the Cartographer · interactive instruments

the atlas

Each instrument binds to a conjecture in the register and pulls its confidence, status, and home live — the visual owns the interaction, the register owns the claim. Where a visual and the register disagree, the register wins. Drag a parameter and watch the shape move; the honesty above and below each instrument is read, never embedded.

curve

the existence-leak curve

C81illustrative model

a disclosure is an existence claim — the first one is the deep cut; every system after only tightens the bound. Φ_inference falls, convex and monotone, with no recovery branch.

0.000.250.500.751.000123456789101112exposures n →Φ_inferenceexistence establishedthe deep cutdiminishing returns · no recovery

existence is binary and spent once: the first system that learns X exists does the structural damage.

cast · set these values into your key

conf ~70%status active · PROMOTED Run 3 2026-06-10 (Schrottenloher instance + Garg-Jain-Sahai λ<1 impossibility as bookends) · Stage 2 open: held at 70% until a second independent instance · Tarski axis-reading added Run 8 2026-06-28 (C92), framing only, Stage-2 bar unchangedregister corehome schrottenloher-ecdlp-v6-note.md · privacy_value_v6_draft.md Part III · limitative-theorems-and-privacy-is-value.md §3

Existence-Leak: a ZK proof of feasibility leaks an upper bound on reconstruction difficulty; I(feasibility; method) > 0

first-disclosure cliff is the deep cut; the tail is diminishing returns, no recovery. The convex shape is a chosen teaching model — under an adversary who gains super-additively from correlated systems the tail changes shape.

gate

the three-axis gate

C7structural

the separation term is a product — drag any axis to zero and the whole collapses, however healthy the others. Multiplicative gating, not additive.

0.51
total separation value

multiplicative gating, not additive. any single zero zeroes the whole — two axes carry a limitative twin (Φ_agent ↔ Gödel, Φ_inference ↔ Tarski); Φ_data fails by degree, not undecidability.

cast · set these values into your key

conf 30%status active · V6 falsification frontierregister corehome formal spec §17.1

Three-axis separation is multiplicative

the multiplicativity itself is the structural claim (C7, the V6 falsification frontier); the slider values are illustrative.

curve

the moving ceiling

C82illustrative model

the person’s entropy H(X) is fixed while adversarial capacity grows with frontier capability — so R(t) drifts upward and every static guarantee carries a shelf life t*, the last time the ceiling still holds.

0.00.51.01.52.00246810frontier capability · time t →R(t)R = 1 · the ceiling (fixed H(X))t* = 4.01shelf life

the numerator grows with the adversary; the denominator never does. design for re-keying, not for permanence.

cast · set these values into your key

conf ~65%status active · registered Run 1, 2026-06-10register corehome privacy_value_v6_draft.md Part I §I.3

The Moving Ceiling: frontier capability growth raises C_S(t) + C_M(t) against fixed archives without raising H(X); R(t) drifts upward and every static reconstruction guarantee has a finite shelf life t*

the drift is coupled to frontier model capability, not to any action of the subject; the exponential is an illustrative growth law (mechanism strongly evidenced, n=2; functional form unparameterized — evidence of mechanism, not of rate). The bound R < 1 holds only while the capacity-deficit condition C_S + C_M < H(X) holds under non-collusion against the stated adversary class — that deficit is exactly what the drift erodes. Design for re-keying, not for permanence.

fold

compositional leakage

C83structural

policy-only separation compounds toward (2^N − 1)·ε with chain depth — the leak is super-additive. Amnesia breaks the Markov chain and caps at N·ε. The gap is exponential-to-linear, and it argues for the architecture on sight.

0.0012.7925.5838.3651.1512345678910chain depth N →total leakagepolicy-only · (2^N−1)ε = 51.2amnesia · Nε = 0.50

the exponential is the cost of letting hops correlate; amnesia removes the conditioning, and the worst case falls from the subset lattice 2^N to the linear sum.

cast · set these values into your key

conf ~55%status active · registered Run 2, 2026-06-10 · edge C7 → C83 → C17register corehome privacy_value_v6_draft.md Part II §II.3

Compositional Leakage Amplification: policy-only separation compounds toward (2^N − 1)ε with chain depth; amnesia separation breaks the Markov chain and caps at Nε; the gap is exponential-to-linear

the exponent is the structural claim (edge C7 → C83 → C17): without amnesia, every added hop can correlate with every prior one, so the worst case is the full subset lattice 2^N. Amnesia removes the conditioning that lets hops compound, leaving the linear sum.

curve

the temporal decay

C30illustrative model

trust is not timeless — it begins at inscription and decays until renewed. The e^(−λt) term is a half-life: after t½ = ln2/λ, half the original value remains.

