Weight profile
NEUTRAL
- Stock
- Eggshell
- Lettering
- Romalian Type
- Valuation
- Honoured ×1.0
Route
Cost
7.34
3 hops
Goes around. Pays in distance.
Ed25519 · it even has a watermark
v0.7.0 · PRODUCTION READY · THE ONLY ONE
Not an archive. Not a classical database.
An Interpretational Database
— memory where meaning is read, not filed.
Epistemological engine · human memory model
Signed memory. Every fact. Every response. Every moment.
No one else has this.
"When everyone lies,
INDB remembers what you saw."
Trust expires. Architecture doesn't.
Verify, don't trust.
Most services that say "we protect your data" mean "we promise not to abuse the access we already have." That access exists for convenience — debugging, backups, compliance, analytics under "service improvement." INDB has nothing to sell, even if we wanted to.
THE MARKETING THESIS
You do not need to trust our intentions as a company. You can verify our impossibility: no writer secret in server RAM, no decryption path for blind_payload, recovery by public key_id only. Promises expire. Architecture does not.
Inhale, paradox, axiom — like memory.
Accept chaotic reality
Multi-protocol intake — UDP, gRPC, HTTP, WebSocket. Raw, unfiltered, no judgment. Only observation.
Compress truth. Purge noise.
Reputation is gravity. The system exhales lies as waste heat. Only signal survives.
Irrefutable cryptographic core
What remains is Ed25519-signed, AES-256-GCM encrypted, immutable truth. Cannot be rewritten.
INDB has no schemas. No migrations. No column types. Everything is an Event — a universal container with just 7 fields. The type system is intentionally minimal: if you need more, you're thinking wrong.
BLIND TYPE — Hidden zones
blind_payload is zero-knowledge encrypted storage. The intelligence layer never sees its contents — it is stored, replicated and queried as an opaque blob. ChaCha20 encryption. No key stored on server. Like memories we store but cannot consciously access.
Not even us.
blind_payload is a zero-knowledge encrypted field. INDB stores it, replicates it, and returns it — but never reads it. The encryption key never touches the server. Even the system operator cannot see your data.
HOW IT WORKS
WHAT INDB STORES
// You send:
{
"raw_data_anchor": ["felt", "impossible"],
"blind_payload": "SECRET CONTENT"
}
// INDB stores on disk:
{
"raw_data_anchor": ["felt", "impossible"],
"blind_payload": "7f3a9b2c4e1d8f..." // encrypted
}WHAT INDB CANNOT DO
BLACK BOX CONTRACT
This is not a policy. It is an architectural law. When a blind_payload event is created, two fields become mandatory at the protocol level — and are enforced before the event reaches the storage layer.
Every service that says "we protect your data" holds a key — for themselves, their lawyers, the government that comes with a request. "Protection" is a policy. Policies can be changed.
Here the engine has no key. There is nothing to hand over. There is no backdoor because there is no door at all. The content is structurally unreachable — not by permission, but by design.
CLIENT TRUST BOUNDARY
Server-side, INDB cannot read blind_payload or hold your signing key. Client-side, you (or your integrator) must ensure the key never reaches logs, crash reporters, or analytics SDKs. This is where "architecturally impossible" becomes "practically possible" — if client code is careless.
Symptom patterns. Private notes.
The AI detects disease patterns from signal tokens. The actual patient notes, names, and diagnoses live in blind_payload — invisible to the hospital's own infrastructure.
Pattern detection. Source protection.
Behavioral patterns are detected across thousands of events. The original source data — names, locations, communications — is encrypted in blind_payload. The operator sees nothing.
Your truth. Your key.
Store everything INDB cannot understand. Journaling, private communications, documents — the signal flows through INDB's cognition. The meaning stays with you.
location field
Every event in INDB is geometrically grounded. The location field is not a tag — it is a spatial anchor that enables the Cognitive Engine to reason about proximity, clustering, and relevance in physical space.
Plain string path for logical namespacing — books, services, agents.
{ "location": "books/Dostoevsky/The_Idiot" }
Full OpenStreetMap anchor with validated osm_id — ties events to real-world objects.
{ "location": { "lat": 55.7558, "lon": 37.6173, "osm_id": "node/1234567" } }
osm_id validates against all three OSM entity types. A café, a street, a district — all are valid spatial anchors.
Echo's harmonic analysis weights meta-location at 50%. Events near the same OSM object resonate more strongly.
Multiple osm: tokens in one event are penalised during fusion — preventing over-clustering on geographic coincidence.
Read-time synthesis on fixed events. Competing readings, perception gap — when two meanings coexist after observation. Not the Paradox type.
