Skip to content

the Cartographer · interactive instruments

the atlas

Each instrument binds to a conjecture in the register and reads its confidence, status, and home from the bundled register snapshot — the visual owns the interaction, the register owns the claim. Where a visual and the register disagree, the register wins. Drag a parameter and watch the shape move; the honesty above and below each instrument reflects that snapshot. Source changes appear after the mirror is regenerated and the site is rebuilt.

Read the shape, then test the claim

Slider values are illustrative inputs. Register confidence is an attributed estimate, not a measured success rate. C7’s multiplicative form remains conjectural; the moving ceiling distinguishes background-information erosion from certification changes; the composition cap requires the full WP-07 assumptions.

Carry a question into the research loop: record the source, parameters, assumptions and a result that would challenge your interpretation. A cast records a reading; it does not establish a theorem or grant authority.

curve

the existence-leak curve

C81 ↗illustrative model

a disclosure is an existence claim — the first one is the deep cut; every system after only tightens the bound. Φ_inference falls, convex and monotone, with no recovery branch.

0.000.250.500.751.000123456789101112exposures n →Φ_inferenceexistence establishedthe deep cutdiminishing returns · no recovery

existence is binary and spent once: the first system that learns X exists does the structural damage.

cast · set these values into your key

conf ~70%status active · PROMOTED Run 3 2026-06-10 (Schrottenloher instance + Garg-Jain-Sahai λ<1 impossibility as bookends) · Stage 2 open: held at 70% until a second independent instance · Tarski axis-reading added Run 8 2026-06-28 (C92), framing only, Stage-2 bar unchangedregister corehome schrottenloher-ecdlp-v6-note.md · privacy_value_v6_draft.md Part III · limitative-theorems-and-privacy-is-value.md §3

Existence-Leak: a ZK proof of feasibility leaks an upper bound on reconstruction difficulty; I(feasibility; method) > 0

first-disclosure cliff is the deep cut; the tail is diminishing returns, no recovery. The convex shape is a chosen teaching model — under an adversary who gains super-additively from correlated systems the tail changes shape.

gate

the three-axis gate

C7 ↗illustrative model

explore the proposed multiplicative form: setting one axis to zero collapses the displayed product. C7 remains conjectural; the sliders do not validate that composition.

0.51
total separation value

multiplicative gating, not additive. any single zero zeroes the whole — two axes carry a limitative twin (Φ_agent ↔ Gödel, Φ_inference ↔ Tarski); Φ_data fails by degree, not undecidability.

cast · set these values into your key

conf 30%status active · V6 falsification frontierregister corehome formal spec §17.1

Three-axis separation is multiplicative

C7 is an active conjecture. This instrument evaluates the proposed product; it does not test whether that form holds empirically.

lattice

the three-axis gate on the lattice

C7 ↗illustrative model

the same product, drawn on the 64: even parity is the boundary agent, odd parity the delegation agent, the edges between them the gap. Σ pulls the halves apart, Δ draws the custody boundary, Γ lets the leak chords through. Grab it.

⚔️ boundary agent · even parity🧙 delegation agent · odd parity⿻ the octahedral core · C89custody boundary · Δleak chords · 1 − Γ
0.51
total separation value

grab the background to turn the figure and tilt the separation; grab a vertex and its neighbours follow, then the lattice springs back. dragging changes nothing about the model. the same instrument runs on agentprivacy.org.

cast · set these values into your key

conf 30%status active · V6 falsification frontierregister corehome formal spec §17.1

Three-axis separation is multiplicative

geometry as reading, not proof: parity halves = the two tetrahedra (C88), the middle stratum = the octahedral gap (C89); the collapse rule is C7. Shared engine with agentprivacy.org (instrument.js), lifted 2026-09-05.

curve

the moving ceiling

C82 ↗illustrative model

hold the released transcript and budget fixed while background information reduces H(X | B_t). Explore an illustrative informed ratio R_inf(t); the rate is uncalibrated and crossing one is a loss of the deficit guarantee, not evidence of an attack.

