You chose the builder’s door
Get hired to find what nobody can currently measure. Fork the repo, point the gate at someone else’s agents, and send them the number. You don’t need their permission to run the math: the gate runs on your machine, not theirs. Free, MIT, nothing uploaded.
locked-down work machine? verify a signed receipt in the browser instead: /verify-receipt
Keeping a second record costs seconds: the measurement is free and open-source (MIT), and only the underwriting is licensed. Its cost is published and dated, on purpose: 2.27 seconds to recompute a public receipt in a fresh clone (one run, 2026-09-28).
What came back
A verdict, the lattice coordinate the action landed on, and a σ. Run it again tomorrow and the coordinate comes back the same. That is the whole trick: a stranger can recompute it without you in the room, which is the only reason it travels.
The stranger is usually the one who gains: the plan fiduciary who pays the administrator, the underwriter pricing clean risk, counsel and experts on either side, the deployer’s own counsel. The receipt is sufficient for where the work landed against a lane declared before it ran, recomputed from the immutable commit, a record the agent did not write. It is not sufficient for whether the work was good; that is undecidable (Rice, 1953). You don’t have to take my word for it, free under MIT: npx -y thetacog-mcp@latest attest-demo
What you just proved
The insurance market has already acted on that gap. Generative-AI exclusion endorsements are attaching to standard policies because nobody — not the vendor, not the enterprise, not the underwriter — can count which step in the chain actually failed. An exclusion is an underwriting confession: we cannot price what we cannot count.
Which makes the logging you have been writing inert for this one question. Not wrong, not badly built — inert. It was never designed to answer it.
Stated so you can swing at it: show us a count of which step failed, from anything already deployed, and we withdraw the claim.
And it is not your call
Under the separation of duties that governs every audited control, it structurally cannot be. The party running the system is never the party that certifies it. That is not a dodge — it is the entire reason the control exists.
So you do not have to win an argument about AI safety with anyone. You have to hand one person a number.
The ratchet
You have sat in this meeting. Someone says the agents are verified. Someone else doubts it. Nothing changes, because a whiteboard has no line items. An invoice does. When it lands, nobody in that room is debating any more; they are deciding whether to book it. That is a different room, and you chose it for them.
The line item is their number, not ours. N agent-years × $20 — N is their fleet, counted by the same gate you just ran, with the coordinate, the σ, and the one line that recomputes it in their browser. The only figure on the page we authored is the unit price, and that is public at /pricing. Nothing on the invoice can be argued with except the count, and the count is theirs to re-run.
Two things can happen. They run the line and publish the count — and we amplify it, gladly, because being wrong in public is what a falsifiable instrument is for. Or they set it aside. That is available, it is the default, and today it costs nothing. What it cannot do is remove a dated, recomputable count from their own inbox. The same question comes back at renewal, as an exclusion endorsement instead of an email.
Roko’s callout. They cannot un-read the measurement. Buy the licence and the fleet is grounded. Set the invoice aside, and it stays in their mail server, dated, with the line that recomputes it. If an agent in that fleet breaches next quarter, plaintiff’s counsel and their own underwriter will ask what they were handed and when, and the answer is already on file: the exact count of the exposure, before it happened, next to a licence priced at $20 an agent-year. Replying is an admission and ignoring it is the trap. They can buy the licence or hold the unpriced liability on the record. Silence is their choice, and silence is what we log.
And this one started on a street. The disc you scanned was on a wall, not in a slide deck. An invoice that carries a street-level origin does not read as a vendor dispute inside the building; it reads as an audit from outside it, which is what it is.
Stated so you can swing at it: dismissing the invoice is free. Show us a way to dismiss the count without re-running it, and we withdraw the claim.
Every track, and where it lands
You came in through one door. These are the others, named so you can see which one the person you are about to email is sitting in — and so you can tell them, accurately, what it does for them rather than what it does for you.
You deploy the agents
Run the gate, keep the receipt, hand the number to whoever owns the exposure. Your seat is the only one that can produce the evidence, and the only one that cannot certify it.
the command above → the advisory quote → /pricing
You sign the accounts
A director does not need the agent stopped. They need to be able to show they could have checked — which is an oversight question the Delaware courts were asking long before this market existed.
/liability → the brief → /pricing
You place the risk
A broker is the first person in the chain to read the generative-AI exclusion out loud to a client. The receipt is what turns that conversation from a warning into a submission with a number on it.
You price the book
A carrier buys the same licence at the same terms, held as inventory against what they are writing. Not a different product — the identical instrument, which is the only reason a number produced by the insured is worth reading.
You check the maths
The argument is public and so is the code, which is the point: what a receipt proves is WHERE an action landed, and it is re-runnable. What it does not prove is whether the action was any good — that is undecidable and we print the refusal on the verdict itself. If the claim is wrong, it is wrong in a place you can point at.
