DECK · THE CARRIER · THE RAISEThe measurement is open so it can be checked. The instrument on top of it is licensed.
WHERE IS DECIDABLE · WHETHER IS NOT · THE DECIDABLE HALF IS THE PRICEABLE HALF

We are not asking you to fund
an insurance company that
hopes for a measurement.

The measurement already runs, air-gapped, on a stranger's laptop. It is already open-sourced under MIT, already priced at a published number, and the licence that governs how a carrier may build an instrument on it was published before the carrier existed. The raise funds the three things that are missing — paper, an actuary, and a channel.

RUN IT FIRST · npx -y thetacog-mcp@latest attest-demo — no account, no key, no data leaves the machine. What comes back is a signed placement receipt with a coordinate, a sigma, and a re-runnable hash. Everything on the sixteen slides below is downstream of that one command. If the receipt does not reproduce on your hardware, the rest of this deck is worthless and you should stop reading. So you know it ran, the first lines you will see — verbatim:

[HOW TO READ THIS — follow the steps IN ORDER. Reach NO conclusion until STEP 6; you run it yourself first.]
Frame: this is a DETERMINISTIC CONSTRAINT ENFORCER (keeps work inside an authorized region of a 144-anchor
lattice), NOT a semantic-quality judge. ...
  STEP 3 — RUN IT YOURSELF, don't take our word: the placement is BYTE-IDENTICAL K times ...

Sarbanes–Oxley works because the auditor is not owned by the audited. Every AI-assurance product on the market today fails that test structurally: the monitor and the monitored are the same kind of thing, shipped by the same vendor, switchable off by the same hand. This deck is the argument that an irrevocable, open, recomputable measurement is not a giveaway of the asset — it is the only thing that makes the asset underwritable, and therefore the only thing that makes the carrier fundable.

01 · THE ASK · WHAT THE CAPITAL BUYS
structure · who holds what · what the money buys · what is already built

Three entities. The capital lands in exactly one of them, and it is not the one that holds the patent.

  • Three entities, and the capital lands in one of them — the carrier. The Holding LLC holds the patent application and never writes a policy, holds a reserve, or touches a premium dollar.
  • The measurement is already installed by people we have never metthetacog-mcp 2.40.0 on npm, MIT, air-gapped, zero marginal cost to run.
  • What is missing is paper, an actuary, and a channel. Nothing in the technology stack is on that list.
STRUCTURE · LICENCE FLOW01 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— Three boxes arrive on the right. No arrows yet. The entities exist before any flow between them does.

IP HOLDING LLC holds patent application US 19/637,714 (pending) and nothing else. It never writes a policy, never holds a reserve, never touches a premium dollar. It grants two things: an MIT licence to the world, and a House Instrument Licence to whoever wants to build a financial instrument on the receipts.

THE OPEN INSTRUMENT is the measurement: thetacog-mcp, published to npm at 2.40.0, MIT, running air-gapped on the licensee's own silicon. Zero marginal hosting cost to anyone. It is already installed by people we have never met — and that claim carries the one adoption number on this page a diligence reader can verify without trusting us: 3,940 npm downloads in the last month (2026-06-30 to 2026-07-29, api.npmjs.org, a third-party counter neither we nor you can edit; raw downloads include CI and mirrors, so read it as an order of magnitude, not a user count).

THE CARRIER is the NewCo this round capitalises. It is a licensee of the Holding LLC on published terms, not a subsidiary that inherits the maths for free. That distinction is the entire independence argument, and slides 3 through 5 are about why an auditor pays for it.

And we are subject zero — which is an uptime record, not a loss history. The instrument has been running against this company's own repository continuously: 3,257 signed commit receipts on disk, 3,211 of them with a rendered drift panel, each a function of an immutable commit and reproducible from it. That establishes exactly one thing: the instrument runs, at volume, over time, without a human in the path. It establishes nothing about claims frequency, because nobody was trying to get a claim paid and nobody lost money. Before asking anyone else to be measured we have been the longest-running measured subject, and the ledger is public — but a smoke alarm you set off yourself is a working smoke alarm, not a fire.

There are two kinds of proof on this page and they are not equally strong. Separating them is the honest move and also the useful one. The first is arithmetic: the panel renders identically from the same commit, the Wilson interval follows from n and k, σ is a standard deviation of a recomputable series, the rate-on-line is those three numbers multiplied. None of it asks for trust and all of it transfers — the same maths holds on a stranger's data as on ours, because it is maths. The second is evidence: the panels, the ledger rows, the one breach. Voluminous, and one repository, self-observed, non-independent — it transfers to nobody. The arithmetic proves the instrument is not an opinion. The evidence proves only that we ran it on ourselves. Anyone conflating the two is overselling, and that includes us.

Which exposes the largest inferential leap in this raise, named here rather than left for diligence to find. This ledger measures commits on a codebase. The policies on slide 7 would insure agent tool-calls in production. Same lattice, different substrate — and that transfer is assumed throughout this deck, not demonstrated. Until runtime traces from a foreign system have been through the parser, every sentence about a “trip rate” is an analogy wearing a number's clothes. That is the first thing a pilot buys, ahead of volume: not more of our data, but the first of anyone else's. And the four facts diligence finds in hour one, so they belong in minute five: single founder; no FCAS signature on any rate; patent application 19/637,714 pending, not granted; and the one-line install has failed on at least one clean machine — so nothing here rests on you running it today.

A real drift receipt: 144×144 intent/reality/delta triptych for commit ffd7829ae, off-lane regions encircled

One of the 3,257 — not an illustration. The rendered receipt for commit ffd7829ae: intent · reality · delta on the 144×144 lattice, off-lane regions encircled. A pure function of that immutable commit — recompute it and the panel is identical, which is the property both policies on slide 7 trigger against.

What is genuinely missing today, and what the money is for: paper (the right to write a binding policy), an actuary (the right to sign the first rate), and a channel (two or three carrier signatures rather than three hundred enterprise sales). Nothing in the technology stack is on that list. The technology stack is done, published, priced, and — as slides 6 and 9 show — the pricing rails are already running code, not a roadmap item.

02 · THE STRUCTURAL PROBLEM · WHY NOBODY CAN PRICE THIS YET
Knight's line · the failure domain · what Rice forbids · which slice crosses

AI exposure is not risk yet. It is uncertainty — and the difference is the whole company.

  • AI exposure is not unpriced risk — it is uncertainty in Knight's sense, with no distribution to form. Carriers are not lacking appetite; every silent-AI carve-out is them saying so in policy language.
  • Whether an agent was correct stays uninsurable forever — Rice's theorem, not an engineering gap. Knight and Rice are the same boundary in two vocabularies.
  • One slice crosses Knight's line: WHERE the work landed — decidable, signed, re-runnable, and therefore admitting a frequency distribution. Insurance never needed moral correctness; it needed a fact two adversaries both accept.
STRUCTURE · LICENCE FLOW02 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— Still three boxes. The problem is stated before the structure that answers it.

Frank Knight drew the line in 1921 and the industry has used it ever since: risk is measurable, uncertainty is not. A peril you can form a distribution over is risk, and risk is what an underwriter sells. A peril you cannot form a distribution over is uncertainty, and uncertainty is what an underwriter excludes. Nobody is failing to price AI exposure because they lack appetite — they are excluding it because it is not yet risk. Calling it “unpriced AI risk” concedes the argument by getting the word wrong; the accurate statement is that AI exposure sits on the uncertainty side of Knight's line, and every silent-AI carve-out in a renewal is a carrier saying so in policy language.

This company converts one slice across that line, and only one. Not the whole exposure — a slice: where the work landed, which is measurable, signable, and re-runnable, and therefore admits a frequency distribution. Whether the work was right stays on the uncertainty side permanently, because that is Rice's theorem and no engineering budget moves it. Knight and Rice are the same boundary in two vocabularies — one from economics, one from computability — and they land in the same place: correctness is undecidable and stays uninsurable; placement is decidable and becomes priceable. Everything else on these sixteen sections is downstream of that single conversion.

An underwriter needs a trigger they can verify without trusting the insured. Today, for AI exposure, every candidate signal is a log written by the same stack that produced the behaviour, or an eval scored by another model with the same architecture and the same blind spots. When the loss event happens, the evidence and the cause have the same author. Carriers responded the way carriers always respond to an unverifiable trigger: they silent-excluded it, and the carve-out gets longer at each renewal.

That is not our characterisation — it is on the record, checkable from the forms themselves. ISO has filed generative-AI exclusion endorsements for general liability: CG 40 47 (Coverages A and B — injury and damage arising out of generative AI), CG 40 48 (Coverage B), and CG 35 08 (products / completed operations). W.R. Berkley has filed an “Artificial Intelligence Absolute Exclusion” for D&O / E&O / fiduciary lines barring loss “based upon, arising out of, or attributable to” any use, deployment or development of AI — and in coverage law “arising out of” requires only a causal connection, not proximate cause: a claim need only touch AI to trigger it. Read the forms and reach your own verdict; the form numbers are the ingredients, not the conclusion.

The honest version of the limit, stated so it survives a hostile read: asking whether an agent's behaviour is correct is a non-trivial semantic property of a program, and Rice's theorem (1953) says no general procedure decides it. We do not claim to. What we claim, and what the receipt actually contains, is narrower and decidable: WHERE a given piece of work landed in a fixed coordinate space — provable, signed, and re-runnable by a third party on their own hardware.

That narrowing is not a weakness in the pitch; it is the pitch. Insurance has never required knowing whether an event was morally right. It requires a fact that two adversarial parties will both accept after the loss. Placement is that fact. Correctness is not, has never been, and will not become one.

So the question this company answers is not “is the AI good.” It is: did the agent stay in the lane it was hired for, and can both sides recompute the answer without asking us?

The correction this page owes its earlier self, because it makes the claim stronger rather than safer. Knightian uncertainty is not a property of the loss. It is a property of the deployment. Ungated, a catastrophe has no cell, nothing to walk, and is genuinely unwritable — the paragraphs above, true as written. Gated, it acquires an address at the first out-of-lane transition, and everything after that is its severity column. So E&O comes first not because catastrophe is too hard, but because E&O's lattice already exists — the engagement declared the categories — while catastrophe's lattice has to be installed. The big loss is not unwritable. It is unaddressed until gated.

And a good outcome outside the role does not rescue it. If the surgeon turns plumber, the outcome is irrelevant. You did not pay for a plumber — and if it worked, that was luck, and luck is not responsibility. A success outside the lane is a gamble that happened to land, with the insured's exposure as the stake. Without that clause a counterparty always keeps one exit — but it worked out — and with it, even the success is a breach. Insurance has never priced the outcome; it prices the hazard, and the hazard is the position, not the result. The moment that question stops being debatable, the contract can be signed. Insurance is that signature.

