diff --git a/docs/deck/01-github-profile-analysis.md b/docs/deck/01-github-profile-analysis.md new file mode 100644 index 0000000..2d601fe --- /dev/null +++ b/docs/deck/01-github-profile-analysis.md @@ -0,0 +1,119 @@ +# GitHub profile analysis -- HarperZ9 / ZentropyLabs + +> Census taken 2026-07-30 from the live account listing. Counts are exact at +> that timestamp. Companion files: 02-vertical-value.md, 03-target-audiences.md, +> 04-property-assessment.md. Slide deck: flywheel-telos-deck.html. + +## Headline numbers + +| Measure | Count | Note | +|---|---|---| +| Total repositories | 159 | 158 under HarperZ9 + ZentropyLabs-ai/.github | +| Original (non-fork) | 104 | the portfolio proper | +| Forks | 55 | upstream OSS + curated awesome-lists + eval/agent tooling | +| Private | 37 | security line, dev monorepos, site experiments | +| Public | 122 | | + +## The five-tier taxonomy (per the site's own catalog) + +### Tier 1 -- the fourteen public engines +flywheel (route + verify; desktop client v0.2.2), telos (the shared workbench, +live v0.2.0), index (2.9.0 beta, PyPI `index-graph`), gather (1.6.1 shipped, +PyPI `gather-engine`), forum (1.13.0 shipped, PyPI `forum-engine`), crucible +(1.2.0, PyPI `crucible-bench`), emet (1.1.0, PyPI `emet`, four independent +language implementations), buildlang (v1.2.0, 1,605 passing tests), learn +(v1.6.0), relay, plexus, mneme, studio-engine, build-color (1.0.2 beta, +PyPI `build-color`). + +Six confirmed PyPI packages -- the site publicly corrected an earlier "19" +over-count to this honest figure. + +### Tier 2 -- the private line ("public where safe") +- **orca** (Runtime) -- security-engagement workbench, v1.0.0, 361 tests; + metadata-only, cannot reach the target it assesses. The most revenue-shaped + private asset. +- **aleph** (Checkpoint) -- release/supply-chain coordination across docs, + contracts, MCP declarations, CI, receipts. +- **kun** (Vault) -- path-only receipts, rotation discipline, value-free. +- **behavior-transform.io** (Boundary) -- public repo; mode-aware + read/write/exec/fetch/input receipts; raw content stays in local adapters. +- **seed** (Lab) and **sofer** (Ledger) -- private/proprietary; honestly labeled + as needing a public-safe split (credential-pattern corpora inside). +- Adjacent private security cluster: offensive-platform, red-team-platform, + adversarial, protected-corridors, protected-research, legal-intl, + warden-reporting / warden-clp / warden-prefire-primitive (warden as a public + brand is retired into proof-surface), emet-internal, met-monorepo, + ai-safety-prefire, ai-safety-guardrail-manager, unified-engine, aurora, + apps, flywheel-host. + +### Tier 3 -- substrates +proof-surface (652 tests, zero deps -- the shared proof-packet foundation), +coherence-membrane, accountable-surface, accountable-engine (Forming; "the +inward half is owed"), provenance-sensorium, reconcile, raw (D3D11 mid-frame +graphics proxy), witnessing-spine (five regulated-sector adversarial +steelmans, DOI 10.5281/zenodo.20778927), senses-and-sensibility, +faithful-transpile, coherence and kernels lines (signal-kernels, +anomaly-kernels -- C++23 header-only). + +### Tier 4 -- bricks (release + agent toolkit) +secret-redact-io, release-surface-scanner, public-surface-sweeper, +repo-proof-index, proof-surface-report, model-provenance-validator, +gpu-trace-validator, agent-audit, agent-routing-kit, agent-hook-pack, +context-curator-lite, workflow-harness-lite, consulting-template-kit, +calibrate-pro, wol-pi. + +### Tier 5 -- research + receipts-in-the-wild +Receipt repos aimed at other ecosystems: crewai-kickoff-replay-receipt, +vllm-ci-forum-receipt. Research surface lives on the site: 3 theses, +10 experiment packets, 6 DOI'd preprints (arXiv endorsement-pending), +with a formal claim-status ladder (SOURCE_LEAD → … → LAW_CANDIDATE, plus +UNVERIFIABLE). + +## The build/creative lines + +- **Build product line** (former "Quanta", renamed): build-engine, build-color, + build-oracle, build-ui, build-finance, build-universe, build-ecosystem, + buildlang + buildlang-vscode + buildlang-tmLanguage. +- **Graphics/ENB line** (the consumer-traction record): elder-enb (900k+ + downloads, 150k+ unique users, ~280 releases over ~2 years), truth-enb, + elder-weathers, enb-runtime-core, enb-validation-lab, enb-bridge-f4 (private), + brender-archival, skyrimbridge, skse/skse-playground (private), gaussian + splats (site page), engine-revival, studio-engine. +- **Site/property repos**: HarperZ9.github.io (deployed output; canonical + source telos-v2, private), harpercompliance-site (private), + sendmyletter-site (private), freelance (private). + +## The fork belt (what it signals) + +55 forks cluster into: agent/eval infrastructure (pydantic-ai, deepeval, +langfuse, inspector, agent-runtime-observatory, SmallHarness, runtrail, +scorekeeper), MCP ecosystem curation (a dozen awesome-mcp-* lists, registry, +python-sdk), core Python tooling (numpy, poetry, setuptools, isort, tomlkit, +typeguard, grimp, datasette, llm), and agent-security reading +(system_prompts_leaks, awesome-ai-agents-security). Read as a map: the +account tracks exactly the frontier its products verify -- agents, evals, +MCP, and the supply chain under them. + +## Engine-state cross-check (dev vs public) + +| Surface | Routes / lanes | Version | +|---|---|---| +| `flywheel` public repo gateway | 11 API routes | 0.1.0 | +| `local-model` dev engine gateway | 96 API routes | dev (CC-1 era) | +| Lane registry (identical in both) | 7 lanes | gather 1.6.1 · crucible 1.2.0 · index 2.9.0 · forum 1.13.0 · learn 1.6.0 · telos 0.2.0 · local-model bundled | +| Marketplace | 17 built-in MCP connectors + unlimited user-registered plugins | | +| SUPERPROJECT roster | 11 mission-tier flagships (5 live MCP spine + 6 declared) | curated 2026-07-06 | + +The freshest engineering proof point is CC-1 "Certified Commons" +(STATE.md 2026-07-25): `flywheel gate` reaches rewitness=MATCH from a fresh +clone with byte-identical digests; shown able to FAIL first (verdict tamper → +DRIFT); 85 + 243 passing tests on that slice; CI across three OSes. + +## Reading the whole profile in one line + +One person, one discipline -- perceive, transform under a named criterion, +carry a re-checkable receipt -- applied across model infrastructure, compilers, +color science, graphics, security practice, and research, with the honesty +mechanics (published nulls, self-caught over-counts, maturity tiers) intact +everywhere. The portfolio's weakness is not depth or range; it is that no +single surface assembles this into an offer a buyer can say yes to. diff --git a/docs/deck/02-vertical-value.md b/docs/deck/02-vertical-value.md new file mode 100644 index 0000000..54fc380 --- /dev/null +++ b/docs/deck/02-vertical-value.md @@ -0,0 +1,82 @@ +# Vertical value assessment -- two industries, each tool alone and as the system + +> Companion to 01-github-profile-analysis.md. The claim discipline of the +> portfolio applies to this document: where a value statement is a projection +> rather than an observed result, it says so. + +## The shared premise (why either vertical pays) + +Machines made claiming nearly free; checking stayed expensive. Both verticals +below are drowning in AI-produced output whose acceptance currently rests on +confidence. The system's one operation -- propose, verify against an external +criterion, keep a re-checkable receipt -- is the missing accept path. The +pitch deck already names the wedge categories (originality-verification, +accountable-agent-action, provenance) and is honest that they have no analyst +TAM yet: that is the whitespace, and also the risk. + +## Vertical A -- sales & marketing (greenfield) + +Grep-verified: the current site has zero sales/marketing surface area. No +positioning debt, no incumbent framing to unwind -- and no existing proof of +demand either. Everything below is a mapping of shipped capabilities onto +known agency/martech pains, not observed traction. + +| Asset | Alone, it is | In this vertical it becomes | +|---|---|---| +| **gather** + snapshot (citation freezing) | research intake with provenance receipts | Claims substantiation: every public sentence traceable to a frozen, hashed source that outlives the live web. Ad-claim defense files that assemble themselves. | +| **forum** | agent orchestration on a replayable causal hash-chain ledger with human gates | Agency accountability: campaign automation the client can re-check instead of trusting a report. A deliverable format no incumbent offers. | +| **flywheel** routing + receipts | one request shape over every