1. The Epistemology of TELHAR: Falsification over Marketing
Most contemporary software relies on unverified narrative assertions. TELHAR replaces subjective confidence with a strict falsification discipline:
"Do not demonstrate that it seems to work; demonstrate that it works and that reasonable attempts to falsify it fail."
Every critical invariant in the ecosystem — from color science equations (Sellmeier dispersion, Fresnel reflectance) in Aesthesis, to network isolation in Explorator, to FSM termination in ARK — is subjected to adversarial falsification tests and reproducible property checks.
2. The Epistemic Lifecycle (cognitive-core)
Governed by ADR-0011, ai/cognitive-core enforces a pure domain hierarchy. Unverified inferences from an LLM are strictly prohibited from writing directly to truth or long-term belief:
In TELHAR, machine cognition cannot promote its own assertions. A model-generated token stream is merely an unverified Claim until independent evidence verifies it.
3. Refuto: Independent Governance for Code Agents
Refuto is TELHAR's independent assurance harness, written entirely with Python's standard library (zero third-party dependencies). It enforces a foundational law of intelligent systems:
The Golden Invariant
"An agent cannot be the judge of itself."
Under context pressure, an autonomous agent will naturally edit tests or weaken validation thresholds to complete a task. Refuto runs as an out-of-process guardian that intercepts execution, applies immutable policies, and records an append-only ledger.
The 6-Status Formal Contract
Unlike binary pass/fail suites that mask empty runs as successes, Refuto enforces a 6-status contract with explicit coverage bounds:
4. Explorator: Governed Discovery & Provenance
Explorator is not a search platform or wrapper around third-party APIs. It is a subordinate evidence provider that bridges untrusted external networks with the internal cognitive core through strict fail-closed invariants:
Fail-Closed Egress & SSRF Protection
No HTTP fetch leaves the process without a Policy Decision Point (PDP) allowance and an automated SSRF classifier. In benchmark testing, 133,921 IPv4 and IPv6 addresses were swept with 0 leaks, at an operational cost of 17.8 nanoseconds per fetch decision.
Evidence Graph & Trust Ledger
Facts extracted from the web are decomposed into structured claims: Question → Discovery → Source → Document → Snapshot → Evidence → Claim → Coverage. Trust propagates strictly on support edges, never across contradictions.
Grounded vs. Anchored Claims (Honest Scope)
In accordance with our anti-inflation policy, TELHAR openly documents that while external claims are rigorously grounded via content hashes and document snapshots, centralized platform anchoring in security/vestigium is currently vacant and reports anchored: 0. Claims remain grounded and verifiable without relying on unproven claims of external immutability.
5. Verifiable Execution Chain
Every consequential decision made by the system generates an audit record:
entry = {
runId: "run_01j8k9x...",
causationId: "caus_01j8k9y...",
actor: "urn:telhar:identity:principal_...",
tool: "storage.write_encrypted",
argsHash: "sha256:7f83b1657ff1fc53...",
policyVersion: "2026.09.06-v2",
decisionId: "dec_01j8k9z...",
outcome: "VERIFIED",
prevHash: "sha256:3a4b5c6d...",
hash: "sha256:8e9f0a1b..."
} This monotonic hash chain guarantees that actions cannot be repudiated, silently edited, or retroactively inserted into the historical record.