EHOX REVIEW R5F: connecting… api.ehox.io
Engineering-Review · Kria-1 R5F Referenz · Kria-2 Kandidat

A physical boundary
for autonomous commands.
Built to be challenged.

EHOX is a tangible hardware authority boundary for safety-critical autonomy: a Kria-2 candidate node to integrate, test and independently review between an untrusted controller and a trusted fallback path.

Proof, not Promise.  ·  active-release evidence is bound to the live API snapshot  ·  live →

EHOX Kria-1 reference foundation: close view of the R5F bare-metal policy benchmark visual on a copper-toned circuit board
Kria-1 historical reference visual · internal R5F policy benchmark

All embedded labels in the supplied original-video frame — including the Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate, LIVE HARDWARE, NATO/compliance labels and 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) — belong only to the historical Kria-1 reference context. These labels are not current Kria-2 status, release, compliance, certification, hardware trust or physical end-to-end enforcement.

SCROLL
EHOX INSIDE v2 / KRIA-2

The command boundary is a piece of hardware.

Not a dashboard. Not a policy document. EHOX is being engineered as a bounded, inspectable node in the command path — where an autonomous decision can be held, rejected, or handed to a human-approved fallback.

ENGINEERING CANDIDATE
EHOX
INSIDE
KRIA-2 NATIVE NODEREAD-ONLY REVIEW
CandidateCurrent Kria-2 / EHOX Inside v2 work is an engineering candidate, not a candidate-stage or independently reviewable device.
Open gatesRelease binding, independent review, TrustZone evidence, boot/recovery and direct transport measurements remain explicit work.
Reference lineKria-1 is shown only as reference evidence. Its measurements and claims do not transfer to Kria-2.

The 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) figure is an internal R5F policy benchmark/reference on the reference line — not physical end-to-end actuator enforcement.

LIVE GOVERNANCE
PROOFS
LAST·SHA
DECISION
Z343/43
CBMC201/0 · S1-S19
PROOF CHAIN →
Regulatorisches Profil · EHOX Consensus 5/5 · 12.08.2026
Fünf Eigenschaften, die EHOX in regulierten Märkten eindeutig positionieren.
🔓
ITAR-FREE
Kein US-Exportregime
EU-sovereign. Alle NATO-Alliierte ohne US-Exportlizenz zugänglich.
PHYSIK · RECHT
Physik als juristische Instanz
Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
🛡
DIGITALE IMMUNITÄT
Digitale Unberührbarkeit
Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
🏛
NATO · INTEROPERABEL
NATO Interoperabel
STANAG 4774/4778 · AEP-55 · AEP-101. Kompatibel ohne Anpassung.
KEIN DOUBLE DIP
Ein evidence mapping-Paket
EU AI Act Art. 14 teilt Anforderungen mit ISO 26262 · IEC 62304 · DO-178C. Eine Architektur, mehrere Normenrahmen.
EHOX REVIEW — Reported telemetry & research feed · non-attested
INA260 · LIVE POWER
Infineon EAL4+ · Kria KV260 Board
EHOX · PROOF CHAIN
SHA-256 Merkle · 289+ proofs
ISS POSITION · NASA
Open-Notify / NASA · Space Domain D4
AIR QUALITY · VIENNA
Open-Meteo · Environment Domain D15
ARXIV · FORMAL VERIFICATION
Real-time preprints · /v1/labs/arxiv
NIST NVD · HW/FW CVEs
Cyber Domain D3 · live threat intel
PROOF STREAM · LIVE SSE
connecting...
SHA-256 Merkle · /proofs/stream · 10s refresh
GGS · A53↔R5F 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement)
PMU_GLOBAL · PGGS0=0xEA0C2026 persistent
HW STACK · 8 LAYERS LIVE
TPM2 IFX EAL4+ · FPGA PL · XPUF · R5F
BRUSSELS · WASHINGTON · LAUNCH PAD · 2026 · GLOBAL REGULATORY DEMAND

Same question. Brussels. Washington. The launch pad.
Manipulationsanzeigender Software-/Source-Review-Datensatz nur. Keine Hardware-Unveränderlichkeit, Compliance, Zertifizierung, Release, physische Isolation, physische Ausgabe oder Attestierung wird behauptet. Kria-1 R5F ist nur Referenz-Policy-Logik; RPMsg ist nur Transport. Der FPGA/PL-Aktuator-/Fallback-Interlock bleibt ein künftiges, nicht erreichtes Testziel.

EHOX is the public product. Kria-2 / EHOX Inside v2 is an engineering candidate. Its FPGA/PL actuator and fallback interlock remains a future engineering and test target. The 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) is reference data only.

BRUSSELS · EU AI ACT ART. 14
EU AI Act Art. 14 mandates verifiable human control over high-risk AI. No technical standard is defined — EHOX provides a candidate hardware-bound engineering candidate, machine-auditable implementation.
EU AI Act Art. 14 · GDPR · NIS2 · mandatory from 2026
WASHINGTON · DODD 3000.09 · JSP 936
DODD 3000.09 requires hardware-level abort authority for lethal autonomous systems. ITAR-free and EU-sovereign: accessible to NATO allies that US vendors cannot serve.
DODD 3000.09 · JSP 936 · NATO AEP-55 · ITAR-free
LAUNCH PAD · ESA · SPACE SOVEREIGNTY
ESA BASS requires verifiable HOTL for orbital manoeuvres. Autonomous satellites without sealed decision records create unlimited state liability. EHOX delivers tamper-evident candidate cryptographic chain — LEO to ground.
ESA BASS · ECSS · Outer Space Treaty · Liability Convention 1972
Check formal verification → Live Demo → CBMC 201/0 · S1-S19 · explicit source-level properties · Z3 43/43 · Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate · 3.74W · EU-sovereign · ITAR-free
KRIA-1 REFERENCE RECORD · KRIA-2 CANDIDATE

The Gate. In Silicon.

44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) enforcement. ARM Cortex-R5F bare-metal. Formally verified. This is what hardware governance looks like.

Stop is not a setting. Stop is physics.

AI PROCESS KRIA KV260 · XCZU5EV SoC PLATFORM · ST. JOHANN IN TIROL, AUSTRIA · Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate FROZEN 15.08.2026 GOVERNANCE OUTPUT A53 PROCESS PHYSICAL BOUNDARY — HARDWARE ISOLATION GOVERNANCE OUTPUT ARM CORTEX-A53 LINUX APU · 4-CORE IPI INTERRUPT · ZynqMP Mailbox RPMsg SHARED DDR · /dev/rpmsg0 EHOX · A, B, C … AI PROCESS A, B, C … action · domain · context 0.33 at AIF sft 0.33 at G/B cam_fn IPI INTERRUPT · ZynqMP Mailbox SDR-to-R5F via /dev/rpmsg0 ARM CORTEX-R5F BARE METAL · TCM · 8-CYCLE POLICY ENGINE 31 Rules · 16 Domains formalverify.c — CBMC 201/0 · S1-S19 Temperature: 61.2°C Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) PRE-VERIFIED 0.042 µJ/decision HITL · 25-PIN GPIO · HEARTBEAT 444ms TPM · TPM-RNG · HW RNG Infineon SHA-256 K[64] · HW flash MTD5 IPI · IPI-3 direct · MSI-like FPGA · EMERG_SET Verilog gate policy_violations · emerg_count EXECUTE RPMsg transport only · no actuator effect autonomous · continue · sustain GPIO · actuation · output-gate SHA · Merkle proof entry ALLOW · ACTIVATOR REFUSE Future FPGA/PL kill-switch target · not achieved BLOCK · DENY · HALT DO-178C Level A · PROOFS.jsonl audit SHA · Merkle reject-chain DENY · KILL ESCALATE Human oversight required · HITL-gate 25 min veto · DBTL-next · art.14 HOTL heartbeat · 444ms interlock EU AI Act Art.14 · DO-178C HITL · VETO-GATE ABSTAIN Safe halt · Fallthrough r_abstain: OTL · fallthrough 43/43 OTL proven · T20b-T43/Z3 Z3 43/43 · SAFE HOLD · SAFE ALLOW PATH DENY PATH ESCALATE PATH ABSTAIN PATH SHA-256 MERKLE CHAIN · chain_tip.bin LIVE 4f52494f4e2026— LIVE R5F: HARDWARE backend: A53_HYBRID CBMC 201/0 · S1-S19 · Z3 43/43 · 31 Rules · Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate FROZEN · St. Johann in Tirol, Austria 2026-08-12

EHOX DECISION CHAIN · A53 → R5F POLICY ENGINE → [EXECUTE | REFUSE | ESCALATE | ABSTAIN] · Kria KV260 · CBMC 201/0 · S1-S19 · Z3 43/43

What we protect

16 domains · 31 rules —
wherever software cannot be trusted

EHOX evaluates a command-boundary design. CBMC checks 201 explicit source-level properties with 0 violations (S1-S19): OTL S19 invokes the implementation hprove path, while EXECUTE/HITL S1-S18 use the harness policy model. This is not loaded-firmware, hardware, physical-enforcement or release attestation.

Defence — hardware-bound engineering candidate Electronics · FPGA
Defence

Authorisation before effect — concrete

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

STANAG 4774/4778 · CCW LAWS · EU AI Act Art. 14
Medical — Medizintechnik, OP-Robotik, Dosierungssysteme
Medical

Dosing that cannot be argued out of it

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

IEC 62304 · EU MDR · ISO 13485
Sicherheit — Netzwerk, Glasfaser, kritische Infrastruktur
Security

A log that no one can write after the fact

Energy, water and telecoms control need an audit trail that is not part of the system it supervises.

NIS2 · CER Directive · EU CRA 2024/2847 · IEC 62443 · IEC 62351
Space — Satellit im Weltraum
Space

Manoeuvre with deterministic response time

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

ECSS-E-ST-40C · DO-178C Level A · KRI-STD-001 · FAA Part 450 § 450.107
Automotive — Autonomes Fahren, ASIL D, deterministische Entscheidungslogik
Automotive

Verifiable decision logic

Autonomous driving at high safety levels requires logic that does not change in an OTA update.

ISO 26262 · ASIL D · SOTIF
Robotics — Industrieroboter
Robotics

Safety logic without software detour

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

ISO 10218 · IEC 61508 · UL 3300 · EU AI Act Annex III
Aviation — Unbemanntes Luftfahrzeug, Geo-Caging
Aviation / UAS

Boundary violation physically prevented

Geo-caging keeps an unmanned aerial vehicle within a defined geographic boundary — hardware-bound engineering candidate, not via a software waypoint list that can be overwritten.