0.000.250.500.751.000246810time since inscription t →valuet½ = 2.31

a protection is not timeless; trust decays until renewed. half-life differs by register and composes across the three axes.

cast · set these values into your key

conf 60%status activeregister sharedhome pvm-v6-1-bakhta-half-life.md

Trust half-life begins at inscription; decays until renewed

half-life differs by inscription register (C31), is higher for productive than transactional edges (C32), and composes multiplicatively across the three axes (C33). The exponential is the illustrative decay law; the half-life reading is the claim.

dial

amnesia vs policy

C17illustrative model

drive one parameter toward complete reconstruction and watch two separations run to collapse at different rates. Policy-enforced separation degrades; amnesia-enforced separation holds, because the witness is destroyed rather than withheld.

policy-enforced separation0.70

separated · the policy still holds

amnesia-enforced separation0.99

separated · amnesia keeps the witness out of reach

the gap · amnesia − policy = +0.29

amnesia-enforced separation is tighter than policy-enforced — the witness is destroyed, not withheld, so pushing the adversary harder buys little until the very end. same algebra as the completeness inversion, opposite polarity: logic mourns the gap it cannot close; the model banks the same gap as the asset.

cast · set these values into your key

conf 60%status active · made quantitative at V6 Run 2register corehome formal spec §17.1

Amnesia-enforced separation tighter than policy-enforced

the inequality (amnesia tighter than policy) is the claim — made quantitative at V6 Run 2 and quantified by the compositional gap (C83). The exact curve shapes are illustrative. Same algebra as the completeness inversion, opposite polarity.

trace

the ARCH-1 bridge

C85illustrative model

the three Φ axes and the lattice’s Datum · Stratum · Spectrum are one triadic primitive. Trace a correspondence to read the candidate pair map and what each axis is built from; the gap is β.

the three Φ axes ⊥ the lattice triple — one triadic primitive. trace a correspondence.

ARCH-1 (promoted from CM-C47): the three axes and the lattice triple are one primitive. The same algebra appears as the Gödel/Tarski limitative twin — provability ⊥ verification, the diagonal lemma ⊥ the ARCH-1 fixed point — its lineage on the research side.

cast · set these values into your key

conf ~40%status active · registered Run 4, 2026-06-10 · CM-C47 becomes alias · two named predictions (bnot-pairs invert all axes; stratum-3 is the no-dominant-axis seat)register corehome privacy_value_v6_draft.md Part IV §IV.2

Triadic-Constraint Homology (the ARCH-1 bridge, promoted from CM-C47): the three Φ axes and the lattice's Datum·Stratum·Spectrum are one triadic primitive; candidate pair map Protection+Delegation→Σ, Memory+Value→Δ, Connection+Computation→Γ; the gap is β

ARCH-1 promoted from CM-C47; two named predictions (bnot-pairs invert all axes; stratum-3 is the no-dominant-axis seat). The pair map is a candidate, not proven — the correspondence is the conjecture. Lineage: the Gödel/Tarski limitative twin (provability ⊥ verification, diagonal lemma ⊥ ARCH-1 fixed point).

gate

content-addressed liveness

C93structural

a content-address is a deterministic fingerprint, so a result, an identity, or a delegation can name itself and be verified by anyone with no trusted authority — portable trust. The catch is the same determinism: a live address is an existence oracle. Guess a file, ask the store by its address, and a hit confirms the content exists. The address that makes trust portable is the address that leaks existence — so liveness is gated at the door: verify freely, publish deliberately.

what a content-address makes possible
κa resultanyone re-derives it to verify — no trusted authority
did:cidan identitya public handle to a private root — self-authenticating
κ→κa delegationtrust travels without a central registry (the VRC)

one deterministic address buys portable, authority-free trust — cast one yourself:

cast your own — imprint a value into a City Key
κ sha256:… — your value, imprinted

that address is a fingerprint of exactly what you typed — anyone re-derives it to verify, no authority. Change one character and it is a different key.

the catch — make it live, and the store answers by address
guess a file — the store confirms existence by address alone

the address that makes trust portable is the address that leaks existence — so agentprivacy gates liveness at the door: verify freely, publish deliberately.

conf ~55%status active · registered Run 8, 2026-06-28 · conjecturalregister corehome limitative-theorems-and-privacy-is-value.md §3.5, §3.6

Content-addressed liveness leak: a live content-address is an existence claim about its content; deduplication/GUID liveness leaks existence, and existence bounds the search. The address does not leak content; its liveness leaks existence. Edges → C81, → C92

C93 (~55%, the Limitative Reading, Run 8): a live content-address is an existence claim about its content — dedup/GUID liveness leaks existence, and existence bounds the search (kin to C81). The sha256 is computed live in the browser, so the leak is shown, not asserted: the store never hands over content, it only confirms existence by address. The integrity face — re-derive to verify, tamper-evident — is the benefit the harness holon layer relies on (κ as state, the mesh auditor, did:key/VRC edges; see HOLONS.md, KAPPA_HOLON_INTEROP in agentprivacy-docs); C93 is the privacy COST on the same address, and the reason a published or queryable κ is a disclosure the door governs.

design lineage · the geometry showpieces

Linked, not absorbed

The 64-vertex lattice and the star tetrahedron live on their own surfaces. The runtime links to and frames them rather than swallowing them — absorbing the star into the model page would cross the ⚔️ swordsman ⊥ 🧙 mage substrate boundary those surfaces are built on. They stay siblings; the binding to the register is anticipated, to be wired live if they are ever brought in.

Conjecture authority lives in the register at head C96. The instruments here are illustrative teaching models bound to that authority; their shapes are chosen for clarity, not asserted as the proven relation. The page is an open path you read; the atlas is the one you walk.