Sovereignty-Preserving Orchestration Mesh
Orchestrates AI inference across member-controlled environments so raw records provably never leave the data owner's boundary; non-egress is enforced and demonstrable rather than promised by policy.
Raw record non-egress is enforced at the network level rather than promised by policy, making data sovereignty a structural property of SI orchestration.
Action-Layer Unsupported-Assertion Detection
Detects, at the action layer, agent assertions not supported by verifiable evidence before those assertions can drive downstream actions; a structural check on agent claims, not a content filter.
Catching unsupported assertions at the action layer before they drive consequences makes AI grounding a structural check rather than a content filter.
Sole-Egress Action-Commit Gate
Routes every agent action through a single controlled egress point where it is committed or refused, giving the operator one auditable choke point for everything an autonomous system does.
A single auditable egress point for every agent action gives operators one real choke point for governing everything an autonomous system does.
Member-Sovereign Data Bridge with Provable Non-Egress
A data bridge that lets members contribute to shared computation while raw records provably never egress, with cryptographic proof rather than operator trust.
Cryptographic proof replaces operator trust as the guarantee that member data never exits its boundary in shared computation.
Inline Multi-Jurisdiction Policy Gate with Citation-Bound Refusals
Evaluates every request inline against multiple jurisdictions' rules and, when it refuses, binds the refusal to the specific legal citation that compelled it, so refusals become auditable artifacts.
Binding every refusal to the specific legal citation that compelled it makes multi-jurisdiction compliance auditable by construction.
Orchestration Mesh, Improved Second Provisional
An improved orchestration mesh with a pinned cache-measurement protocol, single-actor-detectable claims, and a proof-artifact claim, preserving the original sovereignty and non-egress guarantees.
Extends the original sovereignty and non-egress guarantees with pinned cache-measurement and single-actor-detectable claims.
Trust-Gated Capability Registry for Autonomous Agents
A registry where agent capabilities carry version-pinned provenance-plus-behavior trust, re-derived on every version change; low trust excludes a capability from discovery per caller, preventing invocation outright.
Version-pinned, re-derived trust means low-trust agents cannot invoke capabilities at all, not just at reduced privilege.
Energy-Indexed Subjective-Time Meter
Gives a machine a native clock whose subjective time advances with counted irreversible operations, producing chained, verifiable energy-time certificates that downstream systems can recompute and confirm.
Grounding machine time in counted irreversible operations produces a verifiable compute-effort record no downstream system needs to trust on faith.
Per-Action Attestation Gate for Provider-Blind Agent Compute
Requires, for every agent action, a hardware-rooted attestation that the compute is provider-blind plus a control-inheritance assertion rooted to the same hardware, both evaluated as a conjunction, fail-closed.
Hardware-rooted, provider-blind attestation on every action closes the gap between infrastructure flexibility and per-action accountability.
Order-Invariant Reasoning Engine with Confluence Certificate
Guarantees a reasoning result independent of the order inputs arrive: a verifier re-derives canonical order from element contents and admits output to protected sinks only on bit-equality with the certificate.
Content-derived canonical ordering guarantees that a reasoning result never depends on the sequence inputs arrived, making inference deterministic by construction.
Self-Consistent Fixpoint Planner with Contraction-Bounded Commit Gate
A planner that iterates to a classical fixpoint and commits only when a measured contraction bound certifies convergence; non-convergence yields a signed receipt and the commit gate stays closed.
Convergence certification before commit means SI planning is provably stable: the gate stays closed until a contraction bound is measured.
Substrate-Independent Cognition Portability with Behavioral-Equivalence Attestation
Moves a cognitive workload to a new substrate and proves the move: golden-probe runs establish tolerance-bounded behavioral equivalence, attested and gated through a graduated production cut-over.
Golden-probe behavioral equivalence attestation proves that intelligence moved to a new substrate still behaves the same, so sovereignty survives relocation.
Cross-Tenant Cache-Segment Admission with Payload-Bound Provenance Proofs
Lets tenants safely reuse each other's cached inference segments: every segment carries a payload-bound provenance proof the consumer spot-checks by trust-free local recomputation, failing closed to local recompute.
Payload-bound provenance proofs that consumers recompute locally mean cross-tenant cache reuse carries verifiable origin and authorization without trusting the cache operator.
Escrowed Compensating-Transaction Gate for Agent Execution Authority
An agent receives execution authority only after a validated compensating transaction, the undo, is signed into escrow; authority tokens are digest-bound and non-compensable actions route fail-closed.
Escrowing the compensating transaction before granting execution authority means every non-reversible agent action is gated by a pre-committed undo path.
Signed Progress-Token Liveness Verification for Multi-Agent Call Graphs
In a multi-agent call graph, each agent emits signed progress tokens whose liveness is verified across the graph, so a stalled, silent, or spoofed agent is detected and the call chain fails closed rather than hanging on an unverifiable participant.
Signed progress tokens across the call graph let every participant verify liveness, so a stalled or spoofed agent is detected rather than silently hanging the system.
