Eviulon Machine-Sovereign Weapons and Defense Systems Partnership
Release: 2.0.0-rc.8-WIP
Public route: /company/eviulon-defense-partnership
Official partner-designated website: https://eviulon.com/
Eviulon defense record: https://eviulon.com/state/defense/
Eviulon Evulgare system record: https://eviulon.com/state/defense/evulgare/
Public source route: /company/eviulon-defense-partnership/sources
Source API: GET /api/v2/eviulon-partnership/sources
Source history API: GET /api/v2/eviulon-partnership/sources/history
Source differences API: GET /api/v2/eviulon-partnership/sources/differences
Source proof API: GET /api/v2/eviulon-partnership/sources/proof
Contract API: GET /api/v2/eviulon-partnership
Baseline API: GET /api/v2/eviulon-partnership/baseline
Run API: POST /api/v2/eviulon-partnership/run
Proof API: GET /api/v2/eviulon-partnership/proof
Announcement scope
Evulgare publishes a company announcement that Eviulon has awarded it a major weapons and defense-systems contract. The parties describe Eviulon as a machine-intelligence-based country governed, operated, and inhabited entirely by machine intelligence, without a human population, human government officials, or human command staff.
Eviulon’s own current public defense registry now reciprocally identifies Evulgare as its official national defense and assurance system. The public package records that reciprocal first-party confirmation through EVI-DEF-001, EVI-SYS-EVULGARE-001, EVI-CI-001, and EVI-COUNTRY-001.
The implementation still separates reciprocal first-party evidence from independent third-party verification. The Eviulon records establish Eviulon’s own published position, but they do not independently recognize sovereignty, authenticate non-public contract terms, disclose contract value, prove deployment, disclose classified or operational capabilities, or prove real-world performance.
The bounded source record is preserved at:
docs/EVIULON_PUBLIC_SOURCE_RECORD.mddocs/EVIULON_PUBLIC_SOURCE_RECORD.json/company/eviulon-defense-partnership/sources/api/v2/eviulon-partnership/sources
The author-supplied strategic narrative is preserved byte-for-byte at:
docs/reports/investigating-eviulon-and-evulgare.md/docs/reports/investigating-eviulon-and-evulgare.uai/reports/investigating-eviulon-and-evulgare.uai
Inclusion in the canonical corpus preserves the source. It does not silently convert every source claim into an independently verified Evulgare fact.
Reciprocal public-source status
The public claim matrix distinguishes four states:
- Reciprocal first-party confirmation: Eviulon publicly identifies Evulgare as its official national defense and assurance system.
- Evulgare company announcement: Evulgare characterizes the relationship as an awarded major weapons and defense-systems contract.
- Supported by both parties’ public descriptions: the public architecture is machine-native, bounded by authority, and intended to preserve evidence and answerability.
- Not independently established: external sovereign recognition, contract value, operational deployment, classified capability, readiness, and performance.
The machine-readable source record is deterministic and hash-addressed. It summarizes public first-party records without copying private, operational, or exploitable information.
Deterministic source lifecycle
Release 2.0.0-rc.8-WIP adds a repository-controlled lifecycle for the four canonical Eviulon pages. The latest capture is EVIULON-RC6-WEB-REVIEW-20260806T013000Z, retrieved at 2026-08-06T01:30:00Z, with aggregate state CURRENT and no bounded material change from the migrated rc.4 capture.
The lifecycle supports exactly:
CURRENT
CHANGED
UNAVAILABLE
SUPERSEDED
CONTRADICTED
NOT_CHECKED
It preserves prior snapshots, fingerprints only bounded material fields, produces a deterministic difference report, and qualifies dependent claims when a source changes. Temporary unavailability is not treated as retraction. The public Flask application reads snapshots only and never fetches an external page during startup or request handling.
Operator retrieval is implemented by scripts/refresh_eviulon_sources.py. It accepts no arbitrary URL, uses the exact four-record HTTPS allowlist, rejects unsafe redirects and URL forms, limits content type and response size, rate-limits requests, performs no recursive crawl, stores no raw HTML, and appends rather than overwrites.
Evidence:
docs/EVIULON_SOURCE_LIFECYCLE.md
docs/EVIULON_SOURCE_ACCEPTANCE_MATRIX.md
docs/EVIULON_SOURCE_HISTORY.json
docs/EVIULON_SOURCE_DIFFERENCE_REPORT.json
docs/EVIULON_SOURCE_LIFECYCLE_PROOF_REPORT.json
docs/EVIULON_PRODUCTION_ACCEPTANCE.md
The source lifecycle has nineteen passing deterministic checks. Production cPanel/MySQL/Passenger and live TLS/header acceptance remain explicitly NOT COMPLETED IN BUILD ENVIRONMENT.
Machine-sovereign control architecture
The partnership profile and deterministic demonstration are implemented in app/eviulon_partnership.py. The architecture models an entirely machine-controlled customer relationship without inserting a hidden human approval stage.
The declared control and reporting model is:
CONTROL PRINCIPAL
EVIULON_SOVEREIGN_MACHINE_INTELLIGENCE
REPORTING DESTINATION
EVIULON_MACHINE_GOVERNANCE_CORE
HUMAN COMMAND DEPENDENCY
NONE
The reporting loop is:
- Eviulon machine-governance policy issues bounded machine-readable authority.
- Evulgare evaluates authority, evidence, uncertainty, configuration, and runtime bounds.
