Zain Dana HarperCheckpoint · private-line release checkpoint

PROJECT TELOS PRIVATE-LINE PLATFORM

One checkpoint. Six working tools.

Checkpoint is the public contract for the Project Telos private line: Checkpoint (Aleph), Ledger (Sofer), Lab (Seed), Vault (Kun), Runtime (ORCA), and Boundary (behavior-transform). It verifies presentation, package shape, MCP readiness, CLI contracts, provenance receipts, and release state before anything is described as ready.

Public where safe, private where required, checkable delivery.

Project Telos Catalog Runtime Vault Boundary Ledger private Lab private
Checkpoint README-style hero: Project Telos private-line release checkpoint with six tools, receipts, CI, and MCP.
private by design · public contract · no secrets in the presentation layer

WHAT IT IS

A release checkpoint for tools that have to be usable alone or inside a larger surface.

The live public flagships now use a simple pattern: direct purpose, visible artifact, installation path, reason it matters, and current status. Checkpoint brings the same standard to the private line. Four repos are public now: Checkpoint, Runtime, Vault, and Boundary. Lab (Seed) and Ledger (Sofer) remain private until their public-safe splits are complete.

The private-line standard is concrete: command surfaces must be inspectable, package metadata must agree with the docs, MCP or host-neutral integration must be declared, graphics must match the Project Telos presentation language, and every readiness claim must resolve to a receipt.

THE SIX UNITS

Each tool has a clear job.

Checkpoint

Aleph. Product shell for the private line: docs, package contracts, MCP declarations, CI state, and receipt checks. Public repo.

Ledger

Sofer. Agent workflow routing through intent, admission, execution, evidence references, replay, and verification records. Private/proprietary until the public-safe split removes credential-pattern corpora and internal security-research material.

Lab

Seed. Controlled native assessment labs with synthetic fixtures, scenario packs, detection engineering, and deterministic outputs. Private/proprietary until the public-safe split removes internal modules and token-shaped corpora.

Vault

Kun. Local access-recovery and owner vault surface that records path-only, read-only receipts instead of exposing sensitive material. Public repo.

Runtime

ORCA. Local runtime modules, run state, artifact layout, and release provenance for owner-held workflows. Public repo.

Boundary

behavior-transform. Host boundary wrapper for read, write, exec, fetch, input, and model-boundary receipts. Public repo.

CURRENT STATUS

Evidence first, same as the public flagships.

presentation readinessMATCH
release_verdict: MATCHMATCH
docs coverage4/4 docs
brand coverage3/3 brand
CI stategreen
public boundaryclean
PresentationAll six private-line repos carry the live Project Telos visual language: off-white hero, pale wordmark, direct purpose, and shared docs/brand asset layout.
VisibilityPublic now: Checkpoint, Runtime, Vault, and Boundary. Private until split: Lab (Seed) and Ledger (Sofer).
ReleaseThe local release checkpoint checks the docs and package surfaces before a readiness claim is allowed to stand.
IntegrationCLI, MCP, plugin, IDE/TUI, and app-host boundaries are documented as host-neutral contracts rather than single-surface demos.
PrivacyThe public surface explains what the line does without publishing secrets, credentials, private logs, or high-risk internals.

WORK WITH IT

Private by inquiry, not cryptic by default.

A private-line tool can still be readable. The public promise is deliberately plain: Checkpoint makes the private line shippable by forcing each tool to say what it is, how it is operated, which receipts support the claim, and which boundary keeps sensitive behavior out of public documentation.