Weights
Base and license lineage, immutable hashes, clean load, held-out evaluation, restart evidence, resource envelope.
diff --git a/.gitattributes b/.gitattributes index 7f823e21d25b4ad569e5fd8e27ac932829856dae..6a8e7f5b2897dcda8c2bd1009aa0fdc69c1e0406 100644 --- a/.gitattributes +++ b/.gitattributes @@ -1,45 +1,4 @@ -*.7z filter=lfs diff=lfs merge=lfs -text -*.arrow filter=lfs diff=lfs merge=lfs -text -*.bin filter=lfs diff=lfs merge=lfs -text -*.bz2 filter=lfs diff=lfs merge=lfs -text -*.ckpt filter=lfs diff=lfs merge=lfs -text -*.ftz filter=lfs diff=lfs merge=lfs -text -*.gz filter=lfs diff=lfs merge=lfs -text -*.h5 filter=lfs diff=lfs merge=lfs -text -*.joblib filter=lfs diff=lfs merge=lfs -text -*.lfs.* filter=lfs diff=lfs merge=lfs -text -*.mlmodel filter=lfs diff=lfs merge=lfs -text -*.model filter=lfs diff=lfs merge=lfs -text -*.msgpack filter=lfs diff=lfs merge=lfs -text -*.npy filter=lfs diff=lfs merge=lfs -text -*.npz filter=lfs diff=lfs merge=lfs -text -*.onnx filter=lfs diff=lfs merge=lfs -text -*.ot filter=lfs diff=lfs merge=lfs -text -*.parquet filter=lfs diff=lfs merge=lfs -text -*.pb filter=lfs diff=lfs merge=lfs -text -*.pickle filter=lfs diff=lfs merge=lfs -text -*.pkl filter=lfs diff=lfs merge=lfs -text -*.pt filter=lfs diff=lfs merge=lfs -text -*.pth filter=lfs diff=lfs merge=lfs -text -*.rar filter=lfs diff=lfs merge=lfs -text -*.safetensors filter=lfs diff=lfs merge=lfs -text -saved_model/**/* filter=lfs diff=lfs merge=lfs -text -*.tar.* filter=lfs diff=lfs merge=lfs -text -*.tar filter=lfs diff=lfs merge=lfs -text -*.tflite filter=lfs diff=lfs merge=lfs -text -*.tgz filter=lfs diff=lfs merge=lfs -text -*.wasm filter=lfs diff=lfs merge=lfs -text -*.xz filter=lfs diff=lfs merge=lfs -text -*.zip filter=lfs diff=lfs merge=lfs -text -*.zst filter=lfs diff=lfs merge=lfs -text -*tfevents* filter=lfs diff=lfs merge=lfs -text -hero.png filter=lfs diff=lfs merge=lfs -text -assets/08_body_graph.png filter=lfs diff=lfs merge=lfs -text -assets/a11oy_avatar.png filter=lfs diff=lfs merge=lfs -text -assets/amaru_avatar.png filter=lfs diff=lfs merge=lfs -text -assets/rosie_avatar.png filter=lfs diff=lfs merge=lfs -text -assets/sentra_avatar.png filter=lfs diff=lfs merge=lfs -text -assets/vessels_avatar.png filter=lfs diff=lfs merge=lfs -text -assets/szl_banner.png filter=lfs diff=lfs merge=lfs -text -assets/group_shot_v1.png filter=lfs diff=lfs merge=lfs -text -roster.png filter=lfs diff=lfs merge=lfs -text +*.svg text eol=lf +*.html text eol=lf +*.json text eol=lf +*.md text eol=lf diff --git a/HONEST_DISCLOSURE.md b/HONEST_DISCLOSURE.md index c52212f9eda01cbb633fdd9e6a911f2036dd4b18..5db572debaca6460950f13cd8c57cd04a64cbd86 100644 --- a/HONEST_DISCLOSURE.md +++ b/HONEST_DISCLOSURE.md @@ -1,25 +1,25 @@ -# What is honest right now — Doctrine v11 +# Honest disclosure -This is the standing honesty disclosure for SZL Holdings. We surface only machine-checked facts as fact; everything else is labeled experimental, conditional, or conjectured. +This static Space is the public Hugging Face front door for SZL Holdings. It +organizes links and describes publication contracts. It is not a model, +benchmark, customer deployment, certification, authorization to operate, or +independent third-party assessment. -**lutar-lean @ tag `lutar-v18.0.0` / `c7c0ba17`:** +## What the running page proves -- **749 declarations · 14 unique axioms · 163 tracked sorries** (112 baseline + 51 Putnam). `lake build` clean. -- **Locked proven set = 5 formulas** (Lean, sorry-free): **F1, F11, F12, F18, F19**. These are the only formulas we surface as "proven." -- **Λ (the trust aggregator) is Conjecture 1** unconditionally. **Unconditional** uniqueness is machine-checked **false** (Round13 `maxAgg_ne_Lambda`). It is proven **CONDITIONAL** on slice-multiplicativity (separability) under {A1,A2,A3,A5}, axiom-free — **CUT-2** (`lambda_unique_of_separable`, PR #202). Λ is never stated as an unconditional theorem. **Byzantine BFT safety is Conjecture 2**, not a theorem. -- **Experimental waves** (proof waves 5–14 + the agentic loop) live in experimental Lean scopes on `main` @ `b910c276`, are **CI-green** with every `#print axioms ⊆ {propext, Classical.choice, Quot.sound}`, but **excluded** from the locked v11 baseline. Through Wave 14: Wave 11 CF-1/2/3/5, Wave 12 CUT-2 + CF-13 + CF-17, Wave 13 replay-root + non-Byzantine vote + HM-bottleneck, Wave 14 CF-18/19/20/21. They are labeled experimental, never folded into the locked five. +- the static route was reachable at the time it was requested; +- the served `deployment.json` identifies a GitHub source revision; +- the declared source files can be compared with that revision and the Hub + commit recorded by the deployment workflow. -**Supply chain:** -- **SLSA L1 build provenance (honest)** on all service images — cosign-signed, verifiable via `cosign verify`. **SLSA L2 is on the roadmap; we do NOT claim L2-verified today.** **No** L2-verified / L3 / FedRAMP / Iron Bank / CMMC is claimed. -- The `szl-mesh` UDS bundle is **cosign-signed** (keyless OIDC). The GitHub attestation for the bundle itself was not minted (token scope); per-image cosign signatures are intact and verifiable. +## What it does not prove -**Receipts:** -- Decision receipts are **DSSE envelopes over a SHA-256 hash chain**. Where a signing key is present (the killinchu engagement surface carries a real ECDSA-P256 cosign key), receipts are **genuinely signed** and verifiable offline. Where no key is present, receipts are **honestly marked unsigned** — never fabricated. +- that every linked model loads or meets its intended quality threshold; +- that every dataset row has passed provenance and license admission; +- that every Space is healthy end to end; +- that a signature establishes accuracy, safety, compliance, or fitness; +- that Hub download events are unique users, customers, or deployments. -**Data honesty:** -- Maritime AIS on the field surface uses a clearly-labeled **sample/replay** dataset, not a live production feed. -- Live public feeds (CVE/NVD, CISA KEV, MITRE ATT&CK, USGS) are honestly attributed where shown. - -**Compliance posture:** Aligned with **EU AI Act Article 12** (record-keeping) + **NIST AI RMF (MANAGE)**. These are alignment statements, not certifications. - -*Built by Stephen P. Lutar Jr. · stephenlutar2@gmail.com · Doctrine v11 LOCKED.* +Each artifact owns its evaluation, provenance, security, and runtime evidence. +Unverified evidence must remain `UNKNOWN`, `PARTIAL`, or `UNAVAILABLE` rather +than being inferred from this organization card. diff --git a/README.md b/README.md index e3a348ccf0c74a1a6624160c54f5908275784edb..987d688a5b3b0c4b5dcf4410a3d7d8c5e36650d9 100644 --- a/README.md +++ b/README.md @@ -1,117 +1,135 @@ --- -title: SZL Holdings — Governed-AI Command Platform +title: SZL Holdings — Governed Decision Infrastructure emoji: 🛡️ colorFrom: gray colorTo: yellow sdk: static -short_description: Governed AI you can prove — signed, verifiable receipts +short_description: Governed AI that can explain, constrain, and verify action pinned: true +license: apache-2.0 --- - -
+# Governed models, data, and demonstrations
-# SZL Holdings
+SZL Holdings publishes the model and data layer for systems that must reason,
+act within authority, and return evidence another party can verify.
-### Governed AI you can prove.
+[**Open a11oy**](https://a-11-oy.com) ·
+[**Inspect evidence**](https://a11oy.net) ·
+[**View source**](https://github.com/szl-holdings) ·
+[**Read documentation**](https://holdings.a-11-oy.com/docs-site/)
-Models ship with signed training & eval receipts. Surfaces label every value — LIVE, MEASURED, REPORTED, or DEMO. Trust is measured — not asserted.
