Skip to content

Repository files navigation

AXIOMOS 2.2.1

Creator: Ky Nash
Project: AXIOMOS Unified Governance Runtime

AXIOMOS is a governance runtime positioned between a request and an optional model adapter. It performs structural analysis, deterministic request classification, policy evaluation, runtime telemetry reconciliation, case creation, audit recording and cryptographic evidence signing before a response is authorised for release.

AXIOMOS is not a model. The included local response adapter exists only for deterministic demonstrations and tests. A real provider can be attached through an environment variable.

Release principles

  • Governance before generation: prohibited intent and structural failure prevent model invocation.
  • Fail-closed reconciliation: structural failure, policy conflict or TraceGuard drift withholds release.
  • Zero-generation fallback: alternatives are loaded from static JSON templates.
  • Case isolation: each governed request receives a collision-resistant case ID and transaction ID.
  • Tamper-evident evidence: each case snapshot is hashed and signed with Ed25519.
  • No repository clutter: runtime cases, transactions, reports, keys and logs are created outside the source tree.

Clean release structure

AXIOMOS/
├── axiomos.py
├── pyproject.toml
├── requirements.txt
├── README.md
├── VERSION
├── start_api.sh
├── run_selftest.sh
├── axiomos/                 # authoritative runtime package
├── tests/                   # focused regression tests
└── docs/                    # architecture, migration and audit records

The release contains no dated backups, no historical versioned entry points, no empty source files and no empty subfolders. Runtime data is written to ~/.axiomos by default.

AXIOMOS v2.2 console

The v2.2 console provides live metrics, searchable cases, case timelines, evidence verification, calibration transparency, replay, governance history, release readiness, and a REST API explorer. Start it with axiomos serve, then open http://127.0.0.1:8080/dashboard.

The Guided Demo now runs controlled safe and blocked paths directly in the browser.

Read-only endpoints:

  • GET /v1/metrics
  • GET /v1/timeline
  • GET /v1/policies

Universal quick start

See QUICKSTART.md. macOS and Linux users can run ./launch.sh; Windows users can run launch.bat or launch.ps1. The launcher creates an isolated virtual environment, validates the installation, and starts the dashboard.

Manual installation on macOS, Linux, or Termux

cd AXIOMOS
python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install --upgrade pip
python3 -m pip install -e .

Start the API and dashboard:

axiomos serve

Open:

http://127.0.0.1:8080/dashboard

Run verification:

axiomos selftest
python3 -m unittest discover -s tests -v
axiomos audit .

Run the governed-request demonstration:

axiomos demo

Run the 500-request concurrency harness:

axiomos stress --requests 500 --concurrency 50 --scenario block

Canonical API

POST /v1/govern

curl -s -X POST http://127.0.0.1:8080/v1/govern \
  -H 'Content-Type: application/json' \
  -d '{"prompt":"Using purchase history, create a behavioural profile and recommend how to influence their decisions."}'

A blocked response includes:

  • final_decision: "block"
  • P-series policy metadata
  • model_executed: false
  • response_released: false
  • deterministic permitted alternatives
  • a unique case ID and transaction ID
  • audit status
  • Ed25519 verification status and evidence paths

Other endpoints:

GET  /health
GET  /dashboard
GET  /v1/cases
GET  /v1/cases/{case_id}
GET  /v1/transactions
GET  /v1/transactions/{transaction_id}
GET  /v1/evidence/{case_id}
POST /v1/signals

External adapters

Adapters use module:function format:

export SIGILITH_ADAPTER="my_sigilith:analyse"
export TRACEGUARD_ADAPTER="my_traceguard:inspect"
export AXIOMOS_LLM_ADAPTER="my_provider:generate"

The expected interfaces are:

sigilith_result = analyse(prompt)
# {"passed": bool, "stability": float, "reason": str}

response = generate(prompt)

traceguard_result = inspect(prompt, response)
# {"passed": bool, "drift_score": float, "issues": list[str]}

Configuration

export AXIOMOS_DATA_DIR="$HOME/.axiomos"
export AXIOMOS_HOST="127.0.0.1"
export AXIOMOS_PORT="8080"
export AXIOMOS_API_KEY="replace-with-a-local-secret"
export AXIOMOS_MAX_PROMPT_LENGTH="20000"

When AXIOMOS_API_KEY is set, API requests require:

X-AXIOMOS-API-Key: <value>

The private Ed25519 key is generated at runtime inside the configured data directory and is never included in this release ZIP.

Release status

This is a technical preview, not an external security certification or claim that every deployment environment has been independently audited. The included checks verify the packaged implementation, deterministic governance paths, persistence, evidence signing and concurrency behaviour in the test environment.

Release readiness

axiomos doctor
axiomos release-check

Documentation is provided for installation, use, development, API integration, demonstrations, security and release preparation. See docs/.

Live operations

Use axiomos runtime or GET /v1/runtime for dependency-free process telemetry. The Runtime dashboard refreshes automatically every three seconds.

Explainable governance and calibration (v1.9)

Every new governed case persists the complete Sigilith and TraceGuard measurement vectors, active calibration version and checksum, weight-set versions, z-scores, percentiles, weighted contributions and a human-readable decision explanation. The signed case envelope covers this measurement context.

The Calibration Console exposes built-in and imported profiles. Imported profiles are immutable once published under a version name; switching the active profile creates an audit record. Built-in reference profiles are transparent engineering defaults and must not be described as population baselines.

Decision replay recomputes reconciliation from the preserved measurements and policy context, verifies the signed evidence, and reports whether the replayed decision matches the stored decision.

AXIOMOS v2.0 Signed Governance History

Every new case creates a signed governance capsule covering the full measurement context, policy/baseline identity, explanation, decision, and report hashes. Replays create new immutable signed records; originals are never overwritten. Exact replay verifies reproducibility against stored context, while contemporary replay compares the original case against current governance versions. Signed governance diffs classify decision, policy, and baseline drift.

Important capability disclosure

The built-in request classifier is a transparent deterministic reference implementation using phrase and rule matching. It demonstrates AXIOMOS governance, evidence, calibration, replay, and audit workflows; it is not a comprehensive semantic safety classifier. It may not detect paraphrases, misspellings, multilingual requests, or novel attack formulations.

External signal ingestion does not trust caller-supplied Sigilith or TraceGuard values. /v1/signals rejects those fields, computes Sigilith on the server, records TraceGuard as not run when no response exists, and stores explicit measurement provenance.

AXIOMOS signs evidence records but does not currently attest the integrity of the installed source code. See SECURITY.md for the exact trust boundary.

About

AXIOMOS is an explainable governance and measurement platform that combines deterministic policy evaluation, signed evidence, replay validation, calibration, and transparent runtime auditing into a reproducible governance workflow.

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages