AISOS

Volume 1 · Platform Constitution

The trust kernel every AI operation must pass through.

AISOS is not a model and not a wrapper. It is a mediation boundary: eleven semantic calls, a trust-label algebra, deny-by-default admission control, prompt and output firewalls, argument-bound capabilities and a hash-chained evidence ledger. The question stops being which model you use and becomes whether your AI application runs on AISOS.

Active bundle

core.baseline.v4

Bundle digest

650c3af1caf5c50d

Kernel calls

11

Attested endpoints

6/7

Mediated requests

0

this session

Refusals

0

operations that did not occur

Ledger records

0

chain intact

Live endpoints

3

real upstream inference

Kernel boundary — the eleven semantic calls

01

sem_open

02

sem_spawn

03

sem_ingest

04

sem_infer

05

sem_retrieve

06

sem_recall

07

sem_remember

08

sem_invoke

09

sem_verify

10

sem_emit

11

sem_close

No AI operation exists outside these calls. Anything that bypasses them is, by definition, outside the trust boundary and is refused at the gate.

Governing principles

deny
  • P1

    Deny by default

    Absent an explicit permit rule whose label floor is satisfied, the operation does not occur.

  • P2

    Data is never instruction

    Retrieved text enters at I0 and cannot be promoted into instruction position by its own content.

  • P3

    Label arithmetic, not guesswork

    Integrity falls, confidentiality rises. Injection becomes an arithmetic violation, not a detection gamble.

  • P4

    Every verdict is accountable

    Policy id, rule, object, label path, remediation and bundle digest — sealed into an append-only chain.