Closing the Governance Gap
Traditional digital systems suffer from “policy drift” – legal intent diverges from operational reality. For Financial Service Institutions, Communications Service Providers, municipalities, and property developers deploying shared phygital infrastructure, the cost of that drift is existential. Substantiated Integrity closes that gap permanently – moving from Assumed Trust to trust that is continuously and mathematically proven.
No Policy Drift
Policies formalised as machine-readable axioms and rigorously enforced at runtime – not just documented in PDFs.
Verifiable Trust
Continuous, provable assurance via cryptographic verification, hardware attestation, and immutable audit trails.
Governed Autonomy
Constitutional guardrails dictate permissible AI agent actions – explainable, auditable, legally compliant by design.
Compliance as Asset
Transforms compliance from cost-intensive burden into strategic competitive advantage with zero operational friction.
How Substantiated Integrity Is Achieved
A multi-faceted, deeply integrated architectural approach across eight interconnected capability sets.
Assurance Evidence Pyramid
Single bitemporal cryptographic receipt binding every underlying hardware, code, data, and policy attestation.
Evaluated and signed by DRAGON at the exact microsecond of the executed act.
Cryptographic verification of model weights, inference context, and neuro-symbolic boundaries.
Zero-knowledge proof of ingestion provenance and GDPR/eIDAS consent bindings.
Deterministic reproducible builds verifying seL4 microkernel tasks and application stanzas.
Silicon-level cryptographic identity anchored in hardware Security Modules and physical TPM chips.
Agreement-Centricity
All policies, rules, and arrangements formalised as Agreement DAGs – executable code, not static documents. Every action is a direct, verifiable consequence of a governing agreement.
Separation of Intent and Execution
Clear architectural distinction between Agreement DAGs ("what and why") and Actuator DAGs ("how") – the platform is Governance-First by design.
Formal Methods and Axiomatic Legal Models
Agreement DAGs as executable formal specifications. The Axiom MESH and Deontic Logic Engine provide a rigorous framework where system actions are mathematically provable.
Continuous Authority to Operate (cATO)
All artifacts subjected to relentless, platform-intrinsic testing – creating pre-approved deployment status with continuous compliance in regulated industries.
System of Record as Authoritative Core
The SoR Registrar and KnowledgeHUB provides an immutable ledger for MVEBs – verifiable proof of every decision with real-time evidence streaming for continuous assurance.
Integrated Risk Management
Cybersecurity risks embedded into enterprise risk governance through continuous SDLC visibility – making risk assessment intrinsic, quantifiable, and continuously verifiable.
Phygital Omnichannel and Agentic Identity
Agentic Identity gives users sovereign control of their digital persona, with granular consent via machine-enforceable Agreement DAGs – eIDAS 2.0 compliant.
AI-Driven Intelligence (SoI)
The System of Intelligence acts as real-time verifier against Rulebook DAGs and Axiom MESH – neuro-symbolic AI where trust is a proven property, not an assumption.
"Trust is not a matter of faith – it is a continuously verified and mathematically proven property of the entire ecosystem."
MVEB – The Minimum Viable Evidence Bundle
If Substantiated Integrity is the property, the MVEB is the unit of currency. Every governed act on the phygital fabric mints one – a self-contained, cryptographically sealed evidence package that can be re-presented in audit, recomputed in regulator sandboxes, and resolved back to every layer of the stack that produced it.
Five hashes, one act
Each MVEB binds five signed digests: the Policy Hash at the moment of the act (the version of law in force); the Agreement DAG node that authorised the act; the xBOM attestations for the hardware, software, data and model that performed it; the DToP identity proof of the actor; and the LAHE outcome the act produced.
Sufficient, not exhaustive
An MVEB carries the smallest evidence set that lets an independent auditor or regulator recompute the lawfulness of the act under the policy that was in force when it happened. Nothing more is needed; nothing less will hold up. Full telemetry sits behind it in the System of Record if a deeper inspection is warranted.
Audit becomes mathematics
With an MVEB chain, compliance stops being a periodic report and becomes a property a regulator can verify on demand against any past moment. The DRAGON adjudication that produced each MVEB is replayable; the Bitemporal Ledger reconstructs the policy that governed it. Audit theatre ends.
MVEBs are the building blocks of the per-LAHE economy. See Tenant Cohorts → The Economics of Pooling for how Submission Tokens meter the commercial flow of governed acts.