++--- -[](https://a-11-oy.com) -[](https://a-11-oy.com/holographic) -[](https://doi.org/10.5281/zenodo.19944926) -[](https://slsa.dev/spec/v1.0/levels) -[](https://a-11-oy.com) -[](https://doi.org/10.5281/zenodo.19944926) +## Start here -
+| Need | Canonical artifact | Boundary | +| --- | --- | --- | +| Governed receipt generation | [SZL-Forge-1.5B-ReceiptAgent](https://huggingface.co/SZLHOLDINGS/SZL-Forge-1.5B-ReceiptAgent) | A model artifact; autonomy requires a validating controller | +| Grounded estate navigation | [SZL-Khipu-1.5B](https://huggingface.co/SZLHOLDINGS/SZL-Khipu-1.5B) | Use cited retrieval and verify sources independently | +| Local quantized evaluation | [SZL-Khipu-1.5B-GGUF](https://huggingface.co/SZLHOLDINGS/SZL-Khipu-1.5B-GGUF) | Quantization changes runtime characteristics; evaluate the exact file | +| Receipt and evidence records | [szl-lake](https://huggingface.co/datasets/SZLHOLDINGS/szl-lake) | Records are admitted by their own provenance and license state | +| Public OSINT corpus | [killinchu-osint-corpus](https://huggingface.co/datasets/SZLHOLDINGS/killinchu-osint-corpus) | Public-source research corpus; not an operational intelligence feed | +| Product demonstration | [a11oy Space](https://huggingface.co/spaces/SZLHOLDINGS/a11oy) | A demonstration surface; verify live state and exact source separately | -**[🛡️ Enter a11oy →](https://a-11-oy.com)** · **[Browse 70+ live surfaces →](https://a-11-oy.com/holographic)** · **[Read Conjecture 1 →](https://doi.org/10.5281/zenodo.19944926)** +Download counters are Hub-reported events, not unique users, deployments, +customers, model quality, or revenue. - +## Artifact contract ---- +Every promoted artifact must identify what it is and what evidence exists. -## The one-of-one hook: models that ship with receipts +### Trained weights -Anyone can publish weights. We publish **proof**. Every SZL model carries its training and evaluation receipts in-repo — `training_receipt.signed.json` and `eval_receipt.signed.json`, **Ed25519 signatures over canonical JSON**, verifiable offline against the repo-declared public key. (The a11oy estate's daily operational receipts are a separate rail: DSSE envelopes, sigstore-keyless.) You can verify what a model was trained on and how it scored *before* you download it. That's the honesty doctrine, made checkable. +- exact base model and license lineage; +- weight or adapter hashes; +- clean load and inference receipt; +- held-out and adversarial evaluation; +- restart and reproduction evidence; +- latency, memory, and energy context; +- an explicit autonomy boundary. -- **LIVE** surfaces are live. **MEASURED** numbers are measured. **REPORTED** is reported. **DEMO** is a demo. We label which is which. -- The lattice is **exactly 8 locked-proven formulas** — {F1, F4, F7, F11, F12, F18, F19, F22}. Not 9. Not "soon." -- **Λ is Conjecture 1** — an open conjecture, never a theorem, never marked green. -- Trust tops out at **0.97**, never 100%. A ceiling is honest; certainty is not. +### Datasets ---- +- source and license provenance at row or source-family scope; +- schema, splits, sizes, and validation results; +- privacy, consent, PII, and update policy; +- known omissions, quarantine counts, and intended use. -## Start here +### Kernels and tools -### 🤖 Models — every one ships with signed receipts +- canonical source repository and immutable revision; +- supported hardware and software matrix; +- executable tests and benchmark protocol; +- no implied training receipt or model capability. -**Start with [SZL-Khipu-1.5B](https://huggingface.co/SZLHOLDINGS/SZL-Khipu-1.5B)** — a compact 1.5B model for governed agent navigation, and the fastest way to understand the whole estate: weights, signed receipts, public eval harness, and a local one-liner (`ollama run hf.co/SZLHOLDINGS/SZL-Khipu-1.5B-GGUF:Q4_K_M`) in one repo. +### Spaces -| Model | Base · Task | Traction (MEASURED all-time, 2026-07-21) | Notes | -|---|---|---|---| -| [**SZL-Khipu-1.5B**](https://huggingface.co/SZLHOLDINGS/SZL-Khipu-1.5B) | Qwen2.5 1.5B · governed navigation | **1,391** downloads (day-1: 1.03k) | **Start here.