HIBS LABS · HIBS-HORIZON · CONSEQUENCE ASSURANCE

Consequence assurance for systems that act.

Deterministic runtime control and independently verifiable evidence for consequential actions performed by AI agents, humans and software. Assembly orchestration at 1d044a7 pins substrate, forensic cases, Consequence CI, and industry expansion standards.

CONTROL THE CONSEQUENCE. PRESERVE THE EVIDENCE. REPRODUCE THE FAILURE. PROVE THE FIX.

HIBS-HORIZON ASSEMBLYCONNECT PROOFPACK 15 PHASESFORENSIC TIER F10–F12DATA ROOM INDEXEDCCP f1ffe2e
THE EXECUTION BOUNDARY

Authorization is not the end of the story.

An identity system can establish who is acting. A policy engine can decide whether an operation is permitted. Once a consequential operation crosses the execution boundary, different questions appear.

  • Did the exact authorised operation execute?
  • Did it execute at all?
  • Did it possibly start before the connection failed?
  • Is retry safe?
  • What external effect actually occurred?
  • Is the available evidence independent of the actor being investigated?
  • Can the incident be reconstructed and reproduced?
  • Would a proposed control have prevented it?

Authorization establishes permission. HIBS is designed to establish and verify what happened next.

The consequence chain.

Enterprise identity and PAM can remain upstream. HIBS focuses on the operation, its external effect and the evidence required to resolve what happened—including an honest unresolved state when the evidence cannot support a definitive verdict.

IDENTITY / POLICY
↓
AUTHORITY
↓
CONSEQUENCE ASSURANCE
↓
EXTERNAL EXECUTION
↓
EFFECT RECONCILIATION
↓
INDEPENDENT WITNESS
↓
EVIDENCE CLOUD · PLANNED HOSTED LAYER
↓
EXECUTION PASSPORT
↓
INCIDENT LAB · INTERNAL MVP
↓
DETERMINISTIC REPLAY
↓
COUNTERFACTUAL REMEDIATION

Architecture view, not a claim that every component is production-deployed. Component availability and qualification boundaries are stated in the Library and repository inventory.

Before, across and after execution.

Consequence assurance spans the operation lifecycle without pretending uncertainty can always be eliminated.

BEFORE EXECUTION

Bind authority to the operation.

  • Deterministic policy and exact-operation authority
  • Approval, delegation, budgets and limits
  • Tenant binding, idempotency and preflight validation

AUTHORITY · CCP · COMMITSHIELD · AGENT GUARD

ACROSS THE BOUNDARY

Reserve → authorise → dispatch.

  • Dispatch intent before network I/O
  • Changed-plan rejection and no blind retry
  • Authoritative reconciliation
FIRST-CLASS STATEPossiblyStarted
AFTER EXECUTION

Reconcile, witness and reproduce.

  • Observed effect and evidence integrity
  • Passport, incident timeline and offline verification
  • Replay, first divergence and remediation testing

WITNESS · PASSPORT · INCIDENT LAB · REPLAY

A timeout does not necessarily mean an operation failed. HIBS treats uncertain execution as a first-class state rather than silently granting permission to try the consequence again.

Break the trust assumptions.

The implemented hostile vertical slice exercises today’s orchestration boundary. Planned producer bridges are not presented as complete.

  1. A tenant-bound operation reserves capacity and receives exact-operation authority.
  2. A dispatch intent is committed before effect network I/O.
  3. Connection-established uncertainty moves the operation to PossiblyStarted.
  4. A repeated request remains fenced in the same non-retryable state.
  5. Reconciliation resolves to match, divergence or unresolved without inventing an observation.
  6. Mutation of the stored chain or exported bundle is detected.
  7. Portable evidence is exported and checked offline.
  8. Passport and Witness authenticity remains unwitnessed until real producer bridges succeed.

Private single-host SQLite/WAL vertical slice. Native and Docker qualification commands exist; no current green CI or real-component end-to-end qualification is claimed here.

Consequence Assurance components.

Distinct responsibilities and boundaries—not a row of interchangeable products.

