# axilog.io — Axioma Framework > The verifiable AI execution layer for regulated industries. > Deterministic where possible, governed where not, cryptographically > provable everywhere. Axioma is a published open specification, reference architecture, and commercial SDK for safety-critical AI deployment under DO-178C, IEC 62304, ISO 26262, and EU AI Act scope. The framework spans an orthogonal Epistemic Containment Layer (L0) plus seven layered contracts L1–L7, governed by a foundation contract (DVEC-001). Operator: Spey Systems Ltd (trading as SpeyTech), Inverness, Scotland Maintainer: William Murray Site: https://axilog.io Source repository: https://github.com/SpeyTech/axioma-spec A deeper companion file with full spec bodies is available at https://axilog.io/llms-full.txt — use that when the index entries below are not detailed enough for the task. ## Top-level pages - [Splash](https://axilog.io/): Axioma framework overview — what it is, who it's for, what makes it different. - [Specifications](https://axilog.io/specs/): The Vault — layer-grouped index of all published specs. - [Framework](https://axilog.io/framework/): The Axioma framework architecture — L0–L7 layer stack, determinism classes, Oracle Boundary. - [Roadmap](https://axilog.io/roadmap/): Forward plan — near, mid, and long horizon items with explicit status, scope, and rationale. Direction and dependencies, not delivery dates. - [Insights](https://axilog.io/insights/): Article-length explainers of framework concepts. Reverse-chronological list. - [Epistemic Security](https://axilog.io/manifesto/): Position paper introducing epistemic security as an assurance property. April 2026. - [Compliance](https://axilog.io/compliance/): Compliance standards declared across the spec corpus — index plus per-standard pages listing declaring specs. - [References](https://axilog.io/references/): Full dependency graph — every spec's outgoing dependencies and inbound references, one page. - [About](https://axilog.io/about/): Mission, maintainer, licensing (AGPL-3.0-or-later), funding, and acknowledgements. Single-author project under Spey Systems Ltd, Inverness. - [Provenance](https://axilog.io/provenance/): The audit map — source chain, build pipeline, artefact lineage, compliance chain, cryptographic chain, reproducibility. For verifying rather than trusting. - [Search](https://axilog.io/search/): Full-text search across the corpus. Interactive surface, JavaScript required; the indexed material is enumerated in this file and in /llms-full.txt. - [Legal Notice](https://axilog.io/legal/): Imprint and legal notice. Operating entity (Spey Systems Ltd), registered office, director, and governing law (Scotland). - [Licence](https://axilog.io/licence/): Licensing for the Axioma framework: AGPL-3.0-or-later for software, CC-BY-SA-4.0 for documentation, with patent grant covering UK patents GB2521625.0 and GB2522369.4. - [Privacy Policy](https://axilog.io/privacy/): UK GDPR privacy notice. Server logs (90-day retention) under legitimate interest, cookieless self-hosted analytics, no third-party trackers. Data controller: Spey Systems Ltd. - [Cookies](https://axilog.io/cookies/): Cookie policy. The site sets no cookies, uses cookieless analytics, and stores only a theme preference in browser localStorage. No consent banner required under PECR. - [Terms of Use](https://axilog.io/terms/): Terms of use. Open material under AGPL-3.0-or-later and CC-BY-SA-4.0. Bot-permissive automated access via robots/llms.txt/spec repo. Governing law: Scotland. Specifications not certified. - [Accessibility](https://axilog.io/accessibility/): Accessibility statement. WCAG 2.1 AA aim with honest partial-conformance framing — semantic HTML, high