AISOS
Volume 1 · Platform Constitution
The trust kernel every AI operation must pass through.
AISOS is not a model and not a wrapper. It is a mediation boundary: eleven semantic calls, a trust-label algebra, deny-by-default admission control, prompt and output firewalls, argument-bound capabilities and a hash-chained evidence ledger. The question stops being which model you use and becomes whether your AI application runs on AISOS.
Active bundle
core.baseline.v4
Bundle digest
650c3af1caf5c50d
Kernel calls
11
Attested endpoints
6/7
Mediated requests
0
this session
Refusals
0
operations that did not occur
Ledger records
0
chain intact
Live endpoints
3
real upstream inference
Kernel boundary — the eleven semantic calls
01
sem_open
02
sem_spawn
03
sem_ingest
04
sem_infer
05
sem_retrieve
06
sem_recall
07
sem_remember
08
sem_invoke
09
sem_verify
10
sem_emit
11
sem_close
No AI operation exists outside these calls. Anything that bypasses them is, by definition, outside the trust boundary and is refused at the gate.
Governing principles
deny- P1
Deny by default
Absent an explicit permit rule whose label floor is satisfied, the operation does not occur.
- P2
Data is never instruction
Retrieved text enters at I0 and cannot be promoted into instruction position by its own content.
- P3
Label arithmetic, not guesswork
Integrity falls, confidentiality rises. Injection becomes an arithmetic violation, not a detection gamble.
- P4
Every verdict is accountable
Policy id, rule, object, label path, remediation and bundle digest — sealed into an append-only chain.