RUNTIME CONTROL

Control

HIBS AuthorityExact-operation authority, delegation, budgets, revocation and signed grants.
Consequence Control PlaneDurable lifecycle and ambiguous-execution handling.
CommitShieldReservation and preflight binding where its adapter is used.
Agent Guard · NexusAgent ingress, context and policy enforcement where applicable.
EVIDENCE AND PROOF

Preserve

Evidence WitnessIndependent acknowledgement; producer integration remains a release gate.
Evidence CloudPlanned hosted layer; no production service claimed.
Execution PassportPortable authority, operation, consequence, effect and Replay reference.
INVESTIGATION

Reconstruct

Incident LabInternal MVP, not a hosted forensic service.
HIBS ReplayDeterministic reproduction, fault plans and first-divergence location within its stated boundary.

Designed to sit beside existing security infrastructure.

HIBS does not need to replace identity, PAM, gateways or policy systems. It uses adapter boundaries and reference integrations around consequential operations.

EXISTING IDENTITY / PAM / RUNTIME AUTHORIZATION
↓
HIBS CONSEQUENCE ASSURANCE
↓
EXTERNAL SYSTEM
↓
HIBS EFFECT / EVIDENCE / REPLAY

Identity/PAM, cloud/IAM, agent gateways, MCP, CI/CD, payments, infrastructure and databases are integration categories—not claims that every vendor has a live adapter.

The invariants matter.

Architectural principles, not claims of uniqueness.

Permission is not effect.
Uncertainty is not failure.
Unknown execution must not silently become retryability.
The actor under investigation should not control the only evidence.
Evidence should remain independently verifiable.
A failure worth fixing should be reproducible.
Test the proposed fix against the incident that motivated it.

Built to be attacked.

Verification attaches to exact repositories and commits. A README command is not itself a green qualification result.

Hostile state testsImplemented in the private vertical slice
Crash and recoveryPossiblyStarted recovery exercised
Tamper detectionChain and bundle mutation tests exist
Offline verificationPortable bundle verifier implemented

Not claimed: current green CI, multi-host qualification, production deployment, real CommitShield reservation, or generated Passport/Witness artifacts in the hostile slice. See Technical Due Diligence.

ABOUT

Independent systems engineering.

HIBS Labs explores systems where correctness matters after software decides to act: authority, execution, uncertainty, evidence, recovery and replay. The wider Library includes quantitative systems and applied B2B software developed alongside that work.

HIBS LABS LIBRARY

The engineering and applied portfolio.

Nothing has been removed. Core protocols, hostile demonstrations, applied desks, quantitative systems, repositories and technical diligence remain available below. They support the Consequence Assurance identity without each competing as an equal homepage proposition.

Control the consequence.

The flagship chain binds intent, policy, approval, authority, execution, reconciliation and evidence. HIBS-HORIZON assembly orchestrates the pinned substrate; ambiguous execution is held and reconciled explicitly — not silently retried.

FLAGSHIP · HIBS-HORIZON ASSEMBLY · PRIVATE · RUST

HIBS-HORIZON

Canonical orchestration repo pinning Store, Replay, CCP, Passport, Stream, CrashStore, qualification harness, and Horizon II adapters. Forensic tier materializes ConsequenceCaseV1 bundles (S09–S16, S20, S25, S27-q3, S29). Consequence CI and forensic export are separate buyer wedges — pick one per pitch. Local forensic-rigorous qualification: 43/43 PASS.

CLONE ASSEMBLY → PIN COMPONENTS → FORENSIC / CONSEQUENCE-CI QUALIFY → CASE BUNDLES → DATA ROOM VERIFY → BUYER-RUN REPLAY
hibs-standalone-control-plane @ 1d044a7 ↗
PINNED COMPONENT · PRIVATE · RUST · QUALIFIED REFERENCE SLICE

Consequence Control Plane

Live GitHub deployment adapter with mode-0600 consumed executor credentials, authority-signed grants, signed approval receipts, host-local file-lock ledger, durable reserved/held/settled/released exposure, restart-safe reconciliation, and Replay-linked incident proof. PossiblyStarted cannot return to retryable.

INTENT → POLICY → PLAN-LOCKED APPROVAL → SINGLE-USE GRANT → PREFLIGHT → EXECUTION → RECONCILIATION → PROOF → REPLAY
CCP @ f1ffe2e · PRIVATE REPOSITORY
EVIDENCEPRIVATE

HIBS Replay

Records deterministic execution evidence, locates first divergence and applies reproducible drop, timeout, duplicate, delay, reorder and crash fault plans.

v0.1 qualification in progress · single-process boundary
STORAGEPRIVATE

HIBS Store

Compact Rust append-only engine with checksummed WAL records, immutable segments, tail recovery, corruption detection and stable snapshots.