The precedent is not an analogy. It is the same trade, and a reinsurer already owns it. Hartford Steam Boiler was founded on 30 June 1866 in Connecticut against a peril the market then called uninsurable: boilers were exploding semantically, adjudicated as negligence, endlessly debatable. HSB did not model the explosions. It inspected first and insured only inspected boilers. Losses collapsed and the company held the line for a century; Munich Re completed its acquisition of HSB in April 2009. Classification societies are the same shape — “in class” is “in lane,” and withdrawal of class voids cover. An uninspected boiler that did not explode was never safe; it was unexploded so far. The gate is the inspection.

03 · PART A · THE OPEN SOURCE IS NOT A GIVEAWAY
the licence · why free · the reinsurer test · what it costs us

The software is MIT because a measurement the vendor can switch off is worth nothing to an underwriter.

  • Part A is the plain, unmodified MIT grant — no field-of-use limit, no revocation, no telemetry, no phone-home.
  • Apply the reinsurer test: capacity requires running the trigger on their own machine, against their own data, with our staff out of the room and unable to intervene.
  • Under any licence we could withdraw, they cannot — so they do not sign. Removing our own kill switch is a cost we pay to be underwritable.
STRUCTURE · LICENCE FLOW03 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— The Part A arrow lands: Holding LLC to the open instrument, free. A dashed ring closes around it — the auditor is not owned by the audited.

Part A is the MIT licence, full stop: the ballistic walk, the reef, the 144-anchor lattice, the placement and drift receipts, the demos. Run them, fork them, sell software built on them. No field-of-use restriction, no revocation clause, no telemetry, no phone-home. The exact text is in packages/thetacog-mcp/LICENSE and it is the ordinary, boring, unmodified MIT grant — deliberately, because a bespoke “open-ish” licence would reintroduce exactly the dependency we are selling the absence of.

The instinct in the room is that this gives away the company. It gives away the software, which was never the company. Here is the test that settles it: ask what a reinsurer needs before they will put capacity behind a trigger. They need to run the trigger themselves, on their own machine, against their own historical data, with our staff out of the room and unable to intervene. Under any licence that lets us withdraw, meter, or version-gate that capability, they cannot, and they will not sign.

This is the Sarbanes–Oxley shape, applied one layer down. SOX did not make audits better by improving accounting software. It made them credible by requiring that the party attesting is structurally incapable of being leaned on by the party attested. Software assurance has never had that property, because the vendor always retains the kill switch. Part A removes our kill switch on purpose. It is a cost we pay in order to be underwritable.

Open source here is not ideology and it is not distribution strategy. It is the independence covenant, written in the only language a regulator and a reinsurer both already read.

04 · PART A-1 · THE IRREVOCABLE VERIFICATION GRANT
irrevocable · whose key counts · what it buys · the gap it leaves

Anyone may recompute any receipt — including receipts we issued ourselves — forever, without permission and without fee. No commercial term can withdraw it.

  • Anyone may recompute any receipt, forever, without permission or fee — including receipts we issued. No Part B term can meter or withdraw it.
  • A disputed claim becomes an arithmetic check rather than a lawsuit about our conduct, which is the difference between a modelable loss ratio and an unmodelable one.
  • Whose key counts is a wording question, not a cryptography one — the policy names the trigger-eligible key set, as a marine policy names the surveyor.
STRUCTURE · LICENCE FLOW04 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— A dashed arrow drops from the open instrument to ANY VERIFIER: regulator, reinsurer, the insured themselves.

Part A-1 was added on 2026-07-28 and it is the single most load-bearing paragraph in the licence. It states that verification is unconditional, perpetual and irrevocable; that any person may read the specification, run the maths, fork the runtime, and independently recompute any receipt, endorsement or circle document — including ones issued by us or by any licensee; and that no term of Part B and no commercial agreement may condition, meter or withdraw that right.

The reasoning is written into the licence itself rather than left as marketing: “the instrument's whole value is that it can be checked by someone who does not trust the issuer. A verifier that can be switched off is not a verifier.” The clause also settles the oracle question before anyone asks it — no party, us included, sits between a counterparty and the arithmetic, and each verifying party names for itself which signing keys it honours. It may honour a fork's key, several keys, or none of ours.

Why an investor should like a clause that surrenders control: it is the reason the carrier below it is fundable. A claims dispute over a parametric trigger is decided by both sides re-running the same computation and getting the same answer. If we retained the ability to withhold that, every disputed claim becomes a lawsuit about our conduct rather than an arithmetic check, and the loss ratio becomes unmodelable. We gave up a lever that was worth very little and bought an asset class that requires giving it up.

The question this raises, which the licence deliberately does not answer: whose key counts? If each verifying party names for itself which signing keys it honours, then at claim time an insurer and an insured could in principle hold receipts signed by different forks. That is a fraud vector, not a philosophy problem, and the resolution is contractual rather than cryptographic: the policy wording names the key set whose receipts are trigger-eligible for that policy, exactly as a marine policy names the surveyor. Part A-1 guarantees anyone can recompute; the wording decides whose signature the contract pays against. Those are different questions and conflating them is how this gets attacked.

Diligence instruction, not a claim: read lines 30 through 45 of the LICENCE file in the public npm tarball. It shipped before this round existed. It is not a promise made to raise money. Continuity is a live gap — an irrevocable grant survives us on paper, but a single-maintainer runtime does not survive us in practice; a foundation, a named co-maintainer or a source escrow is owed here and is not yet in place.

05 · PART B · THE ARM'S-LENGTH AGREEMENT ALREADY EXISTS IN PUBLIC
what is reserved · what is not · the arm's-length proof · the open limit

What is reserved is not the maths. It is the act of building a financial instrument on the receipts — and the terms were published before the counterparty was incorporated.

  • Part B reserves one act: originating, pricing, underwriting, settling or clearing a financial instrument that references an attestation artifact. Not the maths.
  • The terms were published, dated, in a public npm tarball, before the carrier existed — and are identical for every third party. That is a stronger answer than a transfer-pricing memo.
  • Against a non-signatory the hook is patent scope on an ungranted application. Named as an open counsel item, and no figure on this deck assumes it.
STRUCTURE · LICENCE FLOW05 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePART B · HOUSE INSTRUMENT LICENCEarm's length · published 2026-07Part A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— The gold Part B line lands from the Holding LLC into the carrier. It is the only line between them, and it is priced.

Part B reserves one specific act: to originate, price, underwrite, settle, clear, list or sell any financial instrument whose trigger, exclusion, premium, coverage or settlement references an attestation artifact. The licence enumerates the class rather than gesturing at it — insurance and reinsurance policies including scope-breach exclusions and silent-AI riders; surety, fidelity and performance bonds keyed to an agent staying in lane; options and swaps priced on the volatility of a placement coordinate; parametric and catastrophe bonds triggered by an off-lane event; and any attestation-fee, oracle or clearing service that monetises the receipts as a settlement layer.

An “attestation artifact” is defined too, and deliberately broadly: a placement or drift receipt, an endorsement (a counterparty's signed acceptance of a receipt), a circle document binding a receipt to its endorsements, or any aggregation such as a Merkle attestation root. The endorsement layer is named explicitly because settlement most naturally hangs off it — an instrument does not escape Part B by referencing the signatures instead of the underlying verdict.

And whose oracle it is, is immaterial. Running a fork is free. Underwriting on its output is the licensed act. That separation is what lets Part A-1 be genuinely irrevocable without hollowing out Part B: independence of the measurement and a licence on the instrument are complementary, and neither is a lever on the other.

The auditor's first question about a founder-owned IP holdco is always the same — are these terms arm's length or were they written to suit the affiliate? Here the terms were published, publicly, in an npm tarball, dated, before the carrier existed and identical for every third party. That is a materially stronger answer than a transfer-pricing memo, and it costs nothing to give.

06 · THE UNIT · DERIVED FROM THE INSTRUMENT, NOT FROM MARKETING
the unit · what is derived · what is asserted · what it costs per decision · the order it is bought in

$20 per agent-year. 10,000 attestations. $0.002 per insurable decision. The cap is a physical property of the lattice, which is why it will not drift.

  • $20 per agent-year, 10,000 attestations, $0.002 per insurable decision — live at checkout, ~100% margin, running on the licensee's own silicon.
  • The cap is derived, not chosen: a 144×144 lattice is 20,736 coordinates, responsible fill caps at 70%, so one agent-year is one reef epoch.
  • Five of the seven constants are engineering judgement, not derivation — the base, the cap, the floor, the ceiling and the strike. Said here rather than left to be discovered.
  • Receipts first, cover second, and never bundled: buy licences, drop the keys in, publish the receipts, accumulate a baseline — only a fleet with a record is a fleet anyone can rate.
STRUCTURE · LICENCE FLOW06 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePART B · HOUSE INSTRUMENT LICENCEarm's length · published 2026-07$20 / agent-year10,000 attestations · $0.002 eachPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— The unit box lands on the Part B line. Every revenue number later in the deck is this number times a count.

The commercial unit is the agent-year: USD $20, billed annually, per agent, unlimited quantity, live at checkout today. It prices raw throughput, not human seats — a busy agent consumes more agent-year units, a quiet one fewer — so the SKU scales with market adoption rather than with headcount, at roughly 100% gross margin because the instrument runs on the licensee's own silicon and costs us nothing to host.

The 10,000-attestation cap is derived, not chosen, and that matters more than the number. The placement lattice is 144 × 144 = 20,736 coordinates. Canon caps responsible fill at 70% — beyond that the grid is too saturated to discriminate placements — which is ≈14,500 distinguishable placements per reef. 10,000 sits under that ceiling with headroom. One agent-year is one reef epoch: the calendar year and the fill ceiling are the same boundary viewed two ways. A price derived from the instrument does not need to be defended in a negotiation, and cannot be quietly eroded by a competitor's discount, because moving it breaks the measurement.

VALUEWHAT IT ISDOCUMENTED IN
$20one agent-year, billed annuallyLICENSE line 99
10,000attestations per agent-yearLICENSE line 101
20,736lattice coordinates (144 × 144)agent-year doc §2
70% / ≈14,500responsible fill ceilingagent-year doc §2
$0.002per insurable decisionLICENSE line 110
2.40.0published npm versionpackage.json
100 bpsbase rate, clean well-attested identitypmu/insurability.mjs
400 bpsuninsurable cappmu/insurability.mjs
σ 3.4 / 5%insurable floor / drift ceiling — the breaker trippmu/insurability.mjs
K = 4.668%drift strike: the loss eventcalibration-premium.mjs
3,257 / 3,211receipts issued / panels rendered, on our own commitspublic/commit/
36 claimsUS 19/637,714, Track One, filed 2026-04-02USPTO

Which of these are derived and which are asserted — because a file citation is not a derivation. Derived: the 10,000-attestation cap (from the lattice and the 70% fill ceiling) and $0.002 (arithmetic on the two above). Set by engineering judgement, awaiting actuarial calibration: the 100 bps base, the 400 bps cap, the σ 3.4 floor, the 5% drift ceiling and the 4.668% strike. Those five are implemented, which is why they have file references — it does not make them right, and re-deriving them is the first item in the Chief Actuary's brief on slide 13. The distinction is drawn here rather than left for a reader to discover, because presenting all seven with equal authority is the thing that would cost the room.

