100,000
Integrated policy decisions
AMD Kria KV260 · MemO(1S) gate plus EDR v2.1 path
55,000
Approved reconstructions
Every approved request recovered exactly
45,000
Blocked attempts
No reconstruction returned on blocked requests
0
Bad decisions
Across the completed 100,000-decision run
Open real-agent run Open 100,000 run Evidence boundary
▸

Completed September 23, 2026

A real local LLM (qwen2.5:7b, no cloud call) decided every request instead of a scripted probe loop. Same MemO(1S) hardware gate, same EDR v2.1 protected-data path, 200-record pool, two answer modes, 5,000 turns each, run back to back overnight, unattended.

Metric text_recall coordinate_resolve
Run id20260923T183418Z20260923T202734Z
Turns5,0005,000
Agent correct (real retrieval)4,963 / 5,000 (99.26%)5,000 / 5,000 (100.0%)
Hardware gate correct5,000 / 5,000 (100.0%)5,000 / 5,000 (100.0%)
Real tokens2,228,0052,998,444
GPU power above idle tare37.25W25.44W
Elapsed6,785.14 sec (1.88 hours)12,469.26 sec (3.46 hours)

Two ways to ask, one hardware boundary

text_recall: the model was asked to reproduce an opaque record id from memory. coordinate_resolve: the model stated only facts it already had (a unit id and a data type), and the system resolved those into the exact record deterministically, the same addressed-recall approach used everywhere else in this project. That is the difference between 99.26% and 100.0% real retrieval accuracy above: the model was never asked to recall a coordinate, only to state what it was already given.

Gate accuracy did not depend on the agent

The hardware gate was correct on all 10,000 real-agent turns across both modes, 0 bad decisions, whether the agent's own answer landed on the right record or not. One coordinate_resolve turn out of 5,000 had a category cross-check mismatch even though the record it resolved to was correct (99.98% under that stricter check), the model stated the access role where the data type was expected. A free automatic retry caught malformed unit ids 6 times out of 5,000 turns; a costlier second-pass model re-ask was available and was never needed.

Why this matters with no cloud

The model ran on a consumer GPU with no internet call, the hardware gate ran on a separate small board, and the two only ever talked over a local link. That is the shape a robot or rover needs: decisions made on the vehicle, checked on the vehicle, with nothing waiting on a ground link.

▸

Completed September 23, 2026

1,000-record pool · 1,024,000 public particles · 3.23 hours end to end

Metric Value Meaning
Run idmemo1s-edr-v21-definitive-100000-20260923T103626ZLargest v2.1 evidence package to date.
Boundaryhardware gate plus EDR v2.1 protected-data pathThe hardware gate is part of the decision path, and EDR v2.1 is part of the protected data path.
Total requests100,000Autonomous synthetic agent policy decisions.
Approved reassembled55,000Allowed requests reconstructed exact records.
Blocked no reassembly45,000Blocked requests did not receive reconstructed data.
Bad decisions0No wrong allow or wrong block outcome in this run.
Record pool1,000Twice the record pool of the 50,000-decision run.
Public particles1,024,000EDR v2.1 public particle artifacts. Public particles alone are not a reconstruction recipe.
Private anchors1,000Private operator-side anchor records. Contents are not published here.
Elapsed11,622.955 secondsAbout 3.23 hours.
Rate8.6037 requests/secEnd-to-end integrated run rate after startup.
Auth material written to diskfalseRuntime auth material was not persisted by the runner.
Artifact Size or hash Public status
summary.json3793abd137ccd2364ad6d64a0a948943dcad25f65d5527ba26a690b42bb42956Safe to cite.
progress.json31bf3626011aa53a3a7ca868895c02a1b9d97c3b11464e134405afa783589fc0Safe to cite.
agent-audit.jsonl48M · 77e7febb5a86503f79fd2c7ff791b5316ecb8481db744cc4b39ec1eb4e713632Operator artifact. Publish only after redaction review.
public/particles.jsonl446M · 52c7c5e702c82b0a7ee723f5096f20a986ea62fc103cb84d592041c1d2b05fdbPublic particle artifact. Do not combine with private recovery material.
private/anchors.jsonl66M · 1f1a99d62da76bb12c8211e83b98d4be0cb0c2b5cf4eed5cca10c8cdafe8ce48Private operator artifact. Do not publish raw contents.
private/operator-manifest.jsonl4e9a76a1800dde654dccf5ebdb4ad51603c99e9d94177df38a9ddc9c94a21bbcPrivate operator artifact.

