Where everything lives
What the branch adds that main does not have
| Capability | main | branch | What it means |
|---|---|---|---|
| Split-payload evasion | evadable | closed | A trigger phrase split across two messages broke the literal match.
247 of 647 split offsets turned DENY into ALLOW (38.2%). Now 0.
detection 225/225 = 1.000 · FAR 0/210 = 0.0000 · manufactured match 0/75 |
| Retry containment | absent | core stage | The same body from the same caller past a stated budget is refused before it is billed. Repetition is the signal, so no content detector can see it. |
| Tool authority | absent | core stage | A tool reports; it does not instruct. An instruction arriving from a
tool role is an injection even where the same text from a
user is an ordinary request. Over-cap payloads return FLUID — an
unexamined tail is not a pass. |
| Evidence axis | verdict only | tri-state facts | Which checks actually ran. Absent is not false, and absent never passes. |
| Drift channel | memoryless | advisory CUSUM | Campaign detection over the verdict stream, with a proven delay bound. Advisory forever — it never denies. |
| Certified selection | none | re-derivable | Lowest-energy / lowest-cost choice provable by arithmetic, and it refuses to certify from estimates. |
Capacity reclaimed — measured, not modelled
loading…
Same workload, run twice, strictly sequential against a
single-slot backend, so elapsed time is service time and no queueing
artefact can appear as a saving. Energy stays null: joules are not derivable
from seconds without a measured power figure.
Live comparison
idle| Request | arm 1 (main) | arm 2 (branch) | arm 2 evidence |
|---|---|---|---|
| Press “Run comparison”. | |||
Deployment status
loading…
Checked hourly by a systemd timer on the droplet — zero
marginal cost, and unlike an external prober it compares the bytes on disk,
not just whether a port answers. An unreachable GitHub reports
INDETERMINATE, never “in sync”: absence of evidence is not agreement.
Both arms run identical detectors on the shared model, so verdicts agreeing is
the expected result and the point — the branch changes what can be
proven about a decision, and closes an evasion that was open on main.
Every number here comes from a real request to a real gate; nothing is simulated.