Whitepaper

The trust boundary between AI intent and trusted physical reality.

SeedCore is a custody-aware trust boundary that decides whether AI-visible intent is denied, quarantined, or allowed to become a trusted real-world outcome.

The current whitepaper is best read through the narrow 2026 wedge: Restricted Custody Transfer, verification-first proof surfaces, and one partner-convincing trust story.

Deterministic PDPVerification SurfaceReplayable Proof
Platform Thesis

Intelligence can advise. Governance decides.

SeedCore is built for the trust boundary where AI-visible actions become either denied requests or explicitly authorized operations under deterministic policy.

The Problem Most AI infrastructure optimizes response generation, not trusted physical outcome control.

In high-consequence settings, weak authorization and fragmented evidence create compliance, safety, and trust failures.

The Shift SeedCore governs action instead of merely observing it.

Every consequential request is validated against identity, scope, policy, custody context, and risk posture before execution.

The Product Governed receipts and verifier outcomes become a visible trust surface.

High-value outcomes are captured as replayable, cryptographically anchored evidence that withstands external scrutiny.

Core Runtime

Three-layer architecture plus verification closure.

SeedCore separates intelligence, control, and reality while preserving policy sovereignty and proof integrity.

Brain & Intent (Top) Advisory Reasoning Plane

Humans and AI agents propose actions. They build candidate graphs, evaluate trade logistics, or request state changes, but hold zero authority to directly execute.

SeedCore Decider (Center) Stateless Policy Decision Point

The core trust slice. Evaluates actions against policies, verifies actor delegation chains, and decides whether a transition becomes admissible digital truth.

Sandboxes & Reality (Bottom) Physical & Economic Execution

Actuator endpoints, robotics controllers, and settlement ledgers execute authorized commands and emit telemetry. Trusted-edge target profiles add TPM 2.0 or KMS-backed signatures.

Control Stack

Delegation, intent, execution authority, verification, and replay.

This flow turns AI-visible behavior into governable operational action.

Delegation and Identity

[Active RCT Runtime] Operator and administrative ingress uses Google IAP. [Target] Programmatic APIs move toward workload-level SPIFFE/SPIRE identities and DPoP tokens.

Intent Object

[Active RCT Runtime] Each action explicitly declares target, purpose, and context. [Target Sidecar] Logistics backends (cuOpt) act as advisory sidecars only, never as a source of authority.

Deterministic Decision

[Active RCT Runtime] Checks policy synchronously against bounded context. [Target Graphs] In-memory Decision Graph processing remains the target hot-path shape, with offline Enrichment Graphs for metadata and explanation.

ExecutionToken & Edge Profiles

[Active RCT Runtime] Mints short-lived execution authority. Jetson-class nodes serve prototype validation lanes. [Target Edge] Production trusted-edge profiles target NVIDIA IGX Thor / T5000-class deployments.

Verification, Replay & Cache

[Active Preview] Replay contracts can carry freshness markers plus prior_state_binding, result_state_binding, and causal_parent_refs. [Target Scale] Dragonfly client-side caching is a target acceleration layer.

Current Wedge

Start with Restricted Custody Transfer and verification-first proof.

SeedCore's first wedge is a custody-sensitive multi-party workflow where trust must be enforced at runtime, not reconstructed after the fact.

Provenance as Runtime Control Move beyond static traceability to live execution gating.

Actions are authorized only when current actor, device, asset, and context satisfy policy at decision time.

Restricted Custody Transfer Prioritize custody transitions where failure has real cost.

Dual approvals, delegated authority chains, verifier-backed failure, and break-glass handling become first-class flows.

Third-Party Verification Trust outcomes should be independently reviewable.

Partners and auditors can inspect the same signed receipts and replay sequence used internally.

2026 Working Plan

Ship one convincing trust story before broadening the platform.

The next stage focuses on productizing irrefutable governed execution through four practical phases.