This is the reasoning register. The position it argues for — what exists, on which rail, at what state — is stated on the architecture page, which opens with the same identity this page assumes.
The error of a sensing-and-control system cannot be driven to zero under finite resources. A system built as though it can fails silently, because it has no way to say when it does not know.
This programme takes that as its starting point rather than its caveat. Every rail opens with a limit — what cannot be done — and everything above it is built strictly inside that limit. The environment is read as a primary input rather than a disturbance to be sealed out. Constants are declared before the results they govern, limits are published in the same weight as the claims, and every claim carries the thing that would falsify it.
The premise above is a principle. This is what it looks like in three working disciplines, and the finding was not three problems. It was one problem in three substrates — and each record reached for the same word without any of them being written together.
| inference | the error of a sensing-and-control system can, in principle, be driven to zero | fails silently FC-01 |
| quantum | a characterisation taken at calibration remains current until the next one replaces it | a premise rides silently QC-01 |
| structural | the telemetry a structure produces determines, well enough, the structural state it is in | a silent premise SC-01 |
The pain is not that these systems are wrong. It is that when they are wrong, nothing says so. In each case a system consumes an estimate as though it were a standing fact, and the consumption leaves no trace. There is no channel in which the thing says I am now acting past what I measured. The error is not loud and wrong; it is confident and quiet, and it stays quiet until the consequence.
Which is why the same shape appears on three substrates that share no physics. It is not a property of turbines, or of qubits, or of language models. It is a property of any finite observer that acts — this one included. The limit is one we are inside, and the architecture below is what we built to work within it.
What the programme builds. Horos ODC — an observation, decision and control architecture. A horos is a boundary: the line where a thing’s competence ends, and the architecture is named for what every unit in it enforces.
Seven units, declared in the records. What observes without writing back. What detects. What admits, abstains or refuses. What holds state coherent across sessions. What remembers with provenance. What watches the loop. What keeps the account. Every unit is advisory — the operator keeps the plant at every depth. Laid out unit by unit below.
Three instantiations, one architecture: the inference layer, quantum control, and structural monitoring. The limits are built as parts rather than assumed as good behaviour, which is why there are seven of anything.
Nine records, published as one set on the same day. Three rails, three slots in each, three registers each rail lives in — the arrangement is not editorial, it is what the argument requires: a limit has to be established before an instrument built inside it means anything, and an instrument has to exist before the architecture around it is more than a diagram.
Open-access preprints, CC-BY 4.0, not peer-reviewed. Each names its eight sisters by SHA-256 under a declared convention, so the set can be checked rather than taken — the check is at the bottom of this page and it runs in your browser.
The same architecture on three substrates: the inference layer, quantum control, and structural monitoring. Not three projects — one discipline instantiated three times.
The limit that constrains the domain. The instrument built inside that limit. The architecture the instrument sits in. Same order on every rail, because the order is forced.
Each rail exists as a record, as a public statement, and as something you can run. This page is the first. The front page is the second. The three elements are the third.
| The inference layerinference · finite cognition | Quantum controlmicro · QCA | Structural monitoringmacro · SCA | |
|---|---|---|---|
| the limit | FC-01 The Physical Limits of Finite Observation: Seven Bounds on Sensing, Inference, and Control
Seven established bounds assembled from information theory, statistical estimation, thermodynamics, computability and learning theory. No finite observer is at once exact, universal and self-certifying. The bounds are inherited by the other two rails. 10.5281/zenodo.21994190 |
QC-01 The Finite-Calibration Limit: What a Device Characterisation Can Claim Between Calibrations
A device characterisation is an estimate with an expiry, not a standing fact. A control stack that consumes one without an expiry is acting on an unexamined exactness claim. 10.5281/zenodo.21994692 | SC-01 The Non-Identifiability Limit in Structural Monitoring
Telemetry does not determine structural state — not in an un-sensed region, and not below the instrument's resolution within any positive noise floor. Two constructive theorems for a declared observation class. 10.5281/zenodo.21994945 |
| the instrument | FC-02 Deviation as Located Missingness: Turning the Finite-Observation Bound into a Diagnostic Instrument
Two artefacts from the same machine under the same perturbation: a paired residual above a declared threshold rejects the hypothesis that the runs were identical within tolerance, and points at an uncaptured interaction. One-way — a residual below threshold licenses nothing. 10.5281/zenodo.21994447 |
QC-02 Detecting Systematic Bias Drift Before Saturation: A Fail-Closed Precursor Estimator for Cryogenic Quantum Control
