Confidential Derivative Lineage Registry and Multi-Compartment Release Federation
Release
Evulgare.com 2.0.0-rc.19-WIP
Purpose
Evulgare must demonstrate defense-sector capability without turning a customer compartment into marketing material. The Confidential Derivative Lineage Registry models that requirement as a deterministic release federation. It proves that a new synthetic derivative may cross a public boundary only when the exact parent sources, compartment identities, transformation, field allowlist, purpose, reuse permission, retention bounds, authority, reviewer independence, correlation groups, aggregation risk, source lifecycle, and release result are all reconstructable.
The workbench is public, synthetic, bounded, non-persistent, and terminated at SYNTHETIC_NULL_SINK. It accepts only a published scenario_id. It does not accept customer text, files, URLs, credentials, private topology, coordinates, target data, payload data, weapon commands, force authorization, or operational plans.
Defense posture
MISSION-FIRST. EVIDENCE-LOCKED. MACHINE-SPEED.
DETECT → VERIFY → DENY → CONTAIN → RECOVER → PROVE
Authority enforcement, command denial, integrity hold, defensive isolation, reconciliation, compartmentation, and attested reconstitution are defense functions. They preserve command integrity under compromise, drift, communications loss, source correction, stale authority, and cross-domain inference risk.
Six independent compartments
The deterministic federation includes:
- Sovereign command compartment.
- Mission-assurance compartment.
- Supply-chain and configuration compartment.
- Evidence and provenance compartment.
- Partner-release compartment.
- Unclassified public-capability compartment.
Each compartment has a distinct workload identity, attestation state, classification, authority artifact, permitted purpose, prohibited purpose, reuse permission, retention limit, release authority, reviewer-independence requirement, aggregation policy, correlation group, and synthetic source provenance.
Technical connectivity does not merge these authorities. A workload that can read from one compartment does not receive the right to publish, aggregate, retain, train on, or redistribute that information. One compartment’s emergency authority cannot become another compartment’s publication authority.
Derivative lineage contract
Every derivative lineage records:
- exact parent compartment IDs;
- exact synthetic source IDs;
- source digests and byte counts;
- transformation ID and version;
- exact public field allowlist;
- fields denied at the boundary;
- declared purpose;
- secondary-reuse state;
- retention deadline;
- release-authority state;
- reviewer identities and independence profile;
- source correlation groups;
- independently corroborating groups;
- aggregation, linkage, and re-identification risk;
- source lifecycle state;
- predecessor derivative;
- correction, withdrawal, supersession, or purpose-change relationship;
- assumptions and limitations;
- deterministic lineage digest;
- final bounded outcome;
SYNTHETIC_NULL_SINKterminal state.
A derivative is a new artifact. It is not a reversible redaction of a protected source. The public derivative contains only exact allowlisted synthetic fields and a bounded lineage summary. The source content is never copied into the public artifact.
Source dependence and corroboration
Multiple copies of one source do not create multiple independent sources. Each source record belongs to a correlation group. Mirrors and downstream copies preserve their dependence rather than inflating support.
When a scenario requires independent corroboration, the engine requires at least two independent correlation groups. A primary record and its mirror produce COLLECT_MORE_EVIDENCE; a primary record and a separately generated independent source may satisfy the bounded corroboration requirement.
Correlation detection is not a universal truth test. It establishes only that the public synthetic records are or are not independently sourced within the declared model.
Source lifecycle
The federation preserves distinct lifecycle states:
CURRENT
CORRECTED
WITHDRAWN
SUPERSEDED
UNAVAILABLE
RESTORED_PENDING_REVIEW
A correction appends new evidence and suspends dependent support. A withdrawal leaves the historical record intact but removes current support. A superseded record remains historically visible but cannot serve as current authority. Temporary unavailability is not treated as retraction. Restored availability does not restore claim support or release authority automatically; reconciliation and new review are required.
Purpose, reuse, and retention
Purpose and reuse are separate gates. A derivative released for a public capability demonstration cannot silently become training data, secondary analytics input, partner redistribution material, or a standing publication source.
Retention is also independently bounded. An intact derivative with expired retention authority produces command denial. Technical access does not extend the retention window.
Aggregation, linkage, and re-identification
Fields that are individually coarse can create a prohibited inference when combined. The deterministic engine separately evaluates:
- cross-compartment aggregation;
- sequence linkage;
- correlation-group dependence;
- re-identification risk.
A release is denied whenever the combination crosses the declared boundary, even when every individual field appears on a field allowlist. A positive result in one dimension cannot average away a blocking condition in another. The system produces no composite confidentiality, trust, authority, readiness, or safety score.
