Vault

17essays ·All tags

Architecture12 min read

Correctness by Construction

Three traditions — Erlang, Jane Street’s OxCaml, NASA’s Ada/SPARK — arrived at the same conclusion about building systems that cannot fail in certain ways. ClawQL Streams / cellrt / TEE is where that thesis becomes concrete for agentic infrastructure.

  • Security
  • Agents
  • Vault
  • Air Gap
  • Llm Ops
Architecture22 min read

The Session Nobody Started

ClawQL Streams turns any event into an agent session with tools in-process and WORM by default. celld runs Durable Objects you host. clawql-cellrt owns the production runtime. TEE + QR air-gap audit closes the network hole in the trust chain.

  • Agents
  • Llm Ops
  • Mcp
  • Air Gap
  • Serverless
  • Vault
Architecture22 min read

Memory Finds. Ontology Decides.

Semantic vault recall still returns near-misses on institutional questions. We open-sourced CQE — ClawQL’s entity definition format — and a legal Matter pack that turns escrow and non-compete into typed predicates. Here is the schema, the ingest path, the query, and the scores.

  • Agents
  • Memory
  • Ontology
  • Vault
  • Legal Tech
Architecture18 min read

What Convergence Week Actually Proved

Ten-plus product claims on live A/B OpenBench runs: frugal DeepSeek, hard spend caps, graders that demand real tool_use. On scores 1.0, off scores 0.0 — and every passing pack wraps an RTP reasoning trace the training flywheel can consume.

  • Benchmarks
  • Agents
  • Mcp
  • Llm Ops
  • Ouroboros
  • Vault
Architecture12 min read

California Spent $196 Billion and Can't Tell You What It Got

California tracks how bond dollars are spent — not whether the outcomes voters were promised actually happened. Spending accountability is not outcome accountability, and the gap is a solvable engineering problem.

  • Security
  • Arweave
  • Vault
  • Agents
  • Telemetry
Architecture28 min read

The Week Everything Converged: PorTAL, gRPC Transport 1.0, Stateless MCP, and OKF v0.2

Four independent developments in one week — PorTAL portable LoRA adapters, mcp-grpc-transport 1.0, MCP 2026-07-28 stateless protocol, and OKF v0.2 trust signals — each strengthen the same ClawQL architecture. Here's why that convergence matters and what it changes.

  • Llm Ops
  • Agents
  • Grpc
  • Mcp
  • Vault
  • Token Efficiency
  • Supply Chain
Architecture28 min read

Your Agent's Brain Deserves a Git Repository: Version-Controlled, Self-Hosted Agent Memory Over Tailscale

Why the right architecture for agent memory is a Git-backed OKF vault running on your own infrastructure, synced across machines via Tailscale, backed up to R2 or Arweave — and how ClawQL ships this as a single command.

  • Agents
  • Vault
  • Llm Ops
  • Supply Chain
  • Security
  • Arweave
Architecture24 min read

The Audit Trail You Can't Reconstruct

When a regulator asks what your AI system did and why, most teams discover their logs don't answer the question. A structural look at what forensic AI auditability actually requires.

  • Agents
  • Security
  • Telemetry
  • Llm Ops
  • Vault
Architecture24 min read

Why Your IDP Doesn't Know About Your APIs

Document processing tools and API integration tools are built in separate product categories, sold to separate buyers, and never talk to each other. The gap between them is where most enterprise AI workflows break.

  • Agents
  • Llm Ops
  • Vault
  • Rag
  • Security
Architecture24 min read

The $150,000 Invoice

The license fee is the smallest number on your ABBYY or Hyperscience invoice. A complete breakdown of what enterprise IDP actually costs — and what the same outcome costs when you build the pipeline from open-source components.

  • Agents
  • Llm Ops
  • Vault
  • Rag
  • Security
Architecture24 min read

The Institutional Knowledge Tax

Every AI session starts from zero. Your team pays the re-explanation cost every single time. A structural look at what cross-session memory actually requires — and why most teams don't have it.

  • Agents
  • Vault
  • Rag
  • Llm Ops
  • Token Efficiency
Architecture24 min read

The Per-Page Trap

Virtual data room vendors charge $0.40–$0.85 per page. A 10,000-page M&A deal room costs $4,000–$8,500 in per-page fees alone, every time you run a deal. A breakdown of how per-page VDR pricing works, why it compounds against you, and what the pipeline-native alternative looks like.

  • Agents
  • Llm Ops
  • Vault
  • Rag
  • Security
Architecture32 min read

The Complete Agent Memory Stack

ClawQL's five-layer memory architecture — OKF vault, vector recall, PageIndex, CodeGraph, Onyx — and how they compose into persistent, auditable, sovereign agent intelligence.

  • Agents
  • Llm Ops
  • Token Efficiency
  • Telemetry
  • Security
  • Vault
Architecture28 min read

The Enterprise Ontology: OOP Taken to Its Logical Extreme — and Why Your AI Agents Need It

How typed entity schemas, permission-aware relationship graphs, and kinetic MCP writes transform AI agents from JSON-blob processors into typed, auditable business intelligence — with ClawQL's `.cqe` format, fixture-backed reads, LOW/MEDIUM kinetic tools, and an honest map of what is shipped vs roadmap.

  • Agents
  • Llm Ops
  • Token Efficiency
  • Security
  • Telemetry
  • Vault
Agent Safety26 min read

Secret-as-a-Service: Credential Rotation for Local and Edge Agents

Long-lived ENV secrets turn a host compromise into a platform breach. Bootstrap once, exchange for short-lived Vault or edge credentials, and never let the agent hold a permanent secret.

  • Secrets
  • Vault
  • Agents
  • Edge
  • Security
  • Trust Boundaries
Agent Safety22 min read

Local Data Residency: Securing Agent Memory at Rest

Long-term memory on disk is a knowledge-base exfil cache. Encrypt at rest, redact at write time, and gate recall by classification — so a stolen laptop or poisoned entry cannot quietly own the agent's history.

  • Agents
  • Security
  • Trust Boundaries
  • Secrets
  • Vault
Architecture28 min read

The Worm That Ate the Supply Chain: What Mini Shai-Hulud Reveals About Every Security Control You're Trusting

How a self-propagating npm/PyPI worm defeated SLSA Build Level 3 provenance attestation, breached OpenAI and Mistral AI, open-sourced its own code, and what a layered defense posture actually looks like against this class of attack.

  • Supply Chain
  • Security
  • Agents
  • Sandbox
  • Vault
  • Arweave