A real local LLM (qwen2.5:7b, no cloud call) decided every request instead of a scripted probe loop. Same MemO(1S) hardware gate, same EDR v2.1 protected-data path, 200-record pool, two answer modes, 5,000 turns each, run back to back overnight, unattended.
| Metric | text_recall | coordinate_resolve |
|---|---|---|
| Run id | 20260923T183418Z | 20260923T202734Z |
| Turns | 5,000 | 5,000 |
| Agent correct (real retrieval) | 4,963 / 5,000 (99.26%) | 5,000 / 5,000 (100.0%) |
| Hardware gate correct | 5,000 / 5,000 (100.0%) | 5,000 / 5,000 (100.0%) |
| Real tokens | 2,228,005 | 2,998,444 |
| GPU power above idle tare | 37.25W | 25.44W |
| Elapsed | 6,785.14 sec (1.88 hours) | 12,469.26 sec (3.46 hours) |
text_recall: the model was asked to reproduce an opaque record id from memory. coordinate_resolve: the model stated only facts it already had (a unit id and a data type), and the system resolved those into the exact record deterministically, the same addressed-recall approach used everywhere else in this project. That is the difference between 99.26% and 100.0% real retrieval accuracy above: the model was never asked to recall a coordinate, only to state what it was already given.
The hardware gate was correct on all 10,000 real-agent turns across both modes, 0 bad decisions, whether the agent's own answer landed on the right record or not. One coordinate_resolve turn out of 5,000 had a category cross-check mismatch even though the record it resolved to was correct (99.98% under that stricter check), the model stated the access role where the data type was expected. A free automatic retry caught malformed unit ids 6 times out of 5,000 turns; a costlier second-pass model re-ask was available and was never needed.
The model ran on a consumer GPU with no internet call, the hardware gate ran on a separate small board, and the two only ever talked over a local link. That is the shape a robot or rover needs: decisions made on the vehicle, checked on the vehicle, with nothing waiting on a ground link.
1,000-record pool · 1,024,000 public particles · 3.23 hours end to end
| Metric | Value | Meaning |
|---|---|---|
| Run id | memo1s-edr-v21-definitive-100000-20260923T103626Z | Largest v2.1 evidence package to date. |
| Boundary | hardware gate plus EDR v2.1 protected-data path | The hardware gate is part of the decision path, and EDR v2.1 is part of the protected data path. |
| Total requests | 100,000 | Autonomous synthetic agent policy decisions. |
| Approved reassembled | 55,000 | Allowed requests reconstructed exact records. |
| Blocked no reassembly | 45,000 | Blocked requests did not receive reconstructed data. |
| Bad decisions | 0 | No wrong allow or wrong block outcome in this run. |
| Record pool | 1,000 | Twice the record pool of the 50,000-decision run. |
| Public particles | 1,024,000 | EDR v2.1 public particle artifacts. Public particles alone are not a reconstruction recipe. |
| Private anchors | 1,000 | Private operator-side anchor records. Contents are not published here. |
| Elapsed | 11,622.955 seconds | About 3.23 hours. |
| Rate | 8.6037 requests/sec | End-to-end integrated run rate after startup. |
| Auth material written to disk | false | Runtime auth material was not persisted by the runner. |
| Artifact | Size or hash | Public status |
|---|---|---|
summary.json | 3793abd137ccd2364ad6d64a0a948943dcad25f65d5527ba26a690b42bb42956 | Safe to cite. |
progress.json | 31bf3626011aa53a3a7ca868895c02a1b9d97c3b11464e134405afa783589fc0 | Safe to cite. |
agent-audit.jsonl | 48M · 77e7febb5a86503f79fd2c7ff791b5316ecb8481db744cc4b39ec1eb4e713632 | Operator artifact. Publish only after redaction review. |
public/particles.jsonl | 446M · 52c7c5e702c82b0a7ee723f5096f20a986ea62fc103cb84d592041c1d2b05fdb | Public particle artifact. Do not combine with private recovery material. |
private/anchors.jsonl | 66M · 1f1a99d62da76bb12c8211e83b98d4be0cb0c2b5cf4eed5cca10c8cdafe8ce48 | Private operator artifact. Do not publish raw contents. |
private/operator-manifest.jsonl | 4e9a76a1800dde654dccf5ebdb4ad51603c99e9d94177df38a9ddc9c94a21bbc | Private operator artifact. |
This page intentionally publishes counts, hashes, paths, and boundaries only. It does not publish private anchor payloads, recovery material, nonce material, auth material, or anything intended to help reconstruct protected records outside the operator environment.
