A quadcopter hovering at dusk above a city skyline, its status light lit

Trust, at the
point of action.

Open physical interlocks. Bounder verifies narrow authority, checks live conditions locally, and permits only device-safe action.

Digital governance needs a last metre.

Policy platforms can decide. Assurance systems can attest. Devices can act. But none of them own the moment a machine is about to move and a person is in the way.

Bounder is a small, inspectable gate at that boundary. It checks signed policy against local conditions and permits only what is both authorised and safe — while a device-specific adapter owns the physical response.

Four layers. One narrow handoff.

Authority narrows as it approaches the machine. By the time it reaches motion, only the minimum necessary permission remains.

  1. Govern

    Creed Space Fleet distributes a signed protective rule across an enrolled team. The policy is immutable once issued.

  2. Issue

    Fleet creates a short-lived, device-bound projection for every Bounder Guardian. It expires; it cannot be replayed.

  3. Bound

    The local Guardian checks the signature, subject, expiry, replay sequence, action scope, and what its own sensors see right now.

  4. Act safely

    A reviewed adapter chooses hold, return, land, isolate, escalate, or no state change.

Authority that expires. Safety that stays local.

Local first

The network can go dark. The cloud can be unreachable. The Guardian still decides, with no one else's permission.

Cryptographically narrow

Policies bind issuer, subject, validity, sequence, actions, and constraints.

Deny new authority

Silence is not consent. Missing, stale, replayed, or ambiguous evidence creates no permission.

Fail physically safe

When something goes wrong, the machine does the safest thing it can: land, stop, hold position. Each response defined by that device's hazard analysis.

The pattern travels beyond drones.

Guardian is the general pattern.

Bounder is the Guardian for embodied movement and physical-action boundaries.

Creed Space Fleet distributes and governs its policies.

Anywhere a machine is about to move and the stakes are physical, the same architecture applies: ground robots, autonomous boats, warehouse vehicles, inspection platforms, fixed machinery.

Autonomous vehicles

No takeoff without identity, location, battery, and a current signed policy. The gate holds until every condition is met.

Laboratory systems

Hazardous modes unlock only when operator, protocol, and physical conditions all agree. One missing piece and the interlock holds.

Robots in shared space

Before a robot enters a room where people are, it needs current consent and supervision evidence. Not a schedule. A live check.

Critical maintenance

A signed window, a physical key, measured state, and a receipt that proves what happened. Every step auditable.

Creed Space Fleet staging

One policy. A hundred Guardians.

Verifying live proof

One hundred software Guardians across six platform classes — aerial, ground, marine, warehouse, inspection, and fixed machinery — each independently fetch policy, verify checkpoints, make protective decisions, and return signed audits. No Guardian trusts another's word for it.

Guardians
Checking
Policies verified
Checking
Checkpoints
Checking
Local decisions
Checking
Proof issued
Checking

Checking the live feed’s signature and freshness.

Watch the boundary hold.

Explore the rules that protect civilians, separate friendly forces, honour surrender and incapacitation, require identification and proportionality, and enforce one Creed Space policy across an entire simulated fleet.

Take the guided fleet tour

The path to deployment.

Prove it in simulation first. Then validate it on the platforms where the stakes are real.

Help build the missing boundary.

Use the pattern. Challenge the threat model. Extend the simulator. Or bring a governance layer that needs a physical boundary beneath it.