szl-holdings/immune

IMMUNE — fail-closed kernel. SENTRA admits, YAWAR seals hashes. NEXUS Lorenz OP is MEASURED software simulation. Product tab a-11-oy.com/immune. Spaces: SZLHOLDINGS/immune + SZLHOLDINGS/immune-lattice.

0

stars

133

commits

TypeScript

primary language

Sep 11, 2026

updated

a-11-oy.com/immune
ai-safety
doctrine-v11
governed-ai
huggingface
lorenz
nexus
provenance
sentra
sha256
spaces
szl-holdings
verifiable-ai
yawar
Browse cluster: Policy-as-Code and Kubernetes Governance

README

SZL Holdings · Doctrine v11 · Λ = Conjecture 1 (advisory, never "green"/theorem) · canonical a-11-oy.com

IMMUNE — Verifiable AI You Can't Fake

org: szl-holdings doctrine

Control before action. Evidence after.

Part of the szl-holdings estate · Product: a-11-oy.com · Proof: a11oy.net

License: Apache-2.0

Stage: REACHABLE · WRITE-READY · MEASURED software simulation. IMMUNE is the governed AI safety layer: every accepted agent action is sealed into an append-only SHA-256 hash-linked receipt chain. Status is CONNECTING, REACHABLE, or UNAVAILABLE — never a fabricated LIVE analog or PASS theorem. Λ = Conjecture 1 OPEN.

Lorenz OP (measured, sealed)

Default NEXUS showcase on both Spaces. Software simulation only.

FieldValue
program / modelorenz / OP
coefficientsσ 10 · ρ 27.9 · β 2.67
steps / dt / drive / chaos / seed320 / 0.01 / 0.7 / 0.45 / 0.2
initialx 0.182 · y −0.046 · z 23.2 · t 0
finalx −7.707920173353 · y −10.567955419679 · z 21.305498529338 · t 3.2
inputHashc5fcc5029392a5e4f7cd65a655d5379cd65d8f915b2ee96a1db5d44e35ea2358
outputHash4071a2f2faca744907747cb2cc82a9d841e125fa287240505f9f9a8454a399ac
invariantsHOLD
energyUNAVAILABLE
uniquenessConjecture 1 OPEN
truthMEASURED_SOFTWARE_SIMULATION
Channel A/B parityhashes match

POST /api/immune/nexus/run returns HTTP 201 with governed.pass=true when SENTRA admits the compact YAWAR payload (hashes, not floats).

Consolidation (do not delete either Space)

There are two Hugging Face Spaces. They are one product, two channels — not two immunes.

SurfaceWhat it isKeep?
SZLHOLDINGS/immuneChannel A. TypeScript HUD + kernel. Already LIVE / WRITE-READY. Estate tiles, a11oy, killinchu handoff.Keep. Canonical public HUD.
SZLHOLDINGS/immune-latticeChannel B. This repo's python/ kernel (stdlib HTTP, port 7860).Keep the URL. Same receipts, same SENTRA/YAWAR/HUKLLA.

This Grok Build COP (src/lib/immune TypeScript ↔ python/immune Python) is the kernel both channels must follow. Lattice is not a second product.

Python kernel

python/
  immune/          canonical · sentra · huklla · persist · runtime · mesh · second_brain · frontier · organs · server
  tests/           unittest — boot WRITE-READY, cycle seal, DEADMAN, 575-handle brain, silhouette, MESH 3-of-4
  space/           HF hologram HUD
pip install -r python/requirements.txt
IMMUNE_DATA_DIR=./data/immune PYTHONPATH=python python3 -m immune.server
PYTHONPATH=python python3 -m unittest discover -s python/tests -v

What it demonstrates

IMMUNE sits between an AI agent's intent and its execution and proves, cryptographically, that the governance actually happened:

LayerCodenameWhat it does
Admission gateSENTRA / GATEInspects every intent for forbidden patterns (token exfiltration, shell escapes) and required fields. No fabricated green lights.
Receipt chainYAWARAppend-only SHA-256 ledger — each accepted action is hashed over canonical bytes and linked to the previous entry (prevHash → hash). Tamper any entry and re-verification breaks at that seq.
TripwiresHUKLLA10 watchers aligned to the OWASP LLM Top 10 and MITRE ATLAS. A violation flips the system into DEADMAN (kill-switch) mode.
Threat intelLive public feeds (Sigstore Rekor transparency log, NVD CVEs, GitHub/HF ecosystem) labelled LIVE / REFERENCE / UNAVAILABLE per source.