An archived Monte-Carlo run of record with thresholds frozen before the batch, and a read-only pass over a 156-qubit device's published calibration history — firing on change, not on badness. 10.5281/zenodo.21994845 | SC-02 Precursor Detection for Structural Systems, Two-Sided
Every claim carries a declared evidence stratum. The telemetry channel benchmarked on NASA C-MAPSS and FEMTO run-to-failure data with constants fixed before the run; the material channel proposed, and priced separately wherever a verdict would rest on it. 10.5281/zenodo.21994986 |
| the architecture | FC-03 The Isolation Requirement: Contradictory Demands, Favoured Partition, and Guarded Finalisation in Finite Systems
Committing execution and wide-field vigilance are not served well by one undivided plane. Partition with re-coupling at the point of finalisation is the favoured resolution, not a forced one, so that nothing is committed against a live defeater. 10.5281/zenodo.21994574 |
QC-03 The Quantum Control Architecture: From a Fail-Closed Estimator to a Governed Measurement-and-Control Layer
The construction the estimator belongs to, stated in public units: observer, detection floor, fail-closed gates, state coherence, provenance-checked memory, lifecycle supervisor. Declared as specified geometry, not as validated middleware. 10.5281/zenodo.21994890 | SC-03 The Structural Control Architecture: Three Channels and a Governed Seam
Three channels with distinct jobs — identity and provenance, structural state, authenticated telemetry — none substitutable for another, composed under a law that carries the weakest link's maturity visibly. 10.5281/zenodo.21995057 |
Horos ODC is a machine for making that silence audible. Each unit answers one part of it: what reads without perturbing what it reads; what detects to a declared floor with a stated boundary; what provides the channel for I do not know; what holds state coherent so drift cannot pass unremarked; what makes what was believed, and on what, recoverable afterwards; and what watches a loop that cannot see its own failure from inside.
The front page names the architecture. This is it laid out, and it is checkable: seven units are declared in the records — six in QC-03 §Units, and a seventh — the append-only audit record — which SC-03 adds and calls load-bearing. Five of the seven carry an explicit clause naming the bound or result that forces them; two are stated as design, and the table says which is which rather than implying all seven are derived.
The table holds two registers at once, and they are not the same claim. The left column states the unit — what it is, and what forces it — as specification: true if it is coherent and derivable. The rail columns state existence: whether that unit has run on that rail, is partial, is gated, or is held by a person. A specification is not an existence claim, and the records draw the line in their own words: the architecture beyond each rail's characterised kernel is specified geometry — internally consistent and buildable to, not validated as live middleware, and an architecture paper claims geometry and composition, never validation.
| unit | The inference layer | Quantum control | Structural monitoring |
|---|---|---|---|
| Non-perturbative observerobserve Reads process and control state without writing back into it. Fires on change, stays silent on stable state. Forced by: Answers the zero-write law, and hosts the wide-field vigilance demand. QC-03 §Units | running dailyIRM — watches the integrity of the coupling on a shared referent and detects silent divergence. | partialThe calibration read is itself zero-write; the standing unit is specified. | gatedIdentity and authenticated-telemetry channels named in SC-03. Opens on an instrumented asset carrying component and sensor identity. |
| The kerneldetect Fail-closed detection on the telemetry the system already produces, operating to a declared error budget with an explicit competence boundary, abstaining outside it. Forced by: The instrument of the architecture in exactly the sense of FC-02: it reads the deviation that locates the missing or varying interaction. QC-03 §Units → FC-02 | running dailyReads the arriving perturbation and the consideration on it. One-way: silence licenses nothing. | builtQCK — 246/354 eligible runs, thresholds frozen before the batch; plus a read-only pass over 159 served calibrations. | builtThe precursor detector — FEMTO 4/6 run-to-failure bearings; C-MAPSS FD001 98/100, FD003 97/100. |
| Fail-closed gatesdiscriminate Every advisory output passes a gate that admits it, abstains on insufficient evidence, or refuses it. The default under uncertainty is closed. Authority is over what may leave the layer — never over the plant. Forced by: The finalisation coupling of FC-03 made into a unit: release occurs only against a current, consulted vigilance state carrying no live defeater. Absence of a defeater, not positive verification of truth. QC-03 §Units → FC-03 | running dailyThe act governor's verdict half, with the router firing the right gate by reflex rather than on recall. | partialThree-way inside the detector — watch, interdict, silent — with thresholds pre-declared. The standing unit is specified. | partialTwo governors ran, with HOLD and UNRESOLVED as first-class verdicts. The integrity governor at full scope is specified. |
| State coherence and equilibriumhold · balance Observer, gates and memory held as one runtime object across sessions and cycles; commits to that state pass an equilibrium discipline, so state change is a governed event rather than a side effect. Forced by: Answers the retention bound of FC-01: a finite system that cannot keep its full history must govern what it keeps. QC-03 §Units → FC-01 | running dailySession seal and wake, bounded engagement, and a maths-architecture coherence gate. | gatedNamed in QC-03. Opens on a live plant and an operator whose decision the verdict enters — until then there is no commit to govern. | gatedNamed in SC-03. Same condition as quantum. |
