Assurance ceiling
A governance product that overstates itself has already failed. This page is the boundary of what our evidence supports, stated before anyone asks for it.
The grade, quoted verbatim from an escalation record
A1: cooperative gate, same-UID operator, tamper-evident and not tamper-proof.
A capable agent can bypass a cooperative gate. The bypass is attributable, not prevented. Every escalation record carries this grade in plain words, so the ceiling travels with the evidence rather than sitting on a page nobody reads.
Hardbound has no external installation
One release artifact has been cut and tested. There is no customer, no pilot, no user and no third-party red team to date. We do not offer the artifact for download, because offering one implies an installation.
Enforcement is not packaged
The pre-action enforcement supervisor is real code whose deny logic demonstrably fires, and then deadlocks on a current kernel. It ships in no package. This belongs in the funding ask, not in a buying argument.
The refusal rate is a floor
1,827 refusals in one 46-day window on one machine is 1.65% of 110,401 governed acts. Scope denials on that seat never reach the chain, so the recorded figure undercounts. We never extrapolate it fleet-wide.
Two different kinds of number
195,267 is a single machine's chain head, verifiable on the spot. 400,000+ is the founder's operational sum of eight such heads. The verifiable unit is the head, not the total.
An upheld appeal does not amend the rule
Two appeals were upheld cross-vendor on 2026-08-27. The identical act was refused again minutes later, because an upheld appeal scores conduct without changing the law. The amendment object is drafted, not shipped.
SAGE does not act in the physical world
One instance sees and hears on real hardware. Network, gaze and tool effectors exist. Physical actuators are stubs, and acting is the research deliverable.
Multi-device identity is untested on the fleet
Implemented and unit-tested end to end, including tamper, replay and ignore-the-claimed-level cases. It has not been exercised across enrolled devices on the live deployment.
Federation is specified, not deployed
Hubs are designed to federate as peers. The federation transport is ahead of live deployment. The Hub Docker image has not been run on an operator machine.
These are house rules, enforced on every page and every document we publish.
We do not say
We say
Why
Tamper-proof
Tamper-evident
A cooperative gate at grade A1 makes a bypass attributable, not prevented.
Production ready
Running on the reference deployment, deliverable, exercised daily
This is R&D. The phrase invites a support and SLA expectation nothing here backs.
Non-repudiable
Cryptographically attributable
A cooperative gate cannot deliver non-repudiation. Attribution is what the record supports.
Court-grade evidence
Independently verifiable, audit-ready, exports into the tooling auditors already accept
No court has evaluated it. The phrase asserts a legal standard nobody has tested.
Signed witness chain
Hash-chained witness record with the signer's identity on every row
There is no per-row signature. Witness marks and delegations are signed separately.
Impossible to reproduce
Harder to reproduce
The enforcement moat is building, and a track record is a history a competitor could in principle accumulate.
Four vendors
Three vendors operate. A fourth is installed and attested.
The fourth has zero rows in the reputation ledger and has never run.
We track SailPoint, Astrix, Noma and Linx closely. They are closed enterprise products sold into one company's infrastructure. Ours is an open standard the identity travels with, across organisations, which puts us closer in kind to SPIFFE than to a SaaS platform.
The concession travels with that sentence: on pure enterprise runtime gating and tool-level access control, several of them are more mature today than Hardbound. Astrix was acquired by Cisco in May 2026. Noma launched in June 2026.