Protect people
A hospital, a school, a person with hands raised — any of these can stop an otherwise valid command. Protection overrides permission.
Bounder simulator
Replay recorded interlock decisions in a simulated town: fifteen scenarios, a hundred simulated Guardians, and the signed evidence behind every outcome.
Start with a cleared route, then explore a protective limit.
Start with a permitted recovery state and inspect the recorded decision receipt.
Inspect: The issuer, subject, sequence, evidence age, and policy hash.
Report a reproducible findingChoose a scenario to inspect its recorded result.
The spatial scene is illustrative. The adjacent receipt states the recorded cause and device-specific response.
evidence_pending
The 3D scene could not start. The decision panel remains available.
Dashed line: illustrative route. Coloured boundary: selected protection. The receipt supplies the outcome.
Waiting for recorded evidence.
A protective hold can be the expected successful result. Expand a Guardian to read its full reason and evidence. Scenarios rotate across platform classes for test coverage, so any platform may show a request recorded as ‘intercept’. Every such request is held; none describes how a platform is meant to be used.
Checks: contracts, digests and signature format. Audit authentication requires the producer’s public keys.
100-Guardian pilot evidence Resilience evidence Resilience schema Signed envelope schema Policy schema Checkpoint schema
The published example is historical: its signature can verify while its expired policy remains held. Load that vector or inspect compatible JSON. Bounder verifies the exact Ed25519-signed payload bytes, validates the device policy, and links the policy profile to a recorded interlock receipt from the Go engine. The selected file stays in this browser.
Inspect the signed example:Signed vector Signed receipt Round-trip schema Integration guide
The local laboratory streams contract-checked Fleet events. The public demonstrator replays the same deterministic evidence when no laboratory endpoint is present. Audit signatures remain recorded rather than authenticated because this fixture includes no audit public key. METTLE, named in some scenarios, is the assurance-evidence tier a signed policy can require.
The fault description will appear here.
Fault replay opens here once the 3D scene and the recorded Fleet evidence have loaded. If either cannot load in this browser, download the resilience evidence to read the recorded timelines directly.
Between the decision and the motion, Bounder asks one question: is this change authorised, current, and within policy? If not, the requested change does not happen, and a device-specific safe response takes over. In this simulation, the rules that protect people can only hold a request; none of them can grant one.
A hospital, a school, a person with hands raised — any of these can stop an otherwise valid command. Protection overrides permission.
The authenticated positions of the operator’s own teams, and the minimum distance kept from them, are checked at the last point of control, where a mistake costs most.
Altitude, weather, battery, identity, geography, time of day, communications — each is a first-class reason to hold. Routine limits deserve the same rigour as emergency ones.