We pointed the operating model at a government hackathon and shipped a governed engine, five missions, and a live war-room overnight. This page does not ask you to trust a screenshot. Every claim below links to a live surface on this same site where the mechanism actually runs. We lead with the proof a slide cannot fake.
Every action, machine and human, lands on one ledger: Ed25519 signatures over a SHA-256 hash chain, with RFC 6962 Merkle proofs, anchored in an S3 Object-Lock WORM bucket. Break any link and the chain no longer verifies. The monitor re-walks the captured envelope entry by entry. It shows the chain, it does not re-sign it.
Verify: replay the signed ledger →The deterministic gate makes every irreversible call: positive hostile identification, the two-person rule, the rules of engagement. The after-action language model narrates, and its role is Denyed from writing the ledger, an explicit deny on PutObject and DeleteObject, read allowed. This is not a promise in a document. It is a permission boundary, proven by policy simulation.
12 of 12 metamorphic invariance checks pass: class-label permutation relations plus a negative control. The fusion result stays correct under transforms that would fool a model that had memorized the key, and the negative control confirms the test can actually fail. The credibility anchor against "is the demo faked."
Verify: invariance.test.ts →A no-model-call test guards the gate path, so the kill-chain decision can never route through a model. A separate narration eval flags any sentence the language model produces that is not backed by a ledger record. The story the demo tells cannot quietly drift from the receipts underneath it.
Verify: the requirements breakdown →Counter-UAS #08, forward operating base #07, seabed #01, convoy #02, and swarm reconnaissance #04 all run on the same gate and the same signed ledger. Swap the sensor and the envelope, nothing forks. The reuse is the differentiator, and it is provable by import graph rather than asserted in a caption.
Verify: the hour-by-hour build timeline →Monday was analysis, no code. The team read all 22 official use cases end to end and found they were one problem underneath. The one engine then covers 62 of 132 requirements spanning 16 of those use cases, and the flagship Counter-UAS mission covers 8 of its own 11.
Verify: the requirements breakdown →The platform was built in-window from a greenfield repository. The prior architecture is disclosed, and no code was carried over: zero files copied, 96% net-new across 176 commits on main, every timestamp a git author-timestamp.
Roughly one dollar a day of edge compute plus a one-time model pass of about three dollars. Set that against the $240K to $960K a conventional team quotes for the same scope, and the result is the point: the model produced overnight what normally costs a quarter-million to a million dollars and takes a quarter. The metrics page is wired to the live producer, so the number is read from the build, not typed into a slide.
Verify: the live metrics →main. Each dot is a feature commit; merge commits excluded. Times US Eastern. The lanes are the pieces that stack into the value above.