1 · Novelty as a U-statistic
A claim no single prior work anticipates but which a combination jointly anticipates is a property of subsets, so the estimator ranges over subsets. Unbiasedness is what makes it defensible in a dispute in a way a tuned heuristic is not.
2 · Report a band, never a number
By Hoeffding's projection the estimator is asymptotically normal, so novelty is always an interval. A claim whose interval straddles the threshold is not borderline approved; it is epistemically unresolved.
3 · Possibility, not probability
An unverified claim in an emerging field has no reference class. Forcing a probability invents information. The gap Π - N is the epistemic ignorance, reported rather than minimized away.
4 · The collapse rule
Commitment gates on necessity (conservative lower bound); rejection gates on possibility (optimistic upper bound). The residual region escalates to a human.
Tier I · nowtier I
Relational calculus gates logical consistency; probability bounds collusion risk and sets the challenge window; game theory and mechanism design align staking and slashing; information theory measures lineage as information transfer; optimization makes disputed replay bit-identical; statistics audit driftRef: APX-SPEC-003; graph theory is the provenance backbone.
Tier II · scheduledtier II
Computability theory and formal methods draw the line between blocking gates that must provably halt and what cannot; the scheduled work is a mechanized proof that recomputation is a total deterministic function. Homology and topology fingerprint network structure so a verified model matches its claimed architecture.
Tier III · frontiertier III
Stochastic PDEs would extend provenance to scientific-ML surrogates; algebraic geometry over parameter varieties is aspirational. The TCIU framework spans tiers: its time-complexity argument is load-bearing, while complex-time representation is a named research option nothing depends on.
The agents that feed AperX operate in dynamic, non-deterministic environments, often disconnected from cloud infrastructure. Kagenti is a universal, compute-agnostic orchestration protocol capable of running in Wasm sandboxes, on edge devices, and in disconnected environments. It handles application-layer mTLS, agent lifecycle state machines, and cryptographic claim signing independent of the underlying substrate.
The Symbiotic Architectureboundary rule
The architecture resolves a foundational tension: autonomous agents must reason in heuristic, non-deterministic ways, yet the claims they produce must live on a deterministic ledger. Kagenti and AperX meet at a sharp boundary.
The ledger does not care how the claim was produced or where the agent executed. It only cares that the math recomputes. A claim generated by a stochastic swarm in a Wasm sandbox or a heuristic search on a disconnected edge device is treated identically once it crosses the boundary.
Physical Node Compromise ProtectionsSECURITY
If an edge node is physically compromised, the local buffer must not leak sensitive claim data or identity credentials. The Kagenti protocol enforces cryptographic shredding of the local SQLite/Wasm buffer.
2. Zeroize on Tamper: Upon detection of physical tamper or unauthorized memory access, the volatile nonce is immediately zeroized.
3. Cryptographic Shredding: Without the nonce, the derived encryption key is unrecoverable, instantly rendering the entire local append-only log cryptographically shredded and indistinguishable from random noise.
4. Revocation: The compromised SVID is immediately broadcast to the SPIRE server for revocation, invalidating any future claims from that principal.
Disconnected Edge Protocol
Agents operating in remote, subterranean, or contested environments cannot rely on continuous connectivity to the AperX cloud ledger. The Disconnected Edge Protocol ensures that heuristic reasoning and claim generation continue uninterrupted, with cryptographic guarantees preserved for eventual synchronization.
2. Local SVID Signing: Claims signed using local SPIFFE SVID.
3. Verifiable Local Log: Claims appended to SQLite/Wasm append-only log.
4. Bulk-Sync: Upon network restoration, deterministic batch transmission to AperX Gateway.
The local verifiable log forms a hash chain. Each entry contains the claim content hash, the SVID signature, a local monotonic timestamp, and the previous entry hash.
Step 08 is the architectural heart: a protocol forced to produce a verdict on every claim produces bad verdicts on hard claims. This one may say "unresolved" and hand the claim to a human.
- Ingest. Receive a content-addressed claim from a Kagenti-orchestrated workload (cloud or edge buffer); verify the SPIFFE SVID; map the SVID to an AperX Principal via
SHA-256(SVID || contract_id || epoch); bind identity and priority under commit-reveal. - Gate. Export control (ITAR / EAR), patent embargo, PHI, residency.
- Formalize. Extract atoms into stratified Datalog; verify KB ∪ Φ_c ⊭ ⊥.
- Featurize. Map to directed, uniform, and pseudo hyperedges; compute lineage multiplicities.
- Partition. Build the exchangeability partition; publish partitionRoot.
- Estimate. Draw the incomplete design at committed seed; compute Û_B and total variance.
- Observe. Each validator posts a bonded, observer-relative verdict.
- Collapse or suspend. Evaluate the collapse rule; on failure suspend to a bonded human privileged observer.
- Commit. Write the hyperedge with attribution signatures; seal; open the challenge window.
- Challenge. Any party recomputes deterministically; divergence is a fraud proof; slash.
- Anchor. Finalize; the claim becomes prior art for every subsequent estimate.
- Supersede. Later refutation appends supersedes(e_new, e_old). Nothing is ever deleted.
UltraMassive pre-print publications, internal critique threads, and working annexes. Access requires execution of the Symbiotic Architecture Two-Way NDA. Production artifacts and ratified discussions are cryptographically synced to the external artifact subdomain.
Pre-Print Access Restricted
Execute the Symbiotic Architecture Two-Way NDA to Authenticate. All access events are cryptographically logged as directed hyperedges on the APX-HL-NDA ledger. Total epistemic anonymity is enforced: all authors and reviewers are identified strictly by cryptographic SVID principals.
ProtoLab hosts the pre-release testnet, the reference validator, and unpublished annexes. Access is a mutual, two-way NDA: you disclose IP-corpus context, we disclose protocol internals. The agreement is counsel-reviewed (revision UM-MNDA-2026.07-v1.0) and produces a genuine SHA-256 execution receipt.