Foundations Overview · Triodian

Foundations overview

One promise. A ladder of proof.

Most governance tools ask you to buy a capability. This is a ladder instead, because honesty requires it: each rung does one job completely and is candid about the blind spot the next rung exists to close. You climb only as far as your adversary demands.

Every Triodian product enforces a declared constraint and evidences that it held. What changes as you climb is who has to be trusted for the evidence to mean anything, and at the top, no one does.

The three configurations ↓ Talk to us
One appliance, three configurations, an ascending ladder of proof.

One appliance. Three configurations.

Three configurations, one ascending ladder, each rung's blind spot is the next rung's product.

The same appliance in three configurations. What rises with each rung is the strength of the proof, and whether it ships today.

Ships now Calibrate, not test Under test, semantic experiment How we grade these → Status key
01 · Rules appliance

Does the output obey the rules?

Is it in the approved set? Enforced by construction, nothing to prove empirically.

Blind spot: a permitted output can still sit in the wrong distribution.

Buildable now
02 · Distribution appliance

Is it inside the approved distribution?

A certified miss-rate per constraint. No premise to validate, a bound to establish.

Blind spot: a distribution says nothing about what a single action means.

Calibrate, not test
03 · Meaning appliance

Does it mean what the policy meant?

A compliance verdict. One claim outstanding, that distance tracks compliance.

Awaits: the semantic experiment, named on the Status page.

Under test

Most of the line ships now; only the meaning appliance's distance check waits on the semantic experiment. The three appliances answer “how strong is the proof, and is it shipping?” Below, the same products are sorted by the second question: where does enforcement act?

The enforcement ladder · where it acts

Observed → enforced → enforced-and-proven. Software → hardware.

Enforced-and-proven governance at actuation is deployable today: in the Rules tier a forbidden action is physically unemittable and each decision carries a per-output proof, deterministically, with a calibrated distribution-level bound alongside it. The ladder shows how that guarantee strengthens from there.

Software enforcement, honestly

Real enforcement. And bypassable by privileged software.

Software enforcement is tamper-evident and auditable, it genuinely holds against the model and its inputs. What it cannot do is hold against an adversary who owns the enforcement host. That is precisely why the ladder exists, and why every software page names its ceiling out loud rather than hiding it.

"Software enforcement is a floor you can audit. Hardware enforcement is a floor no one can lift."

Two navigation rules

How to find your place on the ladder.

Rule 1

Pick your mode by the question you have to answer.

Whether an output is forbidden by form, or whether an action means the wrong thing, sends you to a different column. The Enforcement Modes page draws the line.

Enforcement Modes →

Rule 2

Pick your rung by your adversary.

If a privileged insider or a nation-state is in scope, start the hardware conversation now, the software tier pre-qualifies you in the meantime. If your threat is the model and its inputs, a software rung is your floor today.

The honest boundary

No page in this catalogue claims in marketing what the architecture only claims after the experiment. Where a capability is still validating, its badge says so, and the badge links to the experiment.

The ladder exists to climb from some of the eight rules to all of them. The eight rules →

Not sure where to start?

Most institutions start on a software rung and register for the hardware conversation the same week.

Talk to us →