Evidence

Nine properties. Each independently verified.

Permission at approval time is not necessarily permission at execution time. Verification must occur at the execution boundary. Each property below of the ExecutionProof™ control model is mapped to a preregistered experiment with a live, citable record.

ExecutionProof™ is supported by a public, preregistered testbed corpus covering execution integrity, authority, evidence, state, performance, provenance, and bounded quantum-evidence demonstrations.

75 preregistered experiments · 253 case records250 PASS · 2 preserved FAIL · 1 preserved GATE-STOP66 Zenodo depositions · 9 public repositories

The 253 case-records figure mixes terminal-record counting (earlier phases) with per-scored-case counting (ARK-493–498 +161, ARK-499–501 +21). ARK-502 (bounded operational smoke; ≥14-day endurance not executed) and ARK-503 (reviewer package delivered; no independent human review completed) contribute 0 scored PASS by design and are excluded from the tally. FAIL and GATE-STOP are valid preserved results, not errors.

Latest series · ARK-493–501 (enforcement + enterprise adapters)

ARK-493–498: six experiments and 161 scored cases, all PASS, with zero enforcement leaks and independent dual-guard verification on every record. Independent tamper detection ran 10/10 with 0 false positives (ARK-497); under dependency loss the boundary held fail-closed with a leak count of 0 and 100% independently signature-verifiable proofs in a production-like networked run (ARK-498).

ARK-499–501: the authorization boundary was carried onto real (self-hosted) enterprise adapters — a self-hosted database, a git-based CI/CD path, and RS256 OIDC-JWKS token verification — at 7/7 scored PASS each (+21 cases). The core finding is intentionally negative: the boundary logic did not need to change; only the adapters did. ARK-502 recorded a bounded operational smoke pass (418 operations, 0 leaks; ≥14-day endurance not executed) and ARK-503 delivered a reviewer package awaiting independent human review — both contribute 0 scored PASS by design.

These are bounded engineering evidence on self-hosted adapters (not Docker/K8s/cloud; not Okta/Azure AD/Auth0). Latency and throughput figures are published as production-like overhead characterization — not a benchmark certification and not a production SLA.

Current-state authority

Authority is re-checked against current state at execution time. Permission granted at approval time does not carry forward if state has changed.

Exact-action binding

A verified decision binds to the exact governed action. Detaching authorization from the action, or substituting a different action, fails closed.

Workflow isolation

Prior valid steps confer no inherited authorization on a later irreversible step. Each governed action is authorized on its own terms.

Three-state ALLOW / HOLD / DENY

Conflicting or unknown evidence resolves to HOLD — never to a default ALLOW. Only complete, consistent evidence yields ALLOW.

Self-approval refusal

Self-approval and circular delegation are refused. An actor cannot manufacture its own authority through a delegation loop.

Fail-closed dependency loss

If any governance dependency is unavailable or corrupted, the decision is DENY. The boundary fails closed, not open.

ProofRecord™ tamper detection

Altered decision records are rejected; the original is accepted. Tamper detection was tested, corrected after an honest failure, and re-verified.

Cross-context binding

Authorization from one context cannot be replayed into another (confused-deputy). ALLOW requires an exact match across all five context dimensions.

Enforcement boundary integrity

The gate mechanically enforces authorization decisions across execution paths, preventing enforcement leaks even under adversarial load, deep mutation, timing races, delegation abuse, and network conditions.

Where this applies

The payment / treasury approval boundary

These properties come together at a single governed decision. In a supervised pilot, ExecutionProof™ evaluates each attempted payment at the execution boundary:

1

Request

2

Verify actor, authority, amount, destination, evidence, state, limits

3

ALLOW / HOLD / DENY

4

Bind decision to the exact attempted payment

5

Issue ProofRecord™

How the record was produced

Preregistration locks — code, criteria, and a SHA-256 manifest are committed before any result is produced.

Fixed pass/fail criteria — thresholds are set in advance and never changed post-hoc.

Dual independent verifiers — each experiment is scored by two separate implementations (JavaScript and Python).

Disclosed corrections — any pre-execution harness fix is disclosed and may not touch the decision procedure.

Honest failures preserved — failed and gate-stopped runs are published, not discarded.

Git provenance — full public commit history with manifest hashes for every record.

Live DOIs — every completed record is archived as a citable, publicly accessible dataset.

Public record

The complete corpus is public and preregistered. Remnant Fieldworks maintains nine public repositories: eight experimental and implementation repositories, plus the separate RF-100 standards repository. Every completed record is archived on Zenodo — 66 published DOI records in total, including individual experiment versions and series concept records.

The nine properties above are drawn from the ARK cycle. Full detail for the broader quantum-evidence series — WITNESS, BELLWETHER, CHRONO, OMNI, and TRINITY (a three-processor fused witness) — lives in the repositories below.

ExecutionProof research corpus — Zenodo series (concept DOI)

DOI 10.5281/zenodo.21398675 — always resolves to the latest version

Scope & limitations

These are preregistered research experiments. Each result holds only within its tested model and parameters — for software experiments, within the tested logic, inputs, verifiers, and shot counts; for hardware-adjacent experiments, within the tested circuit model, backend, qubits, calibration, and shot counts. They are not general security guarantees.

This evidence supports the ExecutionProof™ supervised pilot and its control model. It does not replace an independent security audit, penetration test, or third-party certification, and it is not a representation that any specific deployment is secure.

ExecutionProof™ is covered by 48 provisional patent applications (filed January 2026) and 8 pending nonprovisional utility applications — 56 total USPTO filings.

ARK-454 provides technical support for the no-self-approval architecture described in pending U.S. patent applications; it does not legally validate any patent claim. Patentability is a separate legal determination.

Patent pending refers to filed U.S. patent applications. Nothing on this page should be read as a representation that any patent has issued, that any claim has been allowed, or that any third-party system infringes.