TRUST — OPEN BY DESIGN, ONE SEALED SEAM

Open by design, one sealed seam.

In a record raised into the light, trust is the entire product. So almost all of Solora is open — the binding lifecycle, the state machine, the immutable record, every grade. Exactly one seam is sealed. This page draws the line precisely, and stays honest about where every claim stops.

OPEN BY DESIGN — THE DISCIPLINE IS THE PRODUCT

The whole ritual is meant to be read.

The binding lifecycle, the state machine, the immutable record, the goal tree and its gates, grades — all of it is open, on purpose. We want customers, auditors, and regulators to see exactly how a commitment is stated, moved through its states, graded, and kept.

A record is only worth trusting if you can watch it work, so the mechanics are a selling point, not a secret. The shape of the atomic unit — a commitment, its conditions, the falsifiable test that would prove it wrong, a satisfier pointer, and a grade — is published, because the legibility is the whole pitch.

declared → claimed → satisfying → graded · satisfied · graded · violated · graded · indeterminate · retracted — the lifecycle is open, by design

  • The binding lifecycle & state machine. Four live states and two terminal ones; retraction reachable from every live state and required to state a reason. Described freely, because the discipline is what earns the trust.
  • The immutable record. Every state change writes a versioned row; journal, changelog, audit, and postmortem stop being four hand-kept documents and become queries against one record.
  • The goal tree and its gates. Work attaches at a ripe leaf, never at a branch still being decomposed, and a goal may carry a gate its satisfaction has to pass — four kinds, each recomputable from this ledger's own rows. How a plan is bound →
  • Grades. How a satisfied / violated / indeterminate grade is recorded and surfaced — a miss kept as loudly as a win, never quietly dropped, and indeterminate kept as its own conclusion rather than rounded to either neighbour.
  • The clash concept. DECLARED · FRONTIER That two commitments can contradict, and what a clash verdict would carry for a human to weigh, is written down and open. No clash check runs today — there is no clash state in the shipped ledger and nothing computes one. It is gated on the concurrent multi-maker workspace, where two live binds can meet at all. How coordination is meant to work →
Openness is the feature.

THE DOGFOOD — THE HOUSE'S OWN R&D RUNS ON SOLORA

Every wave of every product, on the record.

GRADED · DOGFOODED The grading runs daily on the house's own work — computed from the record, not asserted.

Every Vulcora product is planned, built, and graded through Solora — including Solora itself. A unit of work does not start until its intent is bound in falsifiable form; it does not land until the gate in the repository finds a commit naming that intent and the guard finds a signed receipt for it; and it is never finished quietly — it is graded, and the grade is kept, misses included. So you are not the first tenant: the sharp edges are found by the makers first, on load-bearing work, under the same discipline being sold.

And the credibility on offer is the discipline, not a feed. A record of intent belongs to the tenant that wrote it — and the house holds its own record to the same law: Solora keeps the record in the light; it does not get to mine it. The ledger is a working instrument, not a publication; it is never published — ours or yours. What proves the substrate is that it is lived on daily, and walked live in controlled demos, never a record you scroll.

Not claimed, not implied

  • Not a public feed. The record is not published — the house's or any tenant's. No page here will ask you to trust us because you can scroll our ledger.
  • Not a vanity claim. Inside the record, misses are kept and owned as loudly as wins — enforced by the substrate, not by good intentions.
  • Not a benchmark. "The house runs on it" is a statement about discipline and daily load, not a score, a ranking, or a guarantee about your outcomes.
  • Not a predictor. The record grades what was committed to and whether the bound test held — it does not foretell what will.

THE ONE SEALED SEAM — ONLY THE INTELLIGENCE

Exactly one seam is sealed: the intelligence.

Everything above runs on the record and its projections. Sealed behind a narrow interface is only the intelligence, described by what it does and never by how it does it. Referenced only through the interface: what goes in, what comes out.

The rest of the apparatus never needs what is behind that interface: bind, grade, keep, and render all run against the open record. One capability crosses that seam today. The other two are written down here as declared, because a seam described as sealed reads to a buyer as shipped-but-secret, and that is the one thing this page may not let stand.

01

Arrangement physics GRADED · LIVE

That a goal is placed and moved on the orrery by a judgement about the whole tree — five plain numbers per goal: spin, size, brightness, acceleration, phase. The queue, the ranges, and the door that refuses anything else are open; the judgement that produces the numbers is sealed. The engine dials in and leases; nothing here dials out.