500-record pool · 512,000 public particles
| Metric | Value | Meaning |
|---|---|---|
| Run id | memo1s-edr-v21-definitive-50000-20260921T045200Z | Prior v2.1 evidence package, superseded by the 100,000-decision run above. |
| Boundary | hardware gate plus EDR v2.1 protected-data path | The hardware gate is part of the decision path, and EDR v2.1 is part of the protected data path. |
| Total requests | 50,000 | Autonomous synthetic agent policy decisions. |
| Approved reassembled | 27,500 | Allowed requests reconstructed exact records. |
| Blocked no reassembly | 22,500 | Blocked requests did not receive reconstructed data. |
| Bad decisions | 0 | No wrong allow or wrong block outcome in this run. |
| Record pool | 500 | Five times larger than the 10,000-decision baseline run. |
| Public particles | 512,000 | EDR v2.1 public particle artifacts. Public particles alone are not a reconstruction recipe. |
| Private anchors | 500 | Private operator-side anchor records. Contents are not published here. |
| Elapsed | 4,865.523 seconds | About 1.35 hours. |
| Rate | 10.2764 requests/sec | End-to-end integrated run rate after startup. |
| Auth material written to disk | false | Runtime auth material was not persisted by the runner. |
This page intentionally publishes counts, hashes, paths, and boundaries only. It does not publish private anchor payloads, recovery material, nonce material, auth material, or anything intended to help reconstruct protected records outside the operator environment.
The agent request reaches the MemO(1S) hardware gate before protected data is reconstructed. The model does not serve as the final permission authority.
Approved requests recovered exact records. Blocked requests received no reassembly. That is the useful security shape for edge agents and machines.
The run used public particles and private anchors as separate roles. The page exposes public evidence, not operator recovery material.
A robot can ask for specific data. The hardware gate decides whether that request matches an approved path before EDR reconstructs the record.
Different roles, vehicles, payloads, or sites can be given different approved paths. A blocked path does not get reconstructed data.
Every decision writes an audit row. That helps explain what an autonomous system was allowed to see, what it was denied, and whether any decision failed.
Safe artifact inventory for the completed 50,000-decision run.
| Artifact | Size or hash | Public status |
|---|---|---|
summary.json | 45afd4326b10ce4fe0b7a43a958dd9546c57c6fbfb00ef52522b8f0b215b49dd | Safe to cite. |
progress.json | f5f0c3ad71a356653d51d514bd97a301bc9418107bec5e85163f2d82a02c5bd7 | Safe to cite. |
agent-audit.jsonl | ae83edc3332d24c087bedea587ea32548e5984646c2a2316fab8415f92be748a | Operator artifact. Publish only after redaction review. |
public/particles.jsonl | 223M · c443de8deae582a4a9de6f488d48618e3a9d0ebef9601e471c71633f5f45eed5 | Public particle artifact. Do not combine with private recovery material. |
private/anchors.jsonl | 33M · e7e1671255d9a794abc8218dc653d608af4f3f062e9a15e6ee4e190ce8f7e606 | Private operator artifact. Do not publish raw contents. |
private/operator-manifest.jsonl | 9af661b09b8c2e2433b02cdc19ef6bd93d27d9130a098946b5cb15e7358fc678 | Private operator artifact. |
Collapsible structure for current and future MemO(1S) + EDR v2.1 runs.
| Run | Status | Scale | Result |
|---|---|---|---|
| 50,000 v2.1 integrated run | complete | 500 records · 512,000 public particles · 500 private anchors | 27,500 approved, 22,500 blocked, 0 bad decisions. |
| 10,000 v2.1 integrated run | complete | 100 records · 102,400 public particles · 100 private anchors | 5,500 approved, 4,500 blocked, 0 bad decisions. |
| 100,000 v2.1 integrated run | complete | 1,000 records · 1,024,000 public particles · 1,000 private anchors | 55,000 approved, 45,000 blocked, 0 bad decisions. |
| Pilot customer lane | future | Customer-defined policy, records, and operator boundary. | Requires a reviewed provisioning and redaction plan. |
Use this page as the safe public review surface.