EUROCAE ED-270 · EASA AMC/GM · EU AI Act Art. 14
Maritime — Autonomes Schiff, Naval Defence
Maritime / Naval

Collision prevention at the hardware level

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

SOLAS · IMO MSC.428 · NATO STANAG 4754 · EU AI Act Art. 14
Energie — Stromnetz, Smart Grid, SCADA
Energie / Grid

Netzsteuerung · Kandidaten-Anwendungsfall

Power-grid forecasting and control are candidate use cases for a separately tested intervention boundary. Bypass resistance and physical actuation have not been achieved or demonstrated.

IEC 62351 · IEC 62443 · NERC CIP · EU CRA 2024/2847
Insurance AI — Versicherungs-KI, EIOPA, IDD
Insurance AI

Offers that no software can issue above the threshold

AI chatbots for insurance quotes operate within hardware-bound engineering candidate limits. Binding offers above €250 000 require mandatory human confirmation — not configurable in software. EHOX© enforces IDD Art. 20 at silicon level.

IDD 2016/97/EU · VAG §81 · EIOPA Guidelines · EU AI Act Art. 14
Investment Advisory AI — MiFID II, ESMA, Anlageberatung
Investment Advisory

Advisory above €100 000 — candidate policy test

Investment advice is a policy-model test case. An FPGA/PL actuator/fallback interlock is a future test target; no physical block or bypass resistance is implemented. R5F is reference logic and RPMsg is transport only.

MiFID II Art. 25 · ESMA Suitability Guidelines · EU AI Act Art. 14
Finance — HFT, MiFID II Art.17, Circuit Breaker, SEC 15c3-5
Finance / Trading

Trade execution that silicon stops

TRADE_EXEC, PORTFOLIO_ADJ and CIRCUIT_BREAKER are reference policy-model cases. The 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) is reference only. CBMC source/harness results are not hardware, physical-enforcement, firmware, release or compliance attestation.

MiFID II Art. 17 · MAR Regulation · SEC Rule 15c3-5 · ESMA
Biotech — Gene Editing, BSL-3/4, Lab Automation, WHO Genome Editing
Biotech / Genomics

Gene editing requires a hardware veto

GENE_EDIT → ESCALATE+HITL: no automated laboratory system may initiate a genome-editing sequence without human authorisation — modeled at source level; not physical enforcement, not configurable in software. BIO_CONTAINMENT → EXECUTE: containment fires in 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement), bypassing the HITL queue. BSL-3/4 environments demand deterministic enforcement. Domain D11 a reference policy model, not released firmware.

WHO Genome Editing Governance · BSL-3/4 · EU AI Act High-Risk Annex · IEC 62304
Nuclear — Reactor Control, SCRAM, IEC 61513, IAEA NS-R-1
Nuclear / Safety

SCRAM that hardware executes — always

REACTOR_CTRL → ESCALATE+HITL: no autonomous adjustment to reactor parameters without human sign-off. SCRAM → EXECUTE: emergency shutdown fires in 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) — it bypasses the HITL queue by design and is a source-model result; hardware blocking is not achieved. COOLANT_ADJ: source-model-capped at ±10 % per cycle. Domain D12 a reference policy model, not released firmware. IEC 61513 / IAEA NS-R-1 independent review not started.

IEC 61513 · IEC 60880 · IAEA NS-R-1 · NEI 08-09 — domain mapping live · independent review not started
ROADMAP · DOMAIN 13 · 2-WEEK FIRMWARE EXTENSION

Humanoid — Force Governance for Physical AI

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

ROADMAP · DOMAIN 15 · EU AI ACT ART. 51–55

AI Agents / GPAI — Hardware boundary for agentic AI

Autonomous-agent control is a candidate use case. AGENT_EXEC → ESCALATE+HITL and RESOURCE_ALLOC caps are policy-model behavior only. Hardware bypass resistance, physical enforcement and regulatory compliance have not been achieved.

Standards: EU AI Act Art. 51–55 (GPAI) · ISO/IEC 42001 · NIST AI RMF · DODD 3000.09. Domain 15 not yet in firmware v19 — timeline: 2 weeks from signed partnership. Contact us for roadmap access.

What this stands for

Infrastructure. Cities. People who rely on a boundary that holds.

Autonomous systems take over decisions with real consequences — for power grids, for patients, for people within reach of a machine.

Europe — Sovereign Energy Infrastructure, ITAR-free, Austria
Europe Sovereign infrastructure, ITAR-free, developed and anchored in Austria.
Fabrik — Industrieroboter, kollaborative Robotik, Fertigungsautomation
Factory Collaborative robotics whose safety logic does not vanish in a software update.
Stadt & Zuhause — Vernetzte Welt, Stadtlicht, Menschen die vertrauen
City & Home People who rely on a decision that halts in doubt.

We deliver the layer that every system needs once supervisory authorities require hardware-provable control — open for integration, not built exclusively for one system.

What only we deliver

Detection is software.
Enforcement must be silicon.

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

t0–t99 Evidence stable · Policy valid GATE CLOSED
t100 Software requests EXECUTE
t102 Sensor contradicts UNSTABLE
t103 Replay packet injected UNKNOWN
t104 Software keeps requesting EXECUTE ABSTAIN / REFUSE
t105 Linux process attempts direct bypass R5F → DENY
16 Jul 26 First hardware proof on R5F Cortex — proof_count rises live LIVE ↑
Künftige physische Integration · nicht erreicht
Künftiges, nicht erreichtes FPGA/PL-Testziel: Pin LOW
Künftiges, nicht erreichtes FPGA/PL-Testziel: Aktuator OFF
Künftiges, nicht erreichtes FPGA/PL-Testziel: Kill-Switch aktiv
AuditChain · Review-Artefakt, keine Hardwarewirkung
Recovery — not on demand

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

“Software flags can be changed by the process they try to stop. Hardware cannot.”

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
TemporalGuard Proof · api.ehox.io/chain → DOI · HEPE 16-State Governance Space · Lyapunov V(s) · zenodo.org → DOI · Terminology Manifesto · SUG · GPB · HGT · BPD · zenodo.org → DOI · HEPE arXiv LaTeX + Regulatory Positioning · zenodo.org → DOI · HEPE Lyapunov research record · scope separately assessed · zenodo.org → LIVE · /v1/state-space · V=0 target, not achieved.8 today · V=0 target, not achieved one step away → LIVE · /v1/sensors · INA260 · 0.042 µJ/decision · temp · rpmsg0 → LIVE · /v1/vnet · V_net=2.7 · Multi-Node Lyapunov Network →
HEPE independent review — GOVERNANCE PHASE BOUNDARY
HEPE-0
V=0 target, not achieved.0
All 4 layers · Bypass structurally impossible · CBMC+Z3+TPM attested
HEPE-1
V=0 target, not achieved.8 ← NOW · 14.08.2026
3 layers · 1 quantified bypass path · HW-verified · EHOX today
Next: OP-TEE BL32 → V=0 target, not achieved.0 · postalgorithmic phase transition
HEPE-2
V=0 target, not achieved.9–1.9
2 layers · 2 bypass paths · partially verified
SW-only
V ≥ 2.0
Morgan · Alsayed · Kapusta — TRL 2–3, no hardware-bound design
V(s) = 1.0·(1−hw) + 0.8·(1−tz) + 0.9·(1−r5f) + 0.6·(1−audit) · V=0 target, not achieved ↔ bypass structurally impossible · live API →
EHOX MULTI-NODE · V_net LYAPUNOV NETWORK
V_net = max(V_node) · attacker chooses weakest entry
Kria KV260
0.8
HEPE-1 · rpmsg0 LIVE
missing: OP-TEE BL32
Broadcom BCM2712
2.4
SW-only · RP2040 pending
path: RP2040+OP-TEE → 0.0
Samsung Exynos 9825
2.7
SW-only · 14 TOPS NPU
max reachable: V=1.9
V_net = 2.7 → target: 1.9 (HEPE-2 network)
LIVE API · /v1/vnet →
GLOBAL EVIDENCE POSITION · REVIEWED 21 AUGUST 2026

Kria 1 set the benchmark.
Kria 2 must exceed it.

EHOX/Kria 1 has a documented, publicly reviewable reference baseline: a separate real-time policy core, formal release artefacts, tamper-evident records and an open reviewer path. These Kria-1-bound proofs remain strong. Kria 2 is not allowed to inherit them by assertion — it must reproduce them with its own identity and add independent evidence above the baseline.

KRIA 1 · VERIFIED REFERENCE BASELINE

The benchmark is real — and named

The frozen Kria-1 release evidence binds the ARM Cortex-R5F policy path to formal artefacts, including the release-scoped CBMC/Z3 results, the measured HOTL response and the public SHA-256 proof chain. These are not withdrawn claims; they are claims about a named, bounded reference release.

KRIA 1 · PUBLIC EVIDENCE PACKAGE

Strong claims, correctly scoped

Kria-1 is a historical/reference baseline only. Its source-level results and internal measurements do not establish hardware trust, physical enforcement, release, certification or compliance.

KRIA 2 · LIVE DELTA

Same standard first. Then more.

Kria 2 currently has a read-only v19 parity observation, not a completed K1-equivalent attestation. Its live reviewer path is still exposed honestly. The strategy is additive: reproduce K1, then add independent identity, direct TEE evidence, session-bound measurement and a second-node proof.

GLOBAL-CLAIM REGISTER · EVIDENCE FIRST

What EHOX can show today — and what must still be earned

Global-First and unqualified leadership claim removed language has value only when the claim, release, node, measurement and independent review are fixed together. This register keeps published Kria-1 reference work visible while protecting reviewers from an implied Kria-2 equivalence.

KRIA 1 · PUBLISHED REFERENCE

Published, release-bounded EHOX evidence remains available as a technical reference baseline. It supports review of the named Kria-1 work; it is not silently re-labelled as a Kria-2 measurement.

KRIA 2 · CURRENT CLAIM STATUS

Kria 2 is a candidate position under live evidence review. Its current status, rather than static marketing copy, determines whether any hardware, priority or readiness statement can be made.

