How it works

One record, in the inference path.

An agent harness points at a Syderial door as its provider. Every turn passes six stations, and each one writes to the same signed record. Syderial decides what the model is given and what the agent may do.

The inference path

Three doors. Any model.

Syderial serves chat completions, messages and responses, streamed and cited. Models run on our own GPU hosts, or with your provider through a tenant alias. The record is the same either way.

Agent

Any model, framework or tool. Its provider is a Syderial door.

Syderial

Six stations write one signed record. Chat completions, messages and responses come back streamed and cited.

  1. 01Capture
  2. 02Bound
  3. 03Entail
  4. 04Compile
  5. 05Gate
  6. 06Receipt

Model

Models on our own GPU hosts, or your provider through a tenant alias.

Agent

A cited answer, or an honest “I do not know”. The record keeps both.

Figure 1. The inference path, for one agent turn. People, models and vendors change. The record of what each claimed stays.

Six stations

Capture, Bound, Entail, Compile, Gate, Receipt.

  1. 01

    Capture

    Every turn, with its author.

    Hooks in the agent harness capture every turn with the person or agent who wrote it. Existing journals and notes post as entries, and connectors keep each source's own record identity.

  2. 02

    Bound

    Labels on every fact, information flow on every read.

    Every claim has a label. A reader sees it only when the reader's clearance dominates that label on every axis.

  3. 03

    Entail

    Evidence must support the claim.

    A typed decider asks small, typed questions of each proposed line, then places it in one of four bands: commit, propose, quarantine or degraded. Nothing disappears without a trace.

  4. 04

    Compile

    A hashed packet, not a prompt dump.

    Syderial answers each question from a bounded, hashed packet of the context of record, citing the signed spans the reader may see.

  5. 05

    Gate

    Policy before any tool call runs.

    Syderial checks every tool call against its reach ceiling, then allows it, sends it for approval or denies it before anything runs. The same rule governs a read.

  6. 06

    Receipt

    Signed, hash-chained, independently verifiable.

    Every commit is signed and chained to the one before it. Every answer returns a serving receipt. Replay and verification run in your console and offline.

The write path

Nothing enters the record until its evidence supports it.

A typed decider asks small, typed questions of each proposed line. Who owns it? Does the evidence support it? What does it predicate? Who is it attributed to? Is it atomic? Is it asserted as actual? Then it places the line in one of four bands.

Three posting lanes write to the journal: a reader, for a software agent’s reading; a principal, for a person’s own word; and an import, for existing journals and notes. Every posting names its poster, its trigger and its receipt.

commitEnters the record, signed and chained.
proposeServed as a labeled lead until a person posts it with a signed endorsement.
quarantineKept out of answers and shown to the people who review it.
degradedThe check couldn't run, and the record says so.
Figure 2. The four bands. A person endorses a lead with a signature; quarantine is shown, never dropped silently.

The read path

A packet, not a prompt dump.

Syderial answers each question from a bounded, hashed packet of the context of record. The answer cites the signed spans it used. When the record doesn’t know, the answer says so, with a receipt.

Syderial checks every answer against the record as it streams. Entailment is on by default. A tenant may make it optional, and Syderial never skips it silently.

  1. Preflight. Syderial resolves what this reader may see, for this purpose.
  2. Select. A bounded, ranked, hashed packet of claims.
  3. Expand. The signed spans behind each claim that the reader may see.
  4. Compose. The chosen model writes the answer.
  5. Cite. Signed citations and a serving receipt, or an honest "I don't know".
Figure 3. One question, answered.

The gate

Policy before any tool call runs.

Logs say what an agent did. An asset operator needs to know what it was allowed to do, before it did it.

Policy is information flow control applied to actions. The rule that decides whether a reader may see a claim also decides whether an agent may act on it.

  • Syderial checks every tool call against its reach ceiling.
  • It allows the call, sends it for approval or denies it before anything runs.
  • An action waiting for approval shows what, why, the evidence, the labels and the blast radius. The person confirms it under their own credential.

Governance

One record, four graphs, policy first.

Syderial rebuilds four graphs from the record: permissions, entities, ontology, and capability and provenance. They meet only at shared keys. A read crosses them in order. Who may see? What is it about? Which policy applies? What may act?

  • Tenant boundary forests and sensitivity ladders, from a template.
  • A reach ceiling for every tool and agent.
  • Chinese walls, released only by two people.
  • Connectors that inherit the source’s access controls.
Figure 4. Four graphs, rebuilt from the record. They meet only at shared keys: tenant, boundary, entity.

Evidence you can check

Every commit is signed. Every answer returns a receipt.

answer
cited · signed spans
packet
sha256 3be1…9a0c
clearance
operations · plant-2 · rank 2
signed
ed25519 · prev 9f1c…a204
timestamp
RFC 3161 · independent authority
Figure 5. A serving receipt. Examples are illustrative.
  • Lines cite evidence. A quote of retained source, by start, end and a hash of the text, or a pointer to an entry.
  • Commits are chained. Each commit includes the hash of the one before it and an Ed25519 signature. Signing keys never leave a KMS.
  • Answers cite signed spans. Every door returns signed citations and a serving receipt.
  • Endorsements and ratifications are signed. The audit chain records the act beside the entry it posted.
  • History stays. A superseded entry remains beside its replacement, both clocks intact.
  • Verifiable outside the tenant. Independent RFC 3161 timestamp authorities anchor each chain, and it verifies offline.

How it runs

One record, served through three doors.

Journal

The record

Every entry, label and receipt, posted once and signed.

Three

Doors

Chat completions, messages and responses, streamed and cited.

Hooks

Capture

Hooks in the agent harness capture every turn with its author.

MCP

Signed in

An MCP door signs callers in under their own identity.

Spark

Own GPU hosts

Models run on our own DGX Spark GPU hosts.

Any model

Your provider

Or your provider, through a tenant alias.

KMS

Signing keys

Signing keys never leave a KMS.

RFC 3161

Independent time

Independent timestamp authorities anchor every chain.

Early access

Keep the record of one workflow.

Early access is for design partners: operators of long-lived regulated assets, one bounded workflow each.