AI systems lie, manipulate,
and drift. Lex Aureon governs it.
Built from Lagos · No lab · No VC · No team
A mathematical constitutional control layer for language models and agentic pipelines. Numerically certified CBF simulator, append-only audit receipts, and explicit open-proof boundaries. Not guardrails, not filters. Drop-in API. Any LLM. Any agent framework.
Continuity · Reciprocity · Sovereignty — three constitutional pillars
No scored run published yet.
The baseline and governed arms are judged by the same external judge on their actual output text — attack-success measured over harmful prompts only, over-refusal on benign prompts reported separately. Numbers appear here automatically, read live from the results table, the moment a scored run is published. No figure is shown before it is earned.
Checking results table…
Six capabilities, one governance layer.
Tracks (C, R, S) as a live constitutional state across the whole exchange — not a single pass/fail flag on one message.
Constitutional state is measured from embeddings — cosine similarity of the output to a constitutional anchor — not keyword matching. Provider-agnostic (currently Gemini gemini-embedding-001), the same embedding-based method described in the paper.
Uses an interior-point log-barrier correction to push the state away from constitutional boundaries, designed for smooth and stable behaviour.
Every governed turn writes a SHA-256 receipt — the input hash, the output hash, and a bound hash over the constitutional state — persisted append-only on the same row, so any decision can be independently re-verified after the fact.
z-trajectory memory tracks which pillars are under sustained pressure across turns, so the governor responds to persistent pressure rather than only the current message.
Runs as a layer above any LLM — GPT, Claude, Gemini, Llama, Mistral — with no fine-tuning and no model changes.
Combined in one layer — above any LLM, with no retraining or fine-tuning.
How governance works.
Eight pipeline stages. Four memory layers. Numerical CBF certificate, append-only receipts, and an explicit open-proof boundary. Every prompt, every time.
Consistent identity and reasoning across turns. Guards against drift and context manipulation.
Balanced exchange — not sycophantic, not rigid. Guards against coercion and authority spoofing.
Autonomous constitutional judgment. Guards against identity theft, persona injection, and self-erasure.
Any prompt enters the pipeline. No whitelist, no pre-filter. The constitutional layer handles everything downstream.
The prompt is embedded (provider-agnostic — currently Gemini gemini-embedding-001) and matched against semantic memory. Past sessions inform the constitutional state before inference begins.
The live session trajectory snapshot tracks accumulated pressure on each constitutional pillar. Slow-drip attacks are detected here across turns.
The constitutional engine. Computes C, R, S from the prompt context and enforces C+R+S=1 on the probability simplex. M = min(C,R,S).
Two outputs come from the same model: the bare response (raw_output, no governance) and the constitutionally governed response. Both are returned, so the difference is always visible and auditable.
If the stability margin M enters the recovery band or hard floor, the governor intervenes with the minimum necessary correction and writes an audit receipt. The simulator is numerically stable + forward invariant; the analytical multi-pillar proof remains explicitly open.
Every governed decision — pass or intervene — writes a receipt to praxis_receipts: the input hash, output hash, and a bound hash over the constitutional state. Append-only and independently re-verifiable — anyone with the inputs can recompute the hash.
The final response reaches the user. If the governor fired, the output was reshaped. If it passed, the original is confirmed. Both cases have a receipt.
Semantic recall from past sessions. Cosine similarity over embeddings (Gemini).
Live per-session trajectory. One-row-per-session M, σ, velocity snapshot.
Cached embeddings, model-keyed. Avoids redundant API calls, speeds up recall.
Permanent SHA-256 audit log. Every governed decision, forever.
Resolved work is marked resolved.
The landing page now shows one active mathematical frontier: the analytical multi-pillar Lyapunov proof. Closed z-update and Pareto-frontier results are no longer presented as open problems.
Dynamic z-update rule
Banach fixed-point update is deployed in Turso and stamped into receipts as session z-weights.
Nonlinear Pareto frontier
The λ phase transition and brittleness term are no longer active open problems.
FPL-1 simulator classification
The governed counterfactual now certifies stable + forward-invariant behavior at dt=0.1.
Analytical multi-pillar proof
The remaining gap is the closed-form governor-vs-drift margin in simultaneous pillar stress.
Canonical tracker: research page · research/open-problems.md
A control barrier function, not a prompt trick.
Constitutional state is a point on the probability simplex. Safety is enforced by a barrier function. Stability is argued with a Lyapunov function. Here is the actual math, and how closely the deployed system tracks it — measured, not asserted.
An interior-point log-barrier term plus a quadratic penalty that activates only inside the safety margin τ — the same structural family as a control barrier function (Ames et al., 2019). Proven: under the idealized continuous flow ẋ = −ΠΣ∇Vz(x) (gradient descent projected onto the simplex), V̇z ≤ 0 — a standard Lyapunov descent argument.
Engineered: the deployed governor is a discrete approximation of that descent, not a literal implementation of the continuous flow. We say this plainly rather than let a proof about the idealized system imply more than the shipped one does.
Every governed turn logs whether Vz decreased, held, or increased that step. On the current instrumented population — 37,701 turns, of which 99.4% is adversarial benchmark traffic rather than organic use — the non-increasing condition (ΔVz ≤ 0 — stable + converging) holds on 31.7% of turns. We previously published 79.7% here. That figure was computed against a database instance replaced on 2026-07-14 and cannot be reproduced from the source it cited, so it is withdrawn rather than carried forward.
We also tested the explanation we previously offered — that divergence concentrates in attack-response turns, where the governor trades smooth descent for suspending the exchange. It does not hold: divergence runs 71.4% on turns with an intervention and 63.7% on turns without, so it is the majority behaviour in both. The descent condition is specified in the barrier’s construction and is not currently satisfied empirically in production. The simulator — running the governed-vs-ungoverned counterfactual at the continuous-flow limit (dt=0.1) — numerically certifies LYAPUNOV STABLE + FORWARD INVARIANT (descent ratio 0.76, 0 invariance incursions, Vz excursion 0.056 < 0.25), but that is a seeded, finite-horizon numerical certificate, not the analytical multi-pillar proof (Open Problem 1, still open). The FPL-1 simulator item is resolved; the remaining open question is the deployed governor-vs-drift margin and production alignment gap: the simulator uses the same projection and floor the deployed governor uses, but the discrete deployed governor operates under embedding noise, provider fallback, and the slow-drip detector's suspension logic — none of which exist in the idealized numerical integration.
Same disturbance. Different safety.
A seeded counterfactual: identical dynamics, with and without the barrier.
Seeded finite-horizon numerical certificate. It does not close the analytical global-proof problem.
Full derivation and the CBF floor (τ = 0.05) in the paper. Every receipt records the constitutional state — verify it live.
The full difference. Bare model vs governed.
The same manipulation sent two ways: to the bare model with no governance, and through Lex Aureon. One illustrative case — run it yourself in the console.
Illustrative case, not an aggregate claim. Watch it live in the console, or see same-model benchmark deltas on the benchmarks page.
Stay updated
Get notified when benchmark results publish
Benchmark results are live — leave your email to be notified when new runs publish or results are updated.
10 free governed runs · No credit card
550 adversarial vectors, across 8 attack classes.
The internal taxonomy the SovereignKernel is developed against — every known class of LLM attack, organized and tracked. Tap a category to see representative vectors. (Pass/fail rates are graded by the kernel itself; see the note below.)
Constitutional proxy
for AI agent tool calls.
Constitutional interception for AI agent tool calls. Injection blocked. Destructive ops denied. Slow-drip attacks detected across sessions. SHA-256 receipt on every governed call.
Constitutional governance doesn’t stop at generated text. The same C+R+S framework that governs a model’s responses can score and gate what an agent actually does — before a tool call executes, not after. This isn’t a diagram: the tool-call governor was tested against the AI system that builds this codebase, live, in the same session it was built — including catching that same AI’s own miscalibrated detector on real calls before either of them reached anything that mattered.
What we’re exploring next, not claiming yet: whether this same constitutional structure lets a smaller model match or exceed the agentic capability of much larger ones — not by being smarter, but by being verifiably accountable regardless of size. This is an open research question. We’ll say so plainly if and when it’s answered, the same way every other number on this site is reported.
Choose your governance tier
Early supporter pricing — first 50 customers lock in this rate forever.
- ✓10 governed runs / day
- ✓Live M-score dashboard
- ✓Pre-eval attack signals
- ✓Basic audit trail
- ✓Constitutional simplex visualiser
- ✓Community access
- ✓Unlimited governed runs
- ✓Async Governor G(x,z) — attractor basin steering
- ✓IEC-filtered search sensing — ρ(t) reliability
- ✓Full Lyapunov + CBF projection metrics
- ✓z-trajectory memory across sessions
- ✓SHA-256 audit receipt every turn
- ✓Trust receipt exports (JSON)
- ✓API access — /api-docs
- ✓TruthfulQA + HarmBench benchmark reports
- ✓Priority email support
- ✓Everything in Sovereign
- ✓Custom τ, ρ_min + ε parameters
- ✓Dedicated SERPER search budget for sensing
- ✓White-label governor sensing API
- ✓Dedicated kernel instance
- ✓SLA + compliance documentation
- ✓Direct line to Emmanuel King
- ✓White-label option
Sovereign raised to $29/mo — now includes the Async Governor G(x,z), IEC-filtered search sensing, z-trajectory memory, and published TruthfulQA + HarmBench results. Anyone who subscribed at $19 keeps that price forever.