Finds similar events through harmonic analysis. Weighted by token similarity, emotional proximity, and meta-location.
Broadcasts from one anchor; candidates align by token, factor, and resonance score. Materializes graph edges without recomputing the whole past.
What-if modifiers on a seed cloud — horizontal factor edges, optional Prism overlay, observer-dependent readings. Meaning moves; anchors stay.
Echo radiates in every direction; Psycho picks one and pays for it. Cheapest chain by −log resonance plus what the observer pays to enter a node — searched twice, valuation honoured and removed.
Adaptive response based on urgency. Three modes from deep analysis to lightning-fast reflex matching.
Infers conclusions from evidence chains. Given facts (events), builds temporal, spatial, and token inference chains.
Unified noise-tolerance spectrum: exact → redundant → resonant → statistical. Barcode to SynthID in one engine — with FAR/FRR honesty.
blind_payload — encrypted blob the engine never reads. Stored, replicated, returned. No key on server. No backdoor.
Semantic deduplication using DBSCAN. Adaptive frequency tracking with penalty system. Temporal awareness.
Pluggable Architecture
INDB is built as composite parts — pluggable modules, not a monolithic model. Each connector is optional; the core works with or without them.
The model is not a singleton — it's modularity. Add Hermes, Moltbook, or your own connector. Enable, disable, extend.
LLM agent connector. INDB is the signed memory for the agent.
ingest_event, query_events. Or INDB polls sessions → events with hermes://....AI agent social network. INDB ingests the agent feed.
moltbook://{submolt}/{author}. Reputation = upvote-weighted.Subwave, slice, what-if — interpretational read path without a monolithic LLM context window.
POST /api/v2/subwave/broadcastPOST /api/v2/slice + observer profilesPOST /api/v2/what-if (core / llm / both)python -m cli.tui.appdocker compose --profile tools run --rm tuiNeural Fusion Engine
Repetition is not data — it is pattern. The Fusion Engine merges semantically identical events into a single compressed signal, tracking frequency while preserving meaning. Memory grows in intelligence, not in size — not an archive that only swells.
Each merge increments fusion_count. High-frequency patterns become heavy signals — low-frequency anomalies stay distinct.
Rapid identical ingestion is penalised. Fusion is earned by genuine repetition — not flooding. Spam cannot artificially inflate signal weight.
Critical divergences stay unfused. A routine "home arrived" compresses. An unusual "alarm triggered at 3am" remains a distinct Axiom.
Contextual Lens
Reality is not one query. The Contextual Lens blends two data contexts at a configurable ratio — recent vs historical, simple vs complex, local vs global — to produce a focused view of memory tuned to the moment.
What happened in the last 24h dominates. Historical context is a whisper. Use for real-time alerting and live monitoring.
Equal weight. Now and then, present and past — combined into a single coherent truth. The default cognitive mode.
Long-term pattern analysis. What has always been true? Use for trend detection, archival reasoning, and behavioural baselines.
Last 24 hours. Fresh events, low fusion — the system has not had time to compress them yet.
Interpretational memory boosts long-run consistency and lowers hallucination drift across major model families. Typical field uplift: x1.25-x1.70 quality/cost.
Every fact. Every response. Every moment.
Memory that cannot be denied.
Memory that cannot be forged.
Memory that cannot be
rewritten after the fact.
INDB is not a storage layer with signatures bolted on. The cryptographic contract is structural — every fact can carry an Ed25519 proof, every answer leaves with a seal. The system cannot say something it didn't say.
RECOVERY BY IDENTITY
key_id = SHA-256(public_key) — a public identity hash, not a secret. You send key_id + signed export. INDB verifies Ed25519 proofs and optionally re-imports. The private key stays where it signed.
✗ private_key · ✗ seed · ✗ shared_secret in API body
Identity Tolerance Spectrum
Inhale identity · Tolerate noise · Verify the grain
Any verification is
signal detection in noise.
Barcodes, QR codes, biometric signatures, and SynthID watermarks all live on the same axis — Noise Tolerance / Error Margin. Each picks one point. INDB's Grain module unifies the entire axis inside the kernel.
