LP-1 · v1 · status: published

LP-1 · Disclosures and limitations — the claim, and the claims we refuse

ThetaDriven Inc. — the standing disclosure block for every outward artifact that names the attestation runtime

v1 · 2026-09-10 · Author: Elias Moosman · elias@thetadriven.com NOT LEGAL ADVICE. NOT AN OFFER OF ANY KIND. This document is the set of statements we are willing to stand behind in front of a hostile diligence read, and the set we refuse to make. It is written to be attached, not paraphrased. Where an artifact — a deck, a clause, a landing page, a paper — makes a claim about the runtime, that claim is bounded by this document, and where the two conflict, this document governs.

Companion documents: docs/legal/continuous-standard-of-care-reference-standard.md (what a conforming implementation does) · docs/legal/endorsement-cy-2026-det-continuous-state-verification.md (the specimen policy endorsement) · docs/legal/agent-year-license-terms.md (the commercial terms) · docs/legal/broker-warranty-clause-draft.md (the E&O / operational-risk binder clause).


1. The one claim, stated exactly

We produce a record of where a unit of agent work landed relative to a scope that was declared before that work ran, and that record recomputes to the same result on anybody else's machine.

That is the whole claim. Two properties, both checkable by the reader rather than asserted by us:

1.1 Placement. A unit of work (a commit, a completed task, a discrete decision) is projected onto a fixed 144×144 lattice of declared operational categories. The coordinate it lands on is a deterministic function of the sealed inputs.

1.2 Reproducibility. Re-executing the recorded inputs yields a matching attestation — shape- identical: same structure, same coordinate, same verdict. Anyone holding the inputs can reach the same result without our participation, our servers, or our consent (npx thetacog-mcp prove-rice --check; exit 0 = reproduced).

You don't have to take our word for it — the check is in the previous sentence, and it runs on your hardware, free, before any commercial conversation.

2. What we expressly do not claim

2.1 We do not claim the agent's decision was correct, safe, or non-negligent. That question is undecidable in the general case — Rice's theorem (H. G. Rice, Classes of Recursively Enumerable Sets and Their Decision Problems, Trans. AMS 74:358, 1953). We say so publicly, in the product output itself, and no clause in any of our documents should be read to imply otherwise.

2.2 We do not prevent anything. The runtime is an out-of-band verifier. It observes, places, and — where configured — fires a corrective pass. It does not sit in the execution path, does not block, does not halt, and does not gate. Any description of our function as prevention, containment, blocking, enforcement-in-line, or a "circuit breaker" is wrong and we will correct it. What we guarantee is that a deviation is detected, placed, priced and dispatched — never that it is prevented.

2.3 We do not guarantee behaviour. No configuration of the runtime makes an agent behave. A customer who buys expecting behavioural assurance is buying the wrong instrument.

2.4 We do not certify anyone. We do not operate an approved-vendor list, confer a credential, accredit an implementation, or hold any authority delegated by a government or standards body. A Schedule in somebody's policy may name a runtime; that naming is the insurer's act, not ours.

2.5 We are not an insurer, reinsurer, MGA, broker, or producer. We do not underwrite, bind, place, solicit, adjust, or bear risk, and we take no share of premium. We supply a technical specification and a runtime. We sell the signal; somebody else sells the policy.

2.6 We do not assert that any person or company not using this is negligent. Whether a particular precaution is legally required is a question for a court on a particular record, and saying otherwise in a sales context is both wrong and counterproductive — see §6.

3. Measured limits we publish because they are unflattering

3.1 Placement miss rate ≈ 30% on adversarially-reworded out-of-lane actions, presently observed. This is a measurement, not a marketing number, and it is the number a hostile expert would find anyway.

3.2 Fleet burn-rate sample size is n = 1 (our own repository). Every capacity or meter figure derived from it carries that caveat until licensees come online and we publish the distribution.

3.3 The apparatus/product boundary. The grounding argument for spatial positional determinism climbs four rungs: (1) lattice positions are addresses; (2) a dependent load's latency is observable from userspace; (3) the boundary-crossing cost is measured and reported as a median with its [min,max] spread, printing NOT ADMISSIBLE when the control band fails; (4) the raw performance-counter / MSR read is apparatus scope — privileged, platform-gated, used in the lab. Rung 4 is never presented as a shipped default capability, and any artifact of ours that does so is in error and superseded by this paragraph.

