The Measured Kernel
A self that knows what it does not know.
Every AI in the world is building a version of you that you will never see. Your mail knows how you write. Your phone knows where you go. A dozen models have read something of yours and formed an opinion. None of it is yours, none of it is auditable, and not one of those versions can tell you where it is guessing.
This one is yours. And it is the only one we know of that ships its own ignorance.
Five properties, and the mechanism behind each
1 · It answers from what was actually said
Every sentence in the archive carries its provenance — said, or inferred — and its date. An Echo answering from an inference says so; an Echo with nothing says nothing. The provenance is not a label added afterwards: a memory the weaver cannot support with the person's own words never reaches the archive at all.
2 · It abstains, and the threshold is derived rather than chosen
Abstention is easy to promise and almost never measured. Here it is a bound: conformal risk control, a Hoeffding inequality, one number chosen by a human (the error rate we accept), a floor of observations under which it refuses to conclude at all, and a module that writes down the three things it does not guarantee. The threshold comes out of the outcomes. Nobody tunes it.
3 · It declares its own coverage — and what was never said
A score is a fraction and a fraction needs a denominator. Ours is 404 written quests and 2290 written questions, enumerable, with a record of which were answered. That is what makes the sentence below possible, and no other system on earth can write it:
“Across 46 answered questions that could have brought up brothers and sisters, not one does.”
That is not a gap in the data. It is a result — counted, bounded by its own coverage, and auditable. It carries its caveat with it, always: An absence in an archive is not an absence in a life. And it stays silent where the evidence is not structured, beside a loss, under a class's own floor, or when only a first name was ever used. Today the thinnest classes are brothers and sisters (46), grandparents, and further back (48), a mother, or whoever filled that place (56) — which is exactly where the next questions get written.
4 · It carries a score judged blind by somebody who loves the person
Two answers to the same question, one theirs and one the Echo's, shown without saying which is which, to somebody who knows them. How often they pick the real one is the score. It travels with an abstention rate and — the number that matters — a confidently wrong rate, because that is the only error a person who loves them cannot catch. The scale was fixed on 2026-10-04, before a single measurement existed, and above 5% confidently wrong the instrument is not publishable at all. The Standard Candle has the whole barème.
5 · It plugs into any system by being asked, never by being uploaded
The archive never leaves. A system asks a question and gets a bounded answer carrying its provenance and its confidence — or an abstention. Consent is per class of question, per system, revocable, and every request is logged. We never hand over a file. This is the part the industry has already solved for plumbing and not at all for meaning: there are 256 memory servers, and a retrieval layer always returns something.
The manifest, and why it is a certificate
Each archive carries a signed manifest: what it holds, how much of the question space was answered, class by class, what it proves was never said, the blind score, and what it does not claim. It is signed with Ed25519, and the public key travels inside the document — so the archive's own reader verifies it offline, in ten years, with no network and no us.
Three answers, never two: intact, not signed, or ALTERED. One edited count and it says altered. Anybody can write a document claiming a number; a document that can be shown to be unmodified is a different object, and that difference is the whole of this page.
What it does not claim
- that the archive is complete: it is bounded by the questions that were asked, and they are counted here
- that an absence in the archive is an absence in the life
- that the fidelity score measures identity: it measures resemblance on the questions that were tested
- that anything here was verified by a clinician
- that a consciousness was preserved: nobody knows how to do that
Where this stands today
The coverage index, the Unlit, the conformal bound and the signed manifest are built and in production. The blind score has no measurements yet — the beta is small, and a scale with nothing on it is still worth publishing because it cannot then be chosen to flatter. The asking interface is next. We would rather tell you which of these five is a mechanism today and which is a plan than let a page imply all five are finished.