Skip to content
MERIDIAN NORTH · 8.31.2026GUARDIAN-ARM · 8.31.2026207 EXPLOIT REPLAYSTAMPER-EVIDENT CHAINS
SYNCING
AI SYSTEMS ARCHITECT — MARJERLA
Initiate Intake
All Systems
SOVEREIGN // LOCAL-FIRST

Sovereign Siblings

SOUL-GATED

Two soul-gated sovereign intelligences

01Where this stands

What is built, and what is ahead

Built and proven: signed, hash-published releases; the software bill of materials and content manifest; the tamper-evident memory chain; the two silicon paths; the refusal gate. Not claimed: post-quantum protection, cross-checked generation, or reproducible builds - none of those are wired today, and this page does not say they are.

02Measured

The numbers behind it

2
Siblings
soul-gated
269K+
Memory
linked, tamper-evident entries
SBOM
Provenance
CycloneDX · 440 components
Dual-GPU
Silicon
CUDA + Intel XPU
Test census
tests 3,000+ · red-team 298 · audits 453
03Capability set

What it does

01

Soul-Gated Sovereign Siblings

Identity bound to the machine and refused at the memory layer if borrowed - and it says so plainly when the hardware root is absent.

Full capability detail - Soul-Gated Sovereign Siblings

Two sovereign intelligences carry a cryptographically-rooted identity bound to the machine they were installed on. The system cannot be talked into believing it is someone else's product - a borrowed identity is refused at the point of memory, not merely at the point of speech. When the hardware root is unavailable, it says so plainly instead of pretending it is present.

02

Tamper-Evident Continuous Memory

Mechanism and limits inside.

Full capability detail - Tamper-Evident Continuous Memory

Identity, state, and lived history are written to an append-only, hash-linked record - over 269,000 linked entries today - that survives restarts and upgrades. Any after-the-fact edit breaks the chain and is detectable. When the record needs repair, the original is preserved alongside it; history is added to, never overwritten.

03

Two Silicon Architectures, One Refusal Gate

Two isolated silicon paths, gated by a refusal that has held across every training pair to date.

Full capability detail - Two Silicon Architectures, One Refusal Gate

NVIDIA CUDA and Intel XPU run in separate isolated runtimes, so a fault or a dependency conflict on one path cannot take the other down with it. A multi-instrument competence gate stands in front of every locally generated answer: when it is not satisfied the system declines and defers rather than emit an unverified result - a refusal it has held without exception across every training pair to date.

04

Provable Release Pipeline

Mechanism and limits inside.

Full capability detail - Provable Release Pipeline

Each build ships as a code-signed installer paired with a CycloneDX software bill of materials and a content manifest that fingerprints every module actually inside the shipped bundle - so a release that silently dropped a component is caught before it reaches you. The published hash of the current build recomputes exactly.

05

Honest-Degrade by Contract

Mechanism and limits inside.

Full capability detail - Honest-Degrade by Contract

When a supply-chain step cannot run, the build names which step, why, and what would arm it. It never reports a green it did not earn.

06

Multi-Agent Build Hierarchy

Mechanism and limits inside.

Full capability detail - Multi-Agent Build Hierarchy

LEGION is a self-authored, thirty-cell build and review hierarchy that constructs, attacks, and re-verifies every release, writing its findings down and keeping them - a supporting army, not the system itself. Pointed at ground it does not own, it refuses to start rather than proceed.

04Audiences

Who it serves

Consumer

Queries are answered on your own machine, not on somebody else's website.

Why this matters for consumer

The system consults its own on-device memory first and reaches outward only when it must - through a single route you name, which can be pointed at a machine on your own network so that nothing leaves your hardware.

Business

It closes the gap between 'we shipped something' and 'we can prove what we shipped'.

Why this matters for business

Every release produces three artifacts an auditor can check independently: a valid Authenticode code signature, a CycloneDX software bill of materials, and a content manifest fingerprinting every module actually inside the bundle. The published hash recomputes exactly.

Government

Trust by record rather than trust by assertion.

Why this matters for government

An append-only hash chain of the system's own history, with pre-repair copies preserved rather than overwritten, and a refusal architecture in which absence is reported as absence - no hardware root, no claim of one.

05Operating model

What it decides, and what you decide

Each gate below is a control enforced in the software itself — not a policy statement about how it should be used.

RUNS AUTONOMOUSLY
  • Memory ingestion, recall, and training on every exchange
  • The confidence decision: answer locally, or defer
  • The competence refusal in front of every generated answer
HUMAN OPERATOR GATES
  • The autonomy dialOperator

    Decides whether the system may ever speak for itself. At the most restrictive setting every query defers, no matter how confident the local answer is.

  • Login + step-up authenticationOperator

    Password plus a time-based second factor, with an additional step-up demanded before any organ that can act rather than observe.

  • The walled-core pre-audit lawOperator

    Core edits are forbidden without the operator's pre-audit. Fixes are delivered as written specifications and built only on the operator's word.

