One model, instantiated per industry
EcoKure is not a different product in each sector. It is one operating model applied to different controls, different environments and different failure modes. This page is the model. The industry pages show what it looks like once the domain is filled in.
Six steps, in order, and none of them optional
Steps four and five are the ones organisations usually discover they are missing. A decision that cannot be reconstructed later is an opinion with a timestamp on it.
Define the control
What must be true before this is allowed?
An obligation, a limit or an operating envelope is written as a machine-readable rule with an owner, a version, effective dates and its own test cases. A rule with no named owner and no failing test is not a control, it is a preference.
DCLA · Deterministic Control Lineage Architecture →Evaluate
Does this specific output satisfy it?
The probabilistic system proposes. A separate deterministic lane checks the proposal against the rule. The verifier is designed as an independent deterministic control path and does not rely on the proposing system to validate its own output.
DTL · Deterministic Taxonomy Lanes →Decide
Allow, block, or decline to answer?
Three outcomes, not two. Abstention is a first-class result: when the inputs are insufficient the lane says so rather than guessing. A system that can only allow or block will eventually allow something it could not actually check.
DTL · Deterministic Taxonomy Lanes →Attest
What is the record, and who can read it?
Inputs, rule version, verdict, reason code and timestamp are hashed and signed, then anchored in a tamper-evident chain. The public key is published, so the record can be checked by someone with no access to our source code and no relationship with us.
DELA · Deterministic Evidence Lineage Architecture →Replay
Can this decision be reconstructed later?
The same inputs and the same rule version reproduce the same verdict, byte for byte. A result that cannot be reproduced cannot be validated, which is why replay comes before any performance claim rather than after it.
DTL · Deterministic Taxonomy Lanes →Detect change
What did this change invalidate?
When a rule changes, DCLA identifies the decisions taken under the old one. When source evidence changes, DELA separates the conclusions that are now stale from those that still hold. Affected work is held rather than allowed to continue quietly.
DCLA · Deterministic Control Lineage Architecture →Evidence carries the environment it was produced in, and cannot promote itself
Evidence produced on a development host cannot be labelled as evidence from a representative environment, and representative evidence cannot be labelled as target evidence. The build refuses to emit the higher classification when the conditions for it are absent. Where a target tier is empty below, it is empty because the work has not been done.
Why this matters more than any individual result
Most assurance claims fail not because the test was wrong but because the environment was flattered. A local emulator becomes "cloud". A bench rig becomes "flight representative". Once that slippage is in a document it is almost impossible to detect from outside. Making the classifier part of the build, so it refuses to emit a label the conditions do not support, is the single control that makes the rest of our evidence worth reading.
The same model, three programmes, three very different amounts of evidence
Deliberately not aggregated. An overall figure would let the strongest programme carry the weakest, which is exactly the thing this register exists to prevent.
Enterprise assurance
TARGETREP_AWSThe target-representative AWS run is now recorded alongside the local capability register. It is target-environment evidence, not production customer validation or certification.
Life sciences
PARTNER_INTEGRATIONThe strongest external evidence we hold, and still an integration audit by the integrating party rather than an independent one.
Mission-critical systems
MISSION_CRITICAL_EDGE_REPThe newest programme and the one with the least evidence. The fault-injection benchmark is the honest weak point and is described as such on the programme page.
What changes between sectors, and what does not
The controls, the environment tiers and the failure modes change. The six steps, the three verdicts and the signed record do not.
Regulated life sciences
The evidence changed. What does that affect?
Secondary discoveryFinancial services and insurance
The control changed. Which decisions are now unsupported?
Longer-term pathwayAerospace and safety-critical operations
Should this action be allowed to execute at all?
Start with one workflow
Pick a decision where a change in rules or evidence has already cost you work, or an action where the permission matters more than the explanation. Thirty minutes on that is worth more than a demonstration.
