The four guarantees
Routine work runs on its own. These four checks apply to the actions that matter: money, access, data and changes to systems.
A policy gate before the action
A deterministic gate reads the proposed action and decides: allow, escalate or deny. The rules are code you can read, not a prompt a model can talk its way around.
A rollback path after it
Every change keeps a way back. Decisions and records are superseded with a pointer to what replaced them, never overwritten.
A record a reviewer can check
Each decision goes on an append-only ledger. Every entry carries the hash of the one before it, so editing any entry breaks the chain at that point.
A person who approves
Unusual actions wait for a person. Risky ones are blocked before anything moves. The person's decision goes on the ledger too.
The independent checker
No work counts as done on the worker's own word. A separate checker gates every material step. It runs the test, reads the file or probes the system itself, then records what it found.
A claim without that evidence does not count. The same rule applies to people and to agents.
Owned compute
Agents run on hardware you control, with local inference. Disconnected operation is a supported deployment profile. Sensitive data never leaves the environment.
Cost stays predictable, because there is no per-token cloud bill that grows with every agent.
The evidence ledger, in public
Our internal ledger stays private, but a slice of it is public. White paper v2.3 is bound to ledger entries 3399 to 3428 by a dated addendum.
The public spend governor keeps its ledger the same way: each entry carries the hash of the one before it. Its demo edits one recorded entry on a copy and shows the verifier catching the edit:
# runs offline; exits 0 on pass and prints the index where the chain breaks
git clone https://github.com/cerebrocybersolutions/cortex-governor
cd cortex-governor
python3 demo_scenario.py
White paper v2.3
The architecture behind everything on this page, released 4 October 2026. Every file is hash-stamped, so you can confirm that what you downloaded is what we published.
To check the files, clone the repository and run two commands:
git clone https://github.com/cerebrocybersolutions/cerebro-whitepaper cd cerebro-whitepaper shasum -a 256 -c SHA256SUMS python3 verify_hash_stamp.py VERIFICATION.md
A clean run prints hash stamp clean. An edited or swapped file exits 1 and names the file.
The paper is licensed CC BY-ND 4.0. The checker script is Apache 2.0.
See it run
Questions
What is governed AI?
An AI system where every consequential action passes four checks. A policy gate before it runs. A rollback path after it. A tamper-evident record a reviewer can check. A person who approves anything unusual.
Can governed AI run without an internet connection?
Yes. Local inference on hardware you control is the default, and disconnected operation is a supported deployment profile.
How do I check your claims?
Clone the white paper repository and run its two checks, then run the tamper demo in cortex-governor. None of it needs an account or a call with us.
Who builds this?
Cerebro Cyber Solutions, a service-disabled veteran-owned small business. We run our own company on the same platform, as customer zero.