| Provenance-checked memoryremember What is retained carries its provenance and is checked against it; patterns already seen to fail are refused rather than re-attempted. Fail-closed in the same sense as the gates — it admits, or it declines, and it does not silently fabricate continuity. No forcing clause in the records — stated as design. QC-03 §Units · stated as design | running dailyFour fail-closed gates on everything durable, with a minting pipeline behind it. | gatedNamed in QC-03. Opens with the commit stage. | gatedNamed in SC-03 as provenance-checked memory of verdicts and baselines. |
| Lifecycle and loop supervisorsustain · health Accounts for boot, continuous operation and maturity of the running object, and watches the advisory loop for the failures a fluent loop cannot see in itself — stuck outputs, stiction against an unresponsive plant, verdicts repeating without re-evaluation. No forcing clause in the records — stated as design. QC-03 §Units · stated as design | running dailyA four-beat boot with a three-check, orphan-session recovery, and a verdict ladder at a wall. | gatedOpens on a continuously running advisory loop for a supervisor to watch. | gatedNamed in SC-03 — stuck verdicts, stale baselines, configuration drift. Same condition. |
| Append-only audit recordaccount Append-only and hash-chained, binding every verdict to its inputs, its channel maturities and its governing configuration — so that what the layer believed, when, and why is answerable after the fact without trusting the layer's current state. Forced by: Because the trust model names estimator drift and record tamper as failure classes, the record is load-bearing: an unrecorded verdict history cannot be audited into trust. SC-03 §The audit record | running dailyAppend-only ledger, each entry chaining its content hash to the previous tail. 81 of 81 freeze declarations agree. | partialArchived manifest carrying the script hash and seed rule. A manifest, not a chain. | partialThe provenance block in the hashed receipt. The append-only chain SC-03 calls load-bearing is specified. |
The stream. What each machine reads from — a device's published calibration history, two public run-to-failure benchmarks, arriving claims and proposed acts. It is the input, not a component, and it was never ours: the estate has generated telemetry on no rail. The archived runs prove a reader, not a generator. We begin where readable telemetry exists.
The orchestrator. What turns a reading into the next act, and what carries state across every discontinuity the work runs through — engines change, sessions end, context is lost, the harness is replaced. It is the only element in the system with an unbroken line. It is declared in no record in this set — seven public units, and the one that decides what happens next appears in none of them. On every rail that station is held by a person. That is a finding, not a part, and it is stated here rather than quietly listed among the units.
QC-03 specifies two planes that sit above the unit list. Both are labelled design intent in the record. Both are stated here in full rather than left out: a specification withheld is not modesty, it is a gap with nothing named inside it. Their existence state is given at the end of each, in the same words the record uses.
The measurement plane. Families of features computed from telemetry the stack already produces. At the level of role: dynamical-stability features reconstructed from limited scalar streams; separation of directed multi-channel coupling from noise floors; control-loop stability margins in pulse and reset feedback; and an irreversibility and cost budget on measurement and reset aggression against the thermal envelope. Two disciplines bound it. Every numeric threshold is established per hardware during a coupling window — no universal bound is asserted, because the finite-observation result forbids pretending one exists, and the finite-calibration limit puts an expiry even on the per-hardware values. And the wording is exact: the plane performs precursor and drift-anomaly detection; it does not claim demonstrated pre-collapse prediction. Existence — every feature family in this plane is frontier work until a run of record exists for it.
The integrity plane. The architecture audits itself by the same law it applies to the plant. Self-model honesty: it holds its own calibration model as a validity-bounded estimate, compares that model against live telemetry — prediction residuals, distribution divergence — and downgrades its own competence claim before it can mislead; at expiry or on divergence it refuses, re-establishes, or escalates with a deadline. The residual is treated as located missingness, an address for inquiry, never noise to suppress. Gated portability: transfer to new hardware is not a promise and carries no blanket assurance. It is a gate with three bounded obligations — a per-hardware coupling window that re-establishes every threshold on the target; a demonstration suite with pass criteria declared before it runs; and an audit record binding what was demonstrated to what is claimed. Absent any of the three, the architecture declines to port. What carries across hardware is the law — the units, the gating, the contract — not the numbers; the numbers are re-earned on every target. Existence — design intent, on one rail, unrun.
