The operating model

One model, instantiated per industry

EcoKure is not a different product in each sector. It is one operating model applied to different controls, different environments and different failure modes. This page is the model. The industry pages show what it looks like once the domain is filled in.

The model

Six steps, in order, and none of them optional

Steps four and five are the ones organisations usually discover they are missing. A decision that cannot be reconstructed later is an opinion with a timestamp on it.

Rule or policy change regulation, control, threshold Source evidence change dataset, structure, reference DCLA what does it affect? DELA affected vs preserved DTL is it allowed? accept / block / abstain DAX may it execute? fail-closed boundary Signed evidence what happened, and why checkable without us then record
01

Define the control

What must be true before this is allowed?

An obligation, a limit or an operating envelope is written as a machine-readable rule with an owner, a version, effective dates and its own test cases. A rule with no named owner and no failing test is not a control, it is a preference.

DCLA · Deterministic Control Lineage Architecture →
02

Evaluate

Does this specific output satisfy it?

The probabilistic system proposes. A separate deterministic lane checks the proposal against the rule. The verifier is designed as an independent deterministic control path and does not rely on the proposing system to validate its own output.

DTL · Deterministic Taxonomy Lanes →
03

Decide

Allow, block, or decline to answer?

Three outcomes, not two. Abstention is a first-class result: when the inputs are insufficient the lane says so rather than guessing. A system that can only allow or block will eventually allow something it could not actually check.

DTL · Deterministic Taxonomy Lanes →
04

Attest

What is the record, and who can read it?

Inputs, rule version, verdict, reason code and timestamp are hashed and signed, then anchored in a tamper-evident chain. The public key is published, so the record can be checked by someone with no access to our source code and no relationship with us.

DELA · Deterministic Evidence Lineage Architecture →
05

Replay

Can this decision be reconstructed later?

The same inputs and the same rule version reproduce the same verdict, byte for byte. A result that cannot be reproduced cannot be validated, which is why replay comes before any performance claim rather than after it.

DTL · Deterministic Taxonomy Lanes →
06

Detect change

What did this change invalidate?

When a rule changes, DCLA identifies the decisions taken under the old one. When source evidence changes, DELA separates the conclusions that are now stale from those that still hold. Affected work is held rather than allowed to continue quietly.

DCLA · Deterministic Control Lineage Architecture →
Environment discipline

Evidence carries the environment it was produced in, and cannot promote itself

Evidence produced on a development host cannot be labelled as evidence from a representative environment, and representative evidence cannot be labelled as target evidence. The build refuses to emit the higher classification when the conditions for it are absent. Where a target tier is empty below, it is empty because the work has not been done.

DEVHOST
A development machine. Useful for building software, never cited as evidence for anything.
<DOMAIN>_REP
A frozen build under controlled conditions that represent the target. Real evidence, correctly labelled as representative rather than as the target itself.
TARGETREP_<X>
The actual target environment, usually one a partner or customer controls. Empty until it is genuinely populated, and left visibly empty rather than approximated.

Why this matters more than any individual result

Most assurance claims fail not because the test was wrong but because the environment was flattered. A local emulator becomes "cloud". A bench rig becomes "flight representative". Once that slippage is in a document it is almost impossible to detect from outside. Making the classifier part of the build, so it refuses to emit a label the conditions do not support, is the single control that makes the rest of our evidence worth reading.

Evidence by programme

The same model, three programmes, three very different amounts of evidence

Deliberately not aggregated. An overall figure would let the strongest programme carry the weakest, which is exactly the thing this register exists to prevent.

Enterprise assurance

TARGETREP_AWS

The target-representative AWS run is now recorded alongside the local capability register. It is target-environment evidence, not production customer validation or certification.

Frozen regression suite
Evidenced
Runs on every build. A failure blocks the baseline seal.
Capability register
Partial
28 of 34 capabilities evidenced. The remaining six are listed with their blockers rather than rounded up.
Signing-key custody
Evidenced
AWS KMS ECC_NIST_P256 was configured and independently checked through GetPublicKey.
Target-representative cloud
Evidenced
AWS ap-southeast-2: 117,290 completed verifications, 0 performance errors, 128.1 verifications/sec soak and clean Terraform teardown.

Life sciences

PARTNER_INTEGRATION

The strongest external evidence we hold, and still an integration audit by the integrating party rather than an independent one.

Partner integration suite
Evidenced
126 integration tests passing inside a third party's platform. Their suite, their environment, our engine.
Adversarial correctness
Evidenced
Zero gate bypasses across 395 adversarial inputs. Correctness-adversarial, not load-adversarial, and the distinction matters.
Evidence-change detection
Partial
100 of 100 on a set we selected. An internal research result, not validation.
Regulatory certification
Not claimed
None held. Controls are built to be auditable, which is a different claim.

Mission-critical systems

MISSION_CRITICAL_EDGE_REP

The newest programme and the one with the least evidence. The fault-injection benchmark is the honest weak point and is described as such on the programme page.

Unit and attestation suite
Evidenced
83 tests passing, including the bitflip sweep, signature transplant and attacker-key forgery cases.
Fault-injection benchmark
Under remediation
OrbitGate prototype benchmark, under active validation. Corpus reproduction 101 of 160, up from 54. Frozen at v0.x rather than tuned further, because the rules were developed with the labels visible. Not used as evidence of aerospace readiness. The next result comes from a blind, partly partner-defined fault set.
Representative edge hardware
Pending
No run exists on this tier.
Aerospace hardware-in-the-loop
Pending
Requires a partner environment.
Radiation qualification
Not performed
Not performed, and outside what software testing can establish.

The full claims register and retraction record →

Start with one workflow

Pick a decision where a change in rules or evidence has already cost you work, or an action where the permission matters more than the explanation. Thirty minutes on that is worth more than a demonstration.

Next · Verify the result Evidence & Replay