The architecture

Four layers. Arkaya builds one.

Source systems emit signals; an engine produces a record against the schema; a counterparty reads that record as evidence; Arkaya produces neither the record nor the price.

Why this page exists

The boundaries are the architecture.

Most infrastructure companies describe what they build. The useful description of Arkaya is what it declines to build, because the declining is what makes the rest work. A schema that its steward also produced records against, scored, or priced from would be a rating agency with extra steps, and every counterparty reading it would have to decide how much of the steward's commercial interest was inside the number.

So each layer below states three things: what happens there, who owns it, and what Arkaya does not do at it.

§ 01 · The four layers

Where each thing happens, and who does it.

Layer 0
Observation
Source systems

An organisation's own systems emit signals about what its controls did: identity providers, AI gateways, change management, incident tooling, board and committee records. Permanently competitive, multi-vendor by design.

Arkaya does not operate here. It builds no connectors and competes with no vendor whose system emits. The schema specifies what a signal must carry to be readable; it does not specify who emits it.
Layer 1 · Arkaya
Translation
Arkaya, as Custodian

Giving events a fixed shape so that a stranger can read them. This is the Governance Evidence Taxonomy: the eight observable fields, the eight governance domains, and the Layer 1 material that fixes how a record is canonicalised, digested, chained and sealed so a reader who was not present can check it.

An engine sits at the boundary between Layer 0 and Layer 1: software the organisation or its vendor runs, which reads Layer 0 signals and produces a record against the schema. The schema then performs structural adjudication and nothing more: did the control exist, did it operate, did it pass its own test across the interval.

Arkaya does not produce records and does not sign them. The organisation's engine does, and the record states which key sealed it. Arkaya holds no production signing key, and a passing signature establishes what was sealed, not by whom.
Layer 2
Allocation
The party putting capital at risk

One operation in four steps, performed by an insurer, reinsurer, lender, acquirer or claims handler: observe, verify, price, allocate. Verify here means the proof check that party runs for itself, on the record, the public schema and the signer's public key.

Arkaya issues no score, no rating and no benchmark from Layer 1, prices nothing, and sits nowhere in the path of a proof check. A record is checked with stock open-source libraries and no call to any Arkaya service. That is a falsification condition rather than a promise: it is registered acceptance test V-3, run with every Arkaya-operated domain blocked at DNS.
Layer 3
Accumulation
The organisation

Where priced outcomes compound at the firm: capacity at renewal, terms at signing, refinancing pricing at execution, recovery at claim, enterprise value at exit.

This layer carries a hypothesis under test, not a mechanism. That governance evidence compounds into enterprise value is the proposition the research argues; it is not something the schema demonstrates, and it is not stated here as though it were.

The Doctrine is the argument that this sequence exists. The Schema is Layer 1 in full. The Library is the economics beneath it.

§ 02 · What actually passes

Nine steps, and the one thing that is not a step.

The chain from an obligation to a capital decision, stated as the sequence it is. Each step has one owner and produces one thing.

An obligation is stated — in a covenant, a policy condition or a board protocol.
Signals are emitted by the organisation's own systems.
A person decides. The judgement stays human.
The decision is recorded against the obligation it bears on.
The record is sealed, so that alteration is detectable.
The seal carries a proof — the material a party who was not present needs.
An allocator runs a proof check, with the record, the public schema and the signer's public key.
The schema returns a coverage state: whether conduct of adequate cadence exists against the obligation.
The carrier exercises judgement and decides the price.

Verification is not on that list, and its absence is deliberate. Verification is the name for what results when a party who was not present relies on the outcome. It is a property, not a stage: nobody performs it, Arkaya does not sell it, and no box on a diagram contains it. Translation is the mechanism; verification is the result. A page that drew verification as a step would be selling the result as a product, which is the thing this architecture is built not to do.

Two limits worth stating in the same breath. A coverage state measures adequacy of coverage and nothing else — a covered obligation is not thereby witnessed, and neither is a statement that governance is good. And the arithmetic of a proof check does not decay while the binding of a key to a party may: the recomputation survives indefinitely, the attribution depends on a document held outside the record by somebody with no continuing interest in it. Both are open work and are described as such on the implementer pack page.

§ 03 · What is open and what is licensed

The short answer to what you buy.

The schema is not for sale, and that is the point rather than a concession: a translation layer that charged for its own contract would not be one. What is licensed sits beside the schema, never inside it.

Open · never charged for
Everything a stranger needs to build against the schema, or to check a record.
  • The Governance Evidence Taxonomy itself
  • Cryptographic Profile v5 — canonicalisation, digest, chaining, seal
  • Interface and Conformance Specification v4 — what an emitter emits, what a reader consumes
  • The candidate vector set, 49 checks
  • An independent checker, and a reading-side conformance corpus
  • A specimen record and the fixture keys to check it with
No fee, no licence condition, no account, no call to any Arkaya service. At /get.
Licensed · the commercial work
The material that turns the schema into an underwriting decision on a named risk.
  • The mapping library — obligations to observables to source systems
  • The field sets for a given class of risk
  • The covenant benchmark a counterparty reads a coverage state against
This is Arkaya GET Solutions. The first class is continuous covenant underwriting for AI liability: a live, first-party evidence feed on the insured's AI estate, read into rating, retention, limit and capital by the underwriter, who decides all four. See Solutions.

The boundary is doing real work. Anyone may build an engine, produce records and have them read, without asking Arkaya and without paying Arkaya, because comparability across counterparties only exists if the form is free. What a counterparty pays for is the applied layer: which obligations matter for this risk, which observables evidence them, and what adequate looks like at this cadence.

§ 04 · Status

What is not yet true.

Stated here rather than inferred from silence, and in the same words the material itself uses.

The specifications
In review, pre-ratification. Version-pin what you build against and expect the pin to move once.
The vectors and corpus
Candidates. Normative on adoption by the specification that owns them, not because a tool produced them.
Engines
The conformance programme is a designed open test. Nothing has passed it, so no engine is described here as having done so.
Independent reproduction
Not yet done. Until a party Arkaya does not pay has built a second implementation without Arkaya's code and returned the same outputs across the published set, the honest description of every open file is registered, not recognised.
Signing keys
No production key exists and none is Arkaya's. The keys published are fixtures, derived from fixed seeds, never for production.
Custody of the schema
Held by Arkaya as Custodian, and structured to devolve to the Custos Foundation on four milestone gates. Indicative timing 2029 at earliest.
The company
Pre-revenue.

A reader who wants the cheapest possible test of all of the above should ignore this page and check a record: the four-step procedure and a specimen are at /get, and the check runs with the network switched off.

Resilience Capital is built.
Not asserted.