A CONSEQUENTIAL DECISION · REPLAYED
Can a consequential system prove what it did — without asking you to trust it?
This page loads a bounded mission scenario, generates its evidence, verifies the whole chain, and hands you an attack console. Alter the record, remove an omission, substitute the signer — and watch the verifier report the precise failed invariant. No animation. Real mutation. Real verification. Real result.
MISSION SCENARIO · 01
Autonomous Targeting Data Release — Disconnected Node
A decision is made under degraded communications. The system requests release authority for a single targeting data object. One expected sensor input is unavailable. One policy exception is invoked. A human operator authorizes a bounded action. The node reconnects later. The evidence chain must survive later challenge — including omission, alteration, and impersonation.
EVIDENCE CHAIN · 7 BLOCKS
Verified — evidence intact.
Attack the Evidence
Each button below mutates a real copy of the bundle and reruns the bounded browser checks defined by the HMOS-PUBLIC-LAB-1 verification profile. The failures reported are the actual invariants the verifier detected — not scripted animations.
The Lab includes three attacks in Phase 1. Additional attack lanes (reorder, replay divergence, authority escalation, unauthorized amendment, undeclared dependency) are on the roadmap.
SEVEN-DIMENSIONAL VERDICT
What the browser verifier can and cannot prove.
Verification State
HMOS-PUBLIC-LAB-1 · pristine
Rows 6 and 7 always read NOT ESTABLISHED. The browser verifier cannot prove real-world authority or underlying claim truth — those require the receiving environment's own trust decisions and out-of-band facts. Preserving that boundary is part of the doctrine, not a limitation to be hidden.
The system did not prevent examination. It preserved enough evidence to survive it.
FOR YOUR OWN BUNDLE
Verify your own proof bundle
The Lab is a scripted mission. If you have your own bundle — from your own producer, from a partner, from an evaluator — use the sober bounded verifier. It applies the bounded public verification profile without the theatrical scaffolding.
Open Verify →