Skip to main content

Integrate · APIs, gateways, interoperability, digital and physical, robotics

BUILT

Integrate · APIs, gateways, interoperability, digital and physical, robotics

Forculus. Every door into and out of the record.

Two kinds of door. Systems: ERP, MES, warehouse, point of sale, sensors, trading venues, anything with an API, each a registered identity with explicit scopes, sending data in only signed, fresh, once, within rate and within scope, and receiving data out only at destinations you allowed, for events you subscribed, in the fields each event declares. Machines: vehicles, mobile robots, arms, conveyors and controllers, commanded only when a person authorized it, inside the machine's envelope, with signed telemetry back.

Forculus is not a safety system. It never replaces a machine's own safety functions, emergency stops or certified controller. It refuses to send what it should not send, and the machine's controller remains the final authority on what the machine does.

The gateway

Every system is an identity, and every door refuses by name.

system.scopeA system holds only observe, adapters and egress scopes. It can never decide, approve, execute, command a machine or read the vault.
ingress.signatureEvery inbound request is signed with the system's own key over its timestamp, request id and body.
ingress.staleA timestamp more than five minutes from now is refused.
ingress.replayA request id is accepted once.
ingress.rateEach system has its own rate limit per minute.
ingress.scopeA warehouse system cannot post point-of-sale data.
ingress.revokedRevocation and rotation take effect on the next request.
egress.destinationData leaves only to hosts the organization allowed, and only over https.
egress.scopeA destination receives only the events its system is scoped for.
declared fieldsAn outbound event carries only the fields it declares; rationale, costs and anything undeclared stay inside. Each delivery is signed so the receiver can verify it.

Identity boundaries

Four kinds of principal, and what each may never do.

PersonDecides, approves, commands a machine, grants a disclosure. Accountable by name.
AgentReads, reasons, drafts and proposes. Never decides, never commands, never receives confidential material.
SystemBrings data in and receives events out, within its scopes. Never decides, never commands.
MachineReports signed telemetry and acknowledges commands. Never initiates an action on the record.

Machines: what it refuses, by name

Eleven machine rules, each one a test.

holdA stop is never refused. It reaches any machine at any time, from any named person, with no approval, even a machine that has stopped reporting.
command.unapprovedEvery other command needs an approved Honos request.
command.bindingThe approved request must name this machine; approval for one machine does not move another.
agent.dispatchAn agent never commands a machine. It may propose a request for a person to approve.
envelope.*Speed, zone, payload, program list and set-point bounds are checked against the machine's class before anything is sent.
interlock.estopA machine reporting an emergency stop refuses every motion command.
interlock.presencePeople in the machine's zone refuse every motion command.
device.staleA machine that has not reported for 30 seconds is not commanded: never command what you cannot see.
command.dualHazardous commands, a robot program or a controller set point, need a second named person.
command.expiredA command expires after 60 seconds; an acknowledgment after that is refused, so a stale command never runs after conditions change.
device.signatureTelemetry and acknowledgments are signed with the machine's own key.

What each kind of machine accepts

Vehicledispatch a route, return to base, hold
Mobile robotmove, pick, drop, charge, hold, within speed, zone and payload
Robot armrun a listed program with two people, home, hold
Conveyorstart, set speed within its limit, hold
Controllerchange a set point within its recorded bounds with two people, hold

Where it sits

Honos decides who may authorize a command. Minerva writes to records; Forculus commands machines; neither acts on its own authority. Physical events come back as observations Nerio can reconcile, and an item a robot moves can carry its custody on its Passport.

HonosMinervaRequest an assessment

Film · under three minutes

Every door into and out of the record.

Systems as identities, what may come in and what may leave, the four kinds of principal, and the machines: a stop never refused, everything else inside its envelope.

The EOS family

NerioAssessAwareness, insight and resilienceMinervaActionExecute, reverse, recordHonosGovernCompliance, audit, policyFidesPartnersIdentity, collaboration, permissionsForculusIntegrateAPIs, gateways, interoperability, digital and physical, roboticsPortunusTraceIdentity, custody, carbon, end of life

Also from AssetShop

Fourteen other products, none of them part of EOS. Separate products, no shared runtime, tenancy or credential path. Nothing below is included in an EOS evaluation or an EOS contract. Each carries its status, and nothing is called built until it is.

Enter the consumer layer at assetshop.eth EOS is the Enterprise Operating System. The brand layer it belongs to is name-native. Past that line the rules are different, and it is built by Shadow Key.

✓
Privacy notice · no tracking
This site uses no third-party tracking, no advertising cookies, no analytics beacons.
A single first-party cookie remembers your preference for dismissing this notice. We follow GDPR + CCPA + state-equivalent privacy laws by default. Full detail in our Privacy Policy and Cookies Policy.