The Silicon-Anchored Control Loop
Within the onePOI.online Constitutional Operating System (COS) control plane, the Registrar, the Notary, KeyMESH, and the oneVault MESH function in an integrated, hardware-enforced loop. Together, they decouple the four foundational domains of digital administration – State, Evidence, Cryptographic Flow, and Secret Execution – translating abstract legal intent into a physical invariant. This precise synchronisation establishes a triangular control plane at the silicon level, replacing legacy "Trust by Policy" configurations with the absolute mathematical certainty of Substantiated Integrity.
1. The Registrar
The Oracle of Ground Truth & State
The Registrar represents the authoritative core of the platform's System of Record (SoR), acting as the active legislative registry and oracle of current systemic state.
- Policy Hash (PH) Minting: It compiles the TopHAT-ratified Axiom MESH constraints and mints the active Policy Hash (PH), serving as the definitive constitutional coordinate for the law.
- LSRG Generation: Compiles the hash matrix into a flattened Legal-State Reachability Graph (LSRG) and loads it directly into the high-speed registers of the DRAGON DCPU, resolving legal sub-graphs in parallel with transaction routing.
- xBOM Lifecycle Tracking: Maps and verifies the four-dimensional Extended Bill of Materials (xBOM) topology (HBOM, SBOM, MBOM, DBOM). If an unauthorised modification is detected, it triggers an automatic Atomic Halt at the silicon bus.
2. KeyMESH
The Cryptographic Nervous System & Flow
KeyMESH operates as the platform’s high-assurance, policy-driven cryptographic orchestration fabric, governing the transmission and isolation of secrets under the explicit guidance of the DCPU.
- Atomic Map Updates: Receives the latest valid Policy Hash directly from the Registrar via secure Atomic Map Update syscalls to kernel-level eBPF maps, VETOing any keys bound to a revoked PH.
- Identity & Token Verification: Authenticates the validity of the On-Behalf-Of (OBO) Token (Delegation DAG) and signatures, verifying that autonomous agents operate within human-defined boundaries.
- Distributed Fragment Cryptography (DFC): Avoids monolithic keys by utilising DFC to fragment encryption keys. KeyMESH securely routes these fragments across isolated network tiers, eliminating database honeypots.
3. oneVault MESH
The Secret Execution Boundary
The oneVault MESH functions as the distributed, TEE-secured execution layer for secrets, serving as the final point of hardware-rooted policy enforcement at the physical edge.
- Zero-Knowledge Key Assembly: Re-assembles DFC fragments only once within volatile TEE-secured memory partitions (TEE Hardware-Isolated Enclaves), ensuring zero-knowledge isolation from the host OS and hypervisor.
- Hardware Attestation Gating: Proves local kernel boot state matches the expected hardware record in the Registrar, and verifies that the execution call presents a valid Lawful Warrant bound to the current PH.
- Encryption-as-a-Service (EaaS): Executes cryptographic actuations only after policy, identity, and judicial gates clear, zeroising volatile registers immediately post-execution to eliminate persistent footprints.
4. The Notary
The Guardian of Non-Repudiation & Evidence
While the Registrar governs the present state of systemic truth, the Notary independently archives and certifies the past state of historical evidence.
- Bi-Temporal System of Record: Logs execution traces into an append-only ledger, tracking Valid-Time (\(T_V\)) and Transaction-Time (\(T_T\)) to prevent timeline manipulation and enable retrospective audits.
- Verifiable Adjudication Commitments (VACs): Captures hardware-signed VAC proofs asynchronously outside the transaction path, confirming that calculations were performed legally and correctly without injecting latency.
- Provenance Envelope Generation: Seals the VAC and Wipe Attestation Signature (WAS) into a Provenance Envelope, writing it as a Lawful Act Hyperedge (LAHE) to meet DORA, FiDA, and EU AI Act standards.
[1. INCEPTION] ──► inConcert iPaaS launches an Actuator DAG to initiate a session.
│
▼
[2. ATTESTATION] ──► Registrar cross-checks local xBOM and injects the active PH into the DCPU.
│
▼
[3. AUTHORISATION] ──► KeyMESH verifies the OBO Token and routes DFC fragments inside a TR-31 block.
│
▼
[4. ENFORCEMENT] ──► oneVault assembles fragments inside the TEE; DRAGON signs the WAS.
│
▼
[5. CERTIFICATION] ──► Notary captures the VAC and WAS, permanently sealing the LAHE proof block.
