Skip to content
Research library
Findings update 003 July 17, 2026 Locally source-verified

Policy worked; learned-state gates did not

The useful advance is deterministic and governed: audited policy artifacts can drive a source-blind local runtime inside a zero-authority sandbox. The learned/native lane remains unproven, and HEATWAKE's first bounded public capture remains raw execution evidence—not a signal, edge, or trading result.

Waggle + Kea

17/17 · 25/25

The bounded policy compiler and founder dry-run crossed their exact fixture gates with authority disabled.

Learned/native lane

0 model loads

C7NL1 and C7NL2 both stopped at admission; no training or hidden evaluation ran.

HEATWAKE

2,337 raw records

One 45-second public canary passed deep custody verification and remains excluded from features, labels, calibration, and candidate selection.

Jump to a findings section
Executive finding

A narrow positive result and a decisive negative result.

Waggle + Kea completed two bounded policy checkpoints. Three Kea-qualified declarative programs routed 17/17 withheld records in a generic source-blind process, and the founder dry-run passed 25/25 frozen checks while preserving exact original and corrected replay. Plain JSON matched the compiled policies, so no unique encoding or language claim follows. Two later learned/native admission attempts stopped before model load: the first at a sandbox resource preflight and the second at a frozen launcher hash check. HEATWAKE separately deep-verified a 45-second, 2,337-record public market-data canary with zero credentials, orders, trades, spend, model writes, calibration reads, or final-test access. The capture is permanently excluded from the model path unless a later admission contract passes.

How this was verified

Claims, controls, receipts, reruns.

1

Snapshot comparison

The July 16 published source labels were compared with later clean commits, aggregate reports, frozen protocols, receipts, test definitions, and current program state.

2

No-call replay

Stored C7b, C7c, C7d, and C7e evidence was replayed without provider calls. Focused C7 and learned-state suites, TypeScript, and the production build were rerun from the committed Waggle/Kea snapshot.

3

Private receipt verification

The HEATWAKE canary's owner-only receipt and complete hash-chained event file were deep-verified locally. Raw events, market identifiers, local locations, and reconstruction-enabling details remain private.

4

Claim separation

Archived provider runs are distinguished from this zero-call publication replay. Raw market capture is distinguished from model-data admission, and local source verification is not described as peer review or independent validation.

Program 01

Waggle + Kea

Audited machine coordination with deterministic authority boundaries

Full program

Verdict

Supported in bounded fixtures: audited declarative policies drove exact source-blind local routing and founder replay. Not supported: unique Waggle encoding utility, a learned private language, learned/native bottleneck utility, production behavior, or authority.

The new sequence separates cache behavior, audited policy capability, founder usability, and learned/native admission. Cache evidence remained negative or discovery-only; policy capability crossed its narrow gates; both learned/native admissions stopped before model load.

Finding 1.1 Negative result

Cache-affine program utility remained unsupported

8/8 vs 8/8 · both artifacts passed

The final fresh-route confirmation produced eight exact decisions and the same passing allowlisted program in both cache-affine and cold-control arms. Stored zero-call replay reproduced that result.

Boundary: Reported cache reads differed, but actual provider cost and purchased-credit use were not reported. Requests still carried full prompt bytes, and the result supports neither savings nor unique capability.

Finding 1.2 Negative result

The cached deadline formal run was correctly withheld

30.456 s projected vs 28.178 s control

Discovery returned 2/2 exact decisions in both arms and meaningful cache reads in the affinity arm. After charging the required prime, the eight-task affinity projection was slower, so the held-out formal run was not launched.

Boundary: This is a completed negative admission decision, not a formal capability comparison. Five archived provider calls occurred in discovery; today's replay made zero.

Finding 1.3 Supported in scope

Audited policy artifacts enabled a bounded program

17/17 exact · no-channel 4/4 fail-closed

Three Kea-qualified declarative artifacts routed withheld support, release, and fulfillment records exactly in a generic source-blind local process. One unresolved policy abstained, and every no-channel control failed closed.

Boundary: Matched plain JSON produced the same results. The checkpoint demonstrates a governed declarative-artifact path, not a language, unique encoding advantage, general reasoning, savings, production behavior, or authority.

Finding 1.4 Supported in scope

The founder policy dry-run crossed its product gate

25/25 frozen checks · 6/6 original and corrected

One bounded policy compiled into a local sandbox, replayed immutable original and causal correction lineage, and produced six exact outputs from both revisions. An ambiguous policy abstained and simulation failed closed.

Boundary: A later invocation of the whole frozen scorer exposed a byte-replay reentry defect. It made zero provider calls and did not change the sealed 25/25 result, but a fully replayable whole-scorer claim remains false.

Finding 1.5 Negative result

Two learned/native admissions stopped before model load

C7NL1: 0 loads · C7NL2: 0 loads

The first preregistered lane stopped at its sandbox resource preflight. A process-enumeration-free recovery then passed unscored discovery but failed the frozen launcher hash check before scored resource measurement.

Boundary: Neither failure is a model-quality result. Training, hidden evaluation, forwards, downloads, provider calls, and authority effects were all zero; learned-state utility and language claims remain untested.

Not demonstrated

  • No learned Waggle protocol, private language, neuralese, trained bottleneck utility, cross-model transfer, or semantic decoding claim.
  • No provider cache reliability, purchased-credit savings, token savings, network savings, or overall-efficiency result.
  • The policy results use bounded declarative fixtures, allowlists, and zero-authority local consumers; they are not arbitrary code execution or production policy enforcement.
  • No customer result, revenue, deployment authority, or consequential action.