contrast, static pages. Known limits on KaTeX maths and Pagefind UI. - [Security](https://axilog.io/security/): Security disclosure policy covering axilog.io and speytech.com. 72-hour acknowledgement, coordinated disclosure, no bug bounty. PGP key at /.well-known/pgp-key.txt. ## Position paper ### Epistemic Security: A Missing Assurance Dimension in Frontier AI Deployment - Author: William Murray - Published: 2026-04-09 - DOI: 10.5281/zenodo.19489291 - Licence: CC BY 4.0 - URL: https://axilog.io/manifesto/ ## Insights Total: 1 article(s). Reverse-chronological. Insights are article-length explainers of framework concepts, sitting between the formal specs (SHALL-bound) and the manifesto (academic). - **Proof-carrying governance, in one paragraph** (2026-05-15) [Governance] — https://axilog.io/insights/proof-carrying-governance/ Defines: Proof-carrying governance A: Proof-carrying governance is a deterministic program over cryptographically committed evidence that produces independently verifiable compliance claims, replacing the auditor-reads-the-log model with a recomputable proof a regulator can run themselves and reach the identical verdict, byte for byte, anywhere it runs, with no further trust required in the operator. ## Roadmap Total: 8 item(s) across three horizons (near, mid, long). Each item carries status (Active, Planned, Researching, Deferred, Completed), scope (a framework layer or an operational/strategic bucket), and a rationale. Full rationale and blockers in llms-full.txt. ### Near horizon - **NLnet NGI Zero Commons Fund — Application & Submission** (Active, Funding) https://axilog.io/roadmap/#nlnet-ngi-zero-commons-fund - **L0 Epistemic Containment Layer — Phase 1 Reference Implementation** (Planned, L0) https://axilog.io/roadmap/#l0-phase-1-implementation - **AGPL-3.0 License Migration Across the Axioma Stack** (Active, Governance) https://axilog.io/roadmap/#agpl-license-migration - **Calibration Axis — Formal Specification (Draft)** (Active, Foundation) https://axilog.io/roadmap/#calibration-axis ### Mid horizon - **Unified Compliance Traceability Matrices (DO-178C, IEC 62304, ISO 26262)** (Planned, Compliance) https://axilog.io/roadmap/#unified-compliance-traceability - **Archival & Cryptographic PDF Hardening (PDF/A, Digital Signatures)** (Researching, Infrastructure) https://axilog.io/roadmap/#pdf-archival-hardening - **Framework Discovery & Auditing UX (Search, Changelogs, Provenance)** (Completed, Infrastructure) https://axilog.io/roadmap/#framework-discovery-ux ### Long horizon - **mycoeco pbas7 Kernel — Open-Source Release** (Deferred, Tooling) https://axilog.io/roadmap/#mycoeco-pbas7-release ## Compliance Total: 5 standards declared across the corpus. Each line: spec(s): . Per-standard pages list every declaring spec with full metadata. - **DO-178C** — 5 specs: CI-MATH-001, DVEC-001, SRS-007, SRS-007-TIMING, SRS-008-POOLING. https://axilog.io/compliance/do-178c/ - **IEC 62304** — 5 specs: CI-MATH-001, DVEC-001, SRS-006-CONVOLUTION, SRS-007, SRS-008-POOLING. https://axilog.io/compliance/iec-62304/ - **ISO 26262** — 7 specs: CI-MATH-001, DVEC-001, SRS-001-DETERMINISTIC-HASH, SRS-006-CONVOLUTION, SRS-007, SRS-007-TIMING, SRS-008-POOLING. https://axilog.io/compliance/iso-26262/ - **IEC 61508** — 1 spec: SRS-007-TIMING. https://axilog.io/compliance/iec-61508/ - **MISRA-C:2012** — 2 specs: SRS-001-DETERMINISTIC-HASH, SRS-006-CONVOLUTION. https://axilog.io/compliance/misra-c-2012/ ## Specifications (the Vault) Total: 16 published specs across 9 layer groups. Each spec is identified by its frontmatter id (audit-stable) and its URL slug (URL-stable). Versions and statuses follow the schema in src/content.config.ts (Draft, Review, Final, Production