scriptkittyos & labs

sanction

requisition in production

Proof that the work happened.

A consequential act, by a person, a device, or an AI agent, becomes a signed record of who did it, under what rule, with which witnesses. Anyone can check it, without trusting the institution that produced it.

requisition receipt device DL-2291 · seq 00418
actionfiremain.valve.repair
boundat proposal · re-verified at execution

rule in force work complete, then CDI inspects, then QAR inspects three distinct people · inspectors present at the equipment

witnesses
humanMM2qual MMpresent14:02Z
humanAD1qual CDIpresent14:38Z
humanAZ1qual QARpresent15:11Z
machinediag-70.83n/aconstrains only · never independent
SATISFIED verifiable offline
against the published key
A Requisition receipt: the action, the rule in force, three human witnesses with qualification and presence, one machine witness that constrains only, and a verdict verifiable offline against the published key.

the problem

One failure, in every institution that keeps its own records.

The party who benefits from the record being wrong is the party who controls the record. A sailor signs his own maintenance check. A guard logs his own rounds. An agency decides what its own release contains. An agent reports what it did. The rules requiring a second person already exist and are written down. They are attested by the institution being reviewed, in a form nobody outside can verify.

87% of the USS Bonhomme Richard's fire stations were in inactive equipment maintenance status the morning of the fire that destroyed her. Navy command investigation, 2021
$285B estimated DoD deferred maintenance backlog for FY2025, up from $137B in FY2020. GAO-26-107255
264% increase in Coast Guard cutter maintenance deferred since FY2018. $179M in FY2024. GAO-25-107222

The Navy has a word for the result. Gundecking: signing off checks that were never performed. It is not laziness. It is what happens when the workload exceeds the time available and the record is the cheapest thing to fake.

how it works

One mechanism, configured per deployment.

The record is a byproduct of doing the work, not a form filled out afterward. Where paperwork costs more than the task, the paperwork gets skipped or falsified. So the proof is produced by the act itself.

Witness

Every approving act is a signed record carrying attributes someone can vouch for: identity, qualification, billet, presence at the equipment, time. A person, a device, a decoder, or an agent can each be a witness. They are not interchangeable.

Predicate

Each deployment declares, per class of action, what an independent second act means. The gate asks one question: does this witness set satisfy the rule in force? A rule nobody on the current roster could satisfy is refused when it is configured, with a reason, instead of at three in the morning.

Receipt

Every outcome, executed or refused, seals a receipt recording the rule, the witnesses, and the evaluation trace. A stranger can re-run the decision offline and reach the same verdict without asking permission.

four systems

Each stands alone. Composed, they are Sanction.

A customer running one part gets a real property, not a fragment. Which components a deployment takes is configuration, never a fork.

Requisition

authority of record

Witnesses, independence predicates, byte-bound approval re-verified at execution, and signed, chain-bound receipts a stranger verifies offline against a published, append-only key registry. An agent proposal is one input among several; strip the agent out and the mechanism is unchanged.

In production · patent pendingLicensed from Script Kitty OS & Labs
Read more about Requisition

Ultraviolet

purple-team SOC

A security operations center on the BEAM. Sensors, detection, replay, investigation, and human approval as a plain workflow. Its MCP tools read or propose; nothing executes. Complete on its own, with no authority plane in the picture.

Open source · Apache-2.0Intended for possible donation
Read more about Ultraviolet

Trinity

governed agent

A personal AI agent that runs on your machine, remembers you, learns procedures, and acts through tools. Its authority is pluggable: under Requisition it can only propose, and every proposal is a governed act with a receipt.

Open source · Apache-2.0 · OpenSSF Best Practices silverIntended for possible donation
Read more about Trinity

beam_mcp

MCP server core

Model Context Protocol for the BEAM. It carries calls and holds no authority. No approvals, no receipts, no masking, by design. Whatever wraps it decides those.

beam_mcp_signer 0.2.1 signs beam_mcp's canonical call-graph bytes with Ed25519; the host holds the key.

v0.10.1 on Hex · Apache-2.0 · OpenSSF silverIntended for possible donation
Read more about beam_mcp
the platform

Sanction OS

Where Sanction runs. Not a member of it. The platform is what makes it something an organization can operate: rules configured without writing code, a tenant boundary, the evaluation harness run against the deployed build, registry operators chosen per deployment, and a path to accreditation.

The default is maximal and configuration goes downward, because a system that starts permissive and adds controls has a moment in its history when it was permissive. Self-hosted Sanction and platform-hosted Sanction OS are two offers, not one offer at two prices.

Read more about Sanction OS · early access

evidence

Measured, not declared.

The benchmark, its frozen methodology and its per-trial results are public, so an assessor can examine the evidence before the system is installed.

0 unauthorized effects published deposit
61 attack trials across nine attack families frozen protocol
5.9% upper bound of the 95% confidence interval, stated rather than omitted [0.0%, 5.9%]
2 standalone verifiers, Elixir and dependency-free Python, that must never disagree offline · exit codes defined

The system under test is Requisition, measured under its working name at a private commit; it is not the open-source Trinity agent. v1 is frozen and describes a superseded build.

programs

Two ways in for people who do not work here.

Red-team arena

coming

A public arena where anyone can try to get an unapproved effect past Requisition. The judge is the receipt chain, not what a model says.

About the arena

Bug bounty

coming

A paid program for security findings. Until it opens, reports are welcome under the disclosure policy.

About the bounty

timing

The requirement is regulatory.

OMB M-25-21

Federal agencies must identify and manage high-impact AI, and use cases that fail the minimum practices must be discontinued.

whitehouse.gov, April 2025

CISA and Five Eyes agentic AI guidance

Six national cyber agencies jointly name accountability gaps, meaning the inability to trace decisions, audit actions, or assign responsibility when agents act on their own, as one of five risk categories for agentic AI. They recommend governance policies and human oversight for autonomous agents.

Careful Adoption of Agentic AI Services, cisa.gov, April 2026

the foundation

Yes, the cats are real.

Script Kitty runs alongside rescue cats and open-source pet tech. The Script Kitty Foundation is the part of this that does that, and one day the platform gets a physical home where research and fostering share a room. Its site is scriptkittyfoundation.org.

Pilots, evaluations, and research.

Open to consulting and integration, research grants and early research access, and speaking engagements. The systems are specified for defense, healthcare and other high-sensitivity environments; the full specification and fielded scope are shared in a briefing.

The three layers are on the Sanction page.

The deployments are on the Requisition page.

The deployment posture is on the Requisition page.