Attested Semantic Compare · Triodian

Mode A · Software tier · Flagship

Every AI action checked against your rulebook, on your systems, with proof for each one.

Released, repaired, or blocked. Three physically distinct devices, each separately attested to a private enclave, no single device ever sees both the AI output and the rule set.

Separation of knowledge

No one machine ever sees both the AI's output and the rules.

Device 1

AI-side device

Holds and vectorises the output. Never sees the library.

vectors only

Device 2

Library-side device

Holds and vectorises your rule set. Never sees the output.

The private enclave

Sees only vectors, accepted only from attested devices.

It binds its verdict to the exact inputs and library version it saw. Nothing else can produce a valid verdict.

Rule-set confidentiality

Never exposed in plaintext to the AI side.

Tamper-evidence

A swapped input, library, or verdict fails verification.

On-premises operation

No data leaves the boundary for the check.

Fast library refresh

Re-vectorised and re-attested, not re-fabricated.

Dispositions

Three possible outcomes, each one recorded in a signed token.

Released

In envelope. The action proceeds.

Repaired

Governed convergence pulls the output back toward compliance rather than merely refusing.

Blocked

Outside the envelope, refused. Nothing proceeds.

Every verdict is bound to the named library version in a compliance token.

Grounded, not speculative

The system behind this check is already running in production.

The governed-reasoning lifecycle behind Attested Semantic Compare is the engine already running pinpole in production, at scale.

pinpole.cloud →   Status legend →

Engine✓ proven
Lifecycle & ledger✓ proven
Semantic-divergence signalvalidating

Detection configurations

What you can do today, and what waits for the hardware.

Out-of-distribution loadout

Residual-energy lanes asking: is this state within the approved distribution at all? Measurable now; makes no claim awaiting the experiment.

Distance-to-authored-reference lanes

Loaded separately, gated by the experiment. Named here, not buried.

Three-machine on-prem topology.

AWS Nitro Enclaves reference build.

Control-plane tooling that compiles a validated configuration into an attested deployment.

The honest boundary

Three ceilings, named.

  • Substrate: tamper-evidence and confidentiality, not physical non-bypassability, November 2025 is the standing reminder of what a privileged software adversary does to software controls; the Semantic Enforcement Appliance is the upgrade path.
  • Statistical: the miss-rate is certified against the honest distribution, not an adversary, unless a certified-detection lane is loaded, which bounds adversarial misses only within a stated perturbation budget.
  • Premise: the Validating loadouts are named above, not buried here.

Rules 1, 2, 4, 5 and 6 within the software boundary, the three-machine separation is Rule 1 made physical. Rules 3 and 7 in full arrive in hardware. The eight rules →

Talk to us about a design-partner deployment.

Talk to us →