Every claim in the set carries an evidence class and a named defeater — the thing that, if it happened, would retire the claim. Classes are not interchangeable: a declared simulation is not a public benchmark, and neither is a theorem. Nothing below is weighted by us; it is labelled so a reader can weigh it.
| claim | evidence class | what would end it | record | |
|---|---|---|---|---|
| C1 | Detection before saturation in 246/354 eligible collapse runs (69.5%, 64.5–74.1) | measuredsim | fresh-process replay diverging from the archived summary | QC-02 |
| C2 | Zero false interdicts in 210 healthy runs within the declared calibration window | measuredsim | C3 — the bound expires without reset | QC-02 |
| C3 | The false-interdict bound is conditional on a mandated recalibration: 154/210 without reset | measuredsim | none open | QC-02 |
| C4 | Within the June window, one qubit showed a sustained T1 decline, 88.0 → 19.1 µs over 43 returned snapshots / 42 days | measuredexternal, read-only | archive hash change; provider record revision | QC-02 |
| C5 | Over 159 distinct served calibrations the same qubit shows four excursions with recovery; the endpoint detector then fires on no qubit and the persistence-gated form on one | measuredexternal, read-only | none open | QC-02 |
| C6 | Two independent pulls of the overlapping 46 days are value-identical | measuredreplay | a third pull diverging | QC-02 |
| C7 | Provider retention served every day probed back to 2026-03-04 (≥166 days) | measuredexternal | provider policy change | QC-02 |
| C8 | FEMTO 4/6 run-to-failure bearings detected, no unit-level baseline false alarms | measuredpublic benchmark | dataset hash change | SC-02 |
| C9 | FD001 98/100 and FD003 97/100 engines detected; unit-level baseline FA 3/100 and 5/100 | measuredpublic benchmark | none open | SC-02 |
| C10 | Oracle-free material rig detects 180/180 with 16/180 healthy false interdicts | measureddeclared sim | design-iteration disclosure (v2a) already registered | SC-02 |
| C11 | That material bound expires over a long horizon without reset: 140/180 | measureddeclared sim | none open | SC-02 |
| C12 | The finite-calibration limit holds on the declared validity model | derived | counter-model within the declared class | QC-01 |
| C13 | Non-identifiability with unbounded safety divergence on the declared observation class | derivedtheorem | counter-example in class ⇒ token downgrade cascades to SC-02/SC-03 | SC-01 |
| C14 | Isolation is required and partition favoured, not forced | derived | premise failure | FC-03 |
| C15 | Every instrument and architecture record holds advisory-only authority; no record licenses a plant write | contractual | a record's prose contradicting its declared class (regression entry 13) | contract |
“None open” means no defeater is currently known for that claim — not that none exists.
Named so that nothing on the list can be mistaken for an established result, and so that the debt is not silent. None of it is imported anywhere in the set as demonstrated.
Stated on the front page. Run on NASA C-MAPSS turbofans and FEMTO bearings.
the statement · run itStated on the front page. Run as a fail-closed gate ladder you can attack, with the freeze web verified in-browser.
the statement · run itStated on the front page. Run on a 156-qubit IBM Heron's own published calibration history.
the statement · run itThere are two constants in this work. One is a person, who has been present across every engine, every session and every substrate the work has run on. That constant cannot be handed to anyone. The hash web below is the second, and it is the part that can — continuity a stranger can verify without being told anything, and without trusting the teller.
Each record names its eight sisters by SHA-256, and its own pre-freeze hash, under a convention declared inside the records: the value is the hash of that sister's source with its own freeze block removed. That makes the web checkable rather than circular — delete the marked block from a sister's source, hash what remains, compare.
Nine self-declarations and seventy-two cross-declarations. A dependent claim imported from any sister is live only while that sister's hash, replay and stated assumptions remain cleared; a change of hash without a re-cleared import downgrades the dependent claim to unresolved.
| record | declares | agreeing | hash recomputed in your browser |
|---|
—
Nothing above is checked until you press the button. This page carries no hashes: pressing it fetches the nine sources served from this site, strips each record's freeze block, and hashes what remains with SHA-256 in your browser. To check a copy you brought yourself, paste it into the governor page.
Horos Engineering (Horos Labs Ltd, United Kingdom) ·
info@horosengineering.com
Open-access preprints, CC-BY 4.0, not peer-reviewed. Not affiliated with or endorsed by IBM or NASA.
Horos Engineering is Horos Labs Ltd, a company registered in England and Wales, number 17013272, Birmingham. Nine records published as one set, CC-BY 4.0 preprints, not peer-reviewed; each names its eight sisters by SHA-256 so the set can be checked rather than taken. Backed by a portfolio of filed UK patent applications (priority March 2026, pending), alongside trade-secret integration and calibration know-how. Not affiliated with or endorsed by IBM or NASA.
© 2026 Horos Labs Ltd ·
info@horosengineering.com