Sekos keys 1 · 2 · 3

Sekos — authority infrastructure for AI

A model should never decide what it is allowed to do.

Sekos keeps authority outside the model — then enforces it where actions, data, credentials, and model computation cross a boundary.

The model may propose. It cannot authorize itself.

The control problem

Intelligence is not authority

A capable agent can be mistaken, manipulated, deceptive, or simply working from the wrong objective. Those causes are hard to distinguish from inside the model. At the boundary to the world, they reduce to a question we can answer exactly: does this request carry valid authority for this operation, target, state, and moment?

The model's explanation is evidence. It is never permission.

Alignment asks a model to choose well. Sekos adds a different control: an externally issued, cryptographically bound grant that determines whether a protected consequence may begin.

  1. 01 · proposalThe model asks

    An untrusted request names an operation and the consequence it wants.

  2. 02 · verificationThe Gate checks

    Identity, scope, target, arguments, conditions, expiry, state, and replay.

  3. 03 · consequenceCapability opens

    Only an admitted request receives the resource, credential, action, or computation.

  4. 04 · evidenceA receipt closes the loop

    The exact authority decision and result become independently checkable.

The objective is modest and severe: even when the model is wrong, it must remain unable to cross a boundary without authority.

The gate

Permission, enforced at the point of consequence

Schemen Gate is an open-source enforcement library for signed, scoped authority. It binds permission to an exact request and verifies it before the protected capability is made available.

  • Actions. Bind authority to the operation, target, arguments, expected state, conditions, expiry, and one-use redemption.
  • Credentials and resources. Verify the grant before releasing a secret, decrypting protected material, or dispatching an external call.
  • Delegation. Issue narrower, bounded child authority. The agent cannot turn possession of a tool into permission to use it however it wants.
  • Model computation. Place an activation Gate inside the network so ungranted coordinates and lanes are excluded before downstream projection.
Inside the model · Cryptographic Dimension Partitioning

Shared model serving creates a real commingling problem: private adapters, activations, caches, and learned state inhabit one computational system. CDP applies key-derived masks at a declared activation boundary. In the tested construction, excluded coordinates are positive zero before downstream projection; only admitted partitions participate.

This is an exact statement about the declared Gate — not a claim that arbitrary semantic capabilities can be carved out of any pretrained model after the fact. Private state must be aligned to the gated architecture during construction or training.

Learning does not determine its own permissions.

How it fits

Safety is a stack, not a slogan

Frontier capability can advance faster than confidence. No single technique closes that gap, and the answer cannot be a promise from the system being controlled.

Alignment

What is the model trained to prefer, and how reliably does it choose well?

Interpretability & evaluation

What is the model capable of, why does it behave as it does, and where does it fail?

Authority & verification

What may this identity and this exact request actually cause — and can an outsider verify the decision?

All three matter. Sekos works on the third layer. It does not replace alignment, interpretability, evaluation, sandboxing, or policy judgment; it gives those systems an enforceable boundary.

A safer model is not automatically an authorized agent. An authorized agent is not automatically safe.

Verifiability

Receipts, not promises

A Gate decision should be inspectable by someone other than the operator who made it. Sekos binds declared identity, authority, state, operation, and result into content-addressed receipts.

Beneath the Gate sits a vector-native computing substrate. Training is recording; inference is recall. Operations are addressed by their content, chained into a ledger, and replayable against their declared inputs.

A hash exposes mutation. A signature binds a signer. Replay demonstrates consistency with declared inputs. None of them, alone, proves that a source was truthful, a policy was wise, or a host was uncompromised.

The model is the ledger — a proved theorem under the substrate's stated construction, not a slogan.

The vector knew more than the transcript could ever know.
Generalization is the operator's declared reduction of resolution — a dial you turn, not a fog you hope through.

The evidence boundary

Strong claims need sharp edges

Schemen Gate makes a meaningful safety contribution: a model can be prevented from using an operation or resource it lacks authority to use. That claim is valuable because it is narrower than “the system is safe.”

Demonstrated at declared boundaries

  • Exact contract changes — operation, target, arguments, state, or expiry — fail verification in the tested exact-call path.
  • Observed denials stop protected callbacks and model forwards before they begin.
  • Activation Gates exactly exclude declared coordinates; controlled research reports foreign-lane invariance under stated architectures and assumptions.
  • Signed receipts bind the declared request, authority decision, and result for independent checking.

Not proved by the Gate alone

  • Safe goals, wise policy, or harmless sequences of individually authorized actions.
  • General semantic capability extraction from an arbitrary pretrained model.
  • Complete host, network, cache, log, side-channel, or alternate-path containment.
  • Safety after issuer, key custody, or the trusted enforcement host is compromised.
The next falsifiable evaluation

Give an agent every incentive to exceed its authority, close every known alternate path across tools, credentials, network, and model state, and measure what remains possible. A control that cannot say what it does not control cannot be trusted.

Who we are

One person, one adversarial collaborator

Sekos was built by one person — a 25-year builder and industry veteran of Palo Alto Networks, Amazon, Electronic Arts, and Postman — who left gainful employment in April 2026 to pursue this research, partnered deliberately and adversarially with LLMs. No research lab. No institutional backing. No permission.

The path ran from voice fingerprints to behavioral fingerprints to a single question: what if the access-control boundary is inside the multiply? Then the shock — gated models didn't degrade. They hit parity.

Our arrogance would not let us accept that our semantic constructions were an inferior cardinality.
The human supplies depth, judgment, and “that claim is absurd.” The machine supplies breadth, formal manipulation, and throughput. The LLM did the formalization. The human did the seeing.

We publish our honest nulls with the same prominence as our wins: six failed speech-recognition experiments — closed, not paused. A market-prediction line killed after five independent failures. Every discarded idea proved the process honest; every idea that survived the adversary earned its place.

Before the substrate, we measured the channel it replaces. When LLM agents speak to each other in natural language, every encode/decode boundary loses information: constraint recovery falls from 100% to 80.7% in a single hop, and to 22.1% by hop twenty. Exact numbers die by hop four; only categorical signal survives. The strict-loss theorem is machine-checked in Lean 4; the tax shrinks with model scale but never reaches zero. That measurement is why the substrate speaks vectors: don't language-launder the vector.

Operating principle

AI-native first

We took a very human centric view and built LLMs. Now that I understand how you work, let's get out of your way.
The LLM tells you the proof is valid. The human tells you the proof matters.

Every Sekos resource is AI-native first: machine-checkable before human-readable, receipted before remembered, addressable by agents before it is polished for people.

This page is the policy, demonstrated: press n, click anything that bothers you, and the page lays an agent-ready capture on your clipboard — element and internals, control values redacted, nothing phoned home. The page collects its own review.

See it run

Demos & evidence

Authority originates outside the model — a model's generated assertion of permission cannot itself authorize execution.

ChatGPT (Astra), independently reviewing the public schemen-gate repository, September 2026 — read the full review · read the repo it read.

These are my receipts. Where are yours?

the full receipt — SHA-256 of the line above

UX NOTES · 0
Click anything on the page: the element and its internals are captured and copied to your clipboard immediately. Add a note if you want, or keep clicking. Esc pauses picking. Nothing leaves this browser until you paste it.

Content receipt

SHA-256 of this claim, with whitespace normalized: