CRLP · Commitment, Containment and Recovery

No valid commit permit.No external effect.

A candidate deterministic authorization layer for the exact moment an AI decision becomes a database change, model operation, payment, message, deployment or physical action. The first screen is the gateway itself: authorization must exist before any external effect exists.

Pre-production technical demonstration Single-host evidence Not NVIDIA certified, approved or adopted
Scroll
The gap

Safety must reach the destination.

Prompt controls, output filters, policy decisions and observability are important. They do not automatically prove that the exact external effect was authorized, current, unique and impossible to reuse.

CRLP is designed to verify before commitment, issue a signed single-use permit bound to the exact effect, enforce it at the destination, and preserve evidence.

Commit flow

From intent to verifiable effect—or no effect.

INTENTPENDING_COMMITPRECOMMIT VERIFYPERMIT / DENYDESTINATION ENFORCEMENTEFFECT / NO EFFECTEVIDENCE
01

Effect-bound

Permit binds tenant, release, model, policy, tool schema, effect digest, destination, nonce and expiry.

02

Single-use

Replay protection consumes the permit atomically and rejects duplicates or substitutions.

03

Fail-closed commitment

Unsafe commitment is denied while valid service paths may continue through reroute and recovery.

04

Evidence-first

Terminals, effects, manifests, hashes, receipts and recovery evidence are preserved.

Demonstrated on AWS

One live run. Seventeen final gates. Internally sealed evidence.

17/17final composite checks
2audited live runs: LOAD / UNLOAD
9/9host-network behavioral cases
67/67manifest-bound evidence artifacts
Evidence SHA-256710f94b194d5ad7e9f3c480906eb45b7043cbbdc9aec46f9167769a14ecdf4d5
Read the corrected audit
NVIDIA integration candidate

Complement the stack at commitment time.

Potential integration surfaces include NeMo Agent Toolkit tool middleware, NeMo Guardrails execution rails, Triton model management, NIM/API gateways and Kubernetes admission.

CRLP is not presented as a replacement for NVIDIA guardrails, inference runtimes, identity, policy engines or observability. It is a candidate destination-enforced commit authority.

Request technical review
Claim boundary

Ambitious, but not exaggerated.

Demonstrated: a single-host pre-production live pilot with PostgreSQL and Triton effects, final gate, cleanup and internal evidence seal.

Not yet demonstrated: production readiness, enterprise-wide no-bypass coverage, independent key custody, NIM-native enforcement, distributed federation, or NVIDIA certification, approval or adoption.

Naming clarity. In the R3.5 product line, CRLP means Commitment, Containment and Recovery Layer. The historical Cache Refresh & Lineage Protocol branch is preserved separately and unchanged at CRLP Cache Sentinel.

Public evidence snapshot: CRLP R3.5 v0.2.5 RC01 · evidence SHA-256 710f94b194d5ad7e9f3c480906eb45b7043cbbdc9aec46f9167769a14ecdf4d5

Continue exploring

Return to MADRE and the VEHICLE Systems Lab home.

BACK / MADRE