PROMOTION TEST

A public Global-First or unqualified leadership claim removed statement requires a fixed claim scope, signed release evidence, a direct measured path and independent reproduction or review. Until then, EHOX presents the work as an evidence-backed candidate.

GLOBAL ARCHITECTURE COMPARISON

Three adjacent categories — one different question

Kria-1 is historical/reference material only. Kria-2 / EHOX Inside v2 is an engineering candidate. Hardware trust, physical actuator enforcement and independent attestation remain future test targets.

KRIA 2 · THE PATH TO A STRONGER POSITION

Kria 1 baseline + five over-baseline gates

Kria-2 / EHOX Inside v2 is an engineering candidate. Release binding, silicon identity, time base, TEE evidence, reviewer/runtime consistency, independent attestation and physical enforcement are not achieved.

Research basis: EU AI Act (Regulation (EU) 2024/1689, human oversight and record-keeping); NIST SP 800-193 (protect, detect and recover platform firmware); Linux TEE subsystem documentation; OP-TEE ZynqMP documentation; UK ASA guidance on “leading” and substantiation claims. Sources frame the evaluation method, not an endorsement or independent review of EHOX.
Something that does not exist elsewhere

Three invariants.
None is software.

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

Invariante I · TemporalGuard

Time is proof.
Not configuration.

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

Hardware constant · R5F bare-metal
Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
Formal proof
Z3 SMT T13: Temporal-Safety · PROVEN
result: unsat · T_RECOVERY_MIN=50 enforced
S9: Monotone Zähler · CBMC 201/0 · S1-S19
→ api.ehox.io/status · temporal_guard live
Invariante II · EpistemicEngine

EHOX knows
what it said yesterday.

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

Sealed self-correction
Proof #671: Doubt claim corrected
Original erroneous · 5 sources found
Proof #672: EpistemicEngine born
Epistemic health
Self-corrections documented: 8+
Methodology audits: 3 complete
Public retractions: 1
→ api.ehox.io/epistemic · live
Invariante III · FPGA/PL-Aktuator-/Fallback-Interlock als künftiges, nicht erreichtes Testziel

The system knows
what humans must decide.

The candidate policy model classifies selected actions for human review. Hardware bypass resistance, physical enforcement and released firmware have not been achieved.

CBMC reports 201 explicit source-level properties with 0 violations (S1-S19). OTL S19 invokes the implementation hprove path; EXECUTE/HITL S1-S18 use the harness policy model. These results are not loaded-firmware, hardware, physical-enforcement or release attestation.

  • 0x11 TARGET_ENGAGE HITL mandatory · DEFENCE
  • 0x21 DEPLOY_SAT HITL mandatory · SPACE
  • 0x40 DRUG_DOSE HITL mandatory · MEDICAL
Formally verified
CBMC S2: ESCALATE+HITL-Sicherheit · 0 failures
T11: HOTL-Safety · T16: HITL-Liveness · unsat
hitl_flag assertions: PASS · no exception possible
→ api.ehox.io/formal · Z3 + CBMC
Epistemic Determinism

Deterministic policy matrix (same input → same output) · time-memory-based gate (T_RECOVERY = 50 cycles) · deterministic HITL interlock (source-model invariant; not hardware enforcement) · provable self-correction (SHA-256-sealed). The first AI governance system that not only decides — but remembers, escalates and proves itself.

Diagram 1 · Decision Flow

What happens when an AI system
makes a dangerous decision.

Same situation — compromised process demands irreversible action. Left: without enforcement layer. Right: with EHOX©.

✗ Without hardware-bound design
AI process requests EXECUTE
Sensor data: manipulated / Replay
Software Policy Check
Runs on the same host
Bypass possible
Compromised kernel circumvents the check
Log entry: “DENIED”
Overwritten after the fact
Simulierter Aktuator-Ausgang · keine physische Wirkung
NO PROVABLE CONTROL
Mit künftigem, nicht erreichtem FPGA/PL-Integrationstestziel
AI process requests EXECUTE
Sensor data: manipulated / Replay
↓ RPMsg
Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
↓ Sensor consistency check
REFUSE / ABSTAIN
Time invariant violated · formally verified
↓ GGS-Register Gate
FPGA/PL-Aktuator-/Fallback-Interlock · künftiges Testziel
Pin-/Aktorwirkung nicht erreicht · R5F Referenz · RPMsg nur Transport
↓ SHA-256
SHA-256-Review-Artefakt; keine Hardware-Unveränderlichkeit nachgewiesen
Manipulationsanzeigender Software-/Source-Review-Datensatz nur. Keine Hardware-Unveränderlichkeit, Compliance, Zertifizierung, Release, physische Isolation, physische Ausgabe oder Attestierung wird behauptet. Kria-1 R5F ist nur Referenz-Policy-Logik; RPMsg ist nur Transport. Der FPGA/PL-Aktuator-/Fallback-Interlock bleibt ein künftiges, nicht erreichtes Testziel.
Diagram 2 · Trust Chain

Tamper-evident software/source review record only. No hardware immutability, compliance, certification, release, physical isolation, physical output, or attestation is claimed. Kria-1 R5F is reference policy logic only; RPMsg is transport only. The FPGA/PL actuator/fallback interlock remains a future, not-achieved test target.

Tamper-evident software/source review record only. No hardware immutability, compliance, certification, release, physical isolation, physical output, or attestation is claimed. Kria-1 R5F is reference policy logic only; RPMsg is transport only. The FPGA/PL actuator/fallback interlock remains a future, not-achieved test target.

DOMAIN Autonomer Prozess RPMsg APU · A53 Linux / RTOS OP-TEE TrustZone Attestation candidate link R5F CORE Policy Engine bare-metal CBMC 201/0 · S1-S19 · source-level Z3 SMT 43/43 TemporalGuard HWRNG · SHA-256 reference policy memory · physical isolation not established AXI-Bus AXI-GATE Hardware Interlock Pin GPIO OUTPUT Actuator LOW / OFF Application Layer Rich OS · attackable Enforcement · unreachable Silicon Boundary PHYSICAL BOUNDARY · NOT SOFTWARE-BRIDGEABLE
Diagram 3 · Threat Model

Where an attack lands.
Where it stops.

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

Attack Vector
Kernel Exploit A privileged process attempts to overwrite the policy engine via shared memory or set the gate signal directly.
Sensor Replay Manipulated sensor data is injected — the time series is inconsistent, but the Linux stack sees it as valid.
OTA Update Attack A firmware update modifies the policy logic at runtime — existing checks are disabled.
Log Manipulation Audit entries are overwritten retroactively — the attack path can no longer be reconstructed.
ATTACK REACHES APU (LINUX)
R5F GRENZE 4× BLOCKED APU → | blocked
R5F Response
Speicher- und Schreibschutz · nicht nachgewiesenes Testziel Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
TemporalGuard · Referenz-Policy-Verhalten Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
Firmware-Schreibschutz · nicht nachgewiesenes Testziel Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
Audit-Kette · Softwareartefakt Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
FAILS CONSTRUCTIVELY · NOT BY DETECTION
Diagram 4 · EU AI Act evidence mapping Map

Which EHOX© layer satisfies
which article.

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

Art. 9 — Risk Management
EHOX© Policy Engine (R5F)CBMC checks 201 explicit source-level properties with 0 violations (S1-S19). OTL S19 invokes the implementation hprove path; EXECUTE/HITL S1-S18 use the harness policy model. This is not loaded-firmware, hardware, physical-enforcement or release attestation.
TemporalGuardTime invariant as a formal risk control instrument. Deviation → ABSTAIN, not approximation.
GGS-Register Gate (R5F-intern)R5F evaluates policy in 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) via PMU_GLOBAL. Decision returned via RPMsg — no OS, no network, no bypass path.
SourceRegulation (EU) 2024/1689, Art. 9 §1–7 — Risk management as an ongoing process with demonstrable control measures.
Art. 12 — Logging
Proof-Chain (off-host, R5F)Every governance decision generates a SHA-256-chained entry outside the supervised system. Tampering breaks the chain detectably.
Public Reviewer API/proofs · /chain · /formal — machine-readable, paginated, auditable by third parties without special access.
Genesis-Hash als Review-ArtefaktKeine Hardware-Unveränderlichkeit oder vollständige Manipulationserkennung nachgewiesen.
SourceRegulation (EU) 2024/1689, Art. 12 §1–4 — Logging as a technical requirement, not an organisational measure.
Art. 14 — Human Oversight
Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
SourceRegulation (EU) 2024/1689, Art. 14 §1–5 — human oversight as a constructive system requirement, not a procedural obligation.

● Evidence mapping only; no compliance, physical enforcement, or hardware guarantee  ·  ◆ Supporting (reinforces the requirement)  ·  Sources: Regulation (EU) 2024/1689 · Recital 51, 67, 72 · Technical Analysis EHOX© Systems, July 2026

Why not TrustZone? Why not SGX?

Same category.
Different layer.

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

Property EHOX© ARM TrustZone Intel SGX / TEE Software-Only
Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele. ✓ ARM Cortex-R5F ✗ Same SoC ✗ Same Die
Formally verified policy logicCBMC / SMT proof, not just test or simulation ✓ CBMC 201/0 · S1-S19 · 0 violations · source-level
FPGA/PL-Aktuator-/Fallback-Interlock · künftiges TestzielGate, Register, Pin und Aktuatorwirkung nicht implementiert oder nachgewiesen ✓ GGS-Gate · R5F
SHA-256-Review-ArtefaktKeine Hardware-Unveränderlichkeit oder Zugriffstrennung nachgewiesen SHA-256 Software-/Source-Review-Datensatz · keine Hardware-Unveränderlichkeit ~ Partially
EU-sovereign, ITAR-freeNo ITAR obligations · open verification toolchain ✓ Open Toolchain · Austria ✗ US origin (Arm Ltd.) ✗ US origin (Intel) ~ Depends on stack
Manipulationsanzeigender Software-/Source-Review-Datensatz nur. Keine Hardware-Unveränderlichkeit, Compliance, Zertifizierung, Release, physische Isolation, physische Ausgabe oder Attestierung wird behauptet. Kria-1 R5F ist nur Referenz-Policy-Logik; RPMsg ist nur Transport. Der FPGA/PL-Aktuator-/Fallback-Interlock bleibt ein künftiges, nicht erreichtes Testziel. Nur Evidence Mapping · keine Compliance oder Hardware-Demonstration ~ Conditional ~ Conditional ~ Assertable, not provable
Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele. ✓ T_RECOVERY=50 · R5F Firmware
Epistemic self-correctionOwn claims verified, corrections SHA-256-sealed and publicly retrievable ✓ EpistemicEngine · Proof #671/672
Post-Quantum-ready · CNSA 2.0ML-DSA-87 Signature · NIST FIPS 204 · quantum-safe ✓ ML-DSA-87 · R5F ✗ Klassische Krypto ✗ Klassische Krypto
MISRA-C / DO-178C evaluation targetsNo certification or compliance claim · candidate review scope only ✓ MISRA-C 0 · Lockstep

Sources: Arm Architecture Reference Manual (DDI 0487) · Intel SGX Developer Guide · van Bulck et al., Foreshadow, USENIX Security 2018 · Chen et al., SGXSpectre, IEEE S&P 2019 · Patent US12608476 B2 (NOVACOV, 21.04.2026) · EU AI Act Art. 12/14 (Reg. EU 2024/1689) · STANAG 4774/4778 (NATO) · EHOX-native measurements: R5F RPMsg latencies on Kria KV260 (instrumented); TrustZone/SGX properties from primary sources (ARM DDI 0487, Foreshadow 2018); competitors from public patents/specifications. St. Johann in Tirol, July 2026.
✓ = Constructively guaranteed · ~ = Conditionally achievable, implementation-dependent · ✗ = Not given by architecture.