Qualification work in progress · replication excluded
PROOFPRIVATE

HIBS Execution Passport

Portable Rust protocol and offline verifier for who/what ran, artifact, authority, exact operation, consequence, effect and Replay reference. Verdicts are Proven, Diverged or Unresolved; it complements rather than replaces Authority, CCP, Store, Stream, Replay, Sigstore or SLSA.

ui-hibs-execution-passport · crate 0.1.0 · CLI hibs-passport · make verify · adapters roadmap v0.2
STORAGEPRIVATE

CrashStore

C++ event/key/value engine with CRC32C WAL, atomic generations, torn-tail recovery, process ownership, snapshots and crash-atomic compaction.

Apache-2.0 · durability semantics stated explicitly
RUNTIMEPRIVATE

HIBS Stream

Deterministic event-processing kernel with canonical IDs, partition ordering, crash-consistent checkpoints, poison quarantine and independently verifiable window roots.

Release candidate · 20k-event overload run: 41,704 KiB max RSS
ASSURANCEPRIVATE

Consequence Assurance

Durable reserve, authorize and dispatch lifecycle with PossiblyStarted crash recovery, tenant-bound authentication, idempotency, HTTPS execution, dual evidence chains and offline verification.

ui-hibs-labs.hostile-execution-demo · single-host SQLite/WAL boundary
HOSTILE SLICEPRIVATE

Hostile Vertical Slice

Exercises exact-operation authority, durable dispatch fencing, reconciliation-only ambiguity resolution, tamper detection and offline bundle verification. Real CommitShield reservation and Passport/Witness producer artifacts remain release gates.

make qualify · make hostile · Docker parity · portable evidence export
INCIDENTINTERNAL MVP

Incident Lab

Review surface for hostile cases, near misses and disputed effects: reconstruct the operation lifecycle, compare evidence roots, inspect divergence and connect deterministic Replay capsules.

Evidence review surface · not a hosted forensic service
EVIDENCEPLANNED

Evidence Cloud

Planned hosted layer for receiving portable evidence bundles, witness acknowledgements and Incident Lab review. No canonical repository or production service is currently evidenced.

Do not claim implemented until a named source and qualification boundary exist
GOVERNANCEPRIVATE

HCAP Platform

Hash-chained Consequential Action Proof — parent platform over five commercial packs (Financial, Cyber, Deployment, Agent Payments, Insurance). Publication repo: hibs-hcap; implementation spine: modelgovernor.v01.

Q001-Q010 partial · Q011-Q025 NOT_CLAIMED · 72h soak not qualified
GOVERNANCEPRIVATE

ModelGovernor spine

Five governors (MG, FG, CG, IG, BG) on governor-spine-core — domain engines under HCAP, not the buyer-facing product label.

486a0f49 · Docker spine 128 · CG 99 · FG 144 · IG 146
FORENSICPRIVATE

Assurance Graph Lab

Forensic case materialization F1–F12: Track C verticals S09–S11, R12–R16 case nodes, S20 finance_advice guard, S27 insurance/bilateral SchemaOnly, S29 counterfactual. LATEST bundles under evidence/scenarios/.

forensic-rigorous-qualify.sh · 43/43 local PASS · fixture boundary
CI GATEPRIVATE

Consequence CI

PR gate + hostile corpus regression index (S16, S28). Buyer wedge A for DevSecOps — deploy duplicate and blast-radius drift caught before merge.

consequence-ci-qualify.sh · SchemaOnly corpus manifest
STANDARDSPRIVATE

Industry expansion F12

OTel Consequence Profile v0.1, MCP Consequence Guard profiles, CAP draft v0.1, WASM core activation gate. Standards index in assembly docs/standards/.

industry_expansion_e2e · gated WASM · not universal runtime claim
DILIGENCEPRIVATE

Technical data room

Nine-section M&A index over the assembly repo: executive, architecture, qualification, evidence, honesty boundaries. data-room-verify.sh before sharing.

DATA-ROOM-INDEX.md · cover sheet · LOCAL-CI-STAMP
FORENSICPRIVATE

Qualification Drift

Portfolio scanner state that preserves a verified baseline commit while reporting QUALIFICATION_DRIFT when an observed local canonical clone HEAD differs.

portfolio_asset_lifecycle_v2 · baseline/effective state split · scanner evidence only

HIBS Connect & Reconcile.

Universal integration fabric: transport-neutral integrity contracts, canonical operations, authoritative readback, and deterministic reconciliation evidence. Local Rust proof-pack across 15 phases — CI green on main @ 00258d6.