provider, observed per-provider scoreboard | AI-spend governance: cost-honest routing, escalation receipts, the first "what did the model spend buy us" ledger. | +| **studio-engine** + telos creative | seeded, replayable generative worlds/brand kits | Reproducible brand systems: same seed, same artifact -- campaign creative that is re-derivable, auditable, and provably original-to-seed. | +| **learn** | witnessed courses; every graded step writes a receipt | Enablement proof: onboarding and certification that produce receipts, not completion checkboxes. | +| **mneme** | agent memory where every memory carries provenance | Account knowledge that survives turnover: "who told us this, when, from which document" as a queryable property. | +| **crucible** | falsifiable claim verification | Marketing-claims QA and competitor-claim testing: register the claim, measure it, publish the verdict packet. | + +**As the system**: an agency or in-house team runs intake (gather) → brief +verification (crucible) → campaign orchestration (forum) → creative (studio) +→ delivery with receipts (flywheel/desktop), and hands the client one chained +record. The sale is not "AI tools"; it is *defensible delivery*. + +**Honest boundaries**: no marketing-specific integrations exist today (no CRM, +no ad-platform connectors -- though 17 built-in MCP connectors plus the plugin +registry are the extension path). First proof would need one design-partner +agency. + +## Vertical B -- provenance-critical, privacy-bound industries (assembled, not built) + +The material for this vertical already exists across seven site pages and +several repos; it has never been assembled into one buyer-facing argument. + +| Sector | Live requirement | Shipped answer | +|---|---|---| +| **Compliance / model risk (finance)** | Regulators require model origin and lineage to be auditable; incumbent platforms record lineage as editable database rows (site: writing.html; witnessing-spine, DOI'd, steelmans five financial-sector cases). | Merkle-logged receipts with offline inclusion proofs; hash-chained verifiable store with audit tail; attestation binding sign-off to exactly what was reviewed, overclaims tracked. | +| **Legal / e-discovery** | "The summary is not the record." AI summaries entering matters without their sources. | Citation freezing (page bytes fetched, hashed, stored), content-addressed corpora, comprehension gating (a teach-back that pasting the diff cannot pass). | +| **Healthcare administration** | Summaries must keep uncertainty attached (field-guide clinical lane). | Honest nulls as first-class UI; UNVERIFIABLE rendered as loudly as a win; escalation with the failed local attempt on record. | +| **Newsrooms / media** | Every public sentence must find its source (field-guide media lane). | gather → forum → crucible chain; per-block source hashes; tamper caught on re-read (demonstrated in the recorded demos). | +| **Security / red teams (gov, law enforcement, AI labs)** | Authorized adversarial work needs records that hold up afterward, and a lawful-basis gate. | The existing security.html practice + ORCA (v1.0.0, 361 tests, metadata-only engagement workbench). Already revenue-shaped. | +| **Regulated AI operations** | Agent boundaries must be provable, credentials must not travel. | Boundary receipts (raw content never leaves local adapters), capability grants per run, presence-only credentials in the OS keychain, zero telemetry, fully local loop. | + +**The privacy story is architectural, not contractual** -- this is the +differentiator dense-workflow industries actually buy: +- The desktop client's only base URL is 127.0.0.1:8799; no outbound endpoint + exists in the codebase. +- Credential *values* never enter the app, the gateway refuses to accept them + through the marketplace, and the UI shows presence + source only. +- Proofs verify offline: a third party recomputes the Merkle root from the + leaf with no network, no account, no vendor. +- Write/exec are grants per run; a verify stage without an exec grant reports + UNVERIFIABLE rather than pretending. + +**As the system**: the same loop, pointed at regulated work -- intake with +receipts, judgment that fails closed, orchestration with human gates, sign-off +bound to coverage, and an audit trail that a regulator, opposing