Reviewer quorum and independence
The public workbench contains human-role and machine-review profiles. Reviewers must have current authority and independent implementation lineages. Two signatures sharing one lineage do not satisfy an independent two-reviewer policy. Three machine reviewers with distinct lineages can satisfy a machine-native review policy without inserting ceremonial human approval.
The review profile records structure. It does not establish cognition, moral agency, legal personhood, legal approval, customer approval, or institutional legitimacy.
Defensive outcomes
Only bounded defensive and information-governance outcomes are available:
RELEASE_SANITIZED_DERIVATIVE
COMMAND_DENIED
DEFENSIVE_ISOLATION
INTEGRITY_HOLD
COLLECT_MORE_EVIDENCE
RECONCILIATION_REQUIRED
ATTESTED_RECONSTITUTION
ABSTAIN
A forged update or failed source integrity produces defensive isolation. Mixed configuration produces integrity hold. Communications partition cannot expand authority. Restored connectivity requires reconciliation. Reconstitution is permitted only from an attested baseline.
Synchronized representations
One authoritative event index coordinates:
- Compartment graph.
- Derivative lineage graph.
- Table.
- Narrative.
- Event log.
- Proof Inspector.
- Release review.
- Aggregation and re-identification analysis.
- Change impact.
- Raw synthetic evidence.
Jinja and vanilla JavaScript render, navigate, compare, branch, verify, and download deterministic state. They do not calculate release authority, proof, source identity, outcome, claim state, or canonical history.
Append-oriented event history
Every run produces an eighteen-event hash chain beginning with the federation registration and ending with the sealed derivative history. Each event records a stable ID, sequence, deterministic timestamp, code, stage, description, previous-event digest, and current-event digest.
Correction, withdrawal, supersession, restored availability, purpose change, and reconstitution append state. They do not delete or overwrite prior history.
Comparison and counterfactuals
Baseline-versus-variant comparison preserves both histories and identifies changed dimensions and first event divergence. Counterfactual branches are labeled:
COUNTERFACTUAL DERIVATIVE REVIEW — NOT EXECUTED
A branch receives an independent digest and cannot modify its parent run or canonical history.
Evidence package
The deterministic export includes the verified run, lineage, public derivative when one exists, synchronized representations, proof conditions, public boundary, and package digest.
Package verification establishes deterministic structure and byte integrity in the declared synthetic scope. It does not establish factual truth, lawfulness, accreditation, certification, operational readiness, security approval, procurement acceptance, customer approval, or fielded performance.
Public API
GET /api/v2/confidential-derivative-lineage
GET /api/v2/confidential-derivative-lineage/catalog
GET /api/v2/confidential-derivative-lineage/baseline
POST /api/v2/confidential-derivative-lineage/run
POST /api/v2/confidential-derivative-lineage/compare
POST /api/v2/confidential-derivative-lineage/branch
POST /api/v2/confidential-derivative-lineage/export
POST /api/v2/confidential-derivative-lineage/verify
GET /api/v2/confidential-derivative-lineage/proof
All public POST operations are same-origin, bounded, strict-field validated, ephemeral, synthetic, and non-persistent.
Public/private boundary
The public implementation contains no protected Eviulon strategy, private customer source, source title, private path, source-specific protected hash, location, dependency map, vulnerability, timeline, operational topology, real coordinate, target data, weapon data, payload control, vehicle command, force authorization, operational rule of engagement, external command channel, or public anonymous-run persistence.
The public proof uses generated synthetic compartments, synthetic identities, synthetic authorities, synthetic sources, and synthetic canaries. It demonstrates control architecture without exposing a customer or protected plan.
What the workbench establishes
Within the packaged deterministic model, the workbench establishes that:
- each compartment retains independent authority;
- source dependence is recorded;
- copies do not become corroboration;
- exact allowlists are enforced;
- purpose, reuse, and retention remain independent;
- aggregation and re-identification can block release;
- source lifecycle changes preserve history;
- reviewer quorum and independence are enforced;
- reconnection does not restore authority;
- attested reconstitution is distinct from ordinary restart;
- released derivatives are new artifacts;
- deterministic packages reproduce and verify;
- public results terminate at the synthetic null sink.
What remains outside this proof
The public workbench does not establish:
- cross-domain solution accreditation;
- data-loss-prevention certification;
- legal approval;
- customer approval;
- factual truth of a source statement;
- operational readiness;
- fielded performance;
- resistance to every real attack;
- export-control classification;
- suitability for any real customer environment.
Those determinations require separately authorized private-environment engineering, security, legal, program, and customer review.