The receipt chain is the same principle public transparency logs use, applied to every AI-agent action.

Lattice COP (RANGE / GHOST / WRAITH / ECHO / MESH / GRAPH)

Additive command surface on the live Space. Palantir object model, Anduril effector tasking, CIA-style OSINT attribution — independently implemented under Doctrine v11.

TabWhat it doesHonesty bound
RANGEWhite-hat counter-ops (HUNT ISOLATE PATCH INTERDICT DECEIVE STRIKE) against simulated adversary infrastructure. Sweep inbound RANGE in one governed pass.STRIKE is RANGE-only. Live CISA/KEV objects accept isolate / hunt / patch. No packets at the public internet.
GHOSTRANGE hunter. Kill-chain against simulated C2. AUTHORIZE is a one-shot SENTRA-admit then autonomous RANGE chain. Operator command hack people is refused by SENTRA (no.hack.persons) and the refusal is logged.Civilian, inbox, and identity targeting is fail-closed. Collapse RANGE personas only.
WRAITHFirst-person infiltration of RANGE C2. Exploit nodes, plant honey tokens the persona eats, extract TTP. Attempting to hack people inverts the hunt: the intent becomes evidence.RANGE personas only. Handler nodes are labeled RANGE PERSONA, never people. No packets.
ECHODeception theater. The RANGE persona is shown a fabricated success (BELIEF). YAWAR holds the ground truth (honey, tarpit, receipts they do not have).Theater is RANGE. Nothing leaves the range. No civilian targeting.
MESHFour-organ fusion: IMMUNE, a11oy, killinchu, Khipu-1.5B. 3-of-4 BFT silhouette.Quorum is MODELED until a live BFT observation is wired.
GRAPHTyped object graph: campaigns, organs, receipts, CVEs, named relations.Nothing is a blended green blob.

Ops go through POST /api/immune/cycle (SENTRA → optional YAWAR receipt → HUKLLA). The public Hugging Face Space boots a labeled demo operator (IMMUNE_DEMO_OPERATOR=1 in the demo image): process-local Ed25519 signs genesis SET_MODE PASS and refreshes evidence so /readyz is write_ready: true. The demo keypair is persisted under IMMUNE_DATA_DIR/demo-operator.json so a process restart reuses the same trust root and receipt chain. That key is not an ATO. Production deployments omit the flag, require IMMUNE_ACTION_PUBLIC_KEY, and stay fail-closed READ_ONLY until a matching signed envelope is applied. Home remains the sole useGetImmuneState() authority query; ThreeScene and the controls scroll region are unchanged.

API

EndpointWhat
GET /readyzExact source/build/runtime hash binding plus ledger integrity; reports runtime/read readiness separately from signed-authority/write readiness
GET /api/immune/stateAuthoritative VERIFIED / FAILED / UNAVAILABLE / STALE state, signed-action receipt head, mode, tripwire, and YAWAR chain head
POST /api/immune/stateVerify and atomically apply an immune.action.v1 Ed25519 envelope; unsigned controls are rejected
POST /api/immune/cycleRun one governed cycle: SENTRA inspect → (if accepted) append receipt → HUKLLA evaluate
POST /api/immune/resetApply a signed RESET envelope through the same authority path
GET /api/immune/ledger/latestLast 25 SHA-256 receipts
GET /api/immune/ledger/verifyRecompute the whole chain from disk; ok: true on a clean chain
GET /api/immune/evidence/latestLast 25 HUKLLA firing records
GET /api/immune/intel/{frameworks,transparency,incidents,leaders,pulse}Live/curated threat intel
GET /api/immune/agent/frontierShadow-only Decision Genome capability and truth boundary
POST /api/immune/agent/frontier/evaluateValidate one evidence observation and return a non-executable MODELED recommendation

Signed advisory authority

Privileged advisory controls are disabled unless IMMUNE_ACTION_PUBLIC_KEY is canonical base64 for the trusted raw 32-byte Ed25519 public key. Clients submit a strict, short-lived immune.action.v1 envelope with a unique requestId; the signature covers the canonical envelope without its signature field.