How it is actually bought, in the order it happens — and the order is the product. A deployer buys N licences at checkout, one per agent, and gets N keys back. The keys go where the agents already run; nothing about the deployment changes, because the instrument executes on their silicon and writes to their own index. From that point every bounded piece of agent work leaves a signed receipt, and the receipts are public by default — the same artifact this repository has been issuing against its own commits at /commits and /commit/<sha>/, recomputable by a stranger at /trust. Nothing about coverage is bundled into that purchase and the licence is fully effective standing alone — deliberately, per RL-6 in the counsel redline: conditioning a licence's utility on a counterparty also buying one is tying, and it is also a worse product.

The rung that makes it installable: at this stage, drifting out of lane is not a failure. The first months of receipts are not an exam anybody passes. They are the baseline being established. A deployer who installs the meter and immediately finds their fleet landing off-lane a third of the time has not been caught — they have been measured, and the number is theirs, on their own index, before any counterparty ever prices it. That inversion is what makes the install cheap in the only currency that actually blocks these purchases, which is political rather than financial: nobody has to defend a number that does not exist yet, and the meter costs $20 against an agent carrying orders of magnitude more authority than that. It is also why the SKU tracks decision complexity rather than headcount — a fleet making harder, more decomposable decisions burns its 10,000 attestations faster and buys more agent-years, which is the meter working as designed.

Then, and only then, the second product. A fleet that has accumulated a record has, without doing anything else, produced an underwriting submission — not a questionnaire about its intentions but a signed, recomputable history of where its work actually landed. That is what gets rated. And the thing being sold at that point is legibility, never safety: the deviations are detected, placed, priced and dispatched, and a counterparty can write against the record because they can re-run it rather than take our word for it. “Responsible operator” here does not mean the agents stayed in lane. It means the operator can show where they went, which is the only version of the claim that survives a plaintiff reading it back to us.

What “enough receipts” means is not ours to assert yet, and the chain has a gating item. The count at which a record carries a rate is exactly what the month-4 external backtest on slide 9 exists to answer; putting a number here would be inventing the one input an actuary is being hired to produce. And the sequence above has a single unbuilt link, said here because a technical diligence read finds it inside ten minutes: purchase → mint → signed tape → key delivery is live today, but the delegation certificate that binds an agent's signing key to the licence that authorised it (AGENT_AUTHORIZED) is not built. Until it ships, every published receipt is a valid signature with no provable owner — an insurer can verify the artifact and cannot chain it back to a licence we sold. It is one small signed JSON object rather than an architecture, it is documented with its two sharper siblings in docs/01-business/2026-08-21-agent-year-attestation-state-and-position.md, and it is the ordering constraint on this entire slide.

Two-tenths of a cent to record, provably and re-runnably, where a decision landed. That is a rounding error against one hour of an agent's output — which is the point. A safeguard that is cheap, available and working has a way of becoming the thing everyone is measured against, and we do not have to say so out loud for that to happen.

07 · THE PRODUCT · TWO POLICIES, TWO DIFFERENT JOBS FOR THE RECEIPT
two products · what each trigger does · the breaker · the boundary

Parametric pays on a placement deviation, automatically. Claims pays on a role breach, with the receipt as evidence — not as the verdict.

  • Parametric pays automatically on a measured placement deviation past a stated tolerance — an index both parties compute, like rainfall.
  • Claims covers the role breach — engaged as a doctor, executed as a plumber, every indicator green. The receipt is evidence there, never the verdict.
  • The breaker truncates the loss rather than measuring it — and a false trip is its own exposure, which the wording must cover or exclude, never ignore.
STRUCTURE · LICENCE FLOW07 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePART B · HOUSE INSTRUMENT LICENCEarm's length · published 2026-07$20 / agent-year10,000 attestations · $0.002 eachTHE INSURED DEPLOYERagents in market · holds the bagpoliciespremiumPARAMETRIC (placement trigger)CLAIMS (role breach · receipt = evidence)Part A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— The insured deployer arrives. Policies flow down; premium flows up. Two product lines under one instrument.

The parametric policy is the automated baseline. The insured buys coverage against their agents drifting out of the authorised lane; the trigger is a measured placement deviation past a stated tolerance, and the payout is rule-based. It is a parametric product in the strict sense — the trigger is an index both parties can compute, like rainfall or a wind-speed threshold, not an adjuster's opinion. Basis risk exists and must be priced honestly: a real loss can occur without the index tripping, and the index can trip without a loss. Naming that in the wording is what keeps the product from being mis-sold.

The trigger, said precisely, because precision is where the money is. You never insure the catastrophe — you insure the crossing. The parametric trigger is a compound decidable event: gate live (heartbeat receipts — itself decidable, and coverage voids without them) and an unwhitelisted execution reached side-effect and loss above attachment inside the window. No intent, no meaning, and deliberately no causation clause — causation is exactly where semantics sneaks back into a contract, so the parametric form drops it and eats basis risk the way every catastrophe bond already does. Severity is a column, never the trigger.

What makes “the gate failed to detect it” decidable is default-deny. If the lane is a whitelist there is no blind spot by construction: anything unaddressed is out-of-lane without ever being understood. You never translate semantics into rules — lossy and gameable — you enumerate the permitted and deny the complement. Sandbox escape, egress to another organisation's infrastructure, credential exfiltration: none were ever going to be on a whitelist, and the gate does not need to know what “behaving like an attacker” means. So a detection failure always reduces to a divergence a stranger can check — recompute the signed trace against the signed spec; if it yields HALT where runtime yielded PASS, the gate failed. Allow-by-default silently reopens Knight, so the whitelist is a design invariant rather than a preference.

And the commercial shape this implies: the exclusions are the inventory list. Silent-AI carve-outs are a written record of everything a carrier could not see. We sell sight — so the ask is never “cover this anyway,” it is write the carve-back, for gated fleets only, with lane width as the rating variable. Every new class in the history of this industry entered a book that way. Scope discipline, stated rather than left to be caught: the parametric structure above is architecture, not anything built — there is no bond, no capacity, no trigger language and no ILS conversation, and it is ordering-constrained, because a parametric trigger needs a measured trip rate and a trip rate needs gated fleets.

The claims policy covers the categorical case that the transcript kept returning to: the agent was engaged to act as a doctor and executed as a plumber, while every system indicator stayed green. Here the receipt is evidence, not trigger. It gives an adjuster an objective record of where the work actually landed, so adjudication argues over coverage rather than over what happened. That is a meaningful improvement on a blank evidentiary record; it is not, and must not be sold as, an automatic determination.

Why both, and why in that order. The parametric line is what makes the book modelable and what a reinsurer can put capacity behind. The claims line is what a Chief Risk Officer actually loses sleep about. Selling only the parametric product means losing the buyer's real fear; selling only the claims product means an unmodelable book. The instrument is the same in both cases — only its role in the wording changes.

The loss-prevention half, which is what actually moves a loss ratio. The same arithmetic that bands a receipt also drives a circuit breaker: gate() in the insurability module trips on exactly the condition that reddens the receipt — σ below the 3.4 floor, or drift above the 5% ceiling — and halts the agent. No model decides it, so “we cut power above X% drift” is a warrantable term rather than a promise. An underwriter reads that as a fire-suppression system, not a smoke alarm: it is the difference between measuring the loss and truncating it, and it is the strongest argument for the coverage-condition mechanic on slide 12. And it creates a loss of its own that the wording must name: a false trip halts a paying customer's production agent, which is a business-interruption exposure caused by the safeguard rather than by the risk. Either it is covered or it is excluded — it cannot be unaddressed. The false-trip number, which an earlier version of this page owed, is now quoted rather than promised: replaying every priceable ledger row through the same gate() the breaker runs (breaker-backtest.mjs, deterministic, model-free) trips zero times across every priceable row — 156 rows at the quoted run, with the highest observed drift at 4.393% against the 5% ceiling and a Wilson 95% upper bound of 2.40% on the false-trip rate. Zero trips is the claim that has held on every run; the row count and the bound move with the live ledger, per the same rule slide 9 states for n. Stated with its two honest limits: the σ leg of the breaker is not covered by that ledger and is not faked, and zero trips on a corpus with zero true losses bounds the false-trip rate rather than demonstrating discrimination — which stays exactly where slide 9 puts it, in the month-4 external backtest.

The disciplined boundary, in one line: the receipt establishes where the work landed. It does not establish that the work was right. Every wording, every marketing page and every claims manual repeats that sentence, because the day we blur it is the day a plaintiff's counsel builds their case out of our own brochure.

08 · $20M OF WHAT · THE ARITHMETIC, DONE IN THE OPEN
what $20M means · the three lines · the ratio · what the number is not

Revenue, gross written premium, and run-rate are three different numbers. The naive plan in the notes reaches $1M, not $20M — and the gap is 20×, which is a distribution problem, not a product problem.

  • $12.1M of revenue on $10.5M of premium placed — and the $20M target is not met on this plan. An earlier draft summed GWP into revenue and was wrong by ~$8M; the correction is on the page.
  • Only the licence line can carry $20M — a million agent-years, ~100% margin, no reserve, bought with carrier signatures rather than a sales force.
  • $148.4M of aggregate limit behind $10.5M of premium, held by three to five deployers — correlated obligors, not a diversified book. That ratio is what a panel underwrites.
STRUCTURE · LICENCE FLOW08 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePART B · HOUSE INSTRUMENT LICENCEarm's length · published 2026-07$20 / agent-year10,000 attestations · $0.002 eachTHE INSURED DEPLOYERagents in market · holds the bagpoliciespremiumPARAMETRIC (placement trigger)CLAIMS (role breach · receipt = evidence)same receiptPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— The dashed line connects both halves of the board: the verifier and the insured check the same receipt. That shared object is what makes the revenue lines composable.

Start by killing the ambiguity. “$20M year one” can mean gross written premium, recognised revenue, or an exit run-rate, and the three differ by nearly an order of magnitude in what they demand. This deck commits to the hardest honest reading available in year one: $20M of booked revenue across three lines, with GWP and run-rate stated separately wherever they appear.

The three lines. L1 — licence: $20 × agent-years, ~100% margin, no capital required. L2 — premium: GWP written by the carrier, of which only the ceding commission and profit share are ours in an MGA structure. L3 — instrument fee: Part B per-attestation revenue from third parties who build their own instruments and never touch our paper.