counsel, or +incident reviewer can re-derive without trusting the operator. + +## Value of each tool alone vs. the system + +Each lane is deliberately "a full product that also runs alone" -- gather, +crucible, index, forum, learn are individually pip-installable with their own +receipts. Alone, each competes in a crowded category on speed/cost and honesty +(the battle map publishes THEY_LEAD rows). Together they occupy compositions +with no incumbent: benchmark-claim escrow, accountable-agent-action, +receipt-carrying creative, the concurrent-desktop agent. The system premium is +the moat; the standalone tools are the doors in. diff --git a/docs/deck/03-target-audiences.md b/docs/deck/03-target-audiences.md new file mode 100644 index 0000000..c4d9b41 --- /dev/null +++ b/docs/deck/03-target-audiences.md @@ -0,0 +1,60 @@ +# Target audiences -- where, how, and why these tools matter on today's frontier + +> The frontier condition in one line: autonomous systems now produce work +> faster than any review lane absorbs it, provenance duties are hardening into +> regulation, and public AI claims go unchecked by default. Every audience +> below is someone for whom one of those three pressures is already a budget +> line or a liability. + +## The three frontier pressures → the system's three answers + +| Pressure (where the frontier bites) | The system's answer | +|---|---| +| **Agents outran review** -- autonomous work lands faster than humans check it | The verified accept path: an external oracle decides; models propose, oracles dispose; UNVERIFIABLE is a legal, visible outcome | +| **Provenance became law** -- lineage/origin duties moving into regulation across finance, health, media | Receipts as infrastructure: content-addressed, Merkle-proven, offline-verifiable, vendor-independent | +| **Claiming became free** -- capabilities, benchmarks, and originality asserted daily, checked never | Claim escrow: sealed verdict packets a stranger, competitor, or court can recompute | + +## Audience matrix + +| Who | Where they live | Why now | How they enter | Value to them | Value to us | +|---|---|---|---|---|---| +| **Agency ops lead** | Campaign delivery, client reporting | Clients audit AI-made work; agencies have no proof layer | forum demo: the replayable run ledger | Defensible delivery -- the client re-checks instead of trusts | First design partner in the greenfield vertical | +| **CMO / martech owner** | Brand, content, AI-spend budgets | AI spend unmeasured; claims risk rising | flywheel routing scoreboard + gather claim receipts | Cost + substantiation in one surface | The paying wedge account for vertical A | +| **GRC / model-risk officer** | Banks, insurers, model inventories | Lineage regulation arrived; current audit trails are editable rows | Witnessing Spine findings + a receipts inclusion-proof demo | Tamper-evident lineage a regulator can re-derive | The regulated flagship reference | +| **Legal ops / e-discovery lead** | Firms, corporate legal departments | AI summaries entering the record without their sources | snapshot (citation freezing) + attestation | Summaries bound to frozen records; sign-off bound to coverage | The dense-workflow proving ground | +| **Newsroom standards editor** | Media, fact-check desks | Generated content floods intake; provenance IS the product | field-guide media lane: gather → forum → crucible | Source-checked publishing with per-block hashes | A public credibility case study | +| **Red team / security lead** | Government, law enforcement, AI labs | AI attack-surface work needs lawful, replayable records | ORCA + the security.html engagement gate | Engagement records that hold up afterward | The already-revenue-shaped practice | +| **Clinical admin / health-ops** | Hospital administration, payer ops | Summaries must keep uncertainty attached | field-guide clinical lane (gather + forum) | Honest-null summaries; UNVERIFIABLE stays visible | Entry into the highest-stakes provenance market | +| **Builders & researchers** | OSS, eval/agent infrastructure | Already served -- the audience the site speaks to today | PyPI packages, recorded demos, DOI'd papers | Tools + receipts + a falsifiable research program | Contributors, field testers, standing -- not revenue | + +## Where each audience is reached + +- **Agencies / CMOs**: martech and agency-ops communities; the deck's Act II-A + is the first artifact that speaks to them -- nothing on the site does yet. +- **GRC / model risk**: the Witnessing Spine paper is citable; model-risk and + AI-governance forums; the "editable rows vs. Merkle proof" demo is the hook. +- **Legal**: e-discovery and legal-ops conferences; the citation-freezing demo + is self-explanatory to anyone who has fought over a dead link in a record. +- **Newsrooms**: the field guide's media lane is already written as a script + with a break test -- publishable as-is. +- **Security**: the practice exists with a lawful-basis gate; the audience is + reached by referral and credential, not marketing. +- **Builders**: already arriving via PyPI, the demos, and the papers. + +## The honest split + +The audience that already responds (builders, researchers) is not the audience +that pays. The audiences that would pay (compliance, legal, agencies, regulated +ops) are named nowhere on the current public surface except behind the +security page's authorization gate. Closing that gap is a positioning task, +not an engineering one -- the evidence is already written, scattered across +seven pages. + +## Why this matters to each side (the deck's dual promise) + +For the owner: each tool is independently sellable (pip-installable, own +receipts, own demo), so every audience above is reachable without waiting for +platform adoption. For the audience: the system never asks to be trusted -- +every claim it makes about their work arrives with the means to re-check it, +which is precisely the property their regulators, clients, editors, and +courts are beginning to demand. diff --git a/docs/deck/04-property-assessment.md b/docs/deck/04-property-assessment.md new file mode 100644 index 0000000..2ad21fc --- /dev/null +++ b/docs/deck/04-property-assessment.md @@ -0,0 +1,120 @@ +# Web-property assessment -- the two domains + +> "Both domains" per the owner's direction: (1) the harperz9.github.io +> portfolio/Project Telos site, and (2) the Flywheel product surface +> (public engine repo + flywheel-desktop + its distribution page). +> Assessed 2026-07-30 from full clones. No registered custom domain exists +> today; behavior-transform.io appears only as a GitHub repository name. + +## Property 1 -- harperz9.github.io (Project Telos site) + +### What it is +72 sitemap pages (87 HTML files), actively maintained (PR #89 merged +2026-07-29), hand-authored on a shared design cascade, deployed from the +private telos-v2 source with a verification gate. + +### Strengths (VERIFIED) +- Near-100% metadata hygiene: title/description/OG/Twitter on 71 of 76 root + pages (the five exceptions are intentional redirect stubs); reproducible + 1200×630 social cards generated from a committed template. +- Tested like a product: ~30 JS unit tests, 8 Python site-contract tests, a + link-check crawler, a visual contract test, CI. +- Accessibility by rule: skip links, reduced-motion mandates, ARIA labels. +- An honesty discipline with no known peer: a published self-audit + (SITE-FIX-LIST.md) that caught its own stale versions and over-counts, a + public correction note ("the honest figure was six"), and a published null + against its own product's uplift claim. All previously-listed defects were + re-verified fixed at assessment time. +- Deep evidence library: 4 recorded receipt-backed demonstrations, 14 research + pages with named falsifiers, 6 DOI'd preprints, a 15-page investor deck. + +### Gaps (DRIFT) +- **No custom domain.** Free github.io hosting; zero owned domain authority; + brand identity split three ways (Zain Dana Harper / Project Telos / + ZentropyLabs, with a ZentropyLabs-ai GitHub org besides). +- **Zero analytics** (grep-verified: no GA/GTM/Plausible/Umami/Fathom/Clarity). + The site is unmeasurable -- by its own thesis, it cannot make a measured + claim about itself. +- **No conversion instrument.