Accepted actions and resulting state are committed together to data/immune/authority.sqlite in WAL/FULL mode. Receipts are append-only, request IDs remain single-use across restarts, and a missing trust root, read failure, stale receipt, or chain mismatch can never render green. The public UI holds no operator private key unless IMMUNE_DEMO_OPERATOR=1 or IMMUNE_ACTION_PRIVATE_KEY is set on the server. With those flags the process signs genesis SET_MODE PASS and auto-refreshes so evidence stays VERIFIED. The demo operator is labeled authority.demoOperator and is not a production ATO. Without them the UI accepts an already-signed envelope and is otherwise read-only. IMMUNE_EVIDENCE_MAX_AGE_MS may override the default 15-minute freshness window; stale state remains observable but cannot authorize a governed cycle.

/readyz remains explicit while that trust root is absent: verified immutable runtime bytes and a clean receipt ledger may be read_ready: true, but the contract stays status: READ_ONLY, ready: false, authority_ready: false, and write_ready: false with blocker ACTION_TRUST_ROOT_UNCONFIGURED. The public demo image sets IMMUNE_DEMO_OPERATOR=1 so the live Space is status: READY / write_ready: true after genesis.

The frontier evaluator consumes the shared @szl-holdings/contracts/decision-genome schema from Platform. It does not define a second contract, authorize an action, or claim measured detection performance. Missing or stale provenance, future-dated evidence, and insufficient calibration fail closed to review or withholding. The receipt-writing evaluator shares the agent abuse budget (three accepted requests per IP per minute and 300 accepted requests per UTC day) and returns HTTP 409 when the governed cycle does not seal the recommendation.

Repository layout

frontend/            React + Vite + Tailwind SPA ("cyber-HUD" UI, three.js + framer-motion)
  src/               App entry, Home page, panels (Controls, Audit, Intel, Pulse, Leaders), 3D scene
  deploy/            Dockerfile + build-standalone.sh + deploy README (assembles the HF Space image)
server/              Minimal standalone Express app for the demo
  immune-standalone.ts   Mounts ONLY /api/immune + serves the built SPA (no DB/auth/Bingle/Mulé)
  routes/immune/         canonical · sentra · huklla · ledger · state · intel · index
data/immune/         The REAL seeded receipt/evidence chain (ledger.jsonl, huklla_evidence.jsonl)
LEDGER_FIELD_KEYS.md Frozen ledger field-key decision (why `sentra` stays an internal hash-input key)

Build & deploy (the live Hugging Face Space)

After pnpm install --frozen-lockfile, run pnpm run build. The historical frontend/deploy/build-standalone.sh command delegates to the same cross-platform Node builder. It:

  1. Builds the Vite frontend at site root (BASE_PATH=/).
  2. Bundles server/immune-standalone.ts (all deps inlined) into a single dist/immune-server.js via esbuild.
  3. Copies the built SPA to dist/public/ and seeds the real chain into dist/data/immune/.

frontend/deploy/Dockerfile (Node 24 Alpine, non-root UID 1000, port 7860) copies that dist/ and runs node immune-server.js. See frontend/deploy/README.md for the exact commands.

Provenance note. This repository is now independently installable, typecheckable, buildable, and smoke-testable. The deploy workflow always rebuilds from the exact merged GitHub revision, replaces the Space runtime whitelist, and verifies /.well-known/szl-source.json plus the live ledger before it reports success. Shared Decision Genome concepts retain their canonical Platform origin; the Apache-2.0 schema is mirrored locally so the runtime no longer depends on a private workspace link. /readyz binds the exact source and build revisions to the deployment-manifest digest, canonical artifact-set digest, server/UI artifact hashes, and current ledger audit.


SZL Holdings · Doctrine v11 · honest by design · Apache-2.0


Explore the SZL estate: a11oy console · LLM Router · Receipt format spec · Lean proofs · Docs · 🤗 SZLHOLDINGS

Contributors

dependabot[bot]

15 commits

Carlota-1

7 commits

szl-holdings/immune

IMMUNE — fail-closed kernel. SENTRA admits, YAWAR seals hashes. NEXUS Lorenz OP is MEASURED software simulation. Product tab a-11-oy.com/immune. Spaces: SZLHOLDINGS/immune + SZLHOLDINGS/immune-lattice.

