WHAT IT IS
A release checkpoint for tools that have to be usable alone or inside a larger surface.
The live public flagships now use a simple pattern: direct purpose, visible artifact, installation path, reason it matters, and current status. Checkpoint brings the same standard to the private line. Four repos are public now: Checkpoint, Runtime, Vault, and Boundary. Lab (Seed) and Ledger (Sofer) remain private until their public-safe splits are complete.
The private-line standard is concrete: command surfaces must be inspectable, package metadata must agree with the docs, MCP or host-neutral integration must be declared, graphics must match the Project Telos presentation language, and every readiness claim must resolve to a receipt.
THE SIX UNITS
Each tool has a clear job.
Aleph. Product shell for the private line: docs, package contracts, MCP declarations, CI state, and receipt checks. Public repo.
Sofer. Agent workflow routing through intent, admission, execution, evidence references, replay, and verification records. Private/proprietary until the public-safe split removes credential-pattern corpora and internal security-research material.
Seed. Controlled native assessment labs with synthetic fixtures, scenario packs, detection engineering, and deterministic outputs. Private/proprietary until the public-safe split removes internal modules and token-shaped corpora.
Kun. Local access-recovery and owner vault surface that records path-only, read-only receipts instead of exposing sensitive material. Public repo.
ORCA. Local runtime modules, run state, artifact layout, and release provenance for owner-held workflows. Public repo.
behavior-transform. Host boundary wrapper for read, write, exec, fetch, input, and model-boundary receipts. Public repo.
CURRENT STATUS
Evidence first, same as the public flagships.
WORK WITH IT
Private by inquiry, not cryptic by default.
A private-line tool can still be readable. The public promise is deliberately plain: Checkpoint makes the private line shippable by forcing each tool to say what it is, how it is operated, which receipts support the claim, and which boundary keeps sensitive behavior out of public documentation.