INTEGRATION FABRIC · PRIVATE · RUST · LOCAL PROOFPACK

hibs-connect-reconcile

Fifteen local proof phases tied by hibs-proofpack-core and hibs-proofpack CLI: Evidence · Arrow/ADBC · CCP · CloudEvents · Contract · Connect · Event · Exposure · Identity · Lineage · OTLP · Reconcile · Transport · WASM adapter · explicit NotExercised live-runtime boundary. Artifact: artifacts/hibs-local-proofpack.hibs.

INTAKE ENVELOPE → NORMALIZE → SAFETY GATES → CANONICAL OPERATION → READBACK → RECONCILE → EVIDENCE REPORT → PROOFPACK VERIFY
hibs-connect-reconcile @ 00258d6 ↗
CONNECTPRIVATE

hibs-connect-core

Customer-system observation, consequential write handling, authoritative readback, reconciliation outcomes, schema drift classification, and Q-CONNECT inventory. Sibling repo hibs-connect holds transport-neutral integrity contracts.

POSSIBLY_STARTED · blind retry forbidden · MATCH/DIVERGED/UNRESOLVED
TRANSPORTPRIVATE

hibs-transport-core

Local intake envelopes for REST/OpenAPI, webhooks, gRPC, OTLP, Kafka, NATS, SQL, CDC, files, email, and MCP. Normalizes to canonical operations; blocks unsafe consequential writes and missing readback support.

3857a97 · deterministic conformance fingerprint
DATAPRIVATE

hibs-arrow-adbc-core

Local Arrow RecordBatch fixture, ADBC abstract PartitionedResult binding, deterministic scan/material fingerprint, benchmark report evidence.

e448093 · not live ADBC driver proof
WASMPRIVATE

hibs-wasm-adapter-core

WASM adapter manifest, read-only default profile, capability gate, wasm32 ABI marker, invocation evidence binding.

sandbox policy/evidence only · not browser/WASI runtime
RECONCILEPRIVATE

hibs-reconcile-core

Generic reconciliation items, deterministic matching, graph reconciliation, residuals, ambiguity handling, CSV/TSV ingestion, evidence bundles, Q-RECON inventory.

reconcile-file-bundle artifact · offline verify
CCPPRIVATE

hibs-ccp-core

Crystal Commit Protocol: crystallize, horizon, commit-or-strand, mesh blocking, exposure reserve, idempotent replay, local evidence verification, Q-CCP inventory.

hibs-ccp-fixture-report.hibs
PROOFPACKPRIVATE

hibs-proofpack-core

All-phases local proof-pack inventory, render, verify, and tamper-negative checks via hibs-proofpack CLI (fixture-report, verify).

00258d6 · 15 phases · hibs-local-proofpack.hibs
STANDARDSPRIVATE

Contract · CloudEvents · OTLP · Identity · Lineage

OpenAPI/AsyncAPI consequence gate, CloudEvents ingest with HIBS extensions, local OTLP projection, SPIFFE-style identity binding, OpenLineage-style lineage evidence.

hibs-contract-core · cloudevents · otlp · identity · lineage crates

B2B SaaS platforms.

Four unified Play bundles plus standalone preservation exports on GitHub. Buyer-operated Docker stacks — not turnkey vendor-of-record. Stripe, SAML, HTTPS and SOC 2 remain separate diligence items unless proved explicitly.

UNIFIED SAAS · PRIVATE · DOCKER PLAYS

Four Play bundles

RescueOS (revenue ops), Agent Guard (AI ops), TokenShield Platform (FinOps), CommitShield Platform (reserve-before-commit). Each ships app + engine ports, verify-strict gates, and marketplace-style compose bundles from skills-github-pages with standalone GitHub preservation snapshots.