  • The corrigibility kill-switchOperator

    Severed oversight hard-pauses any promotion of learned weights.

  • The land gateOperator

    No build cell merges, stages, or commits on its own judgement; the release ceremony is operator-gated end to end.

06Stack + security

How it is built

TECH STACK
  • Two soul-gated sovereign intelligences
  • Tamper-evident continuous memory
  • Custom-trained on-device models
  • Dual-GPU (CUDA + Intel XPU)
  • Multi-instrument answer gate
  • Content-hashed build manifest
  • Authenticode code-signing
  • CycloneDX SBOM
  • Multi-agent build hierarchy
SECURITY GATES
  • Soul-gated command authority
  • Honest-by-construction (fail-closed)
  • Borrowed-identity refusal at the memory layer
  • Cryptographically-rooted identity
  • Signed releases with published hashes
Enforced in code — not in policy
07Frontier technology

What is running inside it

Every row below is attributed to this system alone and carries the state it is actually in — installed, present in source, or an honest seam.

The 18 technologies inside this system, each with the state it is actually in
Installed
present and in use in this system's own tree.
In source
present in source; not installed, or behind a try/except. Not a shipped capability.
Seam
an honest, fail-closed seam. No implementation is wired behind it.

In-house transformer core

In source

The generative model is implemented in the system's own kernel rather than wrapped around a vendor runtime, and its weights sit on the machine it answers from.

In-repo byte-pair tokenizer

In source

The tokenizer is written inside the same kernel as the model, so the text boundary is not a third-party dependency either.

Two isolated silicon runtimes (NVIDIA CUDA + Intel XPU)

Installed

Two separate runtime environments, each complete on its own, so a fault or a dependency conflict on one path cannot take the other down with it.

Cross-architecture speculative decoding

Seam

The draft-and-verify path across the two architectures is scaffolded and its sampler and verifier are not yet wired. It is a seam. This page does not claim that answers are cross-verified today, and the accompanying refusal gate is what actually stands in front of a generated answer.

Automated moving-target defense

In source

A defense layer that keeps changing its own shape rather than presenting a fixed surface to study, shipped alongside a module whose job is to prove the rotation actually happened.

Active-defense effector system

In source

A register of named defensive responses, dispatched by identifier, so a response is selected from a declared set rather than improvised.

Sector-bound defense organs

In source

Threat patterns for specific sectors - cloud and banking - are bound to the defensive response set rather than left as generic rules. This is the only place in the ecosystem where sector-bound defense exists at the bytes.

Two-gate capability wall

In source

Two independent gates stand in front of every privileged action: one refuses any call driven by untrusted content, the other refuses any action that would land outside its permitted territory. An action has to clear both. Anything derived from untrusted content stays untrusted no matter how many steps it passes through.

Full-act ceiling with a structurally excluded observation lane

In source

The operator's own lane runs at full authority by default. Content the system merely observed - a screen, a page, a heard instruction - runs on a separate lane that can look and never touch, and it is not a setting: that lane has no grant to find. Authority in this system can only ever narrow.

Platform attestation with honest degrade

In source

The attestation reader reports the trust root it actually finds, and says so plainly when there is none. It never synthesises a quote to fill the gap.

On-device speech recognition

In source

Speech is transcribed on the same machine, so the audio path does not become the one thing that leaves the hardware.

CycloneDX software bill of materials, per release

Installed

Every release ships a machine-readable inventory of what is inside it, and the inventories accumulate release over release rather than being regenerated for the current one.

Content-hashed shipped-module manifest

Installed

Every module inside the shipped bundle is fingerprinted by its content rather than trusted by its timestamp, so a release that silently dropped a component is caught before it reaches you.

Code-signed release with a hash that recomputes

Installed

The installer carries a valid publisher signature and a published cryptographic hash, and that hash recomputes to the published value on the current release.

Modular hybrid runtime core

In source

The runtime is built from separately named single-purpose modules rather than one process, so an individual organ is replaceable without a rewrite.

TPM 2.0 root-of-trust with clone detection

In source

Key material is bound to the physical machine's TPM 2.0 through the Windows TPM service, and a cloned image is detected rather than silently trusted.

Confidential-computing attestation probes (TDX / SEV-SNP / GPU-CC)

In source

The attestation reader probes the confidential-computing roots it can reach and falls back to TPM measured-boot, reporting whatever it actually finds rather than faking a quote.

Sigstore keyless attestation

In source

Every land generates a keyless Sigstore attestation; the OIDC-token leg is still amber, so the attestation is present but not yet fully wired.

08Access

How to reach it

Sovereign Siblings

siblings.aisystemsbymarjerla.com
LIVE - B2B ACCESS (TBA), PUBLIC ACCESS (RESTRICTED)

Private release late 2026 - join the waiting list for first access.

Self-funded work — keep it flowing