** Signed receipts + public harness; [GGUF →](https://huggingface.co/SZLHOLDINGS/SZL-Khipu-1.5B-GGUF) | -| [**SZL-Forge-1.5B-ReceiptAgent**](https://huggingface.co/SZLHOLDINGS/SZL-Forge-1.5B-ReceiptAgent) | Qwen2 1.5B · receipt agent | **2,026** downloads | Receipt-native sibling forge; signed receipts in-repo | -| [**SZL-Khipu-1.5B-GGUF**](https://huggingface.co/SZLHOLDINGS/SZL-Khipu-1.5B-GGUF) | quantized Khipu | **656** downloads | Q4_K_M · Q5_K_M · Q8_0 · F16; Ollama-ready; receipts travel | +- canonical source and deployment revision; +- pinned dependencies and runtime behavior; +- privacy and retention behavior; +- visible limitations and reproducible local path. -Counters are HF-reported all-time downloads, snapshotted daily → [szl-telemetry TRENDS](https://github.com/szl-holdings/szl-telemetry/blob/telemetry-data/TRENDS.md) (deltas DERIVED). +A model card is not operational proof. A Space in `RUNNING` state proves +transport availability only. A signed receipt establishes integrity and origin +within its stated scope; it does not automatically establish correctness, +safety, or authorization to operate. -### 📊 Datasets — 30 total, receipts on the record +## One governed loop -| Dataset | Downloads | What it is | -|---|---|---| -| [**killinchu-osint-corpus**](https://huggingface.co/datasets/SZLHOLDINGS/killinchu-osint-corpus) | **24,737** `MEASURED all-time 2026-07-21` | OSINT corpus behind the killinchu demo | -| [**a11oy-verifiable-corpus**](https://huggingface.co/datasets/SZLHOLDINGS/a11oy-verifiable-corpus) | **2,282** `MEASURED all-time 2026-07-21` | Verifiable-claims corpus for governed eval | -| [**szl-lake**](https://huggingface.co/datasets/SZLHOLDINGS/szl-lake) | **1,459** `MEASURED all-time 2026-07-21` | The Khipu receipt lake — published signed-receipt chain | +```text +signal → reason → policy → bounded action → receipt → independent verification + ↑ │ + └──────────── verified feedback ───────┘ +``` -### 🌐 Live surfaces +The model proposes. The controller validates authority and evidence. The +runtime executes only within a declared bound. The receipt lets a separate +party inspect what happened. -| Surface | Status | Link | -|---|---|---| -| **a11oy console** — the flagship | `LIVE` | [a-11-oy.com](https://a-11-oy.com) | -| **Holographic** — 70+ live surfaces | `LIVE` | [/holographic](https://a-11-oy.com/holographic) | -| **killinchu** — counter-UAS & maritime C2 demo | `DEMO` | [open →](https://szlholdings-killinchu.hf.space/) | -| **Estate hub** — live index of every Space | `LIVE` | [open →](https://szlholdings-szl-estate-live.static.hf.space) | +## Evidence language ---- +Claims use **PROVED**, **MEASURED**, **REPORTED**, **MODELED**, +**CONJECTURE**, or **ROADMAP**. Runtime status uses **OPERATIONAL**, +**PARTIAL**, **DEGRADED**, **UNAVAILABLE**, or **HISTORICAL**. -## Collections & highlights +Lambda uniqueness remains **Conjecture 1**, not a theorem. No artifact is +promoted solely because it has a card, a counter, a live route, or a filename +that sounds like a model. -
+This company front door is source-controlled at
+[`szl-holdings/.github`](https://github.com/szl-holdings/.github/tree/main/huggingface/org-card)
+and deployed with an exact source-revision manifest. Inspect
+[`deployment.json`](https://szlholdings-readme.static.hf.space/deployment.json)
+on the running static Space for the served source binding.
-A public index of every reachable surface in the SZL flagship mesh — five organs, the unified
- 4-pane operator shell, the formula corpus, the multi-LLM ensemble vote, and the provenance trail.
- Status pills below are live: each card probes its own /healthz in your browser.
- Endpoints that aren't live yet show gray — never faked.
SZL Holdings builds governed autonomy with a checkable receipt for every decision. Every autonomous - action carries a machine-checked, tamper-evident warrant — proof of under what authority - it acted, on what trust evidence, and that the record was not quietly rewritten.