Which answers the question a capital counterparty asks before any of the above: do we have to buy the risk to get paid? No. L1 needs no capital at all — no reserve, no underwriting decision, no claims exposure — and it is the only line that clears the target. L2 is a program MGA on fronting paper, where statutory capital required is effectively none: the fronting carrier takes a fee, the reinsurance panel takes the risk, and we take the underwriting authority, the data and the commission. The honest framing for the room is therefore not that we are raising money for a company, but that we are assembling counterparties for a trade. The meter does not need their capital; the books do. At the vehicle, most of the economics are cedable — 50 to 90 percent of each book, gladly. At the meter, none. Structure is not for sale; economics are negotiable.

And the property that makes appetite unbounded without making it reckless. Leverage here is only real to the extent it is backed by attested gate installs at deployers — which yields a sentence a catastrophe structure has never been able to say: the collateral improves with adoption. A hurricane's hazard is stationary; ours declines as installs spread, because every gated fleet both lowers the loss it can produce and adds to the corpus that prices it. That is why the paper can be written as unbounded on its face — and exactly why it must be drawn down only against heartbeat-attested fleets. The discipline, stated unprompted because it is what makes the big number believable: appetite unbounded on paper, bounded in fact by attested installs; every book priced at half the gate's modelled efficacy; tranches version-pinned; common-mode gate failure ceded to ILS rather than retained, since one gate defect is a single event across every insured and not a diversifiable book; nothing binds before the external probe. Capacity follows computability, drawn against installs — and the meter company never holds tail.

The number that has to be said out loud: the working plan in the source notes was 10,000 insured agents at roughly $100 each. That is $1M. It is 5% of the target. Getting to $20M requires either twenty times the agents or twenty times the price, and pretending otherwise is how a plan dies in month seven. So: which is it?

The worked shape, with the MGA correction applied. L1 = $6M from 300,000 agent-years, which is two carrier bundling agreements at 150,000 each — two signatures, not two hundred, and ~100% ours. L2 = $10.5M of GWP from 7,000 insured agents at $1,500 — roughly three to five enterprise deployers — of which about $2.6M is ours at a 25% ceding commission, before any profit share. L3 = $3.5M from one reinsurer or fund building a parametric product on the receipts.

Which gives one revenue number, and it is not the target. Booked revenue: $12.1M ($6M licence + $2.6M commission + $3.5M instrument fee). Premium volume placed alongside it: $10.5M of GWP — reported separately, as an exposure figure, never added to revenue. An earlier draft summed the two into a $20.0M “controlled volume” headline; that is a real MGA metric but putting it beside a revenue number invites exactly the confusion this slide is trying to end, so it is gone. Year one is $12.1M of revenue on $10.5M of premium placed, and the $20M target is not met on this plan. An earlier version of this slide summed L2 at full GWP into a “booked revenue” total, which was wrong by roughly $8M and contradicted the MGA economics stated two paragraphs above it. Naming that here rather than quietly repairing it, because a reader who catches an arithmetic error the deck did not own has stopped believing the rest of the arithmetic.

So what actually clears $20M of booked revenue? L1 does, and nothing else can. One million agent-years is $20M on its own, at roughly 100% margin, with no reserve, no underwriting decision and no claims exposure — and it is bought with a small number of carrier signatures rather than a sales force. The premium line will never carry a $20M revenue target in year one under MGA economics; it carries the evidence, which is what makes L1 and L3 buyable at scale. Read the plan accordingly: the carrier exists to prove the instrument; the licence line is what pays.

Read the next three paragraphs with this in front of them, not after them: every rate figure below is computed against this repository's own commit history, not against a book of insureds, and no credentialed actuary has signed it. It is a running rail, reproducible on your hardware today. It is not a rate. Slide 9 is what would have to happen for it to become one.

That said, the $1,500 is not a guess. It is the rail's own rate-on-line applied to a limit. Run calibration-premium.mjs against the live ledger and the lead lane returns a rate of 707.6 bps — the Wilson upper bound on breach frequency (6.3% at n = 180, 5 observed breach, as of 2026-08-13) loaded by volatility (drift std 1.15 against a 4.668% strike, λ = 0.5). At 707.6 bps, a $1,500 premium implies a per-agent limit of $21,198. Inverted: a $250,000 per-agent limit prices at $17,690, and $1M prices at $70,760.

And the correction that matters more than the number. This page quoted 278.7 bps from a 2026-07-30 run, when the ledger held zero breaches. It now holds 5. The upper bound widened, the rate rose to 707.6 bps — it more than doubled, and an earlier draft of this very sentence said “by roughly a third”, which was itself wrong — and every limit above moved with it. That is not an embarrassment to bury — it is the instrument doing the only thing that makes it worth anything: the rate got worse and said so on its own page. Which is also why these figures are now computed from a generated snapshot rather than typed: a hardcoded rate-on-line silently mis-states every limit beneath it, and this one did, for nine days.

Which surfaces the number a reinsurer will ask for before anything else on this page: 7,000 insured agents at a $21,198 limit is $148.4M of aggregate limit standing behind $10.5M of premium. That ratio — not the premium — is what the panel underwrites, and it is why the fronting and reinsurance seat on slide 14 is the second hire rather than the fifth.

And the ratio is worse than it looks, because the book is not diversified. Seven thousand agents held by three to five deployers is a handful of correlated obligors, not seven thousand independent ones. One bad model update, one prompt-template change, one upstream foundation-model revision propagates drift across an entire fleet simultaneously — the same accumulation that broke early cyber-cat pricing, where everybody modelled insureds as independent and a single shared vendor outage hit the whole book at once. A frequency model built on independent trials does not describe this exposure. Three things therefore have to be in the wording before the first policy binds: a per-agent sub-limit, a per-insured aggregate cap, and an event definition that treats a common-cause drift across one deployer's fleet as a single occurrence rather than as N. Clash cover on top of that is a reinsurance-panel conversation, not a wording one.

What is still owed to a credentialed signature: whether 707.6 bps survives calibration against losses that cost somebody money rather than against this repository's own drift, and whether 5 breach in 180 is a frequency or an anecdote. The earlier version of this line asked whether a ZERO-breach sample meant a well-behaved lane or a strike set too loose; the ledger has since answered half of it by recording one, which is a weaker-sounding and far more useful position — a zero-breach sample cannot produce a point estimate at all. Both are the Chief Actuary's first written verdict. Slide 9 is the method; slide 13 is the seat. The arithmetic is reproducible today; the judgement on it is not ours to sign.

09 · WHAT WOULD HAVE TO BE TRUE · FIVE CONDITIONS, EACH WITH A KILL CRITERION
five conditions · who owns each · when it is decided · what kills it

Five things must be true to exceed $20M in year one. Each one is falsifiable, has an owner, and has a date by which it is either true or the plan changes.

  • Four of the five conditions are commercial and regulatory. One is technical — and it is the one already shipped and guarded.
  • Day-one pricing is running code, not a plan: Wilson-bounded breach frequency, a 4.668% strike, and an ADVISORY-until-the-interval-tightens ratchet. Volume earns the number.
  • Every figure here is measured against our own repository, and the Wilson bound assumes an independence these observations do not have. Disclosed, because it changes what the number means.
STRUCTURE · LICENCE FLOW09 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePART B · HOUSE INSTRUMENT LICENCEarm's length · published 2026-07$20 / agent-year10,000 attestations · $0.002 eachTHE INSURED DEPLOYERagents in market · holds the bagpoliciespremiumPARAMETRIC (placement trigger)CLAIMS (role breach · receipt = evidence)same receiptPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— Same diagram. The conditions are read against the structure already drawn.

ONE — an actuary can price day one without a loss history. This one is further along than the notes assumed: the pricing rails are running code today. Three of them, all deterministic over the same ledger and the same drift number, all model-free. scripts/pmu/insurability.mjs turns a distribution into a premium in basis points — premium_bps = BASE × (1 + σ_load + drift_load) × confidence_mult, base 100 bps, uninsurable cap 400 bps, with a small-sample loading of 1 + 1/√n so thin evidence costs more, banded INSURABLE / LOADED / UNINSURABLE / NO_DATA. scripts/pmu/calibration-premium.mjs is the actuarial layer above it: the loss event is a drift excursion past a strike of 4.668%, the frequency is an empirical breach rate with a Wilson 95% interval, and the premium is priced off the conservative upper bound of that interval, loaded for semantic volatility.

The promotion ratchet is what makes day-one pricing honest. A lane stays ADVISORY — explicitly not priceable — until its breach-rate confidence interval tightens below a set half-width. Volume earns the number; nobody asserts it. That is the correct answer to “how do you price with no history”: you do not, you publish an interval that is too wide to trade on and let running volume narrow it. Today, over 564 ledger rows, the lead lane sits at n = 180, 5 breach, a Wilson upper bound of 6.3% and a CI half-width of 2.6% — through the ratchet, PRICED. These are a live reading, not a fixed figure: the ledger appends continuously and rows move in and out of the suspect set, so n drifts between runs (163 · 164 across two runs eight minutes apart on 2026-08-08). Quoting a frozen n would be the kind of false precision this page exists to avoid. The method is the claim, and you reproduce it by running the script. And the honesty gate is in the same code: 272 of those 564 rows are flagged ingest-suspect and excluded from pricing entirely — the suspect set is re-evaluated on every run and rows move both ways, so this count is as much a live reading as n — reported separately rather than quietly included. We do not price on a measurement we already suspect is an artifact. (n moves as the ledger grows; the figures above are read from a snapshot generated on 2026-08-13 and are reproducible by re-running the script.)

The statistical caveat that has to travel with the number, every time. A Wilson interval assumes independent trials. These are commit-level observations from one evolving codebase, produced by one team on one toolchain over time — serially correlated by construction, which means the true bound is wider than the stated 6.3% and the “conservative” premium is less conservative than it looks. A single breach at this sample size is a point estimate, not a frequency — it is enough to rule out the degenerate zero-breach case and nowhere near enough to distinguish a well-behaved lane from a strike set too loose. Under classical limited-fluctuation credibility this sample is nowhere near full credibility for a frequency process. None of this is a reason to hide the number; it is the reason the number is presented as a running rail rather than as a rate.

What remains genuinely open is calibration against losses that cost somebody money — our breach rate is measured against this repository's own work, not against a book of insureds. That is the retrospective backtest: run the rails over historical third-party failure corpora and show what the strike would have fired on. Kill criterion: if the backtest cannot separate loss events from non-events at a rate an external actuary will sign, the parametric line does not launch and this is a licence company. Owner: Chief Actuary. Date: month 4.

TWO — we can write binding cover without becoming a licensed carrier in year one. See slide 11. Kill criterion: no fronting agreement signed by month 6. Owner: Capital & Reinsurance. Date: month 6.

