SwypikBuilt in EuropeInvestors
Nexus · how it fits together

AI that proposes.
A system that proves.

Nexus is the contract between three products we build ourselves. Ilaria proposes typed plans. Swyp defines and verifies what they mean. SwypikOS owns every effect, capability and device. No layer has to trust the one above it — each one checks.

Ilariaproposes typed plans and model artifacts
Swypdefines semantics, contracts and verification
SwypikOSowns effects, capabilities, devices and execution
Architecture

Five layers. One direction of authority.

Hover or tap a layer. Each one has a job, a boundary it never crosses and an honest status.

Authority

SwypikOS.

Owns
Control Kernel, capabilities, leases, recovery, Compute Fabric, devices and drivers, sandboxing and UI.
Never
Treats model confidence as authorization. Every effect needs an explicit capability.

Desktop & agent built · first-party kernel seed (QEMU-validated)

The Nexus loop

One loop. Four independent checks.

A plan only becomes an effect after a deterministic verifier, an authority layer and an evidence check have each said yes — and the evidence feeds the next proposal.

  1. 01Ilaria

    Proposes.

    Returns a typed Swyp plan in CorticalResponse — a proposal with zero authority attached.

    proposed_swyp_plan
  2. 02Swyp

    Verifies.

    Compiles to Core IR and checks contracts, effects and ownership deterministically. No model required.

    Core IR · contracts
  3. 03SwypikOS

    Executes.

    Grants exact scoped capabilities, enforces budgets and containment, and signs an effect receipt.

    capability · signed receipt
  4. 04Ilaria

    Checks evidence.

    Independently verifies the receipt’s signature, hash and expected epoch before anything is committed.

    evidence-check

Cross-product protocol types are generated from .swyp specs. CI regenerates them and rejects drift — so the products cannot quietly disagree about what a message means.

Dependency rules

Three rules we don’t bend.

  1. 01

    Ilaria never holds ambient OS authority.

    It may emit or consume Swyp schemas and plans. It may not act on the machine. A proposal is not a permission.

    Ilaria may emit or consume Swyp schemas/plans, but must not gain ambient OS authority.
  2. 02

    Swyp works without a running model.

    Verification is deterministic. Switch the model off and every contract, effect and ownership check still runs.

    Swyp must remain usable without a running model.
  3. 03

    Effects run only through explicit capabilities.

    SwypikOS mints exact, scoped grants, enforces budgets and containment, and signs a receipt of what actually happened.

    SwypikOS executes effects through explicit capabilities.
Integrated across all three products

Milestones, not mockups.

Each completed milestone was closed by a cross-product integration gate that builds all three products and checks their boundaries end to end.

  1. Complete

    Broker effects v1

    A real Swyp program reads through SwypikOS and is verified by Ilaria.

    • Swyp safe interpreter emits effect requests with no authority
    • SwypikOS scoped fs.read / clock.read on a live lease
    • Ilaria verifies the signed receipt
  2. Complete

    Plan supervisor v1

    Complete immutable plans, end to end.

    • Persisted cumulative budgets
    • Independent verification before commit
    • Restart refusal · measured CPU and RAM
  3. Complete

    Plan supervisor v2

    Recovery made explicit; limits moved into the OS.

    • Conservative reconciliation — no blind replay
    • Lifecycle containment for every approved process
    • Repeatable performance measurements
  4. In progress

    Plan supervisor v3

    Resume equivalence and verified caches.

    • Interrupted runs resume to the identical result
    • No provider replay for resolved effects
    • Energy reported only when truly measured

Supervisor v3 is in integration; its document is explicitly not a completion claim. Passing these gates does not establish model quality or real-device kernel readiness — those have separate gates.

Vision · Myriad

Every device a cell.

Where Nexus is heading: every SwypikOS device runs an Ilaria cell. With explicit consent, the Compute Fabric feeds signed, verified training work back into the next model — while personal memory never leaves home.

  • personal episodic memory remains local by default
  • global training has no implicit access to personal memory
  • only verifier-backed outcomes may strengthen inter-cortex edges

Invariants from Ilaria’s Myriad spec. Swypik apps are the consumer surface, listed in the SwypikOS app catalog. This section describes direction, not a shipping network.

laptopedgeinfotainmentphonerobotverified rounds
signed training shardverified checkpointpersonal memory stays on the device
Why it matters

Anyone can wrap a model.

Owning the model, the language it must speak and the machine it must ask is a different kind of company. The boundaries between them are the product — and the moat.

Own model.

Ilaria: its own architecture (IMC), designed to be trained from scratch, served by its own Go inference runtime. Quality is measured by separate gates — never assumed.

Own language.

Swyp: the typed contract between AI and machine. It generates the protocol types every product speaks, and CI rejects drift.

Own OS.

SwypikOS: a verified native desktop today, a first-party kernel seed (QEMU-validated), and capability security by construction.

Built in Europe.

Romanian-first, local-first, with the critical layers owned rather than rented — the shape of a sovereign stack.

Auditable by layerEach boundary is a spec, a generated type and a test gate — reviewable without trusting a model.
Hard to copy piecemealThe value is in the contracts between products, not in any one of them alone.
Honest by defaultEvery surface separates verified, prototype, research and vision — so diligence goes faster.

See the whole picture.

Status, evidence and roadmap for Swypik, Ilaria, Swyp and SwypikOS — in one place.

Try “open movies”, “open go”, “stiri” or “investors”.