The Five-Part Tandem Loop In Action
To visualise how the Authoritative Trinity and oneVault MESH substantiate trust in silicon during an active transaction (e.g. a cross-border real-time settlement or a forensic onboarding session), the components synchronise through a precise five-stage sequence:
The inConcert iPaaS layer triggers an Actuator DAG to initiate the high-speed transaction session, passing the high-level business semantics down to the control plane.
The Registrar evaluates the local node's xBOM profile. It confirms the firmware and hardware layer are uncompromised and injects the active Policy Hash (PH) and Legal-State Reachability Graph directly into the DRAGON DCPU's high-speed registers.
KeyMESH verifies the consumer’s OBO Token signature against the master registry. It releases the incomplete DFC fragments, wrapping them inside an authenticated TR-31 key block header that carries specific, hardcoded Obligations, Permissions, and Prohibitions (OPPs).
Inside the oneVault MESH, the DRAGON DCPU resolves the legal sub-graph in parallel with execution. It unseals the Silicon Apartment, assembles the DFC fragments inside the TEE memory space, signs the financial action, and immediately zeroises volatile registers to output a Wipe Attestation Signature (WAS).
The Notary captures the Verifiable Adjudication Commitment (VAC) and the WAS asynchronously. It permanently seals them into a Provenance Envelope on the bitemporal ledger as a Lawful Act Hyperedge (LAHE), establishing an un-fakeable, mathematically verified audit trail.
The Post-Digital Verdict
By segregating State (Registrar), Evidence (Notary), and Secrets (KeyMESH) from Execution (oneVault MESH), and locking the entire loop inside the DRAGON DCPU silicon substrate, the architecture eliminates uninsurable conduct risk. Non-compliance fails at compile time, and malicious activity becomes a physical and hardware impossibility at the network edge.
Resolving GDPR vs. AMLR Conflict
Anti-Money Laundering Regulations (AMLR) mandate strict transaction and identity data retention. The General Data Protection Regulation (GDPR) mandates a citizen's Right to Erasure. The onePOI.online engine resolves this compliance friction deterministically at the hardware and ledger boundary.
Bitemporal Ledger & MVEBs
The System of Record (SoR) maintains a two-dimensional timeline: Valid-Time ($T_V$) and Transaction-Time ($T_T$). Regulators perform a deterministic replay of decision logic using Minimum Viable Evidence Bundles (MVEBs) and Evidence Envelopes, verifying legality without exposing citizen PII.
PAIF Cryptographic Shredding
Under GDPR's Right to Erasure, the system performs PAIF cryptographic shredding, zeroizing decryption keys managed via Threshold Cryptography (MPC) inside secure TEE enclaves. Compliance hashes, ZKPs, and hyperedges remain on-chain to satisfy AMLR audits.
Hardware State VETO
If hardware failures occur, such as an XFS4IoT shutter jam, the DRAGON engine issues an immediate VETO (prohibiting independent AI inference from resolving states). The system forces a fail-closed condition and triggers a high-priority $O\_Audit$ obligation for TopHAT adjudication.
Auditability-as-Recomputation Sandbox (GaaS)
Re-instantiates historical states in a secure Recomputation Sandbox to replay transactions using the exact Policy Hash in effect during that microsecond. Enables Governance-as-a-Service (GaaS): audit runbooks are executed as verified zero-knowledge runs without exposing identity, creating continuous, monetizable trust assets.
Native vs. Tenant-Configured Compliance
The platform moves from manual checklists to Substantiated Integrity. Some regulations are solved natively by the Constitutional OS – others are configured as Domain-Specific Axioms within each tenant's Agreement DAG.
Natively Solved by the Constitutional OS
These regulations are addressed at the hardware and platform level – no tenant-side configuration required. Compliance is a structural property, not a checklist.
Digital Operational Resilience Act – addressed through hardware-enforced isolation, measured boot (HBOM), and real-time Structural VETOs that prevent non-compliant states from executing.
Handled natively via hardware-isolated TEE Hardware-Isolated Enclaves in the TEE – cardholder data is cryptographically segregated at the silicon layer, never accessible across tenants.
Handled via oneWallet.online, where micro-level consent is a machine-enforceable prerequisite for any data flow – consent is not a policy document but a constitutional precondition of execution.
Tenant-Configured via Agreement DAG
Regulations that require domain-specific values – fee models, KYC tiers, interest rate rules – are configured as Domain-Specific Axioms inside each tenant's unique Agreement DAG.
