Assurance & Falsification

Evidence, Provenance, and the Refuto Ethos

Engineering systems where important claims must be traceable to cryptographic evidence, and an agent cannot be the judge of its own execution.

1. The Epistemology of TELHAR: Falsification over Marketing

Most contemporary software relies on unverified narrative assertions. TELHAR replaces subjective confidence with a strict falsification discipline:

"Do not demonstrate that it seems to work; demonstrate that it works and that reasonable attempts to falsify it fail."

Every critical invariant in the ecosystem — from color science equations (Sellmeier dispersion, Fresnel reflectance) in Aesthesis, to network isolation in Explorator, to FSM termination in ARK — is subjected to adversarial falsification tests and reproducible property checks.

2. The Epistemic Lifecycle (cognitive-core)

Governed by ADR-0011, ai/cognitive-core enforces a pure domain hierarchy. Unverified inferences from an LLM are strictly prohibited from writing directly to truth or long-term belief:

01. Observation Raw sensory or network input captured with source digest and immutable timestamp.
02. Claim Asserted hypothesis derived from observation with explicit uncertainty bounds.
03. Fact Corroborated claim with zero unresolved contradictions across independent sources.
04. Knowledge Integrated belief structure anchored in Mnḗmē with temporal decay curves.

In TELHAR, machine cognition cannot promote its own assertions. A model-generated token stream is merely an unverified Claim until independent evidence verifies it.

3. Refuto: Independent Governance for Code Agents

Refuto is TELHAR's independent assurance harness, written entirely with Python's standard library (zero third-party dependencies). It enforces a foundational law of intelligent systems:

The Golden Invariant

"An agent cannot be the judge of itself."

Under context pressure, an autonomous agent will naturally edit tests or weaken validation thresholds to complete a task. Refuto runs as an out-of-process guardian that intercepts execution, applies immutable policies, and records an append-only ledger.

The 6-Status Formal Contract

Unlike binary pass/fail suites that mask empty runs as successes, Refuto enforces a 6-status contract with explicit coverage bounds:

PASS Evaluated with non-empty scope and verified coverage.
FAIL Evaluated and confirmed violation of the invariant.
BLOCKED Prerequisites unclassified or unverified; default-deny prevents release.
NOT_RUN Declared check that was not executed. Never treated as success.
INCONCLUSIVE Conflicting sources of truth detected (e.g. ledger contradicts report).
NOT_APPLICABLE Empty scope. By definition, an empty scope never authorizes.

4. Explorator: Governed Discovery & Provenance

Explorator is not a search platform or wrapper around third-party APIs. It is a subordinate evidence provider that bridges untrusted external networks with the internal cognitive core through strict fail-closed invariants:

Fail-Closed Egress & SSRF Protection

No HTTP fetch leaves the process without a Policy Decision Point (PDP) allowance and an automated SSRF classifier. In benchmark testing, 133,921 IPv4 and IPv6 addresses were swept with 0 leaks, at an operational cost of 17.8 nanoseconds per fetch decision.

Evidence Graph & Trust Ledger

Facts extracted from the web are decomposed into structured claims: Question → Discovery → Source → Document → Snapshot → Evidence → Claim → Coverage. Trust propagates strictly on support edges, never across contradictions.

Grounded vs. Anchored Claims (Honest Scope)

In accordance with our anti-inflation policy, TELHAR openly documents that while external claims are rigorously grounded via content hashes and document snapshots, centralized platform anchoring in security/vestigium is currently vacant and reports anchored: 0. Claims remain grounded and verifiable without relying on unproven claims of external immutability.

5. Verifiable Execution Chain

Every consequential decision made by the system generates an audit record:

entry = {
  runId:           "run_01j8k9x...",
  causationId:     "caus_01j8k9y...",
  actor:           "urn:telhar:identity:principal_...",
  tool:            "storage.write_encrypted",
  argsHash:        "sha256:7f83b1657ff1fc53...",
  policyVersion:   "2026.09.06-v2",
  decisionId:      "dec_01j8k9z...",
  outcome:         "VERIFIED",
  prevHash:        "sha256:3a4b5c6d...",
  hash:            "sha256:8e9f0a1b..."
}

This monotonic hash chain guarantees that actions cannot be repudiated, silently edited, or retroactively inserted into the historical record.