Fork-Lineage Event Chain for Verifiable Agent Instance Identity
Cryptographically verifiable identity and lineage for AI agent instances that fork, clone, migrate, or restore — with descent proofs a relying party can check and revocation that prunes an entire descendant subtree.
Binding each agent instance to a checkable descent proof means a forked, cloned, or restored agent is trusted or revoked by lineage — identity and accountability survive replication.
Energy-Budget Controller for Certified Agent Computation Rates
A controller that allocates AI reasoning compute against an accountable energy budget and emits a signed, independently verifiable record of requested-versus-delivered computation — a delivery receipt for sold "thinking."
A signed receipt of requested-versus-delivered computation makes sold reasoning accountable, so an agent's thinking can be verified rather than taken on trust.
Conflict-Copy-Tolerant Coordination of Multi-Agent Sessions Over an Eventually-Consistent Synchronization Folder
Lets autonomous agent sessions on separate machines coordinate through nothing but a consumer file-synchronization folder — no coordination server — by turning the conflict-copy duplicates such folders produce into the coordination primitive: a deterministic, content-based adjudication rule elects a single lock winner without any compare-and-swap, heartbeat-staleness detection triggers automatic takeover of a stalled owner, and interrupted work resumes from handed-off state rather than restarting.
Conflict-copy-tolerant coordination lets sovereign, self-hosted agents cooperate over an ordinary synchronization folder with no central coordinator, so multi-agent operation survives partition, interruption, and disagreement.
Mid-Flight Revocation of Delegated Agent Authority at a Protected Commit Sink
Revokes an agent's delegated authority even while an action is already in flight: an authority advances a monotonic per-grant revocation epoch, and a protected commit sink re-checks the grant at every commit boundary, admitting the next effecting step only on a fresh, grant-bound proof that the delegation is unrevoked as of the current epoch. The re-check is performed by the sink independent of the delegate and fails closed on any revoked, stale, or unverifiable proof, so an action authorized before a revocation cannot complete a commit that follows it.
Enforcing revocation at the commit sink, independent of the delegate, means authority pulled from an agent mid-action takes effect before the action lands — a withdrawn mandate cannot still commit.
Decision-Bound Verifiable Compute-Spend Attribution with Coverage Verification
Attributes an autonomous system's measured compute-spend to the specific orchestration decision that caused it: at each decision point a signed decision-attribution record binds the decision, a promised operating point of quality class and spend budget, a delegation chain to an accountable principal, and a spend-evidence commitment to independently verifiable metered records, chained into an attribution tree. A verifier reconciles the metered records against the decisions — validating each delegation chain, checking delivered computation and quality against the promised operating point, and performing coverage verification that maps every metered record to exactly one authorized decision and emits an unattributed-spend finding for any consumption no decision accounts for — and only a passing reconciliation gates the downstream settle, bill, or escalate action.
Binding verifiable compute-spend to the decision that caused it, and reconciling every metered record against the authorized decisions, makes an autonomous system's resource use accountable per decision rather than aggregate and opaque — an auditor can revoke a component's authority on an unattributed-spend or broken-promise finding.
Offline-Verifiable Compliance Evidence Packs with Completeness Attestation
Assembles a tamper-evident compliance evidence pack that can be verified completely offline — no connection to the issuing system required — carrying a built-in attestation that the pack is complete, so a reviewer can confirm both the integrity of each item and that nothing has been omitted.
Compliance evidence that verifies offline with a completeness attestation lets any party confirm the record is both intact and whole without trusting the system that produced it.
Acknowledgement-Bound Action Routing for Autonomous Agents
A safeguard that only lets an autonomous agent's action proceed once the required party has provably received the mandated notice for that action, and fails closed otherwise — binding the agent's authority to act to a verifiable acknowledgement rather than an unconfirmed send.
Gating an agent's action on proof that the required party actually received the mandated notice — failing closed if not — makes notification a load-bearing precondition, not a fire-and-forget courtesy.
Composable Cross-Producer Provenance with Offline Verification
A method to combine and independently verify provenance records originating from many different producers — without needing to understand each producer's individual data format — so a downstream party can compose a single verifiable lineage across heterogeneous sources and check it offline.
Composing and verifying provenance across producers without parsing each one's format makes cross-source lineage checkable end to end, even for records the verifier's own systems never generated.
70+ Patent Candidates in Pursuit
The twenty-three filings above are the first of a planned series spanning seven technology domains within the sovereign AI and SI infrastructure stack. Each domain addresses a critical requirement for safe, accountable superintelligence emergence and the coexistence of SI and biological life under the Declaration of Goodness: agent mesh protocols, governance mechanisms, data sovereignty primitives, inference orchestration, alignment systems, cryptographic trust layers, and compliance automation.
All filings described on this page are U.S. provisional patent applications. Provisional applications establish a priority date and provide 12 months to file a corresponding non-provisional application. They do not constitute issued or granted patents. "Patent Pending" is the correct and only accurate designation.
Interested in licensing or partnership?
For licensing inquiries, partnership discussions, or questions about the Cliff Labs IP pipeline, please reach out directly.
Contact Us