Portable Proof Verifier
JavaScript / Python / Go independently reconstruct the declared semantic projection.
Explore →SITE 65 · NON-AMPLIFYING REALITY KERNEL
Site 64 made Reality Commit non-bearer and single-use. Site 65 makes derived consequence authority monotonic: it may narrow executor, effect, resource, time, use and delegation scope, but it may never widen them or change the governing outcome, semantics, graph or policy.
Fourteen systemic depth mechanisms
Each mechanism strengthens the shared parent substrate instead of creating another constitutional kernel.
JavaScript / Python / Go independently reconstruct the declared semantic projection.
Explore →Key, authority, runtime, transparency, calibration and epoch changes can REOPEN dependent outcomes.
Explore →Multiple independently rooted appraisal results bind to the same obligation, graph and evidence root.
Explore →Context resolves externally accepted authority paths and refuses ambiguous routes.
Explore →Physical measurements crossing a decision boundary stay INDETERMINATE.
Explore →3 downstream outcomes in the current reference dependency chain are identified from one foundational trigger.
Explore →Mutation sequences are searched compositionally rather than only enumerated one at a time.
Explore →12 company-specific primitives share one parent Reality substrate.
Explore →12 machine-readable semantic libraries specialize the shared kernel without forking it.
Explore →8 cross-domain profiles compose multiple vertical obligations into higher-order outcomes.
Explore →Signed, expiring, independently rooted resolver views detect stale state and forks instead of silently selecting one.
Explore →Consequential unresolved obligations are prioritized without changing their truth state.
Explore →Protocol evolution cannot silently change the semantic obligation.
Explore →Institutions can federate signed authority commitments without exposing raw private graph nodes.
Explore →Constitutional boundary
Portable verification does not mean a proof-assistant theorem has been completed, and a seller-authored authority route does not establish jurisdictional acceptance.
Site 62 · verified fabric
These mechanisms shrink the trusted surface and make cross-domain conclusions more independently checkable rather than adding another vertical brand.
Proof objects compose only when child outcome bindings remain valid.
Explore →Hash-chained trust events plus Merkle inclusion proofs make trust changes auditable.
Explore →Authority assertions and governing acceptance are separate objects; self-promotion fails.
Explore →State truth cannot be upgraded to causal attribution without stronger evidence.
Explore →Physical uncertainty propagates across composed measurements before threshold decisions.
Explore →Immutable dependency snapshots carry portable REOPEN witnesses.
Explore →Engineering depth can increase defensibility, but monetary value still requires defensible economic evidence.
Explore →Site 63 · trusted microkernel
A downstream system receives a portable Reality Capsule rather than a raw success boolean. Rollback, expiry, open assumptions, missing proof bindings or REOPEN deny the effect.
Binds semantic hash, authority graph, evidence root, execution attestation, runtime measurement, proof, assumptions and lineage.
Explore →A deliberately small verification contract separated from the rest of the Finality application surface.
Explore →Typed payment/title/collateral/insurance/capex/deployment/robotic effects consume a current valid FINAL capsule or fail closed.
Explore →A Go standard-library verifier is compiled to WASI/WebAssembly as a reference independent execution target.
Explore →Site 64 · consequence capability runtime
A capability is issuer-signed and bound to the presenter key, executor, effect request, capsule, semantic obligation, authority graph, policy, nonce and expiry. A deterministic Reality VM then evaluates the narrow effect policy; an append-only effect ledger detects double consumption.
Proof-of-possession-style consequence credential bound to one exact Reality state and one downstream effect.
Explore →A tiny deterministic no-ambient-I/O policy machine for effect gating.
Explore →Hash-chained executor receipts make double consumption and rollback observable.
Explore →Bypass resistance exists only when an external executor is configured to reject effects without a valid capability.
Explore →Site 65 · non-amplifying kernel
The exact outcome/capsule/semantic/graph/policy identity is immutable across delegation. Executor set, effect set, resource ceilings, validity window, use count and delegation depth can only narrow. The separately hash-addressed TCB lets an independent reviewer focus on the code that actually gates effects.
Derived authority is rejected if any dimension becomes broader than the parent.
Explore →512/512 declared effect-state combinations pass with zero violations.
Explore →6 trusted files / 206 nonblank noncomment lines in the declared source TCB.
Explore →JavaScript and independent Go attenuation logic agree; a WASI artifact is shipped for portable checking.
Explore →