Four layers, four questions
Together they control what AI is permitted to decide or execute, and produce independently verifiable evidence of what occurred, under which rules and using which evidence.
// returned by the lane, signed before it is returned { "verdict": "accept", "lane": "dela.evidence-change", "reason": "material change in coordinates; 3 dependent analyses affected", "inputs": { "current": "sha256:9f2c…a71d", "candidate": "sha256:4b80…c2e9" }, "impact": { "affected": 3, "preserved": 41, "replayed": 3, "held_for_review": 1 }, "deterministic": true, "chain": { "index": 18274, "prev": "sha256:0c15…8fa2" }, "sig": "ed25519:7d41c0…9b3e" }
A verdict as returned. Categorical, not probabilistic, with the dependency impact and a signature checkable against the published key.
Four questions a regulated organisation has to answer
Existing systems record versions and produce governance reports. They do not answer these, quickly, with evidence a third party can check.
Deterministic Taxonomy Lanes
Is this output or decision allowed?
DTL routes an output or decision into a defined verification lane, applies machine-readable rules, and returns a categorical result with the reasoning recorded. It does not score confidence. It decides, or it declines to decide.
DAXDeterministic Action Execution
Is this physical action allowed to happen?
DAX places a permission boundary between a decision and an action that affects hardware, machinery, infrastructure or another physical system. It is fail-closed: if the check cannot complete, the action does not proceed.
DCLADeterministic Control Lineage Architecture
The governing rules changed. What does that affect?
DCLA tracks changes to regulations, policies, controls and operating requirements, then identifies the systems, decisions, evidence and previous approvals that may need reassessment. Affected work is held rather than allowed to continue on a superseded rule.
DELADeterministic Evidence Lineage Architecture
The underlying evidence changed. What does that affect?
DELA detects changes in scientific, operational or other source evidence, traces the affected dependencies, preserves the work that remains valid, selectively replays reproducible operations, and routes non-reproducible work to qualified human review.
How the layers connect
It surrounds your systems. It does not replace them.
Receives
- AI model outputs and workflow decisions
- Scientific and operational source evidence
- Control and policy states
- Proposed physical actions
Processes
- Normalisation into machine-readable components
- Control and evidence change analysis
- Deterministic lane execution
- Action permission where execution is physical
Returns
- A categorical verdict, or an explicit abstention
- The affected set and the preserved set
- A qualified review queue
- A signed evidence pack
What EcoKure is not
Not a general-purpose AI model. Not a replacement for your governance, risk and compliance platform, your quality management system or your scientific tooling. Not a certification. It sits around the systems you already run and produces checkable evidence about them.
Enterprise deployment
| Concern | Position |
|---|---|
| Deployment model | Cloud, on your own infrastructure, or hybrid. The verification lanes are deterministic and do not require an external inference call. |
| Data residency | Lanes can run entirely inside your network. Where they do, no output, evidence or prompt leaves it. |
| Tenancy | Multi-tenant with isolation, or single tenant on your infrastructure. |
| Evidence signing | Ed25519 signatures with a tamper-evident chain. A third party can verify a pack without our source and without trusting us. |
| Availability behaviour | Fail-closed. An unreachable gate is recorded as unavailable, never as a pass. This is the property auditors ask about first. |
| Integration | A metered API, with connectors defined per workflow during a pilot rather than assumed in advance. |
| Certification | Controls are built to be auditable. EcoKure holds no certification today, and says so rather than implying otherwise. |
Start with one workflow
The useful first conversation is thirty minutes on a workflow where a change in rules or evidence has already cost you work, so both sides can tell quickly whether this is worth pursuing.