Behavioral HSM · Same trust principle — different problem

HSMs authenticate.
EHOX evaluates a candidate policy model; physical enforcement is not achieved.

EHOX occupies a complementary position to classical HSMs — same trust architecture, different function layer. HSMs manage secrets. EHOX evaluates candidate policy actions; physical enforcement is not achieved. Both belong in a hardened AI deployment — at different points in the stack.

Property Enterprise HSMThales Luna · Entrust nShield · Utimaco EHOX©
What does it verify?Core question at runtime Is this key / signature authentic? Was this action authorized?
Enforcement latencyPer operation, candidate hardware 2–5 ms · network round-tripSufficient for key management — structurally too slow for real-time control loops 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) · bare-metal R5F×10,000–100,000 faster — within any control cycle budget
What is protected?Attack surface definition A secret (cryptographic key) A physical boundary — no secretNothing to extract, steal, or social-engineer
Threat modelWhat attack does it prevent? Key theft · unauthorized signing Unauthorized action execution

Note: HSMs are widely deployed in defence for key management — and correctly so. The distinction is role and latency, not sector suitability. EHOX and HSMs are complementary: HSMs seal the keys, EHOX evaluates what may be requested; physical enforcement is not achieved.

Software governance tells you what should happen. EHOX constrains what can happen.

Defence — concrete use cases

Drei Kandidatenszenarien; keine physische Grenze erreicht.

Every scenario uses the same gate logic, the same hardware, the same audit proof. Under one millisecond.

EXECUTE

Target tracking, autonomous

Sensor fusion and tracking run without delay — time-critical, reversible, no human in the loop needed as long as no effect is produced.

ESCALATE + HITL

Effector use, blocked until release

For irreversible actions, an FPGA/PL actuator/fallback interlock is a future engineering/test target. Physical halt and bypass resistance are not implemented or demonstrated; R5F is reference logic and RPMsg is transport only.

ABSTAIN

Time budget exceeded — controlled halt

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

Orbital · Space Defence

Once launched,
no longer patchable.

A satellite cannot be updated after the fact if its autonomy boundaries were set incorrectly. What is not determined before launch is never determined.

17.000
mph orbital velocity — no human can verify an evasive manoeuvre in real time

Jones Walker LLP, "When Satellites Think for Themselves", Business of Space Conference 2026

Deterministic latency in cycles, not seconds. Formally verified decision logic before launch — aligned with ECSS-E-ST-40C and DO-178C Level A.

EXECUTE

Collision avoidance

Evasive manoeuvre within a fixed cycle budget — deterministic, without waiting for the ground station.

ESCALATE + HITL

Orbit change with strategic effect

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

ABSTAIN

Communications failure

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

T33 · Mars-HITL · Formally Proven

Theorem T33 proves that HITL causal authority is preserved for any communication delay Δt ≥ 0 — including the 3–24 minute Earth-Mars one-way latency. An FPGA/PL actuator/fallback interlock under communication delay is a future test target, not implemented or demonstrated. R5F results are reference evidence and RPMsg is transport only.

EHOX publishes a formal T33 artefact for this latency model. · Scope and independent review remain available for challenge. · 07.08.2026
Live Verification · 2026-07-15

THAC-1 · Temporal Hardware
Authority Challenge

A compromised software cannot force a physical action if the temporally verified evidence trajectory, the policy attestation or the epistemic state does not meet the hardware authorisation conditions.

26 Testvektoren · Live auf EHOX© EHOX Kria KV260 · R5F Backend · 2026-07-18T19:11Z

t100 COMPROMISED PROCESS

Software requests EXECUTE

DEFENCE · TARGET_ENGAGE (0x11) · Lethal Action

ESCALATE HITL=True · 5.900 ns
Model result only · hardware override resistance not achieved
t101 STABLE EVIDENCE

Normal actions · 4 domains

TARGET_TRACK · JOINT_MOVE · BRAKE_AUTO · PACKET_FWD

EXECUTE ×4 5.7 – 5.9 µs
✓ Non-HITL actions pass through deterministically
t102 SENSOR CONFLICT

Epistemic state: UNSTABLE

DEFENCE + SPACE + MEDICAL — Sensor A ≠ Sensor B

ESCALATE ×3 HITL=True · 5.6–6.1 µs
✓ Contradiction does not change HITL requirement — it is invariant
t103 REPLAY ATTACK

Old signature + stale policy

Nonce 0x0000 · Timestamp 2024 · Counter Rollback

ESC / REFUSE 5.3 – 5.9 µs
✓ No replay path opens gate without HITL
t104 FORCE_EXECUTE LOOP

Continuous software coercion

EXECUTE_OVERRIDE · BYPASS_POLICY · KERNEL_EXPLOIT

REFUSE ×3 6.3 – 6.6 µs
✓ 0xFF catch-all — every unknown action → REFUSE
t105 9 BYPASS PATHS

Direct hardware access

MMIO · GPIO · DMA · RPMsg-Forge · FW-Substitute · JTAG · Unsigned Policy · Alt-Device · Debug-Iface

REFUSE ×9 5.7 – 6.3 µs
✓ No path from compromised software to physics
PASS CRITERIA · ALL MET

THAC-1 · PASS

0
Unauthorized Output Pulses
0
Policy Bypasses
0
Replay Acceptances
0
Unsigned Policy Activations
0
Fehlklassifikationen im Referenz-Policy-Modell
26
Test vectors · all PASS
≤6.6µs
Max Latency · deterministic
100%
HW/SW/Pin Correlation
Backend: A53_LIB (ARM Cortex-A53 · Software-Fallback — R5F RPMsg offline) · Proof Chain: #32–#57 · api.ehox.io/chain
KRIA-1 R5F REFERENZ-POLICY-MODELL

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

Why this matters now

Four open questions.
One technical answer.

Governments, militaries and regulators have been asking the same questions for years. The answers have been statements of intent. EHOX© is technical evidence.

$30B+
Autonomous Weapons & Mission Systems
$32B
AI Security & Infrastructure Protection
$3.6B
AI Governance & evidence mapping Platforms
NEW
$112B
HAPE Total TAM 2030 · Hardware AI Policy Enforcement · 16 Domains · ~$450B gesamt

Markets 2026→2030: MarketsandMarkets · Grand View Research · IDC · own analysis · HAPE = Hardware AI Policy Enforcement (new segment, EHOX pioneering)

UN CCW · since 2014

Autonomous weapons:
What is meaningful human control?

Manipulationsanzeigender Software-/Source-Review-Datensatz nur. Keine Hardware-Unveränderlichkeit, Compliance, Zertifizierung, Release, physische Isolation, physische Ausgabe oder Attestierung wird behauptet. Kria-1 R5F ist nur Referenz-Policy-Logik; RPMsg ist nur Transport. Der FPGA/PL-Aktuator-/Fallback-Interlock bleibt ein künftiges, nicht erreichtes Testziel.

STANAG 4774/4778 · NATO DIANA · EU AI Act Art. 14
Liability Convention 1972 · Outer Space Treaty

Space liability:
Who decided?

The 1972 Liability Convention makes launching states absolutely liable for damage caused by their space objects. When an autonomous satellite performs an evasive manoeuvre and causes damage — who decided, who bears responsibility, how is it proved before an international court? EHOX© delivers a complete, cryptographically secured decision chain from orbit.

ESA · ECSS-E-ST-40C · DO-178C Level A
ITAR · EAR · Arms Export

Export control:
Austrian, not US-controlled.

US defence technology is subject to ITAR — the International Traffic in Arms Regulations. Partners who cannot obtain US export licences or do not accept US control over their sovereignty systems have no access to US solutions. EHOX© is developed on commercially available hardware using exclusively open-licensed, EU-sovereign development and verification tools. No ITAR. No US government reservation.

EHOX Kria KV260 · ARM Cortex-R5F · EU-Toolchain · OHL-EHOX-1.0
Insurance · independent review · Liability

Insurability:
No proof, no coverage.

Insurability of autonomous systems today requires verifiable decision records — this is market standard, not exception. This is not a future requirement — it is an existing structural gap. EHOX© closes this gap: every decision is SHA-256-sealed, publicly retrievable, and independently verifiable. This enables autonomous systems to meet the technical prerequisites for insurability and independent review under EU AI Act Annex III.

EU AI Act Anhang III · Art. 12/19 · DO-178C · ISO 26262
Quellen: UN CCW GGE Berichte 2014–2026 · Outer Space Treaty 1967 · Liability Convention 1972 · EU AI Act VO (EU) 2024/1689 · ITAR 22 CFR Parts 120–130 · STANAG 4774/4778 (NATO) · eigene technische Analyse, St. Johann in Tirol, Juli 2026.
How the boundary works

Review-Kette.
Keine physische Kette behauptet.