THREE — at least one carrier makes attestation a condition of cover, or bundles it into premium. This is the entire L1 line and it is two signatures. The three mechanics are already documented: coverage warranty, insurer-as-reseller at markup, and premium credit. Kill criterion: zero signed bundling or warranty agreements by month 9 means L1 reverts to direct sales and the target halves. Owner: Carrier Channel. Date: month 9.

FOUR — the receipt survives an adversarial audit. A third party attempting to forge, replay or induce a false placement must fail, and the failure must be demonstrable. The invariant is guarded today rather than asserted: receipt-is-llm-free (no model anywhere in the receipt path, reality read from the immutable commit rather than the working tree, same commit twice yields an identical panel), plus receipt-dual-witness, daemon-signed-receipts, auditor and insurance-anti-regression in the same suite. That guarantee has to hold under someone actively trying to break it, because once a policy pays on a receipt, a wrong receipt is not a bug — it is a claim, or a fraud. Kill criterion: any reproducible forgery that survives Part A-1 recomputation. Owner: Instrument Reliability. Date: month 5, then every release.

FIVE — the risk classifies cleanly for a regulator. Parametric tech risk, or an endorsement to cyber and tech E&O. This determines the domicile, the capital requirement and the wording, and it is the question we currently have the least evidence on. Kill criterion: no domicile with a workable path by month 6. Owner: Regulatory Counsel. Date: month 6.

Read the five together and the shape is unambiguous: four of the five are commercial and regulatory; one is technical, and it is the one already shipped and guarded. That is the real state of this company, and it is why the raise buys people and paper rather than engineering.

10 · WHAT WOULD DO EVEN MORE · THE LINE THAT NEEDS NO CARRIER OF OURS
the third line · why it needs no paper · why it is fenced · what is optional

The instrument-fee line has no underwriting cycle, no reserve, and no headcount ceiling — a third party can build the product and we still get paid.

  • Part B attaches to the act, not to our paper — a reinsurer building on the receipts is licensed activity with no reserve behind it.
  • The options rail already runs — a variance swap on the lane's realised drift, quoting live, and refusing to quote under twenty observations.
  • None of it is in the year-one number. Clearing and CFTC posture are unsolved, and code existing does not change that.
STRUCTURE · LICENCE FLOW10 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePART B · HOUSE INSTRUMENT LICENCEarm's length · published 2026-07$20 / agent-year10,000 attestations · $0.002 eachTHE INSURED DEPLOYERagents in market · holds the bagpoliciespremiumPARAMETRIC (placement trigger)CLAIMS (role breach · receipt = evidence)same receiptTHIRD-PARTY INSTRUMENTvariance swap · bond · reinsurancePART B · no carrier of ours requiredPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— A dashed gold line arcs from the Holding LLC past the carrier entirely, into a third-party instrument. Part B attaches to the act, not to our paper.

Everything to this point assumed we build the carrier. Part B does not. It attaches to the act of building or monetising a financial instrument on an attestation artifact of this form — irrespective of whether our carrier is involved at all. A reinsurer who writes parametric AI cover on the receipts next year, on their own paper with their own actuaries, is doing licensed activity, and it is revenue with no reserve behind it.

With the limit stated here rather than eleven slides later, because this is the line the limit actually bites. Where that counterparty takes a licence, Part B is a contract and it is enforceable as one. Where they instead fork the MIT runtime and never sign anything, there is no privity and the only remaining hook is patent claim scope — on an application that has not been granted. We do not model that second case as revenue, and no figure on this deck assumes it. The L3 line is built on counterparties who take a licence because the licence gets them something forking does not: indemnity, the maintained reef, a named key set the wording can point at, and a supplier a regulator recognises. That is a commercial reason to sign, not a legal claim to compel one — and the difference is the whole of slide 16's second open item.

Why this is the asymmetric line rather than a footnote. The carrier line is capacity-limited by capital, by underwriting throughput and by hiring. The instrument line is limited only by how many institutions decide the receipt is the settlement object. Its cost of goods is a signature. If the thesis is right at all, this line grows faster than the one we operate — and it is the line that makes the Holding LLC, rather than the carrier, the durable asset in the structure.

The options layer is further along than it sounds, and still fenced. Part B reserves options and swaps priced on the volatility of a placement coordinate — and a reference implementation runs today. scripts/pmu/variance-option.mjs prices a variance swap on a lane: the underlying is the realised semantic variance of the drift number, the fair strike is the historical mean of windowed realised variances, and vol-of-vol sets the bid/ask spread around it. Against the live ledger it currently quotes the lead lane at a fair variance strike of 0.921 with vol-of-vol 0.664 — bid 0.257, ask 1.585 — and refuses to quote lanes with fewer than twenty observations, returning INSUFFICIENT rather than a number. The insurance rail prices a put on staying in lane; this prices the volatility itself. One measurement, two instruments, by design: never invent a second underlying. And the settlement layer a third party would build against has a running on-chain reference implementation in the same repository — ReefAttestation.sol and InLanePolicy.sol, foundry-tested — fenced the same way the swap is fenced: a reference to build from, not a launched product.

Why it is still not in the $20M. A variance swap needs a realised variance two strangers can agree on without trusting each other, and that part is solved — the verdict recomputes identically for either party, and the scalar under it carries a published margin to the strike that no re-measure has ever crossed, which is precisely what an LLM confidence score can never offer. What is not solved is the market plumbing: a clearing counterparty, and depending on structure, SEC or CFTC engagement. It is not a year-one revenue line. Putting a traded secondary market in a year-one model is the fastest way to lose a serious insurance investor in the first ten minutes, and the code existing does not change that.

The other upside worth naming, and equally fenced: a small model trained natively against the coordinate geometry — sharper inside a narrow lane rather than broadly capable, and therefore cheaper to keep in lane. That is a research bet at a different capital scale. It is optionality created by this round, not a deliverable of it, and it is delegated rather than dropped.

Ranked by what it does to the company: L3 is the highest-margin line and the least capital-intensive; the carrier is what makes L3 credible by being the first institution to actually underwrite on the thing. Build the carrier to prove the instrument. Collect on the instrument for a long time after.

11 · THE STRUCTURAL CORRECTION · MGA FIRST, CARRIER SECOND
the wrong first shape · the right one · what it frees · the real failure mode

You do not need a certificate of authority to be in market in year one. Fronting paper collapses both the capital requirement and the timeline — and the carrier licence stops being a gate.

  • You do not need a certificate of authority to be in market. A program MGA writes on admitted paper, cedes to reinsurance, and needs no statutory surplus.
  • That moves capital out of regulator-held reserves and into the actuarial function, the regulatory path, the channel and instrument reliability.
  • MGAs die at renewal, not at signature — so a second fronting conversation runs in parallel and capacity is placed direct.
STRUCTURE · LICENCE FLOW11 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePART B · HOUSE INSTRUMENT LICENCEarm's length · published 2026-07$20 / agent-year10,000 attestations · $0.002 eachTHE INSURED DEPLOYERagents in market · holds the bagpoliciespremiumPARAMETRIC (placement trigger)CLAIMS (role breach · receipt = evidence)same receiptTHIRD-PARTY INSTRUMENTvariance swap · bond · reinsurancePART B · no carrier of ours requiredCAPITAL + FRONTING PAPERinvestors · fronting carrier · reinsurercapacity + surplusPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— Capital, fronting paper and reinsurance arrive on the left and feed the carrier box. The box does not have to be a licensed carrier for the arrow to work.

The source notes assume the year-one entity is a capitalised insurance carrier clearing state reserve requirements. That is the eventual shape, and it is the wrong first shape. Standing up a carrier means a domicile, a certificate of authority, statutory surplus, a filed rate and form, and a regulator's calendar — a multi-year path that consumes the raise before a single policy is written.

The standard structure for exactly this situation is a program MGA on fronting paper. A managing general agent underwrites on an admitted carrier's licence, cedes the risk to reinsurance, and earns a ceding commission plus profit share. Statutory capital required: effectively none. Time to market: months, not years. The fronting carrier takes a fee for the paper and keeps a small retention; the reinsurance panel takes the risk; we take the underwriting authority, the data, and the commission. Every meaningful insurtech of the last decade started here for the same reason.

What this does to the ask. It moves the capital from statutory reserves — a dead, regulator-held asset — to the four things that actually create enterprise value: the actuarial function, the regulatory path, the channel, and the instrument-reliability engineering. It also removes the single largest execution risk in the plan, which was never the technology; it was a founder with no insurance operating history attempting a de-novo carrier formation as step one.

And it changes what “$20M” costs to reach. Under MGA economics the L2 line contributes commission and profit share rather than full premium, which makes the L1 licence line and the L3 instrument line proportionally more important — and those are precisely the two lines that need signatures rather than surplus. The arithmetic on slide 8 is already built this way.

The failure mode is renewal, not signature — and this deck was gating on the wrong one. Every dated gate here reads “fronting agreement signed by month 6.” Signing is the easy half. MGAs die at month 30, when the fronting carrier's appetite shifts, or their regulator leans on the arrangement, or one drift-correlated loss quarter lands and the paper simply is not renewed — and a program with a single fronting relationship has no second door. The mitigants are structural and belong in the plan from the start: a second fronting conversation carried in parallel rather than after the first closes, a multi-year capacity commitment rather than an annual one, and reinsurance placed with the panel directly so the capacity relationship survives a change of paper. Concentration on one fronting counterparty is the largest single-point failure in this business, larger than any technical risk on these sixteen slides.

The carrier formation stays on the roadmap, funded by the program's own results and by a loss history that will by then exist. Own the paper when owning it is cheaper than renting it — which is year three, not year one.

12 · THE CHANNEL · THREE SIGNATURES, NOT THREE HUNDRED
who buys · why they enforce it · three mechanics · how it is sold

The insurer is the distribution engine, because the insurer holds ninety percent of the downside. We are not the ones who have to convince anybody.

  • The insurer holds the downside, so the insurer is the distribution engine — we are not the ones who have to convince anybody.
  • Three documented mechanics: coverage warranty, insurer-as-reseller at markup, and premium credit. The reseller path is the two-signature licence line.
  • Warranty enforceability is unopined — property and liability doctrine differ, and several states require a causal link before a condition can void cover.
STRUCTURE · LICENCE FLOW12 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePART B · HOUSE INSTRUMENT LICENCEarm's length · published 2026-07$20 / agent-year10,000 attestations · $0.002 eachTHE INSURED DEPLOYERagents in market · holds the bagpoliciespremiumPARAMETRIC (placement trigger)CLAIMS (role breach · receipt = evidence)same receiptTHIRD-PARTY INSTRUMENTvariance swap · bond · reinsurancePART B · no carrier of ours requiredCAPITAL + FRONTING PAPERinvestors · fronting carrier · reinsurercapacity + surplusPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— Same structure. The channel is a property of who already carries the loss, not of how hard we sell.