0

stars

133

commits

TypeScript

primary language

Sep 11, 2026

updated

a-11-oy.com/immune
ai-safety
doctrine-v11
governed-ai
huggingface
lorenz
nexus
provenance
sentra
sha256
spaces
szl-holdings
verifiable-ai
yawar
Browse cluster: Policy-as-Code and Kubernetes Governance

README

SZL Holdings · Doctrine v11 · Λ = Conjecture 1 (advisory, never "green"/theorem) · canonical a-11-oy.com

IMMUNE — Verifiable AI You Can't Fake

org: szl-holdings doctrine

Control before action. Evidence after.

Part of the szl-holdings estate · Product: a-11-oy.com · Proof: a11oy.net

License: Apache-2.0

Stage: REACHABLE · WRITE-READY · MEASURED software simulation. IMMUNE is the governed AI safety layer: every accepted agent action is sealed into an append-only SHA-256 hash-linked receipt chain. Status is CONNECTING, REACHABLE, or UNAVAILABLE — never a fabricated LIVE analog or PASS theorem. Λ = Conjecture 1 OPEN.

Lorenz OP (measured, sealed)

Default NEXUS showcase on both Spaces. Software simulation only.

FieldValue
program / modelorenz / OP
coefficientsσ 10 · ρ 27.9 · β 2.67
steps / dt / drive / chaos / seed320 / 0.01 / 0.7 / 0.45 / 0.2
initialx 0.182 · y −0.046 · z 23.2 · t 0
finalx −7.707920173353 · y −10.567955419679 · z 21.305498529338 · t 3.2
inputHashc5fcc5029392a5e4f7cd65a655d5379cd65d8f915b2ee96a1db5d44e35ea2358
outputHash4071a2f2faca744907747cb2cc82a9d841e125fa287240505f9f9a8454a399ac
invariantsHOLD
energyUNAVAILABLE
uniquenessConjecture 1 OPEN
truthMEASURED_SOFTWARE_SIMULATION
Channel A/B parityhashes match

POST /api/immune/nexus/run returns HTTP 201 with governed.pass=true when SENTRA admits the compact YAWAR payload (hashes, not floats).

Consolidation (do not delete either Space)

There are two Hugging Face Spaces. They are one product, two channels — not two immunes.

SurfaceWhat it isKeep?
SZLHOLDINGS/immuneChannel A. TypeScript HUD + kernel. Already LIVE / WRITE-READY. Estate tiles, a11oy, killinchu handoff.Keep. Canonical public HUD.
SZLHOLDINGS/immune-latticeChannel B. This repo's python/ kernel (stdlib HTTP, port 7860).Keep the URL. Same receipts, same SENTRA/YAWAR/HUKLLA.

This Grok Build COP (src/lib/immune TypeScript ↔ python/immune Python) is the kernel both channels must follow. Lattice is not a second product.

Python kernel

python/
  immune/          canonical · sentra · huklla · persist · runtime · mesh · second_brain · frontier · organs · server
  tests/           unittest — boot WRITE-READY, cycle seal, DEADMAN, 575-handle brain, silhouette, MESH 3-of-4
  space/           HF hologram HUD
pip install -r python/requirements.txt
IMMUNE_DATA_DIR=./data/immune PYTHONPATH=python python3 -m immune.server
PYTHONPATH=python python3 -m unittest discover -s python/tests -v

What it demonstrates

IMMUNE sits between an AI agent's intent and its execution and proves, cryptographically, that the governance actually happened:

LayerCodenameWhat it does
Admission gateSENTRA / GATEInspects every intent for forbidden patterns (token exfiltration, shell escapes) and required fields. No fabricated green lights.
Receipt chainYAWARAppend-only SHA-256 ledger — each accepted action is hashed over canonical bytes and linked to the previous entry (prevHash → hash). Tamper any entry and re-verification breaks at that seq.
TripwiresHUKLLA10 watchers aligned to the OWASP LLM Top 10 and MITRE ATLAS. A violation flips the system into DEADMAN (kill-switch) mode.
Threat intelLive public feeds (Sigstore Rekor transparency log, NVD CVEs, GitHub/HF ecosystem) labelled LIVE / REFERENCE / UNAVAILABLE per source.

