a11oy is the governed substrate beneath the mission: every autonomous decision is checked against authorized limits, ALLOWED or BLOCKED at the exact line it crosses, and sealed into a signed, tamper-evident receipt you can re-verify on screen. Five mission surfaces sit over a deeper catalog of 25 governed demos — 5 problems × 5 each: Cannonico (drone oversight) is REAL TODAY; the other four are honest sample / roadmap on the same proven substrate.
The same deny-by-default governed run the platform uses everywhere. Pick a scenario, watch it cross (or stay inside) an authorized parameter, then Re-verify the sealed record and Tamper test it — a single flipped byte returns verified:false.
a11oy seals every governed decision into a real DSSE envelope signed by an in-image
ECDSA-P256 key — verifiable against /cosign.pub, tamper-evident byte-for-byte. But a
green signature is not a green outcome: re-verification recomputes the hash chain independently, and the
advisory Λ trust score is a research conjecture, not a pass/fail oracle.
Watch an autonomous system make a decision and catch the exact moment it crosses an authorized limit. Every run is sealed into a signed, tamper-evident record — press Re-verify to confirm it, then Tamper test to prove a single changed byte is detected.
The signed, ready-to-ship deployment package — the same artifact deploys from cloud to a disconnected edge node with one command. Existence, digest and signature are read live from the public registry on each click, not asserted from memory.
A live readiness dashboard that tells you who is ready to deploy and who needs review. Each verdict is computed in-image from concrete readiness criteria; missing data forces a review — the system never assumes a member is ready.
Paste any trajectory or orbit data — a JSON array or plain rows — and see it placed in an operational 3D picture instantly. The system auto-detects the fields, assesses each track against real orbital-regime envelopes, and flags anomalies. No bespoke per-source integration.
The whole governed decision running on the device itself, with no connection required. The run executes fully in this container with no outbound call, the on-device model router picks a tier, and the result is signed and re-verifiable — the same container is the package that deploys to a disconnected node.
Each of the five approved problems carries five governed demos — 25 in total, loaded live from the platform and runnable right here. Each run computes a real mechanism in-image and seals a signed, re-verifiable receipt; press Tamper and one flipped byte returns verified:false. Labels are the operator's own: real today for Cannonico, roadmap (proven substrate · sample vertical) for the rest. Nothing here claims more than it is.
— loading the 25-demo catalog from the live platform —