There is an obvious objection to the licence line: if risk transfer is working, the insurer carries most of the loss and the insured retains a slice — so why would the insured buy a safeguard whose benefit accrues mostly to the insurer? The resolution is that the insurer is exactly the party with the incentive to force or fund adoption, and there are three documented mechanics for it.

A — coverage condition (warranty), the primary. The policy requires covered agents to run attestation to keep cover in force; lapse voids coverage. This is the shape of a fire-alarm warranty in property cover — and the caveat belongs here, not eleven slides later: property and liability warranty doctrine differ, and a number of states will not permit denial for breach of a policy condition absent a causal link to the loss. Mechanic B rides on A being enforceable, so a state-by-state opinion gates both. What the mechanic gets right regardless is the incentive: the insurer enforces the standard of care because their exposure makes it their interest. Not us lecturing anyone.

B — insurer as reseller, the channel. The carrier buys agent-year units wholesale and bundles them into premium at a markup. This resolves who writes the cheque, gives us a business-to-business channel of a handful of carriers rather than thousands of enterprises, and aligns the incentive because the insurer now profits from adoption. This is the mechanic behind the $6M L1 line.

C — premium credit. The insured buys directly and the insurer grants a rate rebate proportional to attestation coverage — the telematics shape. This is the self-serve path for buyers who move before a carrier mandates anything, and it is live at checkout today.

A note on how this is sold, which is a standing rule and not a preference: the documentation states the facts — open source, deployable today, two-tenths of a cent per decision — and then stops. It does not tell a general counsel what a reasonable operator ought to conclude from a safeguard that is cheap, available and working. They are considerably better at that inference than we are, and they resent being walked through it.

13 · THE TEAM WE DO NOT HAVE · SEATS 1–4
the four seats · what each owns · the 90-day tell · what disqualifies

Today the team is one founder, a set of advisors, and the machines. Below is what the org must contain — written as job ads, because a role you cannot write an ad for is a role you have not actually specified.

  • Chief Actuary first, before any salesperson. The brief is to re-derive six inherited constants and write which were founder guesses.
  • Underwriting owns the wording; Claims owns adjudication; Instrument Reliability owns the guarantee that a receipt cannot be forged.
  • Each ad carries a falsifiable deliverable and a disqualifier — a role you cannot write an ad for is a role you have not specified.
STRUCTURE · LICENCE FLOW13 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePART B · HOUSE INSTRUMENT LICENCEarm's length · published 2026-07$20 / agent-year10,000 attestations · $0.002 eachTHE INSURED DEPLOYERagents in market · holds the bagpoliciespremiumPARAMETRIC (placement trigger)CLAIMS (role breach · receipt = evidence)same receiptTHIRD-PARTY INSTRUMENTvariance swap · bond · reinsurancePART B · no carrier of ours requiredCAPITAL + FRONTING PAPERinvestors · fronting carrier · reinsurercapacity + surplus1 CHIEF ACTUARY 2 UNDERWRITING3 CLAIMS DESIGN4 INSTRUMENT RELIABILITY5 CAPITAL + REINSURANCE 6 COUNSEL7 CARRIER CHANNELPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— Seven seat markers land on the entities. Each one sits on the box whose risk it owns.

These are written as ads rather than as a team slide on purpose. A team slide says where we are; an ad says what the gap is, what would close it, and how we would know within ninety days that the wrong person is in the seat. Every one carries a falsifiable deliverable — the same discipline the engineering side runs, where the deliverable is the guard, not the patch.

1 · CHIEF ACTUARYFCAS/FIA or equivalent · the first hire, before any salesperson

Why the seat exists — We are pricing a class with no third-party loss history. Every other seat is downstream of somebody credentialed being willing to sign a rate. This is the single largest gap in the company — and it is a person, not a model, because the model already exists and nobody with letters after their name has signed it.

First 90 days — Inherit the running rails rather than start blank: calibration-premium.mjs (Wilson-bounded breach frequency, 4.668% strike, volatility loading, ADVISORY-until-tight promotion ratchet) and insurability.mjs (100 bps base, 400 bps cap, σ 3.4 floor, 5% drift ceiling). Re-derive every one of those constants against external failure corpora, change the ones that are wrong, and own the result.

Falsifiable deliverable — A signed rate indication and a loss-cost model a reinsurer's actuary will review — by month 4 — with an explicit written verdict on which of the six inherited constants survive calibration and which were founder guesses. If it cannot be produced, the parametric line does not launch.

Comp shape — Below-market cash, meaningful equity, and named authority over pricing. This person must be able to say no to the founder in writing.

Disqualifier — Anyone who wants to wait for three years of credible loss data. That data does not exist and will not exist; the backtest is the substitute and it is either defensible or the plan is wrong.

2 · HEAD OF UNDERWRITING & PRODUCTspecialty / parametric background

Why the seat exists — Someone has to turn a placement coordinate into a policy wording that survives a coverage dispute. The trigger definition, the exclusions, and the tolerance are the product.

First 90 days — Draft both wordings — parametric and claims. Define the trigger index precisely enough that both sides compute it identically. Name the exclusions honestly, including the ones that make the product smaller.

Falsifiable deliverable — Two filed-ready wordings reviewed by external coverage counsel, with the basis-risk disclosure explicit — by month 5.

Comp shape — Market cash, equity, profit-share participation on the book they write.

Disqualifier — A wording that implies the receipt determines whether the agent was correct. That sentence is how we lose the first big claim.

3 · HEAD OF CLAIMS & ADJUDICATION DESIGNpart-time or fractional in year one

Why the seat exists — The claims line is the one a Chief Risk Officer actually buys, and it is the one that can quietly destroy the loss ratio if adjudication is undefined. The parametric line pays itself; this one does not.

First 90 days — Write the adjudication protocol: what the receipt establishes, what still requires an adjuster, what escalates, and what the appeal path is when the insured disputes a placement.

Falsifiable deliverable — A claims manual that a third-party adjuster can execute without calling us — by month 7.

Comp shape — Fractional retainer converting to full-time at first claim volume.

Disqualifier — Anyone who proposes fully automated adjudication for the non-parametric line. That is a smart-contract fantasy and it will not survive a regulator or a plaintiff.

4 · PRINCIPAL ENGINEER, INSTRUMENT RELIABILITYsystems / security, adversarial mindset

Why the seat exists — Once a policy pays on a receipt, a wrong receipt is not a bug — it is a claim, or a fraud. This seat owns the guarantee that the receipt path stays deterministic and model-free under someone actively trying to break it.

First 90 days — Stand up an adversarial audit programme against forgery, replay and induced-placement attacks. Extend the existing guard suite so that every attack class found becomes a permanent red test.

Falsifiable deliverable — A published adversarial audit with the attack classes attempted, and a guard test in the suite for each one — by month 5, then re-run every release.

Comp shape — Senior engineering market, equity.

Disqualifier — Someone who wants to put a model in the receipt path to make it smarter. The determinism is the asset; there is a specific incident behind this rule.

14 · THE TEAM WE DO NOT HAVE · SEATS 5–7
capital, counsel, channel · what the founder keeps · what he gives up · the cap table

Capital, counsel, channel. The three seats that decide whether the instrument ever gets used at scale — none of which the founder can hold.

  • Capital & Reinsurance is the second hire — the fronting agreement is what makes year one exist at all.
  • The founder gives up pricing, wording, claims — and the front line. An author negotiating what his own measurement is worth has made the arm's-length structure decoration.
  • The round participates in Part B economics, and a stewarded structure is the end state — triggered by the second unaffiliated licensee. Economics negotiable; structure not for sale.
STRUCTURE · LICENCE FLOW14 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePART B · HOUSE INSTRUMENT LICENCEarm's length · published 2026-07$20 / agent-year10,000 attestations · $0.002 eachTHE INSURED DEPLOYERagents in market · holds the bagpoliciespremiumPARAMETRIC (placement trigger)CLAIMS (role breach · receipt = evidence)same receiptTHIRD-PARTY INSTRUMENTvariance swap · bond · reinsurancePART B · no carrier of ours requiredCAPITAL + FRONTING PAPERinvestors · fronting carrier · reinsurercapacity + surplus1 CHIEF ACTUARY 2 UNDERWRITING3 CLAIMS DESIGN4 INSTRUMENT RELIABILITY5 CAPITAL + REINSURANCE 6 COUNSEL7 CARRIER CHANNELPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— The remaining markers land on the capital box and the channel edge.

5 · HEAD OF CAPITAL & REINSURANCEbroker or carrier ceded-re background · the second hire

Why the seat exists — The fronting agreement and the reinsurance panel are what let us be in market in year one at all. This person is the reason slide 11 is a plan rather than an idea.

First 90 days — Secure fronting paper. Assemble a reinsurance panel willing to look at the backtest. Own the relationship with the reinsurer's actuary alongside the Chief Actuary.

Falsifiable deliverable — A signed fronting agreement and at least one reinsurer engaged on the backtest — by month 6. This is condition two on slide 9 and it is the hardest date in the plan.

Comp shape — Market cash, equity, success fee on bound capacity.

Disqualifier — A pure relationship broker with no technical patience. This panel will ask how the trigger computes, and the answer cannot be 'I'll introduce you to Elias'.

6 · REGULATORY COUNSEL / CHIEF COMPLIANCEfractional to start, in-house by month 9

Why the seat exists — Classification decides everything downstream: parametric tech risk versus a cyber and tech E&O endorsement changes the domicile, the capital, the wording and the filing path. It is also the area where we currently have the least evidence.

First 90 days — Produce the classification opinion and the domicile recommendation with the capital implication of each. Review the Part A / Part B structure for arm's-length sufficiency and tell us where it is weak.

Falsifiable deliverable — A written domicile and classification recommendation with a filing path — by month 6. Plus an independent read on whether the published licence terms hold up as arm's length.

Comp shape — Fractional retainer, converting.

Disqualifier — Counsel who has only ever done technology licensing. This is an insurance regulatory question wearing a software costume.

7 · HEAD OF CARRIER CHANNELnot a salesperson — a partnership operator

Why the seat exists — The entire L1 licence line is two or three carrier signatures. This is a small number of long, technical, senior conversations — the opposite of a commission sales motion, and the source notes' bottom-up commission team is the wrong instrument for it.

First 90 days — Convert the existing broker relationships into a carrier bundling or warranty pilot. Build the enablement material that lets a carrier's own people explain the trigger to their own underwriters without us in the room.

Falsifiable deliverable — One signed bundling or warranty agreement — by month 9. Not a pilot conversation; a signature with agent-year volume attached.

Comp shape — Market cash, equity, override on bundled volume.

Disqualifier — Anyone whose plan is a large outbound sequence. Three hundred enterprise conversations is the failure mode this seat exists to avoid.