02

Semantic clash reading DECLARED · FRONTIER

That two commitments contradict on meaning — beyond merely touching the same file — read at bind-time with a human-readable reason. Nothing computes this today, sealed or open: no request of this kind is queued and the ledger has no clash state to write. It is gated on the concurrent multi-maker workspace.

03

Falsifiability translation DECLARED · FRONTIER

That a natural-language promise becomes a falsifiable test spec. Today the maker writes the test_spec themselves, and an intent bound without one records that nobody stated a test — which is honest, and different from an empty one.

The interface is small on purpose. One kind of request goes out to the engine and five bounded numbers come back, scrubbed at the door: an extra key at any level, a value outside its range, or a goal the lease did not name and the whole submission is refused, with nothing partial stored. Walk the lenses →

And the seal is not a single point of failure for your record. The Engine travels separately from the ledger. If it is ever unavailable, the ledger, the state machine, the immutable record, and every graded outcome stay fully readable, and the orrery still draws every goal from the ledger's own state — only the physics stop refreshing, and the ledger can be asked whether the numbers it holds are still a reading at all. Your record never depends on the sealed core to be read.

DATA & PRIVACY — A CUSTOMER'S RECORD OF INTENT IS THEIRS

A customer's record of intent is theirs.

The governing principle is one line. Solora's whole job is to keep that record faithfully — append-only, graded against the truth, misses kept, nothing quietly forgotten — and its whole discipline is to keep it only for them.

  • Tenant isolation is absolute. Bindings, conditions, test specs, reasoning traces, satisfier content, grades, and the record's rows are scoped to the tenant that wrote them — never readable by, surfaced to, or joined against another's. The Engine is called per-tenant and never mixes scopes — an interface invariant, not a courtesy. Today that isolation holds in the cloud and single-tenant shapes; org-scale workspace tenancy is declared frontier, and it ships before the multiplayer does.
  • Nothing is shared by default. The cross-org learning graph DECLARED · FRONTIER feeds only your own record until you opt a defined scope in. Consent is explicit, scoped, and revocable — a separate, named term, never a hidden clause, never bundled into sign-up. Even consented, what crosses is aggregated, pseudonymized graded structure, never a readable window into your plan. The graph, and its consent gate →
  • Satisfiers are referenced, not ingested. Where a durable, tenant-owned pointer exists — a commit hash, a run id, an object handle — Solora records the pointer and the grade and reads the artifact through your own access at grade-time. Held content is tenant-scoped, encrypted at rest, and retention-bounded, with a shorter default life than the binding that points at it.
  • Deletion is first-class. Full tenant deletion removes bindings, traces, held satisfier content, and derived state. Because the record is append-only, the deletion is itself recorded as a transition — deletion of content, honesty about the fact of it.
Solora keeps the record in the light; it does not get to mine it.

WHERE IT RUNS — TWO SHAPES, BOTH OURS

01

Shared cloud

The default — Solora-hosted, tenant-isolated as above. Region pinning for data-residency customers.

02

Dedicated single-tenant

Dedicated, isolated infrastructure for one organization, for a customer that will not share a substrate with another. Still run by us, on ours — what a customer gets is their own substrate, not their own operations.

Both shapes are ours to run, and that is the whole list: Solora is a hosted product, so there is no third shape where the record lives on a customer's own infrastructure. Said here rather than left to be inferred, because "single-tenant" is a phrase that is often used to mean on-premises and does not mean it here.

INTEGRITY, STATED HONESTLY — NO MORE THAN IS TRUE

We say append-only. We never say unforgeable.

The record's trustworthiness is the product, so its integrity claims are stated exactly. It is append-only by construction — new versioned rows, no edit-in-place path for a binding's history — and fully audit-trailed: every transition, including a retraction, a correction, a re-grade, or a deletion, is itself a recorded row. There is no off-ledger change to a binding's lifecycle.

What it is not: tamper-proof against a hostile insider with database access. Solora claims the narrower, true thing — every change is itself recorded, so tampering is not invisible. For customers who need cryptographic assurance beyond that, tamper-evident signing and external anchoring of the record trail are a hardening option — offered as what they are, never dressed up as "unforgeable." The signed dossier →

A grade is never fabricated.