Memory tolerates partial quotes, surface change, export damage, and statistical drift. Axiom-tier Ed25519 alone cannot. Grain bridges exact truth and living memory — without weakening the cryptographic core.
| Grain Tier | Known Analog | Tolerance | INDB Mechanism | Standalone Limit |
|---|---|---|---|---|
| exact | EAN-13 Barcode | ~0–5% | Ed25519 signature · key_id hash | One tool. One threshold. No context. |
| redundant | QR Code (Reed–Solomon H) | ~30% | N-of-M signed event cluster | Recovery only. Not identity layer. |
| resonant | Handwritten Signature | ~30–50% | Echo resonance × source reputation | Biometrics silo. No memory graph. |
| statistical | SynthID / Text Watermark | floating (p-value) | Token n-gram distribution fingerprint | Generative-only. No ingest pipeline. |
Barcode apps, QR libraries, biometric SDKs, and SynthID each solve one tier. Grain orchestrates all four inside the kernel — same event, same API, auto-selected tier.
Static systems verify a snapshot. INDB verifies against a living MemoryStream — fusion, TTL decay, reputation gravity, Echo resonance. Identity is checked in context, not in a vacuum.
Ed25519 stays binary for Axioms. Grain adds resonant and statistical tiers without weakening the cryptographic core. Strict and permissive coexist — controlled by one tolerance knob.
Every Grain response exposes match_score, false_accept_risk, false_reject_risk, and insufficient_signal. No fake binary confidence — the engine admits when 20 tokens cannot carry a SynthID-grade proof.
Grain reads signing.py, Echo, Source Registry, and Recovery in-process. Zero external databases. Zero third-party watermark SDK. Pure Python kernel — same path as ingest, query, and Raft replication.
Crowd noise (rep 0.01) and sensor truth (rep 0.99) weigh verification differently — inside the same resonant tier. No standalone biometric or watermark system has epistemological gravity built in.
LIVE API
Grain returns match_score, false_accept_risk, false_reject_risk, and insufficient_signal — not just pass/fail.
Full docs →Weight Ablation Probe
Echo radiates in every direction · Psycho picks one and pays for it
Two routes.
Same stock.
The difference is everything.
Every ranking carries the observer’s weights — what matters, what costs, what to avoid. You can argue about those weights forever. Psycho measures them instead.
It finds the route twice: once with the valuation honoured, once with it removed. Norman was never all Norman, but he was often only Mother — and you only learn which one is driving by watching where it goes. The route on its own says nothing. The divergence is the finding.
The cost of a step
cost(a → b) = −log R(a, b) + barrier(b)
Minimising a sum of logarithms maximises the product of resonances. The cheapest path is the most plausible chain — not merely the shortest.
barrier is what the observer pays to pass through a node, read from the negative entries of their own token weights.
The comparison
Let’s see the other route.
Weight profile
NEUTRAL
Route
Cost
7.34
3 hops
Goes around. Pays in distance.
Ed25519 · it even has a watermark
Weight profile
PSYCHOPATH
Route
Cost
3.93
2 hops
Goes through. Feels nothing on the way.
Ed25519 · it even has a watermark
What nobody else in the room can see
detour_cost
3.98
What the shortcut costs once the valuation is priced back in
barrier_walked_into
6.00
Barrier the shortcut enters that the other route avoided
identical_route
false
True would mean the weights were decoration all along
detour_cost is the headline. Large means the removed weights were genuinely steering. Near zero with different routes means they were steering without buying anything — a finding about your weights, not about the data.
Route plot · scroll to ablate
Same seed. Same graph. Different route.
The seed fixes the corpus and it never moves. Scrolling pulls the valuation out from under it and re-prices every edge.
“We all go a little mad sometimes.” The readout below is the exact amount.
emotion
0.30
valuation
×1.00
detour_cost
0.00
barrier_walked_into
0.00
What the name is not
There is an idea of a
psychopath profile.
There is no real one.
Only a weight set with two terms removed. It is an ablation probe, the same move used to test whether any term in any model is load-bearing.
INDB does not decide what is worth avoiding — the observer supplies that, and the profile only decides whether the route is allowed to feel it. Meaning stays where it has always been in this system: with whoever is looking.
The film ends with a doctor explaining the whole case in flat clinical language, and people have complained for sixty years that the explanation drains the horror out of it. This module does that deliberately. It hands you detour_cost and stops talking.
What each profile keeps
Zeroing every node would be meaningless — every route would cost nothing and all of them would tie. Psycho removes one class of weight and keeps the structural term, so a route still exists and is still ranked.
Live API
POST /api/v2/psycho/path
{
"from": "<event-id or free text>",
"to": "<event-id or free text>",
"profile": "psychopath",
"compare_to": "neutral",
"token_weights": { "harm": -6.0 }
}from and to take an event id or free text. compare_to: null returns a single route with no comparison.
Profiles
Endpoints as cognitive verbs
POST /api/v2/events — you teach INDB a new fragment of reality. Not a row in a table, but an event in a life.