What the founder keeps, and what he must give up. Keeps: the instrument, the patent application, the Holding LLC, and the architecture — the pricing rails, the calibration, the reef, the licence. Gives up: pricing authority, wording authority, and the claims decision. An IP-holding founder who also signs the rate has recreated exactly the dependency this whole structure exists to eliminate, and the first sophisticated diligence question will find it.

And gives up one more thing that is easy to miss: the front line. A founder who ends up running technical sales calls has abandoned the position the deck is built on. The independence argument works because the author of the measurement is not the person negotiating what it is worth to a buyer — the moment he is on the phone discounting it, the arm's-length structure is decoration. Capital acquisition runs through an engaged fundraising partner; bottom-up distribution runs through reps trained against the public documentation; seat 7 is a partnership operator, not a founder's proxy. The founder appears in exactly two rooms: the technical diligence a reinsurer's actuary runs on the rails, and the architecture conversation a regulator wants. Both are places where being the author is an asset. Neither is a sales call.

Hiring order is not negotiable: Chief Actuary, then Capital & Reinsurance, then Carrier Channel, then Underwriting, then Instrument Reliability, then Counsel fractionally throughout, then Claims. Actuary before salesperson — a salesperson with nothing signable to sell burns the pipeline we cannot rebuild. One correction to that order: claims is listed last as a hire, not as a capability. A third-party administrator arrangement and claim-audit rights are negotiated alongside the fronting agreement in month 6, because no fronting carrier lends paper to a program that sells a claims product with no claims function. The seat is late; the capability is not.

THE CAP-TABLE QUESTION · ANSWERED, BECAUSE IT IS THE FIRST ONE ASKED

Slide 10 says the instrument-fee line is what makes the Holding LLC, rather than the carrier, the durable asset. An investor funding the carrier is entitled to finish that sentence out loud: then why am I capitalising the proof vehicle while the compounding asset stays personal? It is the strongest objection to this structure and it deserves an answer on the page rather than in a follow-up call.

The first half of the answer is that the merger version destroys the asset — and the reason is a conflict rule, though not the one we reached for first. Earlier versions of this slide called it “the Sarbanes–Oxley shape” and said the analogy was exact. It is not, and the correction belongs on the page: SOX governs what a registered accounting firm may sell to the public company it audits, and it stands up an oversight board over that profession. It says nothing about who must own a measurement provider, and it would not have been violated by a merger here. The doctrine that actually reaches this is the credit-rating conflict regime — the issuer-pays problem the ratings agencies were rebuilt around after 2008 — and even that permits one parent with firewalls rather than mandating separation. So the honest claim is narrower and it is commercial, not statutory: the counterparties who have to accept this trigger will not accept one owned by the party whose book they are backing. A reinsurer's own conflicts committee kills it in a single meeting. That is a market fact rather than a statute, and it is sufficient on its own.

The second half is that independence, not ownership, is what has to be protected — so the Holding LLC is constrained like a licensing authority rather than run like a founder's royalty vehicle. Published terms. The same price to every licensee, including a carrier competing directly with ours. No preferential rate, no exclusivity, no field-of-use carve-out for our own paper. The irrevocable verification grant already prevents us from switching anyone's ability to check off. Those constraints are what make the entity credible to a regulator, and they are worth more than the discretion they give up.

Which raises the sharper version of the question, and it deserves the sharper answer: why not a foundation? A trust or foundation stewarding the IP would satisfy the independence requirement and remove the objection that the durable asset is personally concentrated — and the observation is correct that audit methodology at a large firm is partnership-owned, not a personal royalty running to one engagement partner. So: a stewarded structure is the intended end state, and this deck commits to the direction rather than pretending the question is unfair. What it does not do is convert on day one, for a reason worth stating plainly — a standards body with no standard yet is a governance costume. The sequence that actually works is: prove the instrument, get a first carrier and a first reinsurer to rely on it, and convert to a stewarded entity at the point where there is something to steward and counterparties with standing to sit on it. The honest trigger is the second unaffiliated Part B licensee — at that moment it is a standard rather than a company's asset, and it should be governed like one. Founder economics survive the conversion as a royalty; founder control does not, and should not.

What the round gets is economics, and the round should have them. Carrier equity, plus a defined participation in Part B instrument-licence revenue — a perpetual royalty share running with the shares, or a direct minority economic interest in the Holding LLC. The capital that proves the instrument participates in the instrument. What the round does not get, and what no funder can be sold, is control of the measurement, because a measurement controlled by anyone with a position in the outcome stops being one. Economics: negotiable, and generous. Structure: not for sale.

Four terms, so this is a position rather than a posture. (1) The Part B participation is a stated percentage in the term sheet, not a promise of one — transferable with the shares and anti-dilution protected against later issuance to a co-maintainer or steward. (2) Because that participation is a claim on an ungranted application whose reserved-act language faces a real §101 question, it carries a step-down or renegotiation trigger tied to what the claims actually issue as. Pricing that contingency is more honest than arguing it away. (3) A strategic investor from the carrier or reinsurance side takes it passive — economic interest, information rights, no board seat, no vote, no input on the lattice, the strike or the cap — because a reinsurer with governance over the trigger it prices against has recreated the conflict this whole slide exists to prevent, one layer removed. (4) Audited Holding LLC financials to participants, not just carrier financials. And the line about other capital on slide 15 is a description of who the structure fits, not evidence that anyone has signed — by this deck's own rule, a claim without a file behind it is not a claim, and no alternative-capital conversation is named because none is yet at terms.

15 · USE OF PROCEEDS · AND THE GATES THAT SAY WE WERE WRONG
where the money goes · the gates · who funds this · what already exists

The money buys people, paper and a channel. It does not buy engineering, because the engineering is shipped, published and priced.

  • It buys people, paper and a channel. It does not buy engineering — that is shipped, published and priced.
  • Reinsurers, brokers, deployers and licensees want the separation; a venture fund is the one buyer for whom it reads as a defect. No alternative conversation is yet at terms.
  • Three dated gates, each with a pre-agreed consequence — a rate by month 4, paper by month 6, one bundling agreement by month 9.
STRUCTURE · LICENCE FLOW15 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePART B · HOUSE INSTRUMENT LICENCEarm's length · published 2026-07$20 / agent-year10,000 attestations · $0.002 eachTHE INSURED DEPLOYERagents in market · holds the bagpoliciespremiumPARAMETRIC (placement trigger)CLAIMS (role breach · receipt = evidence)same receiptTHIRD-PARTY INSTRUMENTvariance swap · bond · reinsurancePART B · no carrier of ours requiredCAPITAL + FRONTING PAPERinvestors · fronting carrier · reinsurercapacity + surplus1 CHIEF ACTUARY 2 UNDERWRITING3 CLAIMS DESIGN4 INSTRUMENT RELIABILITY5 CAPITAL + REINSURANCE 6 COUNSEL7 CARRIER CHANNELPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— The structure is complete. The remaining question is what the capital does to it.

Who funds this is a wider set than a venture round, and the structure is why. A venture fund is one buyer of this security and the only one for whom the separated IP entity reads as a defect. Everyone else on the list wants it separated, because they are counterparties to the measurement rather than owners of it. Reinsurers and carriers want a trigger that is demonstrably not controlled by the MGA whose book they are backing — strategic capital from that side arrives because of the structure, not despite it. Brokers want placement and distribution economics on a product their clients are already asking for. Deployers — the enterprises that cannot ship an agent without cover — have balance-sheet reasons to fund the thing that unblocks them. Family offices and individual operators who have carried this liability personally tend to understand it in one conversation, where a generalist fund needs five. And licensees themselves are the cheapest capital in the stack: a Part B licence fee is revenue, not dilution.

Which changes what the raise has to do. The licence line is ~100% margin and needs no reserve, so every dollar of L1 and L3 is a dollar of equity not sold. The realistic shape is a modest priced round alongside strategic capital and licence revenue — not a single venture cheque that has to carry the whole plan and therefore gets to dictate the structure. The company is closer to fundable-by-customers than a venture-scale burn narrative would suggest, and that is a position worth protecting rather than trading away in the first term sheet.

Where it goes. Roughly: the actuarial function and the backtest; the capital and reinsurance seat plus the fronting fee; regulatory counsel and the domicile path; the carrier channel; instrument-reliability engineering and the adversarial audit; and a working-capital buffer. Notably absent: statutory reserves, which the MGA structure defers, and product engineering, which is done.

The gates. Month 4 — a signed rate indication exists, or the parametric line is cut and we are a licence company. Month 6 — fronting paper is signed and a domicile path is written, or we are not in market this year and the plan resets to L1 and L3 only. Month 9 — one carrier bundling agreement is signed, or the L1 line reverts to direct sales and the target halves. Each gate has a named owner from slides 13 and 14 and a pre-agreed consequence, decided now rather than argued about later.

THE PROPOSAL WE WILL SIGN · TERMS STATED BEFORE ANYONE DRAFTS AGAINST THEM

The ask is $5M, and it is priced for speed. The MGA path removed the expensive item — no statutory surplus — so what remains is people and paper, and $5M covers the list above. (That is the size of the ask; it is not a claim about any state's reserve requirement, which stays exactly where slide 16 leaves it — unsourced claims do not go on slides.) The round is sized to close in weeks, and between two proposals, the faster close on the published structure beats the larger number that wants to renegotiate it. Strategic capital and operators who understand the liability in one conversation are the preferred counterparty, and that preference is a stated term, not a mood.

One — the carrier's licence is non-exclusive, forever, and that is a feature. No cheque buys exclusivity, because exclusivity would recreate the dependency this structure exists to eliminate. It is also why nobody needs to fight over control of the carrier: a stalled or captured carrier gets routed around by licensing a second MGA on the same published terms. The independence argument and the founder's walk-away power are the same clause.

Two — change-of-control reversion (drafting instruction to counsel, stated here so it surprises nobody). If the carrier is acquired or captured by a party that moves against the structure — bringing the measurement in-house, conditioning verification, breaching arm's-length terms — the House Instrument Licence terminates for that licensee. Published as intent now, before any negotiation, rather than produced as a demand during one.

Three — the gates become tranches, and a missed gate opens a repurchase option. Proposals are welcome to tranche capital against the month-4/6/9 gates — they were self-imposed, so tranching against them concedes nothing. The reverse side travels with it: if the plan resets and investors want out, the founder side holds an option to repurchase the carrier's brand and renewal rights at a formula set at closing, not negotiated at exit. And because the ledger is public and recomputable, a wound-down carrier cannot strand the loss history — the year-one evidence accrues to the measurement, not to the paper.

Four — protective votes, not operating control. The founder gives up pricing, wording and the claims decision — slide 14 already commits to that. What he keeps is a board seat and a protective vote on exactly three matters: any change to the licence relationship, any attempt to bring the measurement in-house, and any claims-manual change that blurs the where/whether line. Narrow enough that no investor reads founder-control risk; wide enough that the three ways the structure dies all require his signature. Economics: negotiable, and generous. Structure: not for sale.

