How it works
One record, in the inference path.
An agent harness points at a Syderial door as its provider. Every turn passes six stations, and each one writes to the same signed record. Syderial decides what the model is given and what the agent may do.
The inference path
Three doors. Any model.
Syderial serves chat completions, messages and responses, streamed and cited. Models run on our own GPU hosts, or with your provider through a tenant alias. The record is the same either way.
Agent
Any model, framework or tool. Its provider is a Syderial door.
Syderial
Six stations write one signed record. Chat completions, messages and responses come back streamed and cited.
- 01Capture
- 02Bound
- 03Entail
- 04Compile
- 05Gate
- 06Receipt
Model
Models on our own GPU hosts, or your provider through a tenant alias.
Agent
A cited answer, or an honest “I do not know”. The record keeps both.
Six stations
Capture, Bound, Entail, Compile, Gate, Receipt.
- 01
Capture
Every turn, with its author.
Hooks in the agent harness capture every turn with the person or agent who wrote it. Existing journals and notes post as entries, and connectors keep each source's own record identity.
- 02
Bound
Labels on every fact, information flow on every read.
Every claim has a label. A reader sees it only when the reader's clearance dominates that label on every axis.
- 03
Entail
Evidence must support the claim.
A typed decider asks small, typed questions of each proposed line, then places it in one of four bands: commit, propose, quarantine or degraded. Nothing disappears without a trace.
- 04
Compile
A hashed packet, not a prompt dump.
Syderial answers each question from a bounded, hashed packet of the context of record, citing the signed spans the reader may see.
- 05
Gate
Policy before any tool call runs.
Syderial checks every tool call against its reach ceiling, then allows it, sends it for approval or denies it before anything runs. The same rule governs a read.
- 06
Receipt
Signed, hash-chained, independently verifiable.
Every commit is signed and chained to the one before it. Every answer returns a serving receipt. Replay and verification run in your console and offline.
The write path
Nothing enters the record until its evidence supports it.
A typed decider asks small, typed questions of each proposed line. Who owns it? Does the evidence support it? What does it predicate? Who is it attributed to? Is it atomic? Is it asserted as actual? Then it places the line in one of four bands.
Three posting lanes write to the journal: a reader, for a software agent’s reading; a principal, for a person’s own word; and an import, for existing journals and notes. Every posting names its poster, its trigger and its receipt.
The read path
A packet, not a prompt dump.
Syderial answers each question from a bounded, hashed packet of the context of record. The answer cites the signed spans it used. When the record doesn’t know, the answer says so, with a receipt.
Syderial checks every answer against the record as it streams. Entailment is on by default. A tenant may make it optional, and Syderial never skips it silently.
The gate
Policy before any tool call runs.
Logs say what an agent did. An asset operator needs to know what it was allowed to do, before it did it.
Policy is information flow control applied to actions. The rule that decides whether a reader may see a claim also decides whether an agent may act on it.
- Syderial checks every tool call against its reach ceiling.
- It allows the call, sends it for approval or denies it before anything runs.
- An action waiting for approval shows what, why, the evidence, the labels and the blast radius. The person confirms it under their own credential.
Governance
One record, four graphs, policy first.
Syderial rebuilds four graphs from the record: permissions, entities, ontology, and capability and provenance. They meet only at shared keys. A read crosses them in order. Who may see? What is it about? Which policy applies? What may act?
- Tenant boundary forests and sensitivity ladders, from a template.
- A reach ceiling for every tool and agent.
- Chinese walls, released only by two people.
- Connectors that inherit the source’s access controls.
Evidence you can check
Every commit is signed. Every answer returns a receipt.
- Lines cite evidence. A quote of retained source, by start, end and a hash of the text, or a pointer to an entry.
- Commits are chained. Each commit includes the hash of the one before it and an Ed25519 signature. Signing keys never leave a KMS.
- Answers cite signed spans. Every door returns signed citations and a serving receipt.
- Endorsements and ratifications are signed. The audit chain records the act beside the entry it posted.
- History stays. A superseded entry remains beside its replacement, both clocks intact.
- Verifiable outside the tenant. Independent RFC 3161 timestamp authorities anchor each chain, and it verifies offline.
How it runs
One record, served through three doors.
Journal
The record
Every entry, label and receipt, posted once and signed.
Three
Doors
Chat completions, messages and responses, streamed and cited.
Hooks
Capture
Hooks in the agent harness capture every turn with its author.
MCP
Signed in
An MCP door signs callers in under their own identity.
Spark
Own GPU hosts
Models run on our own DGX Spark GPU hosts.
Any model
Your provider
Or your provider, through a tenant alias.
KMS
Signing keys
Signing keys never leave a KMS.
RFC 3161
Independent time
Independent timestamp authorities anchor every chain.
Early access
Keep the record of one workflow.
Early access is for design partners: operators of long-lived regulated assets, one bounded workflow each.