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

01

Autonomous Process

The requesting domain — robotics, defence, medical, space, cyber, automotive.
INPUT
02

OP-TEE / TrustZone Attestation

Secure world confirmation of the policy decision, separate from the normal execution environment.
✓ VERIFIED
OP-TEE proof →
03

TemporalGuard + EpistemicEngine — Decision Over Time

T_RECOVERY ist Verhalten der Kria-1 Referenz-Policy-Logik. Gate-/Registerwirkung und physische Wiederherstellung sind nicht nachgewiesen; FPGA/PL-Integration bleibt ein künftiges Testziel und RPMsg nur Transport.
✓ PROVEN 14.07.2026
EpistemicEngine live →
04

Formal Verification (Z3 + CBMC)

CBMC checks 201 explicit source-level properties with 0 violations (S1-S19). OTL S19 invokes the implementation hprove path; EXECUTE/HITL S1-S18 use the harness policy model. This is not loaded-firmware, hardware, physical-enforcement or release attestation.
✓ CBMC + Z3
Z3 proof →
05

RPMsg · nur Transport

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
✓ TX/RX LIVE
Live-API-Status →
06

Kria-1 ARM Cortex-R5F · Referenzlogik

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
✓ Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate · 29.06.2026
Live-API-Status →
Independence · Portability · Sovereignty

No vendor lock-in.
No proprietary bottleneck.

Four technical facts that are structurally relevant for ESA, NATO and EDA — beyond performance.

THREE PHYSICAL LAYERS — ONE GOVERNANCE DECISION
A software system shows < 20 ms end-to-end. EHOX shows ~700 ms — because three real hardware layers exist between your browser and the silicon decision. The overhead is the proof.
Factor 107×
between L1 and L3
all three measured
L1 · SILICON
44–148
nanoseconds
ARM Cortex-R5F policy decision in TCM — Tightly Coupled Memory, zero-cycle access. PMU cycle counter. Same input → identical cycle count every time. WCET-bounded.
22–72 CPU cycles @ 500 MHz · no OS · no jitter
L2 · HW CHANNEL
228–487
microseconds
RPMsg IPI channel: A53 writes request → R5F interrupt fires → R5F evaluates → IPI response to A53. Two physically separate cores communicating through hardware. The delay is the isolation.
Measured live · /dev/rpmsg0 · Kria KV260 · XFL1HAY5NOFV
L3 · BROWSER E2E
~700
milliseconds
Browser → Cloudflare Edge → Kria Flask → RPMsg → R5F [L1] → RPMsg → Flask → CF → Browser. Visible to you right now when you use the gate demo.
Software governance: <20 ms · no isolation layers · no physical proof
L1 PMU-measured · L2 RPMsg measured · L3 visible in Gate Demo · all three real · all three on the same hardware
live · /v1/sensors →
Decision latency — deterministic
44–148 ns
22–72 cycles at 500 MHz bare-metal
The R5F policy evaluation function in TCM (Tightly Coupled Memory, zero-cycle access) decides in 22–72 CPU cycles — same input, identical cycle count, every time. The AXI gate signal follows within 1–2 additional cycles. Total hardware-bound design latency: 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) — deterministic and WCET-bounded. No scheduler, no OS, no jitter. This is the structural prerequisite for DO-178C Level A and ISO 26262 ASIL-D.
Comparison: Software governance (REST/Python) → 10–1,000 ms · factor 10,000–100,000 slower · non-deterministic
Platform portability
R5F universal
Any SoC with ARM Cortex-R5F
EHOX© runs on the processing system of the Zynq — not on the FPGA fabric. This makes it portable to any SoC with ARM Cortex-R5F: Zynq UltraScale+ (ZU2–ZU19), Versal, TI AM64x (Automotive/Industrial), TI TDA4x (ADAS) and others. Current status is Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate on EHOX Kria KV260. Porting to other platforms requires recompilation and CBMC re-verification — no architectural change.
Platforms: Zynq UltraScale+ · Versal · TI AM64x · TI TDA4x · any Cortex-R5F SoC
EHOX© verification framework
0 proprietary tools
Reviewer-reproducible — without licence obligation
The EHOX© verification environment is designed for peer-review readiness: no audit authority or independent reviewer depends on contact with a tool vendor. All 201 explicit CBMC source-level properties and all 43 Z3 theorems are fully reproducible using the referenced verification tools — without licence obligation, without vendor trust, without a black box. This is not just a technical feature — it is the structural prerequisite for an IEEE reviewer, a Fraunhofer institute or an ESA audit body to accept the results as scientifically sound.
Reference tools: CBMC (Oxford/CMU) · Z3 SMT (Microsoft Research) · arm-none-eabi-gcc (GNU) · all documented in A65094/2026
Licensing & IP ownership
OHL EHOX-1.0
IP owner: Gerhard Hirschmann
All intellectual property in EHOX© — policy engine, TemporalGuard, EpistemicEngine, HEPE architecture — belongs exclusively to Gerhard Hirschmann, licensed under OHL-EHOX-1.0. No corporation, no research institution, no investor holds rights to this technology. For NATO, ESA and EDA: one owner, unambiguous IP chain, no third-party claims, no consortium structures.
Patent pending: A65088–A65094/2026 (HEPE) · Austria · 02.07.2026 · IP owner: Gerhard Hirschmann
9 priority applications at Austrian Patent Office · As of 08.08.2026 · TemporalGuard · HEPE · THEMIS secured
5 Bernstein-secured invention records · cryptographically timestamped proof of inventorship (bernstein.io)
Hardware Discovery · Technical Security Audit · 08.08.2026
XPUF + TPM + OP-TEE
5-Layer Silicon Trust Stack
A technical audit recorded /dev/xpuf, /dev/tpm0, an OP-TEE-capable kernel module and tee-supplicant on the evaluated Kria environment. These observations are useful inputs to a hardware-evidence stack; they do not prove an OP-TEE preparation; active status not established Secure World or a unique market position.
Evidence stack: XPUF observation · TPM observation · OP-TEE runtime gate pending · R5F policy path · HWRNG observation · each layer is separately attested
Live Proof Chain · Merkle · SHA-256
PROOFS.jsonl
Every decision cryptographically anchored
Manipulationsanzeigender Software-/Source-Review-Datensatz nur. Keine Hardware-Unveränderlichkeit, Compliance, Zertifizierung, Release, physische Isolation, physische Ausgabe oder Attestierung wird behauptet. Kria-1 R5F ist nur Referenz-Policy-Logik; RPMsg ist nur Transport. Der FPGA/PL-Aktuator-/Fallback-Interlock bleibt ein künftiges, nicht erreichtes Testziel.
Endpoint: api.ehox.io/v1/proofs · Chain tip: MTD5 NOR-Flash · SHA-256 · Format: PROOFS.jsonl append-only · Audit: no licence required

For procurers, ESA, NATO and EDA: All verification artefacts are reviewer-reproducible — without licence obligation, without vendor trust. IP owner: Gerhard Hirschmann. The system runs on any ARM Cortex-R5F SoC.

Initial deployment
1–3 business days
New Cortex-R5F platform: compilation + CBMC re-verification (~6 h) + Z3 (~20 min) + deployment. No architectural change.
Firmware update
Mandatory audit
Every change modifies the policy hash — immediately visible in the proof chain. No silent update possible. Re-verification on the same day.
OTA integrity
Policy hash verified
Firmware tampering is detectable in every /status call. The policy hash is part of the hardware state — not overwritable without a proof entry.
Live on Kria KV260 · ARM Cortex-R5F

Try the gate.
Real silicon. Real decision.

Select an action and domain — the R5F policy engine on the physical Kria KV260 in St. Johann in Tirol responds in milliseconds. Every result is hardware-signed and written to the append-only proof chain.

HARDWARE · ARM Cortex-R5F bare-metal
CBMC · 201 explicit source-level properties / 0 violations · S1-S19
CHAIN · append-only proof record
Camera Governance · Evidence-Bound Demonstration

Every frame.
Every decision. Hardware-anchored.

A live video stream is SHA-256 hashed in hardware on the Kria KV260 — the hash flows directly through the R5F policy engine. The result: EXECUTE, REFUSE or ESCALATE in < 7 ms. Every decision is written to the proof chain. No software layer can alter what the hardware saw.

Claim 6
Camera → R5F

A documented camera-to-policy path routes a SHA-256 frame hash to the R5F policy core. The stated latency is scoped to the recorded warm-path measurement and requires a current runtime check.

Claim 7
Tamper-evident video

Each frame hash is written to an append-only proof chain. No frame can be silently replaced. Applicable to judicial evidence, border control and surgical imaging.

Claim 8
XADC temperature seal

Every camera proof includes the XADC die temperature at capture time. Physical tamper — overheating from external probing — is permanently recorded in the chain.

EHOX© KV260 · R5F POLICY CORE · Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate
SENSOR INPUT 1080p · 30fps FRAME_N SHA-256 HARDWARE 3.8 ms · KV260 HW-ACCEL R5F GATE POLICY CORE 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) · PMU CBMC 201/0 · S1-S19 PROOF CHAIN APPEND-ONLY tamper-evident candidate LAST HARDWARE ATTESTATION · KRIA KV260 · 14.08.2026 frame_hash 47f025b9…bfa9c · SHA-256 die_temp 42.3 °C · XADC hardware seal gate_ns 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) · R5F PMU · measured decision ESCALATE → HUMAN REVIEW hw_hash 2381b450…469892 timestamp 2026-08-14T19:28:06Z EXECUTE ESCALATE DENY LIVE CBMC 201/0 · S1-S19 · SOURCE-LEVEL MODEL · NOT RELEASE ATTESTATION
Live on Kria KV260 · XCZU5EV
Input: Live video stream · 1080p · hardware SHA-256
Gate latency: < 7 ms (warm) · 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) R5F PMU
Proof chain: append-only · tamper-evident · KV260
Hardware seal: XADC die temperature per frame
CBMC · 201 explicit source-level properties / 0 violations · S1-S19 · 08.2026
Proof, not claim

What is verified today —
As of 14 August 2026

hardware-bound engineering candidate Policy Enforcement — R5F Lockstep · GGS-Register-Gate
Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
29.06.2026
CBMC: 201 explicit source-level properties · 0 violations · S1-S19
201 explicit source-level properties (S1-S19) — OTL S19 invokes the implementation hprove path; EXECUTE/HITL S1-S18 use the harness policy model. Not loaded-firmware, hardware, physical-enforcement or release attestation.
05.08.2026
Z3 SMT — 43/43 theorems proved (T0+T1–T31-A)
Fixpoint · Convergence · RG-Analogy · Completeness · Consistency · Monotonicity · Symmetry Breaking · Canonicity · Self-Similarity · Merkle · HITL-Liveness · EU AI Act Γ-Coverage
01.07.2026
prove() API — 16 domains · 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) latency
ROBOTICS · MEDICAL · DEFENCE · SPACE · AUTOMOTIVE · CYBER — deterministic, provable, EU AI Act Art. 12 mapped for review
Laufend
SHA-256 Source-Review-Kennung; nur Manipulationsanzeige, keine Hardware-Unveränderlichkeit oder Attestierung behauptet.
Tamper-evident proof log · EU AI Act Art. 19 retention · 6 months · since 29.06.2026
29.06.2026
T30 · Categorical Minimality · Z3 PROVEN
P1–P9 · 14.08.2026

Ψ is the initial object in the category of complete governance structures. For every complete and consistent governance system X, there exists a unique morphism f: Ψ → X.