** No form, calendar, newsletter, or pricing; + every CTA terminates at a gmail address. The consulting CTA has no landing + page. +- Homepage is a 4.6 KB JS-dependent shell that leads with a compiler test + count rather than a value proposition. +- Residue: 5 redirect stubs + legacy directories from the Quanta→Build rename; + a stale INDEX.json pointing at a dead branch; publications.html was + nav-orphaned per the fix list (now in the sitemap -- verify nav before citing). +- The strongest traction number (Elder ENB: 900k+ downloads, 150k+ unique + users) is buried in a cover letter. + +### Asset verdict +A world-class credibility engine with the commercial layer deliberately (or +by omission) absent. Its value today is evidentiary: it wins the "are these +people real" check instantly. Its unrealized value is everything after that +check -- measurement, capture, and a priced next step. + +## Property 2 -- the Flywheel product surface + +### What it is +The public `flywheel` engine repo, the `flywheel-desktop` client (v0.2.2, +releases + Inno Setup installer), and the site's flywheel.html distribution +page. + +### Strengths (VERIFIED) +- A real, downloadable product: Windows x64 installer, 20 MB, published + SHA-256, engine frozen inside (no Python, no PATH). The only one-click + artifact in the portfolio. +- Supply-chain honesty: releases built from version tags by a public pipeline + with a gate that refuses mislabeled artifacts; the unsigned-binary caveat is + published with the hash as the stated substitute. +- OpenAI-compatible gateway (point an existing client at it; receipts arrive + under the same API) -- the lowest-friction adoption path in the system. +- Desktop client codebase enforces its own canon in CI (design tokens, verdict + mapping, and version truth are unit-tested; files under 300 lines). + +### Gaps (DRIFT) +- **The public engine lags the dev engine by ~9×**: 11 API routes and v0.1.0 + in the public repo vs. 102 routes in the local-model dev checkout. The + desktop client's README describes surfaces (receipts, plugins, memory, + studio, attest) that the public engine repo does not yet expose -- an + integrity risk for exactly the audience this portfolio courts. +- Distribution is GitHub-releases-only; no product page exists outside the + portfolio site; Windows-only installer today (macOS/Linux runners exist in + CI but no shipped artifact). +- No pricing, license clarity beyond FSL-1.1-MIT on the engine, or support + channel. + +### Asset verdict +The product is more real than its public face. The single cheapest +credibility win in the portfolio is a dev→public sync cadence; the second is +a product page with the installer, the hash, and one recorded demo above the +fold. + +## Adjacent properties on the shelf + +Private repos `harpercompliance-site` and `sendmyletter-site` (both touched +2026-07-15) indicate property experiments beyond the portfolio -- the compliance +name in particular aligns with vertical B and the owner's GRC documentation +history. Not assessed (private, out of session scope); noted as existing +assets when a domain strategy is chosen. + +## Recommendations (in order of compounding) + +1. **One name, one domain.** Pick the commercial identity (ZentropyLabs is the + publisher of record in the installer) and register one domain; serve the + site there with github.io as a mirror. Every DOI, receipt, and release + currently builds authority for a domain the project doesn't own. +2. **Instrument honestly.** Self-hosted, privacy-respecting analytics plus one + conversion instrument (work-thread form or calendar). This is the site's + own credo applied to itself: no claim without measurement. +3. **Publish the two vertical pages.** Vertical B assembles from seven + existing pages; vertical A (sales & marketing) does not exist and is + greenfield. The deck's Act II is the draft. +4. **Sync the public engine.** Keep the public flywheel repo within one minor + version of the dev gateway so the desktop README's claims are checkable + against the code behind them. +5. **Price one thing.** The security/ORCA practice is already revenue-shaped; + give it (or a receipts pilot for GRC/legal) a package and a number. One + priced offer converts the evidence library from portfolio into pipeline. +6. **Promote the traction line.** Move the 900k-download graphics record and + the six-package PyPI roster onto the entry surfaces where a first-time + visitor forms their judgment. diff --git a/docs/deck/flywheel-telos-deck.html b/docs/deck/flywheel-telos-deck.html new file mode 100644 index 0000000..df7f202 --- /dev/null +++ b/docs/deck/flywheel-telos-deck.html @@ -0,0 +1,650 @@ +