- - - - - - - -The governed-AI console: ask-and-act behind deny-by-default gates, a live decision feed, and a - signed receipt for every action.
- - -Air-and-sea field demonstration: live track board, multi-sensor fusion, sanctions and dark-vessel - screening — with verify-it-yourself receipts (effector link is a labeled simulation).
- - -A 3D, navigable map of the governed organism — its organs, how a decision flows through them, - and where each proof and conjecture honestly sits.
- -Pull the public signing key and a signed receipt from a live field node, then verify offline:
-# pull the public key + a signed receipt from the live field node -curl -s https://szlholdings-killinchu.hf.space/cosign.pub -o cosign.pub -curl -s https://szlholdings-killinchu.hf.space/api/killinchu/v1/receipt/export > receipt.json -# verify the DSSE signature offline → "Verified OK" -# tamper a single byte and re-verify → "Verification failure"+
We surface only machine-checked facts as fact.
-• 8 formulas formally proven & locked in Lean (sorry-free):
- F1, F4, F7, F11, F12, F18, F19, F22 — this count never inflates. A larger experimental
- tier is kernel-clean / CI-green on main @ c7c0ba17 across Waves 11–23
- (axioms ⊆ propext / Classical.choice / Quot.sound), labeled experimental — never folded into the locked eight.
- • Λ uniqueness = Conjecture 1 — unconditional uniqueness is machine-checked false.
- The conditional uniqueness (Theorem U, on separability) is proven axiom-free.
- Khipu Byzantine BFT safety = Conjecture 2 (Wave23 proves a conditional quorum-agreement,
- axiom-clean; unconditional stays open).
- • SLSA L1 (honest) · L2 build-attested — container provenance via Sigstore keyless
- (Fulcio + Rekor) where attest-build-provenance runs & verifies (a11oy, killinchu);
- verify with gh attestation verify / cosign verify-attestation.
- L3, FedRAMP, Iron Bank, CMMC, ATO = roadmap.
- • Receipts are genuinely signed where a key is present, honestly marked unsigned otherwise —
- never fabricated. Trust is never 100%.
- • Maritime AIS uses a clearly-labeled sample/replay dataset, not a live feed.
Read the thesis → szl-papers
- · Run the kernel → lutar-lean
- · Deploy the mesh → uds deploy oci://ghcr.io/szl-holdings/szl-mesh:0.4.0 --confirm
Systems that can reason, act within a declared bound, and return evidence another party can verify.
+ +The model proposes. A policy layer validates authority and evidence. The runtime executes only within a declared bound. A portable receipt records the decision path for independent review.
+Models, datasets, tools, and demonstrations are different product objects. Each owns its license, lineage, evaluation, runtime, and limitation evidence.
+Compact receipt proposal artifact. Use with a validating controller; no autonomous or high-stakes boundary is implied.
Inspect the card → + + + Model familyGrounded estate-navigation model family. Pair with cited retrieval and independently inspect the source evidence.
Inspect the family → + + + Evidence datasetReceipt and evidence records with explicit admission boundaries. A stored row is not automatically training-admitted.
Inspect the lake → + + + Research datasetPublic-source research corpus for the operator demonstration. It is not an operational intelligence feed.
Inspect provenance → + + + Kernel registryRuntime and computation artifacts. Kernel source and executable tests do not imply trained model weights.
Inspect compatibility → + + + DemonstrationA public command-system surface. Running transport and operational capability remain separately evidenced.
Open the Space → + +- Client-side reads from the Hugging Face API at page load. Timestamps are HF's own - metadata, not our attestation. A failed fetch says so — it never fakes green. -
-Promotion requires exact lineage, hashes, load and inference evidence, evaluation, restart reproducibility, resource context, and an explicit autonomy boundary.
+Base and license lineage, immutable hashes, clean load, held-out evaluation, restart evidence, resource envelope.
Schema, splits, provenance, consent, PII posture, validation, quarantine, gaps, and update policy.
Canonical source, supported hardware matrix, executable tests, benchmark protocol, and non-model classification.
Source revision, dependency pins, served-revision binding, privacy behavior, limits, and a reproducible local path.
A signature establishes integrity and origin within scope. It does not automatically establish model quality, safety, regulatory compliance, profitability, or authorization to operate.
+This page is published from GitHub. The running Space exposes its source binding at /deployment.json.
Start with the product, follow the evidence, then reproduce the exact path from source.
+ +