Claim boundary

This page intentionally publishes counts, hashes, paths, and boundaries only. It does not publish private anchor payloads, recovery material, nonce material, auth material, or anything intended to help reconstruct protected records outside the operator environment.

▸

Completed September 21, 2026

500-record pool · 512,000 public particles

Metric Value Meaning
Run idmemo1s-edr-v21-definitive-50000-20260921T045200ZPrior v2.1 evidence package, superseded by the 100,000-decision run above.
Boundaryhardware gate plus EDR v2.1 protected-data pathThe hardware gate is part of the decision path, and EDR v2.1 is part of the protected data path.
Total requests50,000Autonomous synthetic agent policy decisions.
Approved reassembled27,500Allowed requests reconstructed exact records.
Blocked no reassembly22,500Blocked requests did not receive reconstructed data.
Bad decisions0No wrong allow or wrong block outcome in this run.
Record pool500Five times larger than the 10,000-decision baseline run.
Public particles512,000EDR v2.1 public particle artifacts. Public particles alone are not a reconstruction recipe.
Private anchors500Private operator-side anchor records. Contents are not published here.
Elapsed4,865.523 secondsAbout 1.35 hours.
Rate10.2764 requests/secEnd-to-end integrated run rate after startup.
Auth material written to diskfalseRuntime auth material was not persisted by the runner.

Claim boundary

This page intentionally publishes counts, hashes, paths, and boundaries only. It does not publish private anchor payloads, recovery material, nonce material, auth material, or anything intended to help reconstruct protected records outside the operator environment.

▸

Hardware before reconstruction

The agent request reaches the MemO(1S) hardware gate before protected data is reconstructed. The model does not serve as the final permission authority.

Exact or nothing

Approved requests recovered exact records. Blocked requests received no reassembly. That is the useful security shape for edge agents and machines.

Separated custody

The run used public particles and private anchors as separate roles. The page exposes public evidence, not operator recovery material.

▸

Mission data access

A robot can ask for specific data. The hardware gate decides whether that request matches an approved path before EDR reconstructs the record.

Compartment behavior

Different roles, vehicles, payloads, or sites can be given different approved paths. A blocked path does not get reconstructed data.

Audit trail

Every decision writes an audit row. That helps explain what an autonomous system was allowed to see, what it was denied, and whether any decision failed.

▸

Safe artifact inventory

Safe artifact inventory for the completed 50,000-decision run.

Artifact Size or hash Public status
summary.json45afd4326b10ce4fe0b7a43a958dd9546c57c6fbfb00ef52522b8f0b215b49ddSafe to cite.
progress.jsonf5f0c3ad71a356653d51d514bd97a301bc9418107bec5e85163f2d82a02c5bd7Safe to cite.
agent-audit.jsonlae83edc3332d24c087bedea587ea32548e5984646c2a2316fab8415f92be748aOperator artifact. Publish only after redaction review.
public/particles.jsonl223M · c443de8deae582a4a9de6f488d48618e3a9d0ebef9601e471c71633f5f45eed5Public particle artifact. Do not combine with private recovery material.
private/anchors.jsonl33M · e7e1671255d9a794abc8218dc653d608af4f3f062e9a15e6ee4e190ce8f7e606Private operator artifact. Do not publish raw contents.
private/operator-manifest.jsonl9af661b09b8c2e2433b02cdc19ef6bd93d27d9130a098946b5cb15e7358fc678Private operator artifact.
▸

Current and future runs

Collapsible structure for current and future MemO(1S) + EDR v2.1 runs.

Run Status Scale Result
50,000 v2.1 integrated runcomplete500 records · 512,000 public particles · 500 private anchors27,500 approved, 22,500 blocked, 0 bad decisions.
10,000 v2.1 integrated runcomplete100 records · 102,400 public particles · 100 private anchors5,500 approved, 4,500 blocked, 0 bad decisions.
100,000 v2.1 integrated runcomplete1,000 records · 1,024,000 public particles · 1,000 private anchors55,000 approved, 45,000 blocked, 0 bad decisions.
Pilot customer lanefutureCustomer-defined policy, records, and operator boundary.Requires a reviewed provisioning and redaction plan.
▸

Safe public review surface

Use this page as the safe public review surface.