Evidence

Nine properties. Each independently verified.

Permission at approval time is not necessarily permission at execution time. Verification must occur at the execution boundary. Each property below of the ExecutionProof™ control model is mapped to a preregistered experiment with a live, citable record.

ExecutionProof™ is supported by a public, preregistered testbed corpus covering execution integrity, authority, evidence, state, performance, provenance, and bounded quantum-evidence demonstrations.

106 documented experiments · 16 public repositories95 PASS · 8 preserved FAIL · 3 special status90 published Zenodo works · 124 versions · 8 pending non-provisional U.S. patent applications

106 documented design-before-execution experiments across 16 public repositories — 95 PASS, 8 preserved FAIL, 3 special status, with 4 validated FAIL→PASS remediations. 90 published Zenodo works across 124 versions under open-access licenses. Special-status records: GATE-STOP (ARK-448), SMOKE (ARK-502), NOT-EXEC (ARK-503). Internal/founder-led experimental corpus; independent academic validation is the next phase.

Latest series · ARK-493–501 (enforcement + enterprise adapters)

ARK-493–498: six experiments and 161 scored cases, all PASS, with zero enforcement leaks and independent dual-guard verification on every record. Independent tamper detection ran 10/10 with 0 false positives (ARK-497); under dependency loss the boundary held fail-closed with a leak count of 0 and 100% independently signature-verifiable proofs in a production-like networked run (ARK-498).

ARK-499–501: the authorization boundary was carried onto real (self-hosted) enterprise adapters — a self-hosted database, a git-based CI/CD path, and RS256 OIDC-JWKS token verification — at 7/7 scored PASS each (+21 cases). The core finding is intentionally negative: the boundary logic did not need to change; only the adapters did. ARK-502 recorded a bounded operational smoke pass (418 operations, 0 leaks; ≥14-day endurance not executed) and ARK-503 delivered a reviewer package awaiting independent human review — both contribute 0 scored PASS by design.

These are bounded engineering evidence on self-hosted adapters (not Docker/K8s/cloud; not Okta/Azure AD/Auth0). Latency and throughput figures are published as production-like overhead characterization — not a benchmark certification and not a production SLA.

Current-state authority

Authority is re-checked against current state at execution time. Permission granted at approval time does not carry forward if state has changed.

Exact-action binding

A verified decision binds to the exact governed action. Detaching authorization from the action, or substituting a different action, fails closed.

Workflow isolation

Prior valid steps confer no inherited authorization on a later irreversible step. Each governed action is authorized on its own terms.

Three-state ALLOW / HOLD / DENY

Conflicting or unknown evidence resolves to HOLD — never to a default ALLOW. Only complete, consistent evidence yields ALLOW.

Self-approval refusal

Self-approval and circular delegation are refused. An actor cannot manufacture its own authority through a delegation loop.

Fail-closed dependency loss

If any governance dependency is unavailable or corrupted, the decision is DENY. The boundary fails closed, not open.

ProofRecord™ tamper detection

Altered decision records are rejected; the original is accepted. Tamper detection was tested, corrected after an honest failure, and re-verified.

Cross-context binding

Authorization from one context cannot be replayed into another (confused-deputy). ALLOW requires an exact match across all five context dimensions.

Enforcement boundary integrity

The gate mechanically enforces authorization decisions across execution paths, preventing enforcement leaks even under adversarial load, deep mutation, timing races, delegation abuse, and network conditions.

Where this applies

The payment / treasury approval boundary

These properties come together at a single governed decision. In a supervised pilot, ExecutionProof™ evaluates each attempted payment at the execution boundary:

1

Request

2

Verify actor, authority, amount, destination, evidence, state, limits

3

ALLOW / HOLD / DENY

4

Bind decision to the exact attempted payment

5

Issue ProofRecord™

How the record was produced

Preregistration locks — code, criteria, and a SHA-256 manifest are committed before any result is produced.

Fixed pass/fail criteria — thresholds are set in advance and never changed post-hoc.

Dual independent verifiers — each experiment is scored by two separate implementations (JavaScript and Python).

