Carnac™ Control Plane · Integration point

One gateway. Proof that the approved instruction arrived unchanged.

Carnac Gateway™ is the door where requests arrive. It compares the arriving instruction with the approved version, countersigns the arrival, and creates a verifiable receipt. Any change, replay, wrong destination, wrong tenant, or broken proof chain is exposed.

Live core, customer integration requiredLive receipt path

What it does

Carnac™ determines what proof each request needs. Carnac Gateway™ then proves what actually arrived: the approved instruction reached the right place, unchanged, for the right tenant, with its proof chain intact. Approved here. Received there. Proven end to end.

Who uses it

Platform and infrastructure teams that want one integration surface for proof across many models, tools, and agents, rather than per-provider plumbing.

Where it sits

In the request path, before your providers. It calls CarnacPrompt™ before inference and CarnacGovernance™ before an effect commits.

What is live now

  • Live now. The receipt path and consequence-based routing logic.
  • Customer integration required. Placing the gateway in your request path, mapping your providers, and setting consequence thresholds.
  • Deployment. Runs as a hosted API today. On-premise or in-VPC placement is a customer-specific integration item, not a shipped option. We will not claim VPC or on-prem unless it is scoped and built for you.
  • Measured, not asserted. The Gateway benchmark reports exact throughput and latency for the reference receipt core, with a signed manifest and a command you can run yourself.

Canon primitives underneath

Canon primitiveWhat it proves hereStatus
Carnac™Reads consequence and routes each call to the proof it warrants.Live core
CarnacPrompt™Commits the prompt window before inference.Live core
AFIRSigns routable inference fragments inside the path.Live core
SiGRSigns the decision into a verifiable receipt.Live core