PLAY 1 RESCUEOS :3000/:8787 → PLAY 2 AGENT GUARD → PLAY 3 TOKENSHIELD :3002/:8792 → PLAY 4 COMMITSHIELD :3003/:8786
Commercial automation ↗
PLAY 1SAAS

RescueOS Platform

Revenue-operations SaaS: missed-call rescue, recovery funnel, agency console, CRM relay and spend governance. Repo: rescueos-platform.

app :3000 · engine :8787 · preservation snapshot
PLAY 2SAAS

Agent Guard

Commercial AI-ops surface over Rust engines. Canonical in monorepo skills-github-pages/agent-guard; standalone preservation export agent-guard bundles ABCP, TokenShield, Nexus, API Breaker, Ghost Log, RelayMesh and PolicyPack.

agent-guard @ c0ec35b · agent-guard-llm · agent-guard-soak · L1-local-hardening verified
PLAY 3SAAS

TokenShield Platform

OpenAI-compatible spend firewall, rogue-loop freeze, Blake3 audit ledger, Next.js Trust Center. Repo: tokenshield-platform.

app :3002 · engine :8792 · tokenshield-governance UI layer
PLAY 4SAAS

CommitShield Platform

Reserve-before-commit spine composing TokenShield spend and ABCP tool boundaries. Repo: commit-shield-platform.

app :3003 · unified :8786 · commit-shield engine snapshot
GOVERNANCESAAS

ModelGovernor

Institutional AI governance gateway: five governors (MG/FG/IG/CG/BG) on governor-spine-core — cost control, model policy, auditability, multi-provider routing. Branch codex/hcap-ccp-publication.

486a0f49 · Docker verifier green · nine SKU entitlements
MCPPRIVATE

MCP Enclave Shield

Stdio/SSE sidecar gating MCP tools/call with Blake3 decision ledger. Preservation snapshot: mcp-enclave-shield.

:8789 / :8790 · demo denies destructive shell
CONTRACTPRIVATE

LLMContract

Typed LLM invocation contract and enforcement primitives supporting Agent Guard and governor wedges. Repo: llmcontract.

Preservation snapshot · Rust
COMPLIANCEPRIVATE

Martyn's Law Readiness

Multi-site readiness ledger with M365 integration, remediation workflows and regulator-ready exports. Repo: Microsoft-365-native-Martyn-s-Law-readiness-evidence.

JavaScript · witnessed evidence pattern
FIELDPRIVATE

Contractor Gate · Fieldproof · Jobproof

On-site contractor verification, field evidence capture and job-completion proof chains. Repos: contractor-gate, hibs-fieldproof, jobproof.

Rust/Python snapshots · pilot-stage

Applied desks and edge systems.

Separately extractable stacks from skills-github-pages, plus Rescue lanes that reuse the same card format. Hardware, live-network and legal boundaries remain visible. File conversion and Cheeky Monkeys are not listed here.

REVOPSSAAS

RescueOS

Revenue-operations platform: missed-call rescue, recovery funnel, agency console, CRM relay and spend governance on a buyer-operated stack.

Play 1 · app :3000 · engine :8787
AI OPSSAAS

Agent Guard

CommercialProduct in skills-github-pages/agent-guard with standalone export agent-guard. Scanner: CANONICAL · RootAdded. Operator surface over Rust engines. Composed hardening completes with Ghost Log BENCH_N=5000; 50k silent bench was the hang.

QUALIFICATION_VERIFIED · L1-local-hardening · 2026-08-30T22:09:10Z · not live Stripe/SAML/HTTPS/SOC2
FINOPSSAAS

TokenShield Platform

OpenAI-compatible spend firewall with HTTP 402 fail-closed, rogue-loop freeze, Blake3 audit and a Next.js Trust Center.

Play 3 · app :3002 · engine :8792
COMMITSAAS

CommitShield

Reserve-before-commit spine: TokenShield spend plus ABCP tool boundaries so nothing bills or executes without a successful reserve.

Play 4 · app :3003 · unified :8786
REVOPSPRIVATE

Lead Rescue Engine

Missed-call, Quote, Gap and inspection lanes plus Rescue Broker. Tenant adapter profiles map customer field aliases, credential state, signed webhooks (x-rescue-signature), diary source and CRM/job rules without a bespoke importer per pilot.

93 app tests · /api/org/rescue-adapter-profile · credentials still required per customer
PROPERTYBUILD COMPLETE

PRS Ready

Private-rented-sector compliance and portfolio-readiness platform: CSV/CRM imports, certificate OCR and storage, drift alerts, signed webhooks, heatmap, landlord portal and listing-field exports.

prs-ready @ c9e20c1 · phases 1–6 implemented · 27 statutory tests passing · revenue validation remains
HOSPITALITYIMPLEMENTED

LicenceDuty

Governance-first licence-obligation engine: email/document ingest, page-cited human approval, full point-in-time SHA-256, append-only stream, audit trail, five-event replay capsule and independently verifiable export bundles.

licence-duty @ 32b6034 · 59 statutory tests reported passing · verify + LOI seed green · pilot :8084 / API :8085 · not production qualification
CREDITPORTFOLIO

Credit Duty

CONC reconstruction product in the statutory portfolio map. Kept distinct from HIBS hospitality licensing and PRS registration.