Disclosed corrections — any pre-execution harness fix is disclosed and may not touch the decision procedure.

Honest failures preserved — failed and gate-stopped runs are published, not discarded.

Git provenance — full public commit history with manifest hashes for every record.

Live DOIs — every completed record is archived as a citable, publicly accessible dataset.

Public record

The complete corpus is public and preregistered. Remnant Fieldworks maintains sixteen public repositories spanning experimental, implementation, and the separate RF-100 standards repository. Every completed record is archived on Zenodo, with 90 published Zenodo works across 124 released versions, counting distinct concept-level records rather than mixing concept records with individual versions.

The properties above are drawn from the ARK cycle. Full detail for the broader research families lives in the repositories below.

ExecutionProof research corpus — Zenodo series (concept DOI)

DOI 10.5281/zenodo.21398675 — always resolves to the latest version

Federal research program

Submitted to the National Science Foundation (under review)

On September 1, 2026, Remnant Fieldworks submitted a full research proposal to the U.S. National Science Foundation PESOSE Track 3 program: "PESOSE: Track 3: ExecutionProof - An Open-Source Ecosystem for Verifiable Pre-Execution Authorization of Autonomous Actions" (Proposal #2641427), requesting approximately $1.5M over 24 months. The proposal is submitted and pending review.

Academic proposal partners are Ohio State University (Carter Yagemann) and the University of Dayton (Phu Phung and Luan Nguyen). These universities are research partners on the proposal, not validators of ExecutionProof.

Separately, Remnant Fieldworks also submitted an NSF SBIR/STTR Project Pitch in Cybersecurity and Authentication on September 1, 2026.

Submission is not an award. Nothing here should be read as NSF funding, endorsement, or validation.

Separate research program

CIF-LAAD - Coherent Inheritance Framework for Low-Altitude Air Domain Awareness

CIF-LAAD is a simulation-stage research program studying low-altitude continuity, false-track suppression, uncertainty, and evidence provenance when observations degrade or conflict. It is a distinct research program and is not part of the 106-experiment ExecutionProof corpus above.

Simulation-onlyTRL 3Research onlyNo hardware validationNo independent validation

Earned claims (within tested simulation envelope)

  • Continuity through approximately 5-second blind intervals in the tested simulation envelope.
  • Strong false-track suppression under tested clutter and crossing conditions.
  • Tamper-evident evidence provenance.
  • Typed rejection of malformed, stale, replayed, or invalid observations.
  • Track-identity stability only within a bounded low-density envelope.

Co-reported limitations

  • Localization RMSE approximately 1.3x to 4x worse under contested conditions.
  • Identity-switch performance worse or inverted at higher crossing density.
  • A plausible schema-valid spoof can pass current validation.
  • The pure-Python implementation met the 50 ms cycle budget only to about 50 tracks.
  • No third-party tracker benchmark yet.
  • The preregistered coherence-gated inheritance hypothesis was falsified and preserved.

Boundary

External sensors → CIF-LAAD → track + classification + confidence + evidence → a downstream command or mission system. ExecutionProof can optionally consume the evidence before a downstream action. CIF-LAAD does not authorize or execute weapon actions.

CIF-LAAD validation-series record

DOI 10.5281/zenodo.22255738

Scope & limitations

These are preregistered research experiments. Each result holds only within its tested model and parameters — for software experiments, within the tested logic, inputs, verifiers, and shot counts; for hardware-adjacent experiments, within the tested circuit model, backend, qubits, calibration, and shot counts. They are not general security guarantees.

This evidence supports the ExecutionProof™ supervised pilot and its control model. It does not replace an independent security audit, penetration test, or third-party certification, and it is not a representation that any specific deployment is secure.

ExecutionProof™ is covered by 8 pending non-provisional U.S. patent applications, building on 48 priority provisional applications filed January 2026.

ARK-454 provides technical support for the no-self-approval architecture described in pending U.S. patent applications; it does not legally validate any patent claim. Patentability is a separate legal determination.

Patent pending refers to filed U.S. patent applications. Nothing on this page should be read as a representation that any patent has issued, that any claim has been allowed, or that any third-party system infringes.