The receipt chain is the same principle public transparency logs use, applied to every AI-agent action.

Lattice COP (RANGE / GHOST / WRAITH / ECHO / MESH / GRAPH)

Additive command surface on the live Space. Palantir object model, Anduril effector tasking, CIA-style OSINT attribution — independently implemented under Doctrine v11.

TabWhat it doesHonesty bound
RANGEWhite-hat counter-ops (HUNT ISOLATE PATCH INTERDICT DECEIVE STRIKE) against simulated adversary infrastructure. Sweep inbound RANGE in one governed pass.STRIKE is RANGE-only. Live CISA/KEV objects accept isolate / hunt / patch. No packets at the public internet.
GHOSTRANGE hunter. Kill-chain against simulated C2. AUTHORIZE is a one-shot SENTRA-admit then autonomous RANGE chain. Operator command hack people is refused by SENTRA (no.hack.persons) and the refusal is logged.Civilian, inbox, and identity targeting is fail-closed. Collapse RANGE personas only.
WRAITHFirst-person infiltration of RANGE C2. Exploit nodes, plant honey tokens the persona eats, extract TTP. Attempting to hack people inverts the hunt: the intent becomes evidence.RANGE personas only. Handler nodes are labeled RANGE PERSONA, never people. No packets.
ECHODeception theater. The RANGE persona is shown a fabricated success (BELIEF). YAWAR holds the ground truth (honey, tarpit, receipts they do not have).Theater is RANGE. Nothing leaves the range. No civilian targeting.
MESHFour-organ fusion: IMMUNE, a11oy, killinchu, Khipu-1.5B. 3-of-4 BFT silhouette.Quorum is MODELED until a live BFT observation is wired.
GRAPHTyped object graph: campaigns, organs, receipts, CVEs, named relations.Nothing is a blended green blob.

Ops go through POST /api/immune/cycle (SENTRA → optional YAWAR receipt → HUKLLA). The public Hugging Face Space boots a labeled demo operator (IMMUNE_DEMO_OPERATOR=1 in the demo image): process-local Ed25519 signs genesis SET_MODE PASS and refreshes evidence so /readyz is write_ready: true. The demo keypair is persisted under IMMUNE_DATA_DIR/demo-operator.json so a process restart reuses the same trust root and receipt chain. That key is not an ATO. Production deployments omit the flag, require IMMUNE_ACTION_PUBLIC_KEY, and stay fail-closed READ_ONLY until a matching signed envelope is applied. Home remains the sole useGetImmuneState() authority query; ThreeScene and the controls scroll region are unchanged.

API

EndpointWhat
GET /readyzExact source/build/runtime hash binding plus ledger integrity; reports runtime/read readiness separately from signed-authority/write readiness
GET /api/immune/stateAuthoritative VERIFIED / FAILED / UNAVAILABLE / STALE state, signed-action receipt head, mode, tripwire, and YAWAR chain head
POST /api/immune/stateVerify and atomically apply an immune.action.v1 Ed25519 envelope; unsigned controls are rejected
POST /api/immune/cycleRun one governed cycle: SENTRA inspect → (if accepted) append receipt → HUKLLA evaluate
POST /api/immune/resetApply a signed RESET envelope through the same authority path
GET /api/immune/ledger/latestLast 25 SHA-256 receipts
GET /api/immune/ledger/verifyRecompute the whole chain from disk; ok: true on a clean chain
GET /api/immune/evidence/latestLast 25 HUKLLA firing records
GET /api/immune/intel/{frameworks,transparency,incidents,leaders,pulse}Live/curated threat intel
GET /api/immune/agent/frontierShadow-only Decision Genome capability and truth boundary
POST /api/immune/agent/frontier/evaluateValidate one evidence observation and return a non-executable MODELED recommendation

Signed advisory authority

Privileged advisory controls are disabled unless IMMUNE_ACTION_PUBLIC_KEY is canonical base64 for the trusted raw 32-byte Ed25519 public key. Clients submit a strict, short-lived immune.action.v1 envelope with a unique requestId; the signature covers the canonical envelope without its signature field.