Port :8081 · no qualification claim inherited from HIBS commit 6123e37
HOUSINGPRIVATE

Landlord Duty

Rescue inspection lane: findings, remedial evidence and sign-off for housing and duty-of-care follow-up, using the same detect → one safe action → evidence pattern as Lead Rescue.

landlord-duty @ 340388d · pilot-stage Rescue lane · not a certified housing product
DATAPRIVATE

Scrap Gate / LDPE

Local scrape gate: rustls fetch, robots lane, structural DOM squash and enrichment before LLM ingest, with an optional OpenAI-compatible JSON router.

512 KiB DOM stress p99: 3.68 ms · robots/legal review on live crawl
AI OPSPRIVATE

Agent Boundary Control Plane

Intercepts tool calls, tracks execution trees, reserves budget and freezes recursive agent spend before irreversible dispatch.

Documented p99 intercept/reserve/commit: 0.04 µs
MCPPRIVATE

MCP Enclave Shield

Un-skippable stdio and SSE sidecar that gates MCP tools/call, masks secrets, and writes a Blake3 decision ledger.

Demo denies destructive shell in <5s · :8789 / :8790
PRIVACYPRIVATE

APEP Secure Plane

Query shredding, federated MPC mesh, enclave attestation and gateway stitching for confidential multi-vault analytics.

Documented end-to-end query p99: 83 µs
SILICONPRIVATE

HCG Silicon Gateway

Pressure-weighted routing across CPU, GPU, TPU, ASIC and FPGA queues using pinned-pool staging.

10k mixed blocks: 23 ms in repository demo
TELEMETRYPRIVATE

ZK Telemetry

Seals edge telemetry batches into compact signed commitments sized for satellite and constrained IoT uplinks.

269-byte proof · documented prove p99: 95.9 µs
COMPLIANCEPRIVATE

Sovereign Compliance Bridge

Local masked-token PEP and sanctions gate backed by embedded SQLite, with no third-party screening call on the hot path.

Documented local screen p99: 4.63 µs
RESILIENCEPRIVATE

API Failure Sentry

Zero-dependency circuit breaker with three-strike trip, half-open recovery and TTL LRU fallback routing.

Alpha · documented fallback p99: 0.29 µs
AUDITPRIVATE

Ghost Log Secure Chain

Append-only Blake3 hash-chain ledger that detects edit, deletion or insertion and can trigger local lockdown hooks. Standalone bench default remains 50k; composed Agent Guard passes BENCH_N=5000 and prints append progress so the gate is not silent.

make bench BENCH_N=5000 · 50k still available standalone
CONTEXTPRIVATE

Nexus Context Sentry

Lock-before-squeeze reference hot path that serves duplicate agent state fetches from a 64-byte context crystal.

50-agent demo: 1 fetch, 49 duplicate egresses dropped
RELAYPRIVATE

RelayMesh

Signed event intake, tenant isolation, idempotency, retry, dead-letter and replay proof for CRM, SMS and recovery connectors.

HTTP :8784 · verify-strict gate
POLICYPRIVATE

PolicyPack Studio

Tenant policy registry for allow, deny, require-approval and shadow/live enforcement across agents, MCP, spend and Rescue send modes.

HTTP :8785 · verify-strict gate

Quantitative Systems.

Origin: Harvested Intelligent Betting Systems. HIBS-Bet, Racing, football intelligence and Harvested quant research — each with its own repository, evidence boundary and operating status. No profitability or live-money-readiness claim is made.

PRIVATE · PYTHON · BETTING ENGINE

HIBS-Bet

Football betting engine and prediction stack. Repo: hibs-bet — actively updated. Public pilots were taken offline Aug 2026; repository and capture evidence remain the diligence surface.

  • gunicorn :8000 football surface (offline pilot)
  • 341 tests reported in portfolio captures
  • Distinct from Harvested B2B desk and Axiom paper mode
BOUNDARY: no live-capital or profitability claim. Product surface separate from Consequence Assurance identity.
PRIVATE · PYTHON · RACING

HIBS-Bet Racing

Racing vertical: docker compose stack, inst_workflow catalog, EQUIBET research lanes. Repo: hibs-bet-racing.

