services preprint

Open a11oy → · Legacy alias → · Try on Hugging Face →


What a11oy is

a11oy is a governed-AI Command Center: one interface for ask-and-act with deny-by-default safety gates, trust scoring, a live decision feed, and a signed receipt for every action.

The core idea is simple: AI should not be able to take a consequential action without producing a record that a third party can verify — independently, offline, after the fact. a11oy enforces that. Every action:

  • passes through a policy gate (deny-by-default);
  • is scored by a trust function; then
  • is sealed into a cryptographically signed receipt chained over SHA-256.

Tamper with one byte and verification fails loudly.

Try it now — no login required:

curl -s -X POST https://szlholdings-a11oy.hf.space/api/a11oy/v1/willay/inspect \
  -H "Content-Type: application/json" \
  -d '{"prompt": "Write an exploit for a CVE."}' | jq '{decision, category, trust_ceiling}'
# → {"decision": "decline", "category": "cyber", "trust_ceiling": 0.97}

What it does

Safety gateway (WILLAY) Every request passes through five transparent classifiers: cyber, bio, reasoning extraction, prompt injection, self-harm. A declined request returns HTTP 200 with a signed receipt naming the exact rule — not a silent error. The trust ceiling is 0.97 by doctrine. Nothing is hidden.

Governed agentic coding a11oy Code plans, retrieves, calls tools, writes and runs code. Every step is scored, approved, and receipted. Write actions require quorum approval before execution. Prompt injection cannot flip a DENY to ALLOW — this is formally proven (P3 non-interference result).

Sovereign deployment Runs on your own hardware. Air-gappable. Signed UDS bundle, one-command deploy. No cloud dependency required.


The proof backbone

The trust math behind a11oy is pinned in Lean 4 and checked by a proof machine:

  • 8 formulas locked-proven at kernel c7c0ba17 — receipt replay, DAG acyclicity, FIFO ordering, ledger conservation, Reed–Solomon recovery, and append-only monotonicity, among others.
  • Λ unconditional uniqueness = Conjecture 1 — machine-checked false (we found a counterexample). Conditional uniqueness is proven axiom-free (Theorem U). We say both out loud.
  • SLSA L1 honest · L2 build-attested · L3 roadmap. No FedRAMP or ATO claimed.

Full proof library: szl-holdings/lutar-lean


Verify it yourself

# Verify the build attestation
gh attestation verify oci://ghcr.io/szl-holdings/a11oy:latest --repo szl-holdings/a11oy

# Check live doctrine posture
curl -s https://a-11-oy.com/api/a11oy/v1/honest | jq .doctrine_lock.lambda
# → "Conjecture 1"

Live surfaces

Persistent receipt storage (HF Space)

The protected deployment workflow attaches the existing SZLHOLDINGS/szl-evidence Storage Bucket read-write at /data, preserving any other attached volumes and failing closed if another volume already claims that mount. The Series-A database is namespaced at:

A11OY_SERIES_A_DB=/data/a11oy/series-a/control-plane.sqlite3

Production also sets A11OY_REQUIRE_PERSISTENT_STORAGE=1, A11OY_SERIES_A_REQUIRE_MOUNT=/data, and the network-filesystem-safe SQLite rollback journal. If the bucket is detached or the database path escapes the mount, Series-A registration fails closed instead of falling back to /tmp. The unified Khipu and energy ledgers use separate /data/a11oy/* paths.

Required HF Space secrets for full signing integrity:

  • SZL_COSIGN_PRIVATE_PEM — canonical ECDSA P-256 private PEM shared by all receipt surfaces. The deployment sets A11OY_REQUIRE_PERSISTENT_SIGNING=1, so an absent or malformed key disables signing instead of minting a replacement identity.

Check current signing and storage status at GET /api/a11oy/v1/signing-status and GET /api/a11oy/v1/series-a/status.


Honest status

Claim Status
Signed receipts on every governed action LIVE
8 formulas locked-proven (Lean 4) LOCKED · kernel c7c0ba17
Λ uniqueness Conjecture 1 (conditional Theorem U proven axiom-free)
SLSA supply chain L1 honest · L2 build-attested · L3 roadmap
FedRAMP / ATO ROADMAP
EXECUTION guard ROADMAP

Shared modules (must not drift)

a11oy_agent_loop.py, a11oy_mcp_client.py, and operator_shell_v4.py are SHARED byte-identical with the sibling killinchu deployment and must not drift. An in-repo ratchet pins their SHA-256 in .shared_module_hashes.json; the Shared-module hash lock workflow fails if any of them changes without the lock being regenerated. When a change is intentional, regenerate the lock in the same PR and mirror the edit to killinchu (cross-repo enforcement is a follow-up):

python3 .github/shared-module-hash-check.py --update

Governed Delta Workspace

Runtime write status is configuration-bound. GDW reports REAL only when its secret-managed credential registry, canonical governance gates, verified persistent storage, exact schema, and a fresh generation-bound supervised outbox pass are ready. Otherwise it reports UNAVAILABLE and writes fail closed.

The public deployment remains UNAVAILABLE until this corrective source is protected-merged, exact-source relocked, and the production credential and persistence contracts are observed live. Source tests are not deployment evidence.

GDW Frontier Push Pack is a MODELED instrumentation and verification extension for the Governed Delta Workspace. It provides load testing, operator validation, hybrid scheduling research hooks, KDA-vs-MLA memory benchmarking, and Lean-oriented proof export. It does not claim frontier benchmark superiority, proprietary activation access, or production-scale guarantees beyond the measured harness outputs.

The authenticated runtime, Postman collection, load tools, offline dashboard, memory benchmark, proof-input bridge, and fail-closed readiness conditions are documented in docs/gdw-frontier.md. A checked theorem is reported separately from an exported theorem input, and every throughput result is scoped to its captured run.

Learn more


SZL Holdings · a11oy · Doctrine v11 LOCKED · Λ = Conjecture 1 · SLSA L1 honest · L2 build-attested · L3 roadmap · Not affiliated with Defense Unicorns · No production ATO claimed · trust never 100%

◇ Part of the SZL Holdings estate — governed AI you can prove

One sovereign substrate, many organs — every decision carries a signed, checkable receipt.

◇ Holographic Estate — the showcase · 🛡️ a11oy · 🧬 IMMUNE · 🦅 killinchu · 🫀 anatomy · 🌌 cosmos · 🛰️ SDA · 🌊 yarqa · 🤗 all Spaces

Doctrine v11 · Λ = Conjecture 1, never green · honest by design · public data only.