3.4 A receipt is a lossy projection and we say so. Placing work on a 144-cell lattice discards information by construction. The projection is sufficient for "where did this land relative to the declared scope"; it is not sufficient for "was this work any good." Every surface we publish is required to state both halves.

4. Legal status of these documents

4.1 Not legal advice; no attorney-client relationship. Every clause, endorsement, warranty and schedule item we circulate is a specimen — drafting material so a wording team has something concrete to react to rather than a blank page. It has not been settled by counsel, is not jurisdiction-tested, and must be reviewed by the recipient's own advisers before use.

4.2 We are not the drafter of anyone's policy. Thresholds, measurement periods, triggers, exclusions, and the consequences of breach are the insurer's decisions in every case.

4.3 No offer. Nothing here is an offer to sell or a solicitation to buy any security, insurance product, or licence, and nothing here creates an expectation of profit derived from our efforts (see agent-year-license-terms.md §11).

4.4 Patent pending — not granted. US Patent Application 19/637,714 (filed 2 April 2026; Track One; 36 claims). It may never issue, and may issue with claims narrower than those that make a licence valuable. The refund/abatement remedy is at agent-year-license-terms.md §8.2.

4.5 Forward-looking statements. Statements about future capability, adoption, market structure, or regulatory movement are estimates, not commitments, and we do not undertake to update them.

5. Licensing and data handling

5.1 The measurement is free; the underwriting is paid. Installing and running the drift-gate is free and open source (MIT). Only the financialization/attestation layer is licensed. This is not a free trial and not freemium: the free tier is not time-boxed and not feature-capped. Anyone can run npx thetacog-mcp and recompute a receipt today, at no cost and with no agreement in place.

5.2 It runs locally. Receipts are minted on hardware the licensee owns. No work-product byte is centralized by us. Nothing about a customer's production system depends on our continued existence, uptime, or consent.

5.3 Keys and chaining. Where a policy conditions the validity of an attestation on its signature chaining to identified key infrastructure, that is the insurer's clause and the insurer's audit. Our role is to make the check reproducible by whoever holds the inputs.

6. The discoverability disclosure — read this one before pitching an enterprise

A continuous record is discoverable. An enterprise that deploys a verification runtime creates contemporaneous evidence about its own operations, and that evidence can be sought in litigation, regulatory inquiry, or a coverage dispute. This cuts both ways: it is the same record that evidences reasonable care.

Two consequences we hold ourselves to:

6.1 We disclose this to the enterprise rather than letting their counsel discover it. In-house counsel blocks tools that surface unflagged evidentiary exposure, and rightly so.

6.2 We do not sell on the claim "this proves when you are negligent." The party that wants an immutable record is the risk-bearer — the carrier, the captive, the syndicate — because it lets them price and resist unearned payouts. The enterprise's reason to adopt is different: it is the record that lets them show they operated inside a scope they declared, and (where a policy so provides) the record their coverage is conditioned on. Retention periods, legal-hold interaction, and privilege are the enterprise's decisions with their own counsel; we make no representation about them.

7. Precedent and prior art — cited correctly

We cite these because a hostile read will, and because two of them are routinely conflated.

Correction of a recurring transcription error. Working transcripts have rendered "Rice's theorem" as "Riesz representation theorem." We do not use the Riesz representation theorem, and no claim of ours depends on it. Any document repeating that attribution is wrong and is superseded here.

8. Trademarks and third-party names

Carrier, broker, model-vendor and standards-body names appear in our material as factual reference only. No endorsement, affiliation, partnership, or approval is implied by the appearance of any third-party name, and we do not present any third party as a customer, partner, or reviewer without their written agreement.


Change control: this file is versioned in git. Where an outward artifact predates a change here, this file governs and the artifact is superseded to the extent of the conflict. Errata are logged in the reference standard, §9.


Recompute this row: shasum -a 256 public/legal/disclosures-and-limitations.html | cut -c1-16 — compare to the register at /legal/index.json.