Accepted actions and resulting state are committed together to data/immune/authority.sqlite in WAL/FULL mode. Receipts are append-only, request IDs remain single-use across restarts, and a missing trust root, read failure, stale receipt, or chain mismatch can never render green. The public UI holds no operator private key unless IMMUNE_DEMO_OPERATOR=1 or IMMUNE_ACTION_PRIVATE_KEY is set on the server. With those flags the process signs genesis SET_MODE PASS and auto-refreshes so evidence stays VERIFIED. The demo operator is labeled authority.demoOperator and is not a production ATO. Without them the UI accepts an already-signed envelope and is otherwise read-only. IMMUNE_EVIDENCE_MAX_AGE_MS may override the default 15-minute freshness window; stale state remains observable but cannot authorize a governed cycle.

/readyz remains explicit while that trust root is absent: verified immutable runtime bytes and a clean receipt ledger may be read_ready: true, but the contract stays status: READ_ONLY, ready: false, authority_ready: false, and write_ready: false with blocker ACTION_TRUST_ROOT_UNCONFIGURED. The public demo image sets IMMUNE_DEMO_OPERATOR=1 so the live Space is status: READY / write_ready: true after genesis.

The frontier evaluator consumes the shared @szl-holdings/contracts/decision-genome schema from Platform. It does not define a second contract, authorize an action, or claim measured detection performance. Missing or stale provenance, future-dated evidence, and insufficient calibration fail closed to review or withholding. The receipt-writing evaluator shares the agent abuse budget (three accepted requests per IP per minute and 300 accepted requests per UTC day) and returns HTTP 409 when the governed cycle does not seal the recommendation.

Repository layout

frontend/            React + Vite + Tailwind SPA ("cyber-HUD" UI, three.js + framer-motion)
  src/               App entry, Home page, panels (Controls, Audit, Intel, Pulse, Leaders), 3D scene
  deploy/            Dockerfile + build-standalone.sh + deploy README (assembles the HF Space image)
server/              Minimal standalone Express app for the demo
  immune-standalone.ts   Mounts ONLY /api/immune + serves the built SPA (no DB/auth/Bingle/Mulé)
  routes/immune/         canonical · sentra · huklla · ledger · state · intel · index
data/immune/         The REAL seeded receipt/evidence chain (ledger.jsonl, huklla_evidence.jsonl)
LEDGER_FIELD_KEYS.md Frozen ledger field-key decision (why `sentra` stays an internal hash-input key)

Build & deploy (the live Hugging Face Space)

After pnpm install --frozen-lockfile, run pnpm run build. The historical frontend/deploy/build-standalone.sh command delegates to the same cross-platform Node builder. It:

  1. Builds the Vite frontend at site root (BASE_PATH=/).
  2. Bundles server/immune-standalone.ts (all deps inlined) into a single dist/immune-server.js via esbuild.
  3. Copies the built SPA to dist/public/ and seeds the real chain into dist/data/immune/.

frontend/deploy/Dockerfile (Node 24 Alpine, non-root UID 1000, port 7860) copies that dist/ and runs node immune-server.js. See frontend/deploy/README.md for the exact commands.

Provenance note. This repository is now independently installable, typecheckable, buildable, and smoke-testable. The deploy workflow always rebuilds from the exact merged GitHub revision, replaces the Space runtime whitelist, and verifies /.well-known/szl-source.json plus the live ledger before it reports success. Shared Decision Genome concepts retain their canonical Platform origin; the Apache-2.0 schema is mirrored locally so the runtime no longer depends on a private workspace link. /readyz binds the exact source and build revisions to the deployment-manifest digest, canonical artifact-set digest, server/UI artifact hashes, and current ledger audit.


SZL Holdings · Doctrine v11 · honest by design · Apache-2.0


Explore the SZL estate: a11oy console · LLM Router · Receipt format spec · Lean proofs · Docs · 🤗 SZLHOLDINGS

Contributors

dependabot[bot]

15 commits

Carlota-1

7 commits

Languages

TypeScript

59.1%

Python

29.1%

JavaScript

4.6%

CSS

3.7%

HTML

3.3%