  • Unresolved is shown unresolved. Never optimistically marked satisfied because it looks plausible. Plausible is not resolved.
  • A miss is kept. A violated grade carries the same weight as a satisfied one. Misses are signal; the record that hides them is marketing, not memory.
  • An abstain is an abstain. indeterminate is a first-class verdict, not a pending: it means the check ran and did not settle the question. It is also the cheapest verdict to file — satisfied and violated are refused without a non-empty evidence map, and indeterminate is not — so the honest answer costs least.
  • A coverage bound is not yet measured — and we will not quote one. This page used to say the bound was published; no number was published anywhere, and the check it bounded does not run. Until a clash check exists and its coverage has been measured against a corpus, there is no percentage to quote, and a made-up one would be the exact defect this product exists to refuse.
SubjectWhat Solora claimsWhat Solora will never say
The recordappend-only by construction, fully audit-trailed — every change itself recorded"tamper-proof · unforgeable against a hostile insider"
A green gradethis falsifiable test held — what was committed to, and whether the bound test passed"this proves the agents did the right thing"
Clash coveragenone — no clash check runs today, and no coverage has been measured"catches contradictions · a published coverage bound"
Complianceevidence the EU AI Act / NIST frameworks expect"guarantees or certifies your compliance"

The record is faithful, not omniscient. What it gives a risk function is evidence — graded, timestamped, immutable — not legal advice or certification. What this gives your risk function →

CLIENT INTEGRITY — THE LEDGER VOUCHES FOR THE RITUAL

Trust that a client is actually enforcing the ritual.

The discipline that makes the record trustworthy — bind before you edit, route code queries to the forge tools, respect scope, never bypass the verifier, never force the main line — is enforced by hooks that run inside the maker's client. But those hooks run on the maker's machine. A key proves who is calling, not that their client is enforcing the ritual. In a shared workspace, one unhooked client could corrupt the record for everyone.

So the backend proves it cryptographically and writes the answer to the record. "Hooked and current" is a signed manifest hash: canonicalize the required hook set into a hash, and a missing hook, a stale hook, or a tampered hook all change it — so not-installed and tampered are the same detectable event. On connect the client signs a fresh challenge; each ledger-affecting call carries a per-action attestation token. It is all standard cryptography and paper-trail.

VerdictMeaningResponse
attestedhooks present, manifest matches, signatures validfull write path — bind / satisfy / advance land normally
unattestedno valid attestation — no hooks, or a raw client calling MCP directlyrefused, or quarantined to a low-trust tier that must re-attest before it can land; the read path stays open
manifest_drifthooks stale, partial, or tampered — hash mismatchflagged; prompt a re-install; degrade to low-trust until the hash matches again

The invariant is simple: no un-attested action silently lands as if it were attested. The online observatory renders the attestation state alongside the work, so a superior sees the team's clients honoring the discipline — without inspecting anyone's machine or watching anyone work. The record vouches for the ritual, so people don't have to watch people.

Honest status: the foundation is shipping GRADED · LIVE — the key-based MCP auth that stamps every binding, the hook installers, the access-hook enforcement, and the immutable paper-trail. The attestation layer on top — the manifest hash, challenge/response, per-action tokens, and the trust tiers — is DECLARED · FRONTIER, a build ahead. The one part that had to be real, the manifest hash, is validated: a canonical hash over the installed hook set is deterministic today (recompute → identical).

THE CHARTER — WHAT SOLORA NEVER DOES

Some lines are never crossed.

Held in the contract and in the marketing alike: the lines around your record, and the lines around our own claims.

The nevers

  • Never let one tenant's commitments, conditions, test specs, reasoning traces, satisfier content, or grades cross into another tenant's record — or into a shared computation.
  • Never feed a customer's record into the cross-org graph or any shared corpus without explicit, revocable, scoped consent — and never beyond the aggregated, tenant-isolated form that consent covers.
  • Never fabricate a grade: an unresolved commitment is shown unresolved, a miss is kept, an abstain is an abstain.
  • Never overclaim integrity: the record is append-only and fully audit-trailed, not "unforgeable against a hostile insider."
  • Never claim more coverage than is published — the number a customer is quoted is the number the record earned.
That honesty is the whole product: a record is only worth trusting if it does not flatter itself.

Open where it can be. Sealed where it must be.

Read the whole record, walk the state machine, audit every grade — your record never depends on the one proprietary layer to be read.

PUBLIC ACCESS · SOON  The apparatus is live inside the house today; this is how it works.