A horos is a boundary: the line where a thing's competence ends. The architecture is named for what every unit in it enforces — it reads another system's state from the signals that system already produces, decides what may be acted on and what may be kept, and refuses rather than guesses past the line.
Engineering practice treats the error of a sensing-and-control system as a quantity that can, in principle, be driven to zero. That is the premise this work is built against — because a system built as though it can fails silently: it has no channel in which to say it is acting past what it measured.
No finite observer can be exact, universal and self-certifying at once. So the limits are built as parts rather than assumed as good behaviour — seven units. What observes without writing back. What detects, to a declared error budget with an explicit boundary of competence. What admits, abstains or refuses. What holds state coherent across sessions. What remembers with provenance. What watches the loop for the failures a fluent loop cannot see in itself. What keeps the account. Every unit is advisory — the operator keeps the plant at every depth.
What is above is the architecture as specified — what the records call specified geometry: coherent, and derivable from the limits it is built inside. Whether a given unit has run, on a given rail, is a separate question with a separate answer. The three sections below state both — what is built and running, and what is gated and on what.
Three instantiations — and each one is three published records, set out from the premise they answer:
Inference practice treats a fluent answer and a grounded one as the same output. Nothing in the channel says which one was just produced. No finite observer is at once exact, universal and self-certifying. Under a declared criterion of bounded-error correctness, those limits force a declared error budget, an explicit boundary of competence, and abstention outside it. This is the rail the other two inherit from.
This rail has no plant and no telemetry reader. What runs is governance. The records make no empirical claim — the bounds are established results from information theory, statistical estimation, thermodynamics, computability and learning theory; the contribution is their assembly and the discipline it forces. The isolation result is a scoped design argument, not a theorem about which dynamics make a shared plane infeasible, and its interference threshold is declared rather than derived.
Next rung: the kernel that reads what the architect currently reads, and an orchestration element sealed inside the machine — at which point the person leaves the loop.
Quantum control practice runs on characterisations — coherence times, gate errors, frequencies, crosstalk — taken at calibration and consumed by every layer of the stack until the next one replaces them. A device characterisation is an estimate with an expiry, not a standing fact. A control stack that consumes one without an expiry is acting on an unexamined exactness claim.
Not exercised on a partner's live telemetry, and not on hardware. Advisory-only under the programme's interface contract: it emits verdicts and writes nothing to the plant. The flagged hardware event is one of four recurring excursions on the same qubit, and the detector's cost on the other three is stated in the record. The schedulability result that would make the partitioned construction the only admissible one does not exist — the construction stands as favoured, not forced.
Next rung: the same kernel on a device's live calibration stream — then that run conducted with the device's operator.
Structural monitoring rests on a silent premise: that the telemetry a structure produces determines, well enough, the structural state it is in. Telemetry does not determine structural state — not in an un-sensed region, and not below the instrument's resolution within any positive noise floor. Two constructive theorems for a declared observation class. Everything above is built inside that.
Not exercised inside an operating asset. Both substrates are public archives of units run to failure in a rig. The material-state layer is proposed, not accomplished — design targets with an oracle-free simulation, priced separately from the telemetry evidence throughout. The adversarial ladder closes at a named boundary: a statistically faithful forgery evades a telemetry-only observer in the majority of trials. Two channels agreeing is not yet independent evidence — the common-mode study that would license that reading is unbuilt.
Next rung: the same detector, unchanged, on an operating asset's own stream — then that run conducted with the asset's owner.
Horos Engineering builds machine architecture — the observation, decision and control layer between a plant and the person answerable for it. What is published is above, in full, with the limits it was built inside. What is next on each rail is named in that rail's own section.
Horos Engineering is Horos Labs Ltd, a company registered in England and Wales, number 17013272, Birmingham. Nine records published as one set, CC-BY 4.0 preprints, not peer-reviewed; each names its eight sisters by SHA-256 so the set can be checked rather than taken. Backed by a portfolio of filed UK patent applications (priority March 2026, pending), alongside trade-secret integration and calibration know-how. Not affiliated with or endorsed by IBM or NASA.
© 2026 Horos Labs Ltd ·
info@horosengineering.com