0.00.51.01.52.00246810illustrative time t (arbitrary units) →R_inf(t)R_inf = 1 · deficit boundaryt* = 4.01shelf life

The exponential is an illustrative choice for background-information erosion, not a calibrated forecast. WP-07 requires ER-1–ER-5 and its declared background-information family. Crossing one removes the informed deficit guarantee; it does not prove reconstruction succeeds. Re-keying alone does not erase information already disclosed.

cast · set these values into your key

conf ~65%status active · registered Run 1, 2026-06-10 · re-typed 2026-07-17register corehome privacy_value_v6_draft.md Part I §I.3; research/pvm-v6-soil-and-the-programme-runtime-evolutions.md

The Moving Ceiling: adversary informational capability grows against fixed archives: the linkage corpus and side priors accumulate along calendar time, shrinking H(X \| B_t) while nothing is added to the archive and no action of the subject is involved; R_inf(t) drifts upward on a schedule and every static reconstruction guarantee has a finite shelf life t*. Frontier-model releases enter only informationally (better extraction of linkage from existing corpora), never as compute against the information-theoretic guarantee, which is compute-saturated. (Re-worded by First-Person ruling 2026-07-17, ledger L149; erosion form proven conditional in WP-07 Def 3.9 + Cor 5.4b, L145; the conjectural content is the RATE. Pre-ruling wording, retired: "frontier capability growth raises C_S(t) + C_M(t)".)

WP-07 Def 3.9 and Cor 5.4b require accumulated background satisfying B_t → X → T, ER-1–ER-5, and the informed deficit. The exponential rate is illustrative. Certification changes are a separate mechanism. Re-keying alone cannot remove information already disclosed.

fold

compositional leakage

C83 ↗illustrative model

compare upper-bound expressions under different assumptions and budget semantics. The linear cap needs all ER-1 through ER-5, including conditional budgets for forward interfaces; erasure alone is insufficient.

0.0012.7925.5838.3651.1512345678910chain depth N →bound expressionpolicy-only · (2^N−1)ε = 51.2amnesia · Nε = 0.50

These are bound expressions under different budget semantics, not measured leakage. The linear result requires all ER-1–ER-5, including conditional budgets for outputs and forward interfaces. Erasure alone is insufficient; the plotted expressions are not clipped to a specified source entropy.

cast · set these values into your key

conf ~55%status active · registered Run 2, 2026-06-10 · edge C7 → C83 → C17register corehome privacy_value_v6_draft.md Part II §II.3

Compositional Leakage Amplification: policy-only separation compounds toward (2^N − 1)ε with chain depth; amnesia separation breaks the Markov chain and caps at Nε; the gap is exponential-to-linear

WP-07 distinguishes marginal-budget and conditional interface-inclusive regimes. These curves are not measured leakage, a universal speedup, or proof that a deployed system satisfies the requirements.

curve

the temporal decay

C30 ↗illustrative model

trust is not timeless — it begins at inscription and decays until renewed. The e^(−λt) term is a half-life: after t½ = ln2/λ, half the original value remains.

0.000.250.500.751.000246810time since inscription t →valuet½ = 2.31

a protection is not timeless; trust decays until renewed. half-life differs by register and composes across the three axes.

cast · set these values into your key

conf 60%status activeregister sharedhome pvm-v6-1-bakhta-half-life.md

Trust half-life begins at inscription; decays until renewed

half-life differs by inscription register (C31), is higher for productive than transactional edges (C32), and composes multiplicatively across the three axes (C33). The exponential is the illustrative decay law; the half-life reading is the claim.

dial

amnesia vs policy

C17 ↗illustrative model

drive one parameter toward complete reconstruction and watch two separations run to collapse at different rates. Policy-enforced separation degrades; amnesia-enforced separation holds, because the witness is destroyed rather than withheld.

policy-enforced separation0.70

separated · the policy still holds

amnesia-enforced separation0.99

separated · amnesia keeps the witness out of reach

the gap · amnesia − policy = +0.29

amnesia-enforced separation is tighter than policy-enforced — the witness is destroyed, not withheld, so pushing the adversary harder buys little until the very end. same algebra as the completeness inversion, opposite polarity: logic mourns the gap it cannot close; the model banks the same gap as the asset.

cast · set these values into your key

conf 60%status active · made quantitative at V6 Run 2register corehome formal spec §17.1

Amnesia-enforced separation tighter than policy-enforced

the inequality (amnesia tighter than policy) is the claim — made quantitative at V6 Run 2 and quantified by the compositional gap (C83). The exact curve shapes are illustrative. Same algebra as the completeness inversion, opposite polarity.

trace

the ARCH-1 bridge

C85 ↗illustrative model

the three Φ axes and the lattice’s Datum · Stratum · Spectrum are one triadic primitive. Trace a correspondence to read the candidate pair map and what each axis is built from; the gap is β.

the three Φ axes ⊥ the lattice triple — one triadic primitive. trace a correspondence.