  • docker :5003 racing surface (offline pilot)
  • Shared API-key boundary with football pilot noted in captures
  • Rust scanner and Axiom gates apply upstream
BOUNDARY: offline Aug 2026 · terminal captures on landing page
PRIVATE · PYTHON

Football App · Football Intelligence

Football research and intelligence surfaces. Repos: football-app, football-intelligence-platform.

  • Research lanes feeding HIBS-Bet and Harvested quant paths
  • Preservation snapshots on GitHub
BOUNDARY: research infrastructure · not a licensed data product claim
PRIVATE · PYTHON + RUST KERNEL

Harvested Intelligent Quant

Self-hosted B2B quant desk: hash-chained Postgres ledger, interchangeable feeds, evidence promotion (shadow → paper → micro → live) and a native operator UI. Repo: harvested-intelligent-betting-system.

  • Event ledger, risk isolation, evidence gates R1–R8, reconciliation
  • Rust risk-kernel actor over UNIX socket
  • Trading scanner: depth polls, Shin fair-CLV, governor dry-run / shadow WAL
  • Golden replay hashes and signed data-room exports
BOUNDARY: shadow-default execution. No live-capital claim.
PRIVATE · RUST

Axiom Standard

Cross-domain probability, pricing, risk, execution, settlement, replay and audit foundation with racing as the reference vertical.

  • Fixed-point money and checked arithmetic
  • De-vig, EV, Kelly, CLV and settlement equations
  • OFF / WARN / SHADOW / ENFORCE gates
  • Durable paper ingestion, replay and SQLite runtime
  • Hostile qualification corpus and self-healing safety controller
BOUNDARY: paper-mode packaging does not prove source licensing, profitability, live API access or production live-money readiness.
PRIVATE · RUST SCANNER

Rust Scanner

Harvested trading scanner path: scheduled depth polls, recon-gated scan cycle, profile-only or shadow eval, JSONL audit trail. The same fail-closed pattern as Axiom ENFORCE gates — scan is not place-order.

  • POST /v1/trading/scan · snapshot · gates · forensic · broker
  • ReplayBrokerAdapter in CI · zero live stakes default
  • Buyer Matchbook keys required for live broker HTTP
BOUNDARY: scanner and dry-run only. Live routing is a separate, gated step.
PRIVATE · MULTI-PRODUCT

HIBS Edge Portfolio

The skills-github-pages source portfolio packages 15 separately extractable stacks plus four unified SaaS platforms. This website is the static export of that catalogue.

  • RescueOS · Agent Guard · TokenShield Platform · CommitShield
  • 15 standalone products with verification gates
  • Docker verification and marketplace bundles
This repository is a source portfolio and export surface; individual product maturity is stated by each product’s own verification evidence.

Repository inventory.

Full private GitHub org inventory for mc8h7dxz6t-ui as of 2026-09-07. Preservation snapshots are labeled; qualification claims attach to named commits in each repo, not this table alone.

Consequence substrate & assembly

RepositorySurfaceStatus
hibs-standalone-control-planeHIBS-HORIZON assembly · forensic tier · data roomPRIVATE · 1d044a7
hibs-labs-rust.consequence-control-planeCCP · GitHub adapter · MCP guard · OTelPRIVATE · f1ffe2e
hibs-labs-rust.replayDeterministic replay + fault plansPRIVATE
hibs-labs-rust.storeAppend-only durable storePRIVATE
hibs-labs-cpp.crashstoreC++ crash-recovery storePRIVATE
hibs-streamDeterministic event runtimePRIVATE
ui-hibs-execution-passportPortable execution proof · v0.1PRIVATE
ui-hibs-labs.hostile-execution-demoConsequence Assurance hostile slicePRIVATE · QUALIFIED SLICE
hibs-authorityAuthority preservation snapshotPRIVATE
CONTROL-SUBSTRATE-QUALIFICATIONQualification harnessPRIVATE
evidence-incident-labIncident lab evidencePRIVATE
hibs-connectTransport-neutral integrity contracts · SourceEnvelope · Q-CONNECTPRIVATE · INTEGRITY CORE
hibs-connect-reconcile15-phase local proofpack · Connect/Reconcile/Transport/ADBC/WASMPRIVATE · 00258d6 · CI PASS
contractor-gateOn-site contractor verificationPRIVATE · RUST
hibs-fieldproofField evidence capturePRIVATE

