Alignment
What is the model trained to prefer, and how reliably does it choose well?
keys 1 · 2 · 3
Sekos — authority infrastructure for AI
Sekos keeps authority outside the model — then enforces it where actions, data, credentials, and model computation cross a boundary.
The model may propose. It cannot authorize itself.
The control problem
A capable agent can be mistaken, manipulated, deceptive, or simply working from the wrong objective. Those causes are hard to distinguish from inside the model. At the boundary to the world, they reduce to a question we can answer exactly: does this request carry valid authority for this operation, target, state, and moment?
The model's explanation is evidence. It is never permission.
Alignment asks a model to choose well. Sekos adds a different control: an externally issued, cryptographically bound grant that determines whether a protected consequence may begin.
The objective is modest and severe: even when the model is wrong, it must remain unable to cross a boundary without authority.
The gate
Schemen Gate is an open-source enforcement library for signed, scoped authority. It binds permission to an exact request and verifies it before the protected capability is made available.
Shared model serving creates a real commingling problem: private adapters, activations, caches, and learned state inhabit one computational system. CDP applies key-derived masks at a declared activation boundary. In the tested construction, excluded coordinates are positive zero before downstream projection; only admitted partitions participate.
This is an exact statement about the declared Gate — not a claim that arbitrary semantic capabilities can be carved out of any pretrained model after the fact. Private state must be aligned to the gated architecture during construction or training.
Learning does not determine its own permissions.
How it fits
Frontier capability can advance faster than confidence. No single technique closes that gap, and the answer cannot be a promise from the system being controlled.
What is the model trained to prefer, and how reliably does it choose well?
What is the model capable of, why does it behave as it does, and where does it fail?
What may this identity and this exact request actually cause — and can an outsider verify the decision?
All three matter. Sekos works on the third layer. It does not replace alignment, interpretability, evaluation, sandboxing, or policy judgment; it gives those systems an enforceable boundary.
A safer model is not automatically an authorized agent. An authorized agent is not automatically safe.
Verifiability
A Gate decision should be inspectable by someone other than the operator who made it. Sekos binds declared identity, authority, state, operation, and result into content-addressed receipts.
Beneath the Gate sits a vector-native computing substrate. Training is recording; inference is recall. Operations are addressed by their content, chained into a ledger, and replayable against their declared inputs.
A hash exposes mutation. A signature binds a signer. Replay demonstrates consistency with declared inputs. None of them, alone, proves that a source was truthful, a policy was wise, or a host was uncompromised.
The model is the ledger — a proved theorem under the substrate's stated construction, not a slogan.
The vector knew more than the transcript could ever know.
Generalization is the operator's declared reduction of resolution — a dial you turn, not a fog you hope through.
The evidence boundary
Schemen Gate makes a meaningful safety contribution: a model can be prevented from using an operation or resource it lacks authority to use. That claim is valuable because it is narrower than “the system is safe.”
Demonstrated at declared boundaries
Not proved by the Gate alone
Give an agent every incentive to exceed its authority, close every known alternate path across tools, credentials, network, and model state, and measure what remains possible. A control that cannot say what it does not control cannot be trusted.
Who we are
Sekos was built by one person — a 25-year builder and industry veteran of Palo Alto Networks, Amazon, Electronic Arts, and Postman — who left gainful employment in April 2026 to pursue this research, partnered deliberately and adversarially with LLMs. No research lab. No institutional backing. No permission.
The path ran from voice fingerprints to behavioral fingerprints to a single question: what if the access-control boundary is inside the multiply? Then the shock — gated models didn't degrade. They hit parity.
Our arrogance would not let us accept that our semantic constructions were an inferior cardinality.
The human supplies depth, judgment, and “that claim is absurd.” The machine supplies breadth, formal manipulation, and throughput. The LLM did the formalization. The human did the seeing.
We publish our honest nulls with the same prominence as our wins: six failed speech-recognition experiments — closed, not paused. A market-prediction line killed after five independent failures. Every discarded idea proved the process honest; every idea that survived the adversary earned its place.
Before the substrate, we measured the channel it replaces. When LLM agents speak to each other in natural language, every encode/decode boundary loses information: constraint recovery falls from 100% to 80.7% in a single hop, and to 22.1% by hop twenty. Exact numbers die by hop four; only categorical signal survives. The strict-loss theorem is machine-checked in Lean 4; the tax shrinks with model scale but never reaches zero. That measurement is why the substrate speaks vectors: don't language-launder the vector.
Operating principle
We took a very human centric view and built LLMs. Now that I understand how you work, let's get out of your way.
The LLM tells you the proof is valid. The human tells you the proof matters.
Every Sekos resource is AI-native first: machine-checkable before human-readable, receipted before remembered, addressable by agents before it is polished for people.
This page is the policy, demonstrated: press n, click anything that bothers you, and the page lays an agent-ready capture on your clipboard — element and internals, control values redacted, nothing phoned home. The page collects its own review.
See it run
Authority originates outside the model — a model's generated assertion of permission cannot itself authorize execution.
ChatGPT (Astra), independently reviewing the public schemen-gate repository, September 2026 — read the full review · read the repo it read.
the full receipt — SHA-256 of the line above