// the governed transaction · rendered from /data/kernels.json

The Trust Layer.

Not a UI wrapper around an LLM — a family of deterministic, zero-dependency governance kernels. Each is a pure decision function (same verdict in browser, edge, and Node), conformance-tested and signable. Together they compose the lifecycle every cross-organizational agent mutation should run through: identity → authorize → clear → settle → audit. EcoCloud decides; it never moves money, runs no ERP connector, and ships no ZK/Wasm.

// operational truth · MCP acts · OKF informs · the Trust Layer proves
Operational truth = signed actions, enforced policy, verifiable state — what the system provably did, not chat logs or wiki pages. It's what remains when you disconnect the client and verify offline.
Who acted?

Verifiable identity

Every action is bound to a signed agent identity with scoped authority — provable, and a strict subset of its sponsoring human.

What was allowed?

Enforced policy

A deterministic allow/deny runs BEFORE every write — the constitution gate, not a model's good intentions.

What happened?

Immutable record

Every action lands in a tamper-evident, ES256-signed audit chain with a Merkle checkpoint anyone can verify — plus signed event export.

What is the state now?

Verifiable state

Prove the current governance state — and that any action closed — offline against the public key, with zero trust in our server.

Context is a separate rail. What we know about the workspace — runbooks, the constitution as docs, project context — lives in the OKF knowledge bundle. It informs agents; it doesn't prove what happened. MCP/REST are the interface agents act through. Only the signed · policy · ledger · proof core above is operational truth.

// three enterprise modules

The same kernels, grouped by what an enterprise actually buys. Each module is a stack of deterministic, conformance-tested kernels — not a roadmap. Click one to jump to its kernels.