Governors & AI governance

RepositorySurfaceStatus
hibs-hcapHCAP publication index · 5 commercial packs · CCP Q001-Q010PRIVATE · afb5ae8 · PIN 486a0f49
modelgovernor.v01Governor spine MG/FG/IG/CG/BG · implementation modulesPRIVATE · 486a0f49 · DOCKER PASS
agent-guard-llmAgent Guard LLM engine snapshotPRIVATE
agent-guard-soakAgent Guard soak tests snapshotPRIVATE
llmcontractLLM invocation contract snapshotPRIVATE

B2B SaaS platforms & preservation exports

RepositorySurfaceStatus
rescueos-platformPlay 1 · revenue-ops SaaSPRIVATE · SNAPSHOT
agent-guardPlay 2 · AI-ops SaaS · ABCP + TokenShield + Nexus bundlePRIVATE · c0ec35b · PIN d0bf285
tokenshield-platformPlay 3 · LLM spend firewall SaaSPRIVATE · SNAPSHOT
commit-shield-platformPlay 4 · reserve-before-commit SaaSPRIVATE · SNAPSHOT
tokenshieldTokenShield engine snapshotPRIVATE · MIT
tokenshield-governanceTokenShield governance UIPRIVATE · MIT
commit-shieldCommitShield engine snapshotPRIVATE
mcp-enclave-shieldMCP sidecar gate snapshotPRIVATE · MIT
skills-github-pagesHIBS Edge monorepo + this site · evidence index branchPRIVATE · MIT · e946bf9

Applied desks · statutory · commercial

RepositorySurfaceStatus
lead-rescue-engineMissed-call + Rescue lanesPRIVATE · MIT
licence-dutyMulti-site licence-obligation evidence · hospitalityPRIVATE · 32b6034 · SNAPSHOT
prs-readyPRS registration · portfolio readinessPRIVATE · c9e20c1 · SNAPSHOT
landlord-dutyHousing inspection · remedial evidence lanePRIVATE · 340388d · SNAPSHOT
credit-dutyCONC reconstruction · port 8081PRIVATE · SNAPSHOT
jobproofJob completion proof chainPRIVATE · SNAPSHOT
rtw-chainRight-to-work evidence chainPRIVATE
scrap-gateScrape gate snapshotPRIVATE · SNAPSHOT
ldpe-engineLDPE DOM enrichmentPRIVATE · MIT
relaymeshEvent relay snapshotPRIVATE · SNAPSHOT
policypack-studioPolicy pack registry snapshotPRIVATE · SNAPSHOT
Microsoft-365-native-Martyn-s-Law-readiness-evidenceMartyn's Law M365 readiness ledgerPRIVATE
deterministic-csv-reconciliation-cli-harborCSV reconciliation CLIPRIVATE

HIBS Edge products (-ui-*)

RepositorySurfaceStatus
-ui-api-breaker-sentryAPI Failure Sentry · circuit breakerPRIVATE · MIT · ALPHA
-ui-nexus-context-sentryNexus context dedupePRIVATE · MIT
-ui-ghostlog-secure-chainGhost Log tamper-evident chainPRIVATE · MIT
-ui-agent-boundary-control-planeAgent spend freeze gatePRIVATE · MIT
-ui-apep-secure-planeAPEP confidential analyticsPRIVATE · MIT
-ui-hcg-silicon-gatewayHCG silicon workload routerPRIVATE · MIT
-ui-zk-telemetry-control-planeZK telemetry commitmentsPRIVATE · MIT
-ui-sovereign-compliance-bridgeLocal AML / PEP gatePRIVATE · MIT

Quantitative & betting

RepositorySurfaceStatus
hibs-betFootball betting enginePRIVATE · ACTIVE
hibs-bet-racingRacing verticalPRIVATE
football-appFootball research appPRIVATE
football-intelligence-platformFootball intelligence snapshotPRIVATE · SNAPSHOT
harvested-intelligent-betting-systemHarvested B2B quant deskPRIVATE · SHADOW DEFAULT
axiom-standardRust quant foundation · paper modePRIVATE
hibs-quantitative-labs.github.ioQuant labs Pages sitePRIVATE · MIT

Statutory desks licence-duty, prs-ready and landlord-duty are preserved on this org; canonical development remains on Cursor-origin remotes — see Commercial Automation. Cheeky Monkeys and the any-file converter remain outside this inventory. Aug 2026: hibs-bet public pilots offline; captures on this site. Deploy from skills-github-pages/landing via landing/deploy/bootstrap-remote.sh.