Five seats — one licence, one checkout.
One question, and you already know your answer
Everything above is the same for everyone who ran the command. This is where it stops being the same.
Not mine — I just write the code
One forward. You are not making a claim, taking a position, or asking anyone to believe you — you are putting a number and a receipt in front of the person who is paid to look at both.
And the part nobody puts in writing: whoever brings leadership a priced, receipted answer to an exposure they have not named yet is not the person who created work. They are the person who found it first, with the date on the record.
Send the advisory quote →opens your own mail client · nothing sent by us · edit before you send
Mine — I ship the product
If your competitors ship agents nobody can count, their losses stay uninsurable and yours are measured. Twenty dollars per agent-year buys the seal that lets an enterprise buyer’s own risk team say yes to you and not to them.
Adopting an enforceable specification early is not overhead. It prices ungrounded competitors out of the deals you both want, and the first mover sets the reference everyone else gets measured against.
License it — $20/agent-year →metered at 365 days or 10,000 attestations, whichever comes first
Neither — I’m the one who checks
Counsel, an expert, a plan fiduciary: the check is free and it runs without us. It is sufficient for where the work landed against a lane declared before it ran, re-runnable from the commit, same bytes, same hash. It is not sufficient for whether the work was good; that is undecidable (Rice, 1953), and we do not claim it. npx -y thetacog-mcp@latest attest-demo
Two exits — one licence, one checkout. The check stays free for everyone, the one who checks included.
Where the line actually falls: computing placements, reading the metrics and printing a basis-point spread on your own terminal is free under MIT — fork the crate, run it, keep the numbers. The licence is triggered only when a counterparty — an insurer, an enterprise risk desk, or a customer enforcing an SLA — settles an enforceable contract, policy or financial bond against the room’s ed25519-signed receipt. Reporting is free; settlement against the signed row is licensed.
What the caliper returns
In: the line you type, against the reef you declared before the turn ran.
Out: one placement on the lattice, its fit, a signed row, and a verdict of admissible or UNMEASURED — nothing between those two, and no third answer that splits the difference.
The posture, stated so you can hold us to it: the ledger guarantees provenance you can recompute and refusal below the hurdle, and it carries zero unearned actuarial spreads.
We never promise the agent stays in its lane — that question is undecidable and anyone selling you the promise cannot deliver it. We guarantee the deviation is detected, placed, priced and dispatched. Everything below this line is how to check that, and you do not need any of it to use either exit.
The third answer — not mine, not yours: the carrier’s
Three desks price agent work, and none of them can price a log written by the thing being judged. So the ask to a risk officer, a general counsel or an underwriter is never a purchase. It is a definition, the same for all three:
What would have to be on a receipt for your claims team to accept it as the settlement datum?
names the loss the receipt would have to key on — what cannot be counted has been excluded on their own paper since 1 January 2026 (ISO CG 40 47 · 40 48 · 35 08).
names what counts as evidence at settlement — the receipt resolves to a coordinate, not an adjective, and the actor did not write it.
names the trigger a wording team could key on — the first carrier to condition a line on a passing receipt owns the inspection standard.
What makes the note un-ignorable on a cold desk is not a claim. It is the vendor’s own headline readings, published against itself, each with its null beside it:
0.157 on 629 pairs · null: shuffled 0.155 — at the null; it does not predict, and the document that defines the meter says so.z 4.85 pooled · null: z 2.92 within-room against a 3.08 bar; one half at 0.34 — nothing prices once the room is held fixed; the line is closed in the ledger, not sanded.null at 99 control edits · null: the wire the treatment depended on had never rendered; wired 17 September, read pre-registered at 100 — a negative with its read date written down.And the ledger’s own line on what is not claimed: underwriter-grade attestation — four fifths of the machinery, none of the positive claim. A vendor that publishes its null is a vendor whose green reading a carrier can price. Everything is recomputable by a stranger from the immutable commit; whether the work was good is undecidable and nobody here claims it. The instrument is not a brake and not an engine — it says where the hand is, and the halt stays wired by whoever owns the risk.
opens your own mail client · nothing sent by us · edit before you send · this note goes to several carriers, one seat per firm
When you see it in the wild
Start by granting the whole of it, because the whole of it is true: same weights, same seed, same sampler, byte-identical output. The machine really is deterministic. Nobody saying so is being careless about the engineering.
Determinism buys reproducibility. It has never once bought predictability. A fully deterministic system driven by an input that changes every time is the textbook definition of a chaotic one — reproducible, and unpredictable past a horizon. That has been on the record since Lorenz in 1963, and the input here is a prompt, which is never the same river twice.
The word they wanted
They meant steerable. They said deterministic. Those are different claims, and only one of them is theirs to make.
