EVA
A sovereign AI companion with a verifiable solving core: it distinguishes in code what it believes, what it verified and what is proven optimal.
What it is for
Offer a personal AI that lives with the user on their own machine — conversation, local voice and governed memory — and that, when the problem allows it, answers with certified solutions instead of opinions.
What it does
Converses with three-tier memory and voice that works offline, and routes optimisation problems — routing, job-shop scheduling — to a core where three computation planes compete over a monotone blackboard and a collapser certifies the result with its evidence level: I believe, I verified, proven optimal.
Sector
Sovereign personal assistants and verifiable optimisation: the same asset is a desktop companion and a certified-solving test bench.
What it improves
Against a chatbot, it removes blind trust: honesty is structural, a gate in the code prevents claiming as verified what was not verified. Against a solver, it adds conversation, memory and explanation on top of the certificate.
Target client
Personal use and teams that want a local AI with no data leaving the machine, plus researchers interested in the pre-registered experimental method.
Status and maturity
Verifiable core built, tested and measured, with two operational domains; conversation, governed memory, local voice and cockpit working. Future capabilities are declared absent by the product itself, with a probe per capability.
Differentiator
The non-negotiable separation between the cortex that proposes and the core that certifies, and a culture of published negative results: when the experiment contradicted the thesis, it was published as it was and the wrong conclusion retracted.
Commercial fit
A sovereign personal product and an embeddable certified-optimisation engine; pluggable domains allow horizontal growth without touching the core.
Architecture
Layered architecture
An AI companion that lives with the user on their own machine, built on a verifiable solving core: the cortex that converses and proposes is separated from the core that only certifies the provable. Honesty is not a writing style, it is a gate in the code that distinguishes three things an ordinary model mixes up: what it believes, what it has verified and what is proven optimal.
-
01
Verifiable solving core
Three heterogeneous computation planes — exact, evolutionary and predictive — compete in parallel processes over a monotone blackboard where knowledge can only improve, and a collapser verifies each candidate through filters of increasing cost. The rule is code, not convention: a conjecture may bias the search, never prune it.
-
02
Reduction boundary
The bridge between conversation and core: it decides which proposal enters the engine under a bounded budget and which stays outside as a hypothesis, and returns a certificate with its evidence level — I believe, I verified, proven optimal — that the answer must declare.
-
03
Governed memory
Three tiers with different rules: curated notes with a fixed budget always present, unlimited memories retrieved by relevance, and the full history on demand. EVA proposes writes to its curated memory but does not apply them without approval, and on reaching the limit it fails with an explanation instead of trimming silently.
-
04
Conversational cortex
The turn loop with tools and streaming replies. The prompt is assembled in deliberately ordered slots: identity outranks capabilities and tone goes last, so it modulates the voice without being able to redefine who EVA is.
-
05
Telemetry and experimental method
Every core run leaves a reproducible trace, and on top sits an experimental apparatus with acceptance criteria pre-registered before running and statistical contrast. When the central thesis came out against expectations, it was published as it was.
-
06
Local voice senses
On-device transcription, voice-activity detection, sentence-level chunking to start speaking as soon as the first one closes, and an optional wake word. Voice biometrics ask instead of asserting: asserting was measured to fail, and the design was built around that result.
-
07
Interface and reach
A text console with governance commands and a web cockpit where the metaphor is the skin and the data is the bone: every number comes from real telemetry and EVA’s figure moves only on measured signals. Completed by skills EVA can write for itself, messaging and scheduled tasks.
Inventory
Status per component
A real inventory of the asset’s components with their declared status. We publish capability, never code or internal figures.
-
Verifiable core: blackboard, planes and collapser
Built and testedThe most tested area of the system, with two operational domains — routing and job-shop scheduling — and verification through two independent code paths.
-
Three-tier memory and its governance
Built and testedHuman approval of writes enabled by default. The asymmetry is deliberate: the user configures EVA, and EVA has no tool whatsoever to touch its own settings.
-
Pre-registered experimental method
Built and testedAcceptance criteria are recorded before running and the report is regenerated from the trace. Negative results are published, and an earlier wrong conclusion was publicly retracted.
-
Sovereignty and prompt defence
Built and testedEverything lives on the user’s machine and the interface listens locally only. A common filter against instruction injection and invisible characters, with a different policy per text origin.
-
Cockpit and reach tooling
Functional with declared debtThe cockpit is validated mostly by compilation, with types generated from the contracts; messaging and skills have thin coverage and the skills catalogue is still empty.
-
Language model
Wired; depends on a third partyExternal provider through a compatible interface, with a real mitigation: pointed at a local model it runs at zero cost with no data leaving the machine. Default speech synthesis uses a third-party service with a fully offline fallback.
-
Vision, liveness and the introduction ceremony
Designed, not implementedDesigned and declared absent by the product itself: every capability has a probe that answers active, off or absent, so nobody mistakes a plan for a feature.
This profile describes capabilities and status, not implementation. Code, architecture documentation and internal figures are shared under a confidentiality agreement during due diligence.
Platforms
Moeris
Prepares an organisation for the day today’s cryptography stops protecting its data.
Hecate
Protects dozens of client companies from a single console, without mixing their data.
Nemea
Turns bank debt and real-estate portfolios into exploitable investment intelligence.
Infinity
Publishes new-build real-estate developments automatically, with its own viewer and the client’s brand.