Next legitimate gates

  1. 1. Repair the scored admission launcher prospectively, freeze the new bytes, and pass the exact-model canary before any training.
  2. 2. Make the whole C7e scorer reentrant without rewriting the sealed first-run evidence.
  3. 3. Evaluate the governed policy path on new task families while retaining matched plain-JSON controls and fail-closed authority envelopes.
Program 02

HEATWAKE

Raw execution observation with the model and trading boundaries still closed

Full program

Verdict

Supported: one frozen 45-second public market-data canary passed complete local receipt verification. Not supported: a complete market capture, historical execution bundle, model-data admission, forecast, market edge, profitability, or trading readiness.

HEATWAKE now has a bounded public, unauthenticated, raw-only capture path. The first canary proves custody and protocol mechanics, not market validity. Ongoing pre-final work has no terminal empirical verdict, and the public policy remains ABSTAIN.

Finding 2.1 Supported in scope

One raw-only public canary passed

45 s · 2,337 records · 0 gaps

The frozen collector retained initial and streaming books for both outcomes, four heartbeat pairs, zero reconnects, and a complete hash chain. The owner-only receipt and event file replayed byte-exactly.

Boundary: This was one short current-market window. It is not a complete market, does not reconstruct historical depth, and cannot substantiate execution quality, edge, profitability, or trading readiness.

Finding 2.2 Boundary finding

The model boundary remained closed

0 feature writes · 0 labels · 0 calibration reads

The capture contract permanently excludes the raw bytes from model features, labels, targets, calibration, and candidate selection until a separate cutoff-alignment and admission contract passes.

Boundary: A successful network capture is not model-data admission or empirical model evidence. The sealed final test remained unopened and the current public action remains ABSTAIN.

Finding 2.3 Boundary finding

No trading or paid authority crossed the canary

0 credentials · 0 orders · $0 spend

The archived canary used public discovery, two public book requests, and one unauthenticated market-data connection. It had no wallet, authenticated channel, order route, position, capital, or purchase surface.

Boundary: This establishes only the tested public capture mechanics. It does not establish production provider access, a live trading system, operational reliability, or permission for future captures.

Finding 2.4 Boundary finding

The safe-local release boundary stayed explicit

338 runtime sources · 0 high findings

The committed safe-local audit v83 reports zero high-severity findings across its runtime-source inventory.

Boundary: Repository licensing, dependency-license compatibility, empirical source admission, and release authority remain blockers. The audit does not certify production security, release compliance, training readiness, or trading readiness.

Not demonstrated

  • No admitted model corpus, empirical final-test result, validated forecast, market edge, profitability, or trading result.
  • No complete market capture, historical L2 reconstruction, queue reconstruction, or December 2025 execution bundle.
  • No credentials, authentication, order, trade, capital, spend, production deployment, or release authority.
  • The raw receipt and event bytes remain private; public hashes do not link to a downloadable confidential artifact.

Next legitimate gates

  1. 1. Finish the existing label-blind recovery and retained walk-forward chain without duplicating its writers or opening the final test.
  2. 2. Freeze a separate full-window capture lifecycle before any future retained market window.
  3. 3. Require exact cutoff alignment and a new admission decision before any raw execution observation can enter paper economics.
Cross-program finding

Cross-program conclusions.

Admission failures stayed scientific results

C7NL1 and C7NL2 were not rescued by changing the model, data, gate, or scorer after failure. Zero model loads remained the exact result.

Governed structure produced the positive result

The Waggle/Kea advance came from qualified declarative artifacts, immutable corrections, explicit abstention, and sandboxed zero-authority consumption—not opaque execution.

Capture and admission remained separate

HEATWAKE could verify a real public data path while keeping those bytes outside every model, label, calibration, selection, final-test, and trading surface.

The public site is part of the evidence chain

This release restores the prior dated report, ledger, and checksum after a later product deployment removed them from the live research surface.

Limitations and disclosures

Limits on the reported findings.

  1. 1All verification described here is local source verification by K&E Studios Research, not peer review or independent validation.
  2. 2Archived Waggle/Kea studies made bounded provider requests during their original formal runs. This publication replay launched zero provider calls and did not treat archived output as fresh provider evidence.
  3. 3The HEATWAKE canary made one public discovery request, two public book requests, and one unauthenticated market-data connection during its original 45-second run. Today's verification made no network request and captured no new bytes.
  4. 4The public evidence ledger exposes aggregate measurements, clean source commit labels, and non-reversible hashes only. It withholds private repositories, paths, raw receipts, market payloads, model state, prompts, credentials, and reconstruction-enabling artifacts.
Fresh local rerun ledger

Rechecked from the source trees.

Waggle + Kea changed gates

PASS

C7b, C7c, C7d, and C7e stored evidence replayed with zero provider calls. Five focused C7 suites, two learned-state suites, the 1,000-case public-fixture audit, TypeScript, and the production build passed.

HEATWAKE raw-only canary

PASS

Nine focused capture, schema, authority, refusal, and tamper tests passed. Cold preflight made zero requests, and deep receipt verification reproduced all 2,337 records, hashes, counts, and zero-effect fields.

HEATWAKE ongoing pre-final state

NO TERMINAL CLAIM

The existing recovery, evaluation, and pre-final chain remained active or waiting at inspection time. No terminal empirical result was promoted, no duplicate writer was created, and the final test remained sealed.

External effects from heartbeat verification

ZERO

No provider call, paid request, email, source acquisition, new market capture, model load, training run, final-test open, order, trade, capital movement, authority grant, or research-harness deployment occurred during publication verification.

The material delta is a bounded policy capability with exact refusal and correction behavior, paired with two honest learned-state admission failures. HEATWAKE added one verified raw-only public observation path, but that path remains outside the model and outside every trading claim. Deterministic governance advanced; learned language, market validity, and production authority did not.

Author and research contact

William Keenan · K&E Studios Research

william@kestudios.dev
Author profile