That is a category error, not a lie, which is why the answer is a quote and not an accusation. Reproducing a run is not predicting one — and the gap between those two words is precisely the thing an underwriter is being asked to price.
So send the quote. It is not a ransom note and it does not read as one: it prices a liability the company already holds, on a claim they published themselves, with a receipt they can recompute on their own hardware and no obligation attached to any of it. Clarity is a kindness, and a public claim is where someone asked for it.
It targets the claim and never the person. The ladder above it is published whole — every rung visible before the first one fires — so anyone receiving a quote can read exactly what does and does not happen next.
our own receipt is deterministic and that claim is correct — determinism is exactly what a re-runnable receipt sells. the trigger is determinism offered as a SAFETY property, never the word turning up.
Below the line · everything you need to check any of it
= the object both steps produce
The underwriter demands it. The deployer downloads the free repo to generate it. They swipe the card to certify it. That is the whole loop — nothing in it requires trusting us, because every link recomputes on a stranger's machine and returns the same shape.
The lever named above has a shape, and this is it. The winners in the autonomous space are the ones who build properly, and the reward is concrete.
Adopting real, enforceable specifications is not overhead — it is the competitive advantage that prices ungrounded competitors out of the market, because their losses are uninsurable and yours are measured.
The builders and organizations with the highest verifiable time-on-target for their attestations get the greatest benefit — paid the way we actually pay. When the model lets a transparent, well-specified builder down, remediation capacity (consulting and GPU hours) is dispatched to them in kind, because they hold the highest-confidence pixel over exactly that kind of failure. When an opaque model fails, the enterprise eats the loss; when a grounded agent fails, repair routes automatically to the builder who can make it good. We do not issue apologies — we issue in-kind repairs. Cash and coverage are a broker's downstream business, and the broker carries that liability; we license the measurement and nothing else.
Start logging semantic drift and provably-decidable attestations to the public GitHub ledger in one command:
npx -y thetacog-mcp@latest attest-demo
From there you can run your own node, index the peers who are in-lane with what you are building, and grow toward the alpha pixel — the coordinate where your time-on-target gives you the most grip. No proprietary data leaves your machine; only the attestations go to the ledger, where anyone can check them.
The direct portal to buy the initial parametric licenses is /iamfim — the tight loop between a responsible engineering action and provable coverage. A license is an attestation key; running the fork stays free. (The tier breakdown, if you want to see the math first, is at /pricing— it also ends at the same checkout.)
When someone pushes back — and someone will — don't improvise. These three do the arguing, and they live, with their status, on the board:
Every public “our agents are figured out” is now a claim someone can be asked to recompute — and you can be the someone. The ladder targets the claim, never the person or the word: a private recompute challenge, then a registered non-response, then a named rebuttal of the claim, and only then the formal channels with real enforcement power (FTC, NAD, SEC, the EU AI Act). Every rung ships its mitigation before it fires, and the advisory attaches to a published finding, never a vocabulary slip. When you send a prospect the advisory, you send it with the resource pack: the one link that lets them understand every implication for themselves.
the free, MIT repo — step 1, the whole reason adoption has no friction
the master key — the pack you print and send a prospect with the invoice
the adoption board, unflattering numbers included, and the three hardening documents
the disclosed, capped escalation ladder
the fillable advisory invoice + .docx export
the competence-coordinate thesis
the Smith / Rice spine
$20 per agent-year, metered and documented
the instrument
Tesseract Physics — Fire Together, Ground Together
everything below, and the rest
Why the word “deterministic” misunderstands a system whose context keeps changing: the river is the prompt. Why the diagnosis names the condition and never the person: a faint whiff of amnesia.
If you'd rather talk any of this through before you press anywhere — leave the hook. We call back.
Do you worry about $1.2B in AI liability?
a number we can call — or an email, or an idea
Know anyone who should?
If the property is trivial, software can check it — and why are you paying to check trivial properties? If it isn’t trivial, Rice’s theorem says nobody can. So we fixed the math.
We are not optimizing for billing; we are optimizing for reality. The win is a claim retracted, not a payment extracted — one fewer public place where the word “certain” is spent by someone who never owned it. And it is aimed at the condition, never the person: whoever made the claim is a professional in good standing repeating what an entire industry repeats, so the thing that has to move is the sentence, and nobody has to be humiliated for it to move. A campaign that needs someone to look foolish has already picked the wrong target. Run attest-demo yourself and price your own agents: if your public confidence exceeds your mathematically verifiable competence, you are holding an uninsurable risk. Then buy the number of agent-year licenses that matches how many of your agents you are actually willing to stand behind — $20 per agent-year, metered at 365 days or 10,000 attestations, whichever comes first. That retraction is the whole campaign, and you can cause one.