ARCH-1 (promoted from CM-C47): the three axes and the lattice triple are one primitive. The same algebra appears as the Gödel/Tarski limitative twin — provability ⊥ verification, the diagonal lemma ⊥ the ARCH-1 fixed point — its lineage on the research side.

cast · set these values into your key

conf ~40%status active · registered Run 4, 2026-06-10 · CM-C47 becomes alias · two named predictions (bnot-pairs invert all axes; stratum-3 is the no-dominant-axis seat)register corehome privacy_value_v6_draft.md Part IV §IV.2

Triadic-Constraint Homology (the ARCH-1 bridge, promoted from CM-C47): the three Φ axes and the lattice's Datum·Stratum·Spectrum are one triadic primitive; candidate pair map Protection+Delegation→Σ, Memory+Value→Δ, Connection+Computation→Γ; the gap is β

ARCH-1 promoted from CM-C47; two named predictions (bnot-pairs invert all axes; stratum-3 is the no-dominant-axis seat). The pair map is a candidate, not proven — the correspondence is the conjecture. Lineage: the Gödel/Tarski limitative twin (provability ⊥ verification, diagonal lemma ⊥ ARCH-1 fixed point).

gate

content-addressed liveness

C93 ↗structural

a content-address is a deterministic fingerprint, so a result, an identity, or a delegation can name itself and be verified by anyone with no trusted authority — portable trust. The catch is the same determinism: a live address is an existence oracle. Guess a file, ask the store by its address, and a hit confirms the content exists. The address that makes trust portable is the address that leaks existence — so liveness is gated at the door: verify freely, publish deliberately.

what a content-address makes possible
κa result — anyone re-derives it to verify — no trusted authority
did:cidan identity — a public handle to a private root — self-authenticating
κ→κa delegation — trust travels without a central registry (the VRC)

one deterministic address buys portable, authority-free trust — cast one yourself:

cast your own — imprint a value into a City Key
κ sha256:… — your value, imprinted

that address is a fingerprint of exactly what you typed — anyone re-derives it to verify, no authority. Change one character and it is a different key.

the catch — make it live, and the store answers by address
guess a file — the store confirms existence by address alone

the address that makes trust portable is the address that leaks existence — so agentprivacy gates liveness at the door: verify freely, publish deliberately.

conf ~55%status active · registered Run 8, 2026-06-28 · conjecturalregister corehome limitative-theorems-and-privacy-is-value.md §3.5, §3.6

Content-addressed liveness leak: a live content-address is an existence claim about its content; deduplication/GUID liveness leaks existence, and existence bounds the search. The address does not leak content; its liveness leaks existence. Edges → C81, → C92

C93 (~55%, the Limitative Reading, Run 8): a live content-address is an existence claim about its content — dedup/GUID liveness leaks existence, and existence bounds the search (kin to C81). The sha256 is computed live in the browser, so the leak is shown, not asserted: the store never hands over content, it only confirms existence by address. The integrity face — re-derive to verify, tamper-evident — is the benefit the harness holon layer relies on (κ as state, the mesh auditor, did:key/VRC edges; see HOLONS.md, KAPPA_HOLON_INTEROP in agentprivacy-docs); C93 is the privacy COST on the same address, and the reason a published or queryable κ is a disclosure the door governs.

design lineage · the geometry showpieces

Linked, not absorbed

The 64-vertex lattice and the star tetrahedron live on their own surfaces. The runtime links to and frames them rather than swallowing them — absorbing the star into the model page would cross the ⚔️ swordsman ⊥ 🧙 mage substrate boundary those surfaces are built on. They stay siblings; the binding to the register is anticipated, to be wired live if they are ever brought in.

For the distinction between derived geometry, chosen perspective and proof, read the Star research direction.

Conjecture authority lives in the register at head C97. The instruments here are illustrative teaching models bound to that authority; their shapes are chosen for clarity, not asserted as the proven relation. The page is an open path you read; the atlas is the one you walk.