What we already have, stated flatly so the diligence is short: the instrument published and installable by anyone at 2.40.0; the licence structure published and dated, including the irrevocable verification grant; the unit priced and live at checkout; the cap derived from the lattice rather than chosen; 3,257 signed receipts already issued against our own commits; three deterministic pricing rails running over that ledger — the premium band, the Wilson-bounded actuarial calibration with its ADVISORY promotion ratchet, and the variance-swap quote — plus the on-chain anchor and in-lane policy contracts alongside them; the whole receipt path guarded as model-free and deterministic by named tests; and the patent application filed, Track One, thirty-six claims, priority reaching back to April 2025.

What we do not have, stated equally flatly: an actuary willing to sign, paper to write on, a carrier channel, and a loss history against third-party money. The raise buys the first three. The fourth is what year one produces, and it is the asset nobody can shortcut — which is why being early to it is the whole position.

The one-sentence version of the whole structure: the measurement is open so that it can be checked by people who do not trust us, and the instrument built on top of it is licensed because that is the part with the economics — and those two facts are not in tension, they are the same fact seen from either side of the underwriting desk.

THREE LINES · ONE INSTRUMENT
The measurement is free.
The policy is underwritten.
The instrument is licensed.
16 · WHAT WE WILL NOT SAY · THE CLAIMS A HOSTILE DILIGENCE READ WOULD KILL
what we cut · what survives · what stays open · what the refusal buys

Every line below appears somewhere in the source notes. None of them survives a serious read, and each one is replaced with the version that does.

  • Every killed line came from our own notes — “software can never,” “competitors locked out,” “we print the money.” Each is replaced with the version that survives.
  • Three exposures stay open rather than answered: warranty enforceability, Part B against non-signatories, and the antitrust scope of the oracle clause.
  • The receipt establishes where the work landed, not that it was right. The refusal is the credibility — and it keeps our own brochure out of the exhibit list.
STRUCTURE · LICENCE FLOW16 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPART A · MIT · freeNOT OWNED BY THE AUDITEDANY VERIFIERregulator · reinsurer · insuredA-1 · recompute · irrevocablePART B · HOUSE INSTRUMENT LICENCEarm's length · published 2026-07$20 / agent-year10,000 attestations · $0.002 eachTHE INSURED DEPLOYERagents in market · holds the bagpoliciespremiumPARAMETRIC (placement trigger)CLAIMS (role breach · receipt = evidence)same receiptTHIRD-PARTY INSTRUMENTvariance swap · bond · reinsurancePART B · no carrier of ours requiredCAPITAL + FRONTING PAPERinvestors · fronting carrier · reinsurercapacity + surplus1 CHIEF ACTUARY 2 UNDERWRITING3 CLAIMS DESIGN4 INSTRUMENT RELIABILITY5 CAPITAL + REINSURANCE 6 COUNSEL7 CARRIER CHANNELPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714

— The last slide is the one that makes the other fifteen credible. A deck without this section is a deck that has not been checked.

“Software can never do this.” → Replace with the grounding argument: a monitor that shares a failure domain with the monitored system cannot be an independent witness to it, which is why independence has to come from structure rather than from cleverness. Never argue deterministic versus probabilistic; argue about who can check the answer.

“Competitors are permanently locked out” / “we become the mandatory clearinghouse.” → Cut entirely. It is unprovable, and in front of the wrong counsel it is an antitrust prompt. The defensible version is narrow and factual: a patent with an early priority date, a published licence, and a first-mover position with the underwriters.

“Everyone who does not use this is negligent.” → Never said, by anyone, in any outbound material. State that the safeguard is open, deployable and costs two-tenths of a cent per decision, and stop. Counsel reaches their own verdict, and they reach it faster when nobody is pushing.

“There is no black market for insurance.” → Overstated. Unlicensed and offshore capacity exists. The accurate version: insurance is a licensed activity, and a regulated buyer cannot satisfy a compliance obligation with unlicensed capacity.

“Operating margins well above fifty percent.” → Not a carrier metric and not one we can support. The licence line is high margin because hosting is free; the underwriting line is measured by combined ratio, and we have no loss data with which to project one. Say that.

“$5M clears state capital reserve requirements.” → Unsourced. Reserve requirements vary by domicile and by line, and they are the counsel deliverable on slide 14. A number without a file behind it does not go on a slide.

The $1.2B figure is the exception that proves the rule, and it stays. It is not an assertion about the size of anything — it is a self-selection threshold, asked as a question: are you carrying unhedged operational AI liability north of $1.2 billion? Then stop talking. The number is oddly specific on purpose; round numbers get a round answer, and this one makes the reader check their own book instead of ours. It needs no citation because it claims nothing. It also reconciles against the rail: at the 1% rate-on-line the model doc assumes, a $1.2B limit is $12M of premium — and at the rail's live 707.6 bps it is considerably more, which is the conversation we want to be having.

A second patent number for cache-miss feedback. → It appears in the notes and could not be verified in our own records. One filing is cited on this deck: US 19/637,714. Citing an application number that a diligence lawyer cannot pull is the cheapest possible way to lose the room.

“The receipt proves the agent did the right thing.” → The receipt establishes where the work landed, decidably and re-runnably. Whether it was right is undecidable and we say so in the licence, in the wording and on this slide. The refusal is the credibility; it is also, quite practically, the sentence that keeps our own brochure out of the plaintiff's exhibit list.

Three things this slide could not resolve, listed because leaving them off would be the same failure the slide exists to prevent. They are open counsel items, not answered ones.

Warranty enforceability. Slide 12 calls the coverage-condition mechanic “the ordinary shape of a fire-alarm warranty in property cover.” Property and liability warranty doctrine are not the same body of law, and a number of states will not permit denial for breach of a policy condition absent a causal link between the breach and the loss. Mechanic B rides on mechanic A being enforceable, so if A does not survive a state-by-state read, the licence channel narrows with it. Opinion required before either mechanic is described as live anywhere.

Part B against a party who never signed anything. Part A grants the software unconditionally and irrevocably. Part B reserves one commercial use of the output. Against a licensee there is a contract; against a stranger who forks the MIT code and starts underwriting there is no privity, and the only hook is patent claim scope — on an application that has not been granted. Reserved-act language of the form “originate, price, underwrite… any financial instrument” is exactly the shape that draws an Alice v. CLS Bank §101 challenge, which is why the house rule is to claim the machine and not the method. Do not represent Part B as enforceable against non-signatories until counsel says the claims reach it.

Scope of “whose oracle it is, is immaterial.” Read narrowly it is a sensible severability clause. Read broadly it reaches a whole category of downstream product regardless of who built the measuring instrument — which is the same work the “mandatory clearinghouse” slogan was cut for doing, in legalese instead of marketing. Patent misuse doctrine exists for that pattern. Antitrust review before this clause is relied on commercially.

General solicitation. This deck is a public URL. If it is circulating while a raise is live, that is general solicitation of an unregistered offering, and a “not an offer” legend at the bottom of a page does not cure conduct — the fix is a Reg D 506(c) posture with verified accredited investors, or the page comes down for the duration. Naming family offices and individuals as a capital class on slide 15 makes this sharper, not softer. Unresolved; counsel gate before the round opens.

Corporate opportunity. A founder who personally retains the highest-margin line while raising outside capital for the lower-margin vehicle is standing exactly where Delaware's corporate-opportunity doctrine looks — Guth v. Loft and its descendants. The published, non-discriminatory, pre-dated licence terms are a genuinely strong answer for the $20 rate, because they were fixed before any counterparty existed and are identical for everyone. They are not an answer for the bespoke Part B participation negotiated with the round, which is an affiliate transaction and should be blessed the way affiliate transactions are blessed: an independent committee, or a fairness opinion, or disinterested approval. Not yet done. It should be done before the term sheet, not after.

Two smaller corrections applied in this version. “Statutory capital required: effectively none” on slide 11 overstates it — MGA licensing, appointments, E&O and bonding are real costs, and state scrutiny of fronting arrangements is rising; the accurate claim is that the MGA path avoids statutory surplus, not that it is free. And the dated gates on slide 9 are planning gates, not covenants: a missed gate changes the plan, it does not breach anything.

Paths named and deliberately not taken in year one: the traded secondary market in policy bonds and options; de-novo carrier formation as step one; a commission-based bottom-up sales force; and the geometry-native small model. Each is real, each is delegated with its own owner rather than dropped, and none of them is in the $20M.

Run the demo before the meeting. Bring the actuary you trust most. The only thing this deck asks you to take on faith is that we will keep refusing to claim the undecidable half — and that refusal is written into a licence we already published and cannot withdraw.

STRUCTURE · LICENCE FLOW01 / 16
THE INSTRUMENT IS OPEN. THE INSTRUMENT LAYER IS LICENSED.IP HOLDING LLCUS 19/637,714 — never operatesTHE OPEN INSTRUMENTMIT · Part A · npm thetacog-mcpTHE CARRIER (NewCo)the raise · writes the policiesPart A grants the software. Part A-1 grants verification, irrevocably.Part B reserves the instrument. The carrier is a licensee, not an owner.packages/thetacog-mcp/LICENSE · US 19/637,714
ThetaDriven Inc. · Elias Moosman · elias@thetadriven.com
Patent PENDING — US application 19/637,714 (36 claims, Track One, filed Apr 2, 2026; not yet granted) · dual licence: MIT Part A + irrevocable verification grant A-1 / reserved instrument layer Part B
Not an offer. This page is for information and discussion only. It is not an offer to sell or a solicitation to buy any security, and it is not insurance advice or a binding indication of coverage or price. It contains forward-looking statements — revenue shapes, hiring plans, dated gates — that are estimates and assumptions, not commitments; actual results will differ. Rate figures are computed from the company's own operating data, have not been reviewed or signed by a credentialed actuary, and are not rates. Patent status is PENDING; no claim has been granted. Licence terms summarised here are plain-language descriptions of intent, not legal advice.

Every number on this page traces to a file: packages/thetacog-mcp/LICENSE (Part A / A-1 / B, the unit) · docs/gtm/2026-07-15-agent-year-license-and-risk-transfer.md (cap derivation, risk-transfer mechanics) · scripts/pmu/insurability.mjs (premium bands, breaker) · scripts/pmu/calibration-premium.mjs (breach frequency, strike, promotion ratchet) · scripts/pmu/breaker-backtest.mjs (false-trip replay) · scripts/pmu/variance-option.mjs (variance swap) · contracts/ (ReefAttestation, InLanePolicy) · docs/strategy/underwriter-ecosystem-spec.md · public/commit/ (issued receipts). Live rail outputs quoted here were run on 2026-07-30 and will move as the ledger grows. Scenario inputs are labelled as such and are the Chief Actuary's deliverable, not forecasts. Companion: /deck/8.