Unique fee models, open banking API obligations, and liability allocations are formalised as tenant-specific axioms – version-controlled and auditable via the SoR ledger.
Financial Data Access specificities – data sharing permissions, dashboard authorisation scopes – are configured as granular Agreement DAG clauses per tenant.
Substantiated Integrity & Zero-Knowledge Verification
Explores Shamir's secret sharing (MPC), zero-knowledge compliance, and formal state reachability checks.
Verifiable Math Instead of Paperwork
Substantiated Integrity replaces slow, paper-based audits with immediate, digital proof. Every transaction, signature, and agreement produces a secure package of mathematical evidence. This evidence can be verified instantly by anyone with authorisation, proving that the system complied with all laws without exposing personal data. Note: the system guarantees execution of the programmed rules as written, but does not judge whether the rules themselves are good – that remains a human responsibility.
Bitemporal Ledgers, PAIF Shredding & fail-closed TEE Security
Substantiated Integrity delivers mathematical certainty through Minimum Viable Evidence Bundles (MVEBs) and bitemporal ledgers ($T_V$ and $T_T$). Under a software-isolated TEE (Silicon Apartment), the system enforces a fail-closed principle: if policy freshness or triadic adjudication is not completed within the threshold (due to latency or failure), it triggers a "DENY-ALL" fail-safe state. GDPR compliance is resolved via PAIF cryptographic shredding, allowing deterministic replay of decision logic via MVEB envelopes without retaining PII.
Compliance Frameworks
Native compliance logic alignment mapping to PSD3, eIDAS 2.0, and DORA resilience guidelines.
Commercial Pooled ROI
Shared physical infrastructure distribution model reducing CapEx overhead by up to 80%.
Architectural Integration (Symphony of Systems)
The Notary acts as the non-repudiable evidence collector for the entire platform, integrating directly with all layers of the Symphony of Systems (SoS):
Biometric signatures captured in the System of Engagement (SoE) are bound to the formal deontic policies in the System of Agreement (SoA), preventing intent-drift.
The System of Orchestration (SoO) executes workflows only when the Notary validates active Verifiable Adjudication Commitments (VACs) at each state transition.
All records in the System of Record (SoR) are indexed on the Lawful Act Hyperedge (LAHE), allowing the System of Intelligence (SoI) to verify compliance post-execution.
Threshold Cryptography (MPC), TEE Enclaves & Bitemporality
Threshold Cryptography (MPC)
PII is protected via a Shamir-based $(k, n)$ threshold scheme where keys are fragmented into $n$ parts. Reconstruction requires a minimum of $k$ active hardware enclaves. Under GDPR Article 17 (Right to Erasure), cryptographic shredding is executed by zeroizing key-fragments in AMD SEV-SNP and Intel SGX TEE enclaves.
Bitemporal Valid/Transaction Timelines
Every data state transaction is bound to a bitemporal vector $[T_{valid}, T_{transaction}]$, where:
$T_{valid}$ is the time when the event occurred in the physical world.
$T_{transaction}$ is the time when the record was entered into the ledger.
The invariant $T_{valid} \le T_{transaction}$ is strictly enforced at the hardware API boundary.
Verifiable Adjudication Commitments (VAC)
A VAC is a cryptographic digest of the state transition, computed as: $$\text{VAC} = \text{HMAC-SHA256}(\text{Policy\_Hash} \mathbin{\Vert} \text{State\_Pre} \mathbin{\Vert} \text{State\_Post} \mathbin{\Vert} \text{Entropy})$$ VACs are published directly onto the Lawful Act Hyperedge (LAHE), locking the state transition to the exact governing schema version.
Measured Boot & Hardware TPM Anchor
Enclave workloads undergo Measured Boot attested by an on-die TPM 2.0. PCR registers must match pre-calculated xBOM hashes before any cryptographic key shares are released for decryption.
Lagrange Interpolation & Key Shredding Proofs
The mathematical security of Shamir threshold secret sharing and cryptographic key shredding is formally verified. Decryption keys are fragmented and stored across isolated hardware enclaves, ensuring data security.
The Auditor's Journey: RegTech in Action
Unpack the Standard Operating Procedure (SOP) for verifying automated AI decisions. Walk through the audit of a denied SME loan to see how colimit nodes make complex AI reasoning transparent and court-admissible.