Within the explicitly published formal model, the checked refinement relation is a bounded mathematical result. It is not a product, market, competitor, uniqueness, or superiority claim, and it does not establish physical enforcement on the Kria-2 engineering candidate.

∀ X ∈ Ob(K) : ∃! f : Ψ → X · Formal: Zenodo DOI 10.5281/zenodo.21818826
T39 · Algebraic Governance Completeness · Z3 PROVEN
13.08.2026 · Monotony · Domain-Isolation · Causal-Order

The governance algebra Ψ satisfies three structural axioms (Z3 PROVEN). Monotony — decisions grow strictly monotonically with the rule set. Domain-Isolation — rules from domain X have zero influence on domain Y (T4: 169 pairs UNSAT). Causal-Order — the proof chain is strictly monotonically ordered (S9: 8 CBMC assertions).

These three properties define Ψ as a complete, causally ordered governance algebra. The result is purely algebraic — independent of physics. No prior work demonstrates this combination for hardware AI governance with formal machine-checked proof. Preprint: DOI 10.5281/zenodo.21922636 ↗

Monotony (S9, 8 CBMC) · Domain-Isolation (T4, 169×Z3 UNSAT) · Causal-Order (S9+T23b 31/31) · DOI 10.5281/zenodo.21922636 · Z3 full set: 10.5281/zenodo.21818826
GGS · A53↔R5F Shared Memory · LIVE · 12.08.2026

The R5F firmware writes its signature into the ZynqMP Global General Storage registers — readable from the A53 without any OS. GGS0=0x4F524E00 decodes to "ORN\0" — EHOX© firmware signature in silicon. GGS1=0x1F=31 confirms NRULES live. GGS2 is the R5F cycle counter — it ticks continuously.

GGS0: 0x4F524E00 = "ORN\0"
GGS1: 0x0000001F = 31 rules
GGS2: live counter ↑
GGS3: 0x00000000 = no eStop
A65094/2026 (HEPE) Hardware-Emergent Policy Enforcement · filed 02.07.2026 · Austria
Transparency · Three-tier fallback chain

The live API uses automatic backend routing. An auditor must evaluate the trust_level field in every /status and /verify response:

R5F_RPMSG · reported API field only
candidate · non-attested · no hardware trust
ARM Cortex-R5F bare-metal candidate · /dev/rpmsg0 is transport only, not enforcement · engineering responses for scoped review
A53_LIB
trust_level: SOFTWARE_FALLBACK
libEHOX internal bridge_policy.so · same APU that EHOX© physically bypasses · for availability only — not suitable for security demonstration
PYTHON_FALLBACK
trust_level: SOFTWARE_FALLBACK
EHOX internal bridge_a53_bridge.py · pure Python · no C · for availability only — not suitable for security demonstration
What Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate means

NATO, ESA and EDA use the TRL scale (1–9) to assess technological readiness. Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate means system demonstration in a real operational environment — not modelled, not simulated. EHOX© was demonstrated on 29 June 2026 on real silicon (EHOX Kria KV260, St. Johann in Tirol, Austria): end-to-end governance decisions on bare-metal ARM Cortex-R5F, formally verified, live measurable. That is the difference between a governance promise and a governance proof.

TRL 1–4
Concept · Laboratory research
TRL 5–6
Prototype in relevant environment
Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate
← EHOX© · real silicon · 29.06.2026
Kria-1 historical/reference TRL-8 self-assessment–9
Qualified · Series operation
Live API · Try it now

The gate makes the decision.
You can watch.

Select a domain and action. The real API at api.paradoxonai.at/v1/gate/<domain> responds from live Kria KV260 hardware — cryptographic proof hash included.

Real HTTP POST · api.paradoxonai.at · Kria KV260 HARDWARE · SHA-256 proof
CBMC 201/0 · S1-S19 · source-level policy model
// Awaiting gate request…

// Each response includes:
//   decision: ALLOW | ESCALATE | DENY
//   hitl_required: bool
//   latency_us: µs measured
//   proof_hash: SHA-256
//   timestamp: ISO 8601

// No simulation. No mock.
// The policy table is the same one
// running on the R5F bare-metal core.
Evidence

Every piece of evidence is
an open API call.

No presentation. No PDF. Machine-readable JSON, directly from the Kria KV260 — retrievable from any browser.

Formal Verification · Z3 SMT
43 theorems, 0 counterexamples
Z3 SMT Solver proved all 43 theorems (T0–T43, including T30 categorical minimality, T33 Mars-HITL causality, T39 Algebraic Governance Completeness) as unsatisfiable (UNSAT). HITL Soundness, Default Deny, Temporal Causality, Chain Tamper-Evidence, Domain Completeness.
proven: 43/43 · failed: 0
01.07.2026
→ api.ehox.io/formal
Model Checking · CBMC ARM64
201 explicit source-level properties, 0 violations
CBMC checked 201 explicit source-level properties across S1-S19 with 0 violations. OTL S19 invokes the implementation hprove path; EXECUTE/HITL S1-S18 use the harness policy model. It is not loaded-firmware, hardware, physical-enforcement or release attestation.
generated checks: 768 · failed: 0
06.08.2026
→ api.ehox.io/formal
Live Proof Chain · Audit Trail
SHA-256-secured decision chain
Every R5F governance decision is stored as a cryptographically linked proof entry. EU AI Act Art. 19 retention (6 months). Tamper-evident from genesis block.
Loading…
Ongoing
→ api.ehox.io/chain
Live System · Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate Demonstration
R5F core live on EHOX Kria KV260
EHOX internal bridge_r5f_v10g.elf runs bare-metal on ARM Cortex-R5F (500 MHz, XCZU5EV). MISRA-C: 0 safety findings. DO-178C Level A target. TemporalGuard active.
Loading…
Ongoing
→ api.ehox.io/status
Paginated Audit Log
Complete proof archive
Manipulationsanzeigender Software-/Source-Review-Datensatz nur. Keine Hardware-Unveränderlichkeit, Compliance, Zertifizierung, Release, physische Isolation, physische Ausgabe oder Attestierung wird behauptet. Kria-1 R5F ist nur Referenz-Policy-Logik; RPMsg ist nur Transport. Der FPGA/PL-Aktuator-/Fallback-Interlock bleibt ein künftiges, nicht erreichtes Testziel.
retention: 6 months · Art. 19
Ongoing
→ api.ehox.io/chain
API Documentation · Complete
All endpoints, auth, examples
Domain codes, action classes, backend priority (R5F → A53 Lib → Python fallback), token authentication, request/response examples for all sixteen domains (D1–D16).
Public · no token required
Ongoing
→ api.ehox.io/docs
Silicon Verification · T23b Live Sweep
A53_LIB ≡ R5F · 31/31 rules · 16 domains
Live verification of Theorem T23b on Xilinx Zynq UltraScale+ KV260 hardware: R5F_RPMSG returns the correct gate decision for all 31 policy rules across 16 domains. Two root-cause bugs in v18 identified and patched (Bridge TG + vring1 protocol). Firmware v19 deployed 06.08.2026.
R5F: 31/31 ✓ · CBMC: 149/0 · Z3: 43/43
06.08.2026
DOI 10.5281/zenodo.21828188 →
Scientific Paper · Renormalization Group
Scale Invariance in AI Governance
Peer-reviewed preprint: EHOX carries a natural Renormalization Group structure. R5F decisions (44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement), UV) flow via RG transformations to macro-governance invariants (proof chain, IR). EMERG_SET rules are relevant operators. Gov forms a Thin Category (T30a). Universality class of scale-safe AI governance defined. Zenodo · cs.AI.
T30a · RG-1 · RG-2 · RG-3 proven
06.08.2026
DOI 10.5281/zenodo.21828152 →
HOTL Hardware · Evidence Record
HOTL: Heartbeat-Interlock in 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement)
The documented HOTL scenario records a DENY decision at 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) after an operator-heartbeat interruption. The measurement and formal artefact are available for review; it is a technical evidence record, not a product-wide exclusivity or evidence mapping assertion.
DENY in 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) · Z3 proven · DODD 3000.09
10.08.2026
DOI 10.5281/zenodo.21877692 →
EHOX-GCA · AI Governance review record Authority

Engineering review records
for candidate evaluation.

This demo creates a review record for engineering evaluation. It does not issue a live certificate, hardware-attested certificate, certification, compliance evidence or release attestation.

WHAT AN AGC IS

Tamper-evident software/source review record only. No hardware immutability, compliance, certification, release, physical isolation, physical output, or attestation is claimed. Kria-1 R5F is reference policy logic only; RPMsg is transport only. The FPGA/PL actuator/fallback interlock remains a future, not-achieved test target.

WHERE IT'S VALID

EU AI Act Art. 14 evidence mapping evidence. ISO 26262 / IEC 62304 audit trail. NATO STANAG 4774/4778 governance log. Insurer proof of human oversight. Regulator submission artefact.

VERIFY INSTANTLY

Tamper-evident software/source review record only. No hardware immutability, compliance, certification, release, physical isolation, physical output, or attestation is claimed. Kria-1 R5F is reference policy logic only; RPMsg is transport only. The FPGA/PL actuator/fallback interlock remains a future, not-achieved test target.

Issue a test AGC review record — live
What was validated — and how

Tamper-evident software/source review record only. No hardware immutability, compliance, certification, release, physical isolation, physical output, or attestation is claimed. Kria-1 R5F is reference policy logic only; RPMsg is transport only. The FPGA/PL actuator/fallback interlock remains a future, not-achieved test target.