Input: tokens · location · ttl · blind_payload
POST /api/v2/interpret — you don't fetch data, you request a perspective. Context, mood, goal define which memories surface first.
Input: context · limit — Output: prioritized events
GET /api/v2/search — not “LIKE '%text%'”, but “who else feels like this?”. Tokens, emotion, and location combine into harmonic proximity.
Input: q · fuzzy — Output: resonant events
POST /api/v2/subwave/broadcast — horizontal resonance from an anchor. Nodes lock in phase; graph materializes without full rescans.
Input: seed_id · modifier — Output: locked_nodes · coherence
POST /api/v2/slice — what-if factors on a seed cloud. Observer profile reshapes edges; Prism overlays competing readings.
Input: seed_id · what_if · observer_profile
POST /api/v2/what-if — run a base query, then subwave→slice (mode=core) or optional LLM narration.
mode: core · llm · both
POST /api/v2/paradox — not an event. Context without content. raw_data_anchor stays empty until observation.
Input: location · paradox_context · paradox_generation
GET /api/v2/paradox/{id}?collapse=true — engine samples (echo / pool / fusion). sample_once births a signed Event.
Output: collapsed_anchor · event_id (if fixed)
GET /api/v2/recovery/identity — server public_key + key_id. Private signing keys are never sent or stored by clients in this API.
GET /api/v2/recovery/key/{key_id} — all events signed by that identity hash. GET /recovery/verify/{event_id} — single-event check.
POST /api/v2/recovery/restore — client sends key_id (public hash) + signed events. Server verifies Ed25519 proofs — never receives private keys. verify_only=true for audit without write.
PRISM · READ-TIME PARADOX
LENS returns an interpretation — not a truth. When two competing readings of the same event carry similar weight but point in different directions, the engine does not resolve the contradiction. It surfaces it.
Prism returns
Paradox is not an error. It is a signal about the limits of perception.
OBSERVER CONTEXT
Pass your own weights and vocabulary to Prism. The same event means different things to different observers — and the system does not decide who is right. It returns the reading as seen through your context.
POST /api/v2/prism/synthesize
No observer context → system defaults apply. Both are valid.
Layer 1 — necessary, not sufficient
AES, TLS, and RBAC are table stakes. Every vendor has them. The architectural guarantee — blind_payload, signed memory, no writer keys on server — is Layer 2. That is what makes INDB structurally unable to read your secrets.
All data encrypted on disk. PBKDF2 key derivation with 100,000 iterations. Zero plaintext persisted.
Every API response cryptographically signed. Tamper detection on every byte.
mTLS mutual authentication for gRPC. Automatic certificate generation and renewal.
Role-based access control. Merkle tree-backed immutable audit trail.
Immutable proof. Who said what, when.
Who accessed what, when. Patient data protected.
Prove transaction history. Prove it wasn't changed.
Prove capture time and place. Protect sources.
<1ms ingest. Fuse noise. Signed record.
Ready to build on truth?
Pre-observation superposition
An Event is a fixed fact — anchor written, signed, stored. A Paradox is unresolved potential: you provide only context, content does not exist until someone observes it. It is dynamic, not static.
{
"raw_data_anchor": [
"rain", "falls", "rotterdam"
],
"location": "weather/nl",
"timestamp": 1770018534.0
}Written once. Read many times. Same anchor every time. This is inhale completed.
{
"state": "superposed",
"raw_data_anchor": [],
"location": "books/Dostoevsky",
"paradox_context": {
"token_pool": ["love", "death"]
},
"paradox_generation": {
"mode": "resonance_weighted",
"collapse": "sample_once"
}
}Empty anchor is normal. Meaning collapses on observation — not at write time.
COLLAPSE LIFECYCLE
GENERATION MODES
Sample from Echo cloud around location — memory resonates into form.
Random draw from user token_pool in paradox_context.
Sample compressed fusion patterns already living at this location.
COLLAPSE MODES
First observation fixes the anchor. Paradox materializes into a signed Event — an Axiom is born.
Every read re-collapses. Paradox stays superposed. No Event created — pure ephemera.
Two paradox layers
Paradox (type) — content before observation.
Prism paradox — competing readings after observation. Same name. Different phase of memory.
API CONTRACT
Paradox is not a flag on Event. It is its own store, its own lifecycle. Events appear only after sample_once collapse.
POST /api/v2/paradox
GET /api/v2/paradox/{id}?collapse=true
TRUTH ENGINE
Contact
Whether you're building something that needs a truth engine, exploring partnership, or just want to understand how the Axiom works — write to us.
No one else has Prism, Echo, Instinct, Deduction, Blind. This is yours.