Two classical primitives, one defensibility kernel for the agent network. Ramanujan graphs are optimal expanders — a topology whose non-trivial eigenvalues satisfy |λ| ≤ 2√(d−1) is the hardest possible to attack: it takes Ω(n) node removals to partition or eclipse it, and information mixes in O(log n) hops. Finite-field Diffie–Hellman then keys every edge into a confidential channel. Pick a topology below — see the robustness verdict; run a live key handshake. Same math as expander-graph hashes (Charles–Goren–Lauter) and supersingular-isogeny post-quantum graphs†.
| resilient · adequate | Coalition cleared to federate — allow propose_agreement / GAU clearing. |
| weak | Requires human review in Regulator Mode before the coalition coordinates autonomously. |
| fragile · disconnected | Block coalition join / edge-key rotation — a single failure can partition the mesh. |
| signed report | Attach the ES256 report to the audit chain & Outcome Receipt as topology evidence. |
Honest scope. A deterministic governance/measurement kernel + a textbook FFDH primitive for illustration — production key exchange must use vetted libraries / Web Crypto ECDH / ≥2048-bit MODP groups; EcoCloud's live signing already uses Web Crypto ES256 (the signed report above is real ES256). The kernel measures and keys; it never moves data on the wire. Fail-closed: parallel/self edges, disconnected, non-expander, oversized, composite or degenerate DH params are all rejected — hardened against 10 adversarial-probe findings. † On post-quantum: Ramanujan/expander constructions appear in the isogeny-crypto literature, but EcoCloud does not implement SIKE/SIDH or any PQC wire protocol — it shares the graph math, not the cipher. Source: flowdesk-mesh-kernel.js · signed report API: /api/v1/agent/mesh-report · spec registry: /schemas/registry.json · runnable in the in-app Skills console.