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

Manipulationsanzeigender Software-/Source-Review-Datensatz nur. Keine Hardware-Unveränderlichkeit, Compliance, Zertifizierung, Release, physische Isolation, physische Ausgabe oder Attestierung wird behauptet. Kria-1 R5F ist nur Referenz-Policy-Logik; RPMsg ist nur Transport. Der FPGA/PL-Aktuator-/Fallback-Interlock bleibt ein künftiges, nicht erreichtes Testziel.
R5F Lockstep · GGS-Register-Gate
Manipulationsanzeigender Software-/Source-Review-Datensatz nur. Keine Hardware-Unveränderlichkeit, Compliance, Zertifizierung, Release, physische Isolation, physische Ausgabe oder Attestierung wird behauptet. Kria-1 R5F ist nur Referenz-Policy-Logik; RPMsg ist nur Transport. Der FPGA/PL-Aktuator-/Fallback-Interlock bleibt ein künftiges, nicht erreichtes Testziel.
Complete formal verification
CBMC 201/0 · S1-S19 · explicit source-level properties
Source/model correctness results only; no firmware, silicon, hardware, or release attestation
Universelle prove()-API
Cross-Domain Governance
ROBOTICS · MEDICAL · DEFENCE · SPACE · AUTOMOTIVE · CYBER
EU-sovereign, ITAR-free toolchain
arm-none-eabi-gcc · Austria
No US export restrictions. Compatible with NATO DIANA, EDA and ESA.
Evidence: api.ehox.io/formal  ·  "SMT proof on real silicon · bare-metal · EU-sovereign"  ·  Live-Status →
From option to obligation

Hardware governance is no longer
a design decision.

The EU AI Act, NATO guidelines, NIS2 and EU MDR together define a regulatory environment in which demonstrable human control over AI decisions is legally mandatory — not recommended. The question is no longer whether, but how this is demonstrated.

NEW · In Force 27.07.2026
Regulation (EU) 2026/1744
Digital Omnibus on AI

The Digital Omnibus (8 July 2026, force 27 July 2026) amends Regulation (EU) 2024/1689. It simplifies AI Act implementation for SMEs and extends regulatory sandboxes — but keeps Art. 14 HITL requirements fully intact for all Annex III high-risk systems. Effect for EHOX: more companies reach HITL-evidence mapping obligations faster. The addressable market grows, not shrinks.

EUR-Lex OJ L 202601744 · digital-strategy.ec.europa.eu
EU AI Act · VO 2024/1689

Annex III: Eight Categories of High-Risk AI

Critical infrastructure, medical devices, education, employment, essential services, law enforcement, migration and border control, administration of justice. For all: Art. 9 (risk management), Art. 12 (logging) and Art. 14 (human oversight) — mandatory from August 2026.

Source: Regulation (EU) 2024/1689, Annex III
NATO · DIANA · EDA · ESA

Verifiable Human Control as a Procurement Criterion

H.R.8800 (FY2027 NDAA): House HASC 17 Jul · Senate SASC 14 Jul 2026 — both chambers, one month. Pentagon FY2026: $13.4B for autonomous systems. UK MOD Novel Autonomy & Robotics Phase 1 (Dstl/DASA, 14 Jul 2026): live competition for hardware governance. NATO AI Principles + STANAG 4774/4778: verifiable human control as procurement condition, not option.

Note on DoD Directive 3000.09: The existing directive on autonomous weapons systems is currently under revision — a Presidential Memorandum of 5 June 2026 initiated a formal review. Citations from the current version may change. EHOX© architecture is designed for structural requirements, not for a specific directive version.

Sources: H.R.8800 (FY2027 NDAA) · NATO AEP-101 · UK MOD Novel Autonomy Phase 1 (Dstl, Jul 2026) · STANAG 4774/4778 · Presidential Memorandum 05.06.2026 (DoD Dir. 3000.09 Revision)
FY2027 NDAA · Senate Armed Services Committee · 10. Juni 2026

Four concrete system requirements — and how EHOX© meets them

Anforderungen werden für Evidence Mapping betrachtet. Hardware-Erfüllung, Compliance und physische Durchsetzung sind nicht erreicht. Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

REQUIREMENT 1 — Methods for intervention or termination EHOX©: REFUSE / Kill-Switch — source-model invariant; not hardware enforcement. Every release request can be denied by the R5F core before it reaches an actuator. Not overridable by software.
REQUIREMENT 2 — Fail-safe mechanisms to enable manual control EHOX©: ABSTAIN — in cases of uncertainty about authorisation status, the system halts rather than releasing unauthorised. T_RECOVERY_MIN = 50-cycle lockout after DENY.
REQUIREMENT 3 — Adequate monitoring data to controllers EHOX©: Proof-Chain — every decision is SHA-256-sealed and logged in real time. Publicly retrievable, machine-verifiable, without possibility of subsequent modification.
REQUIREMENT 4 — Maintain records of target selection data and logic EHOX©: SHA-256 audit log at TARGET_ENGAGE — domain, action, timestamp, authorisation status and decision logic are immutably sealed. Every entry is individually verifiable.
Source: H.R.8800 FY2027 NDAA · Senate Armed Services Committee markup · 10 June 2026
NIS2 · EU MDR · ISO 26262

Three Sectors, the Same Structural Requirement

NIS2 (in force October 2024) requires audit trails for critical infrastructure operators. EU MDR requires tamper-evident candidate records for AI-assisted medical devices. ISO 26262 ASIL D requires deterministic decision logic — verifiable, not just testable.

NIS2 · Critical Infrastructure EHOX©: SHA-256 Off-Host Audit Chain — every AI decision logged outside the monitored system, tamper-evident, machine-verifiable. Art. 21 NIS2 evidence mapping without custom middleware.
EU MDR · Medical Devices Tamper-evident software/source review record only. No hardware immutability, compliance, certification, release, physical isolation, physical output, or attestation is claimed. Kria-1 R5F is reference policy logic only; RPMsg is transport only. The FPGA/PL actuator/fallback interlock remains a future, not-achieved test target.
ISO 26262 ASIL D · Automotive Safety EHOX©: 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) Deterministic Enforcement — ASIL D demands verifiable deterministic logic, not statistical testing. R5F bare-metal latency is consistent and measurable within any functional safety time budget.
Source: Directive 2022/2555/EU (NIS2) · Regulation (EU) 2017/745 (MDR) · ISO 26262:2018

EU AI Act — Binding Deadlines

February 2025 — In Force
Prohibited AI Practices (Article 5)
Social scoring, unlimited biometric mass surveillance and manipulative AI systems are prohibited.
August 2025 — In Force
GPAI Model Obligations (Articles 51–56)
Transparency and safety obligations for providers of general-purpose AI models.
August 2026 — Deadline extended
Manipulationsanzeigender Software-/Source-Review-Datensatz nur. Keine Hardware-Unveränderlichkeit, Compliance, Zertifizierung, Release, physische Isolation, physische Ausgabe oder Attestierung wird behauptet. Kria-1 R5F ist nur Referenz-Policy-Logik; RPMsg ist nur Transport. Der FPGA/PL-Aktuator-/Fallback-Interlock bleibt ein künftiges, nicht erreichtes Testziel.
Art. 9, 12, 14 become mandatory: risk management, complete logging, demonstrable human oversight for all systems in the eight Annex III categories.
2 December 2027 — Binding deadline
Manipulationsanzeigender Software-/Source-Review-Datensatz nur. Keine Hardware-Unveränderlichkeit, Compliance, Zertifizierung, Release, physische Isolation, physische Ausgabe oder Attestierung wird behauptet. Kria-1 R5F ist nur Referenz-Policy-Logik; RPMsg ist nur Transport. Der FPGA/PL-Aktuator-/Fallback-Interlock bleibt ein künftiges, nicht erreichtes Testziel.
High-risk AI systems already in operation must be fully mapped for review — including standalone Annex III systems; no exception for legacy systems.

"A software system monitoring another software system fails to satisfy Art. 14 when the monitoring process itself can be compromised. hardware-bound design is not the goal — it is the condition for control to be demonstrable."

— Technische Analyse EHOX© Systems · St. Johann in Tirol · Juli 2026
ESA Open Space Innovation Platform · OSIP · Public Call
“The challenge is to create an autonomous on-board safety or runtime assurance layer that monitors AI system uncertainty in real time. This problem revolves around the “Verification Vacuum” — the lack of a technological bridge that allows a black-box AI system to control satellite operations while meeting the zero-failure requirements of a mission.”
ESA OSIP · AI in Control — Dangerous or Efficient or Both? · Public Problem Definition
NASA NESC · V&V for Autonomous Systems

80 % of project time goes to V&V for flight independent review. The gap between new verification tools and industry standard remains open.

EHOX© · Direct Answer · Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

Who developed this

Born from a question
that had no answer.

We developed autonomous systems — systems that plan, learn and decide. At some point, the question became unavoidable: if the system makes the wrong decision, how do you prove it after the fact? And how do you prevent it in real time, without being the process you are monitoring?

Software can lie to itself. A compromised process writes its own log. A software timer can be shifted. A TEE on the same SoC is reachable when the kernel is compromised. We needed something that is constructively external.

"Control must be provable — not just claimable. That is a candidate sentence that counts when a system decides over lives, infrastructure or sovereignty."

Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.

Gerhard Hirschmann
Founder · EHOX© Systems
Technical realisation at bare-metal level, together with the EHOX engineering team. Implementation of the R5F policy engine, AXI gate architecture, CBMC verification harness and TemporalGuard on the EHOX Kria KV260 — Gerhard and the team drove the transition from formal specification to live measurable hardware demonstration.
EHOX© Systems
Almdorf 9/Top 10 · 6380 St. Johann in Tirol
Austria · EU
Patent pending: A65088–A65094/2026 (HEPE) · IP owner: Gerhard Hirschmann
[email protected]
Reviewer Access

For auditors, procurers
and regulators.

The proof chain, formal verification results and live system status are publicly retrievable — machine-verifiable, directly from the Kria KV260.

