Carnac™ Control Plane · Integration point
One gateway. Proof that the approved instruction arrived unchanged.
Carnac Gateway™ is the door where requests arrive. It compares the arriving instruction with the approved version, countersigns the arrival, and creates a verifiable receipt. Any change, replay, wrong destination, wrong tenant, or broken proof chain is exposed.
What it does
Carnac™ determines what proof each request needs. Carnac Gateway™ then proves what actually arrived: the approved instruction reached the right place, unchanged, for the right tenant, with its proof chain intact. Approved here. Received there. Proven end to end.
Who uses it
Platform and infrastructure teams that want one integration surface for proof across many models, tools, and agents, rather than per-provider plumbing.
Where it sits
In the request path, before your providers. It calls CarnacPrompt™ before inference and CarnacGovernance™ before an effect commits.
What is live now
- Live now. The receipt path and consequence-based routing logic.
- Customer integration required. Placing the gateway in your request path, mapping your providers, and setting consequence thresholds.
- Deployment. Runs as a hosted API today. On-premise or in-VPC placement is a customer-specific integration item, not a shipped option. We will not claim VPC or on-prem unless it is scoped and built for you.
- Measured, not asserted. The Gateway benchmark reports exact throughput and latency for the reference receipt core, with a signed manifest and a command you can run yourself.
Canon primitives underneath
| Canon primitive | What it proves here | Status |
|---|---|---|
| Carnac™ | Reads consequence and routes each call to the proof it warrants. | Live core |
| CarnacPrompt™ | Commits the prompt window before inference. | Live core |
| AFIR | Signs routable inference fragments inside the path. | Live core |
| SiGR | Signs the decision into a verifiable receipt. | Live core |