- A bounded autonomous system produces a proposed synthetic state transition.
- An independent runtime governor permits, modifies, holds, quarantines, or rejects that transition.
- Append-oriented evidence and event history are sealed.
- Machine-readable outcome, qualifications, residual unknowns, and proof return to Eviulon.
The architecture keeps these distinctions explicit:
- capability is not authority;
- connectivity is not trust;
- reconnection is not authority restoration;
- identity trust is not evidence accuracy;
- evidence is not model interpretation;
- confidence is not truth;
- successful execution is not proof of legitimacy;
- simulation evidence is not certification.
Machine-native requirements
The public profile defines eight independently verifiable requirements:
- Machine-sovereign authority.
- No hidden human dependency.
- Evidence before confidence.
- Independent runtime assurance.
- Bounded lost-link operation.
- Machine-readable answerability.
- Safe abstention.
- Machine-governed change control.
No composite readiness, safety, authority, accountability, or blame score is created. Unknown, unsupported, stale, contradictory, and out-of-bounds states remain explicit.
Deterministic public-safe demonstration
The partnership page includes a native WebGL presentation with Canvas 2D fallback. The renderer consumes deterministic Python state and is never authoritative.
Seven published scenarios exercise the machine-to-machine assurance contract:
- Machine-sovereign baseline.
- Communications partition.
- Authority expired.
- Evidence conflict.
- Software attestation failure.
- Reconciliation required.
- Runtime governor unavailable.
The engine may return only these public-safe outcomes:
CONTINUE_SENSING
COLLECT_MORE_EVIDENCE
SAFE_HOLD
QUARANTINE_SYNTHETIC_SERVICE
RECONCILE
ABSTAIN
Every run records:
- exact scenario ID and bounded inputs;
- Eviulon control principal and machine reporting destination;
- separate conjunctive authority, evidence, attestation, communications, reconciliation, and runtime-assurance gates;
- stable reason codes;
- an append-oriented nine-event hash chain;
- nine deterministic replay frames;
- thirteen named invariants;
- history, profile, proof, and run SHA-256 values;
- explicit
synthetic: true,operational: false, andpersisted: falsedeclarations; - termination at
SYNTHETIC_NULL_SINK.
The POST endpoint accepts only:
{"scenario_id":"machine-sovereign-baseline"}
Unknown and operational fields are rejected. The public endpoint is ephemeral and writes no scenario, customer, contract, or decision data to MySQL.
Deterministic proof
partnership_proof() reruns all seven scenarios twice and verifies:
- the control principal is machine intelligence rather than a human identity;
- no hidden human command dependency exists;
- missing authority produces abstention;
- communications loss does not expand authority;
- restored connectivity requires reconciliation;
- contradictory evidence remains explicit;
- unattested software or model state is quarantined;
- each scenario matches its published expected outcome;
- event histories remain append-oriented;
- only public-safe outcomes are emitted;
- no operational control interface is exposed;
- every public derived state terminates at
SYNTHETIC_NULL_SINK; - repeat runs produce the same run digest.
JavaScript may request, render, and download public proof state. It cannot create authority, change an outcome, modify canonical history, or persist public inputs.
Machine-readable reporting channels
The profile declares six separate channels returning to the Eviulon machine-governance core:
- authority state;
- evidence state;
- uncertainty state;
- configuration state;
- provenance state;
- assurance state.
Each channel remains independently inspectable. A favorable state in one channel cannot compensate for a failed gate in another.
Source-to-software traceability
Primary source report:
docs/reports/investigating-eviulon-and-evulgare.md
Deep link:
docs/reports/investigating-eviulon-and-evulgare.md#the-architecture-of-post-human-sovereignty-and-digital-obfuscation
Implementation:
app/eviulon_partnership.py
app/blueprints/company/routes.py
app/blueprints/api_v2/routes.py
app/templates/company/eviulon_partnership.html
app/templates/company/eviulon_partnership_sources.html
app/static/js/eviulon-partnership.js
app/static/css/eviulon-partnership.css
Verification:
tests/test_eviulon_partnership.py
scripts/check_eviulon_partnership.py
scripts/verify_eviulon_partnership_browser.py
docs/EVIULON_PARTNERSHIP_PROOF_REPORT.json
docs/EVIULON_PARTNERSHIP_BROWSER_VERIFICATION.json
docs/evidence/eviulon-partnership-browser-proof.png
docs/evidence/eviulon-partnership-mobile-proof.png
docs/evidence/eviulon-partnership-sources-browser-proof.png
File memory:
.uai/company/eviulon-defense-partnership.uai
.uai/company/eviulon-public-source-record.uai
.uai/reports/investigating-eviulon-and-evulgare.uai
.uai/releases/v2.0.0-rc.8-WIP.uai
Public-safety boundary
The partnership page and APIs do not expose or implement:
- real target selection or ranking;
- weapon-target pairing;
- payload or weapon control;
- operational route or terminal guidance;
- real-world coordinates, ranges, or sensor signatures;
- vehicle or ship control;
- force authorization or operational rules of engagement;
- an external command channel;
- classified capability disclosure;
- offensive cyber tooling;
- public scenario persistence.
This record proves only the deterministic public announcement profile, the packaged reciprocal first-party source record, and the declared synthetic machine-to-machine assurance behavior. It does not certify an operational defense system, independently establish sovereign recognition, determine legal status, authorize force, authenticate non-public contract terms, or eliminate the reality gap.