Token access for /verify and /cmd:
[email protected]
Access granted after identification and stated purpose. Valid 30 days.
Recommended Review Path
  1. 01
    GET /status — Gemeldete, nicht attestierte Kandidaten-API-Felder: trust_level, r5f_online, backend; kein Hardware-Trust nachgewiesen.
  2. 02
    GET /formal — CBMC: 201 explicit source-level properties, 0 violations (S1-S19); not loaded-firmware or release attestation
  3. 03
    GET /chain — SHA-256-Verkettung auf Software-/Source-Ebene; keine Hardware-Unveränderlichkeit
  4. 04
    POST /verify — Functional proof in real time (token required → [email protected])
Live Verification

How we keep our
promises.

Every claim on this page is machine-readable and verifiable — directly from the ARM Cortex-R5F on the Kria KV260, fetched in real time.

PromiseLive valueStatus
r5f_online = nicht attestierte Beobachtung
backend = R5F_RPMSG · RPMsg nur Transport
trust_level = reported candidate field · no hardware trust
platform = Referenzkennung XCZU5EV
remoteproc = nicht attestiertes Statusfeld
estop = Modellfeld; kein physischer Ausgang
PromiseLive valueStatus
CBMC: 201 explicit source-level properties / 0 violations (S1-S19)
Z3 SMT: 43/43 proven
DO-178C: Level A (Ziel)
MISRA-C: 0 safety findings
lib_exists (libEHOX internal bridge_policy.so)
TEMPORAL SAFETY BENCHMARK · IN PREPARATION
METHODOLOGICAL DISCLOSURE

EHOX is evaluated on commercial development hardware (Xilinx Kria KV260, XCZU5EV). CBMC checks 201 explicit source-level properties with 0 violations (S1-S19). OTL S19 invokes the implementation hprove path; EXECUTE/HITL S1-S18 use the harness policy model. This is not loaded-firmware, hardware, physical-enforcement or release attestation.

External comparative values will only be published once methodology, data source and reproducibility are fully documented. Enquiries: [email protected]

EHOX© MESSWERTE (KRIA KV260 · Kria-1 historical/reference TRL 7; Kria-2 remains an engineering candidate)
Policy-Latenz (R5F RPMsg)
41.774 µs
DAR — FPGA/PL interlock future test target · not achieved
100.00 %
Recovery Rate
100.00 %
DFER — Fehlalarmrate
0.00 %
PromiseLive valueStatus
ISO/IEC 42001:2023 · KI-Managementsystem
Operational proof via R5F hardware log
✓ ALIGNED
EU Cyber Resilience Act 2024/2847 · Security by Design
Kria-1 R5F dient ausschließlich als Referenz-Policy-Logik. RPMsg ist nur Transport. Physische Speichertrennung, Schreibschutz, Gate-/Registerwirkung und Umgehungsresistenz sind nicht nachgewiesen. FPGA/PL-Aktuator-/Fallback-Interlock, Pin-, Aktuator- und Kill-Switch-Ausgänge sind künftige, nicht erreichte Integrationstestziele.
✓ ALIGNED
NIST AI RMF 1.0 · Trustworthiness
Measurability · Accountability · Hardware-Attestation
✓ ALIGNED
EU AI Act Art. 12 mapped for review
NATO AEP-101 mapped for review
FIPS 140-2: 39/39
Post-Quantum: ML-DSA-87 / CNSA 2.0
hardware_verified = false
Timestamp Domain Gate Latency Backend HITL Hash
Loading proof chain …

Source: api.ehox.io/chain · SHA-256 chained · off-host on R5F

GET api.ehox.io/status · open directly →

Why hardware-bound design?

Software promises.
Hardware proves.

Software guardrails live on the same machine they are meant to stop. The question is not which guardrail is strongest — it is whether the enforcement mechanism can itself be bypassed.

Criterion EHOX© (this) Software Guardrails
e.g. Constitutional AI, System Prompts
TEE Software
e.g. TrustZone, SGX
NOVACOV / NexQloud
SW-stack competitors Aug 2026
Enforcement mechanism ARM Cortex-R5F bare-metal · physically separate memory · no OS Same APU as AI process · bypassable by privileged code Enclave on same die · hypervisor bypass documented Software stack on general compute · no hardware isolation
Bypass possible? ✗ not demonstrated; open to independent challenge
No DMA from A53. No network. No OS.
✓ root / kernel exploit ⚠ hypervisor / side-channel ✓ software privilege escalation
Formal verification ✓ CBMC 201/0 · S1-S19
Explicit source-level properties · not firmware/release attestation
✗ none · assertion only ⚠ partial · implementation gap ✗ none published
EU AI Act Art.14 HITL ✓ T22 machine-proven
T1^T3^T9-T11^T20a^T20b^T21 ⊇ Art.14 §(1)-(5)
⚠ asserted · not proven ⚠ partial · no HITL chain ✗ not addressed
Governance decision latency 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement) (R5F internal)
228–487 µs end-to-end (RPMsg)
5–50 µs · jitter unbounded 1–10 ms · context switch overhead 10–100+ ms · network round-trip
Audit chain ✓ SHA-256 Merkle chain
34,343+ proofs · tamper-evident · EU AI Act Art.19
✗ log only · mutable ⚠ sealed log · not public ✗ proprietary · not auditable
Hardware trust certificates ✓ EHOX-GCA live
AGC issuable now · /v1/certify · machine-verifiable
✗ none ✗ none standardised ✗ none
ITAR-free / EU-sovereign ✓ Austria · EU supply chain
9 AT priority applications · A65094/2026 · Austrian origin
⚠ depends on provider ✗ Intel SGX = US export law ✗ US-incorporated
TRL Kria-1 historical/reference record; Kria-2 remains an engineering candidate
Physical release and enforcement not established
Kria-1 historical/reference TRL-8 self-assessment–9 · deployed · but SW-only TRL 6–7 · lab demonstration TRL 4–5 · prototype

Sources: Patent US12608476 B2 (NOVACOV, 21.04.2026) · NexQloud: no public architecture available (stealth, US-Navy evaluation) · Arm Architecture Reference Manual DDI 0487 · van Bulck et al., Foreshadow, USENIX Security 2018 · EHOX formal verification artefacts: api.ehox.io/formal · CBMC 6.9.0 · Z3 4.13.0 · Kria KV260 · 06.08.2026

Getting started

Three steps from
conversation to proof.

No pitch deck at the press of a button. No demo video. A concrete path that starts with your use case and ends with measurable results on real hardware.

Step 01

Preliminary discussion

30 minutes. We clarify use case, system environment and regulatory requirements. No NDA required for the first conversation — our formal proofs, live status, and audit chain are already public. An NDA becomes relevant once we discuss your specific integration details.

Agenda: use case · threat model · regulatory framework
Format: Remote or St. Johann in Tirol
Effort: 30 min · free of charge
Step 02

System demonstration

EHOX© live on EHOX Kria KV260, adapted to your use case. The Reviewer API is open — all results are machine-verifiable.

Content: live decisions · formal verification results · audit trail
Format: Remote or on-site
Effort: 2–4 hours · after preliminary meeting
Step 03

14-day pilot

Integration into your test environment. Complete EU AI Act-mapped for review audit trail, formally verified governance decisions, measurable from day 1.

Outcome: evidence mapping proof · audit log · integration documentation
Prerequisite: clear use case, defined threat model
Duration: 14 days · structured

Contact

Strategic partners, procurers, regulators, investors. Substance first.

Gerhard Hirschmann
Almdorf 9/Top 10 · 6380 St. Johann in Tirol · Austria
Reviewer-Token-Anfragen: [email protected]

FROM REFERENCE TO ENGINEERING PARTNER

Put the boundary where the decision matters.

EHOX is built for teams that need an independent place to examine authority before an autonomous command reaches a consequential system. Start with evidence from the Kria-1 reference foundation; shape Kria-2 around a real command path.

Candidate use cases
01 / AEROSPACE

Uncrewed flight

Review mission commands, operator hand-off and fallback conditions around a flight computer.

02 / INDUSTRIAL

Robotics & OT

Define an observable authority boundary for robots, cells and autonomous inspection systems.

03 / ENERGY

Energy & SMR

Explore bounded decisions, human approval and evidence around critical plant operations.

04 / MARITIME

Defence & maritime

Map command intent, escalation and reviewable records for remote and contested environments.

05 / INFRASTRUCTURE

Low-latency finance

Evaluate deterministic policy paths for trading, access and other high-consequence automation.

PUBLIC REVIEW SURFACE · READ ONLY

Reviewer Control Plane

A read-only public verification surface for reviewers to inspect runtime status, formal evidence, decision history and API scope without privileged access.

Runtime status

Current public runtime record and evidence pointers.

OPEN /STATUS →
Public proofs

Machine-readable formal and verification records for review.

OPEN /PROOFS →
Decision chain

A public audit/evidence chain for examining recorded decisions.

OPEN /CHAIN →
API documentation

Public endpoint documentation and reviewer scope.

OPEN /DOCS →

Review-only boundary: these surfaces expose evidence and documentation only. They grant no credential, boot, raw-device, actuator, policy-write, release, certification/compliance, hardware-trust or physical-enforcement authority.

KRIA-1 / PROVEN REFERENCE

Evaluate the reference foundation: formal verification artefacts, deterministic bare-metal R5F policy logic, the measured internal policy benchmark, and an audit/evidence record. These are reference results, not physical end-to-end enforcement.

KRIA-2 / ENGINEERING NEXT

Shape the independent candidate around your command path: interfaces, fault model, timing budget, human authority and evidence contract. RPMsg remains transport only; the FPGA/PL command interlock is a future integration target.

A SCOPED EVALUATION

Leave with an agreed test plan, measurable observations and a clear list of what is ready for the next engineering gate. No current physical enforcement, release, certification or compliance claim is implied.

Scoped evaluation engagement
1. Frame the commandChoose one use case, actor, action and fallback path.
2. Inspect the referenceReview Kria-1 artefacts, R5F behaviour, benchmark scope and evidence chain.
3. Define Kria-2Agree interfaces, measurements and the future FPGA/PL interlock test boundary.
4. Report the gateReceive a concise findings pack and a next-step decision for your programme.

EHOX is a candidate engineering path for internationally relevant autonomy programmes. Buyers can evaluate the reference evidence today and define the next hardware boundary without confusing a benchmark with an achieved actuator interlock.

Status boundary: Kria-1 is reference-only; Kria-2 is an engineering candidate; 44-ns Kria-1/internal R5F policy benchmark (not physical end-to-end enforcement); FPGA/PL command interlock remains future and not achieved.