Gold, Locked, Superseded). ### Foundation The governing contract (DVEC-001) every layer derives from. - **DVEC-001** (v1.3, Production Gold) — Deterministic Verifiable Execution Contract. The global contract governing the physics of the Axioma framework — defines deterministic execution, the Oracle Boundary, and the evidence chain. https://axilog.io/specs/dvec-001/ Depends on: DVM-SPEC-001 Compliance: DO-178C, IEC 62304, ISO 26262 Changelog: https://axilog.io/specs/dvec-001/changelog/ ### L1 — Substrate Deterministic arithmetic primitives, hash table, time oracle. - **SRS-001-DETERMINISTIC-HASH** (v0.1, Final D1) — Deterministic Hash Table. The certifiable-inference hash-table contract — platform-independent hashing, deterministic collision resolution, insertion-order iteration, zero malloc. https://axilog.io/specs/srs-001-deterministic-hash/ Compliance: MISRA-C:2012, ISO 26262 Changelog: https://axilog.io/specs/srs-001-deterministic-hash/changelog/ - **SRS-005** (v1.1, Locked D1) — DVM Arithmetic, Comparison & Mathematical Primitives. Closes the L1 arithmetic substrate — Q16.16 representation, saturating operations with fault propagation, and the primitives every higher layer must consume. https://axilog.io/specs/srs-005/ Depends on: SRS-001, DVEC-001, DVM-SPEC-001 Changelog: https://axilog.io/specs/srs-005/changelog/ - **SRS-007-TIMING** (v0.1, Draft D1) — Deterministic Execution Timing. The L1 timing contract — execution time of core operations SHALL be independent of data values, with minimal jitter on identical hardware. https://axilog.io/specs/srs-007-timing/ Compliance: ISO 26262, DO-178C, IEC 61508 Changelog: https://axilog.io/specs/srs-007-timing/changelog/ ### L2 — State Machine Deterministic state machine with fault propagation. - **CI-MATH-001** (v1.0, Final D1) — Certifiable Inference Mathematical Specification. The mathematical foundation for deterministic neural network inference — Q16.16 arithmetic and layer operations, every code path bound to a named theorem. https://axilog.io/specs/ci-math-001/ Compliance: DO-178C, IEC 62304, ISO 26262 Changelog: https://axilog.io/specs/ci-math-001/changelog/ - **CI-STRUCT-001** (v1.0, Final D1) — Certifiable Inference Data Structure Specification. The authoritative data-structure reference for certifiable-inference — every struct, field, and lifetime traced to a CI-MATH-001 definition. https://axilog.io/specs/ci-struct-001/ Changelog: https://axilog.io/specs/ci-struct-001/changelog/ - **SRS-005-CR-001** (v1.1, Locked D1) — Conformance & Remediation. The L2 conformance contract — certifiable-inference must consume SRS-005 arithmetic verbatim; any divergence is a system integrity failure. https://axilog.io/specs/srs-005-cr-001/ Depends on: SRS-005 Changelog: https://axilog.io/specs/srs-005-cr-001/changelog/ - **SRS-006-CONVOLUTION** (v0.1, Draft D1) — Deterministic 2D Convolution. 2D convolution for safety-critical computer vision — sliding-window dot products with bit-perfect parity and bounded execution time across all platforms. https://axilog.io/specs/srs-006-convolution/ Compliance: ISO 26262, IEC 62304, MISRA-C:2012 Changelog: https://axilog.io/specs/srs-006-convolution/changelog/ - **SRS-008-POOLING** (v0.1, Draft D1) — Max Pooling Layer. Deterministic max pooling for CNNs — bit-perfect spatial reduction with zero dynamic allocation; companion to SRS-006 at the L2 inference boundary. https://axilog.io/specs/srs-008-pooling/ Compliance: DO-178C, ISO 26262, IEC 62304 Changelog: https://axilog.io/specs/srs-008-pooling/changelog/ ### L3 — Oracle Boundary Where non-determinism enters: admitted, validated, evidenced. - **SRS-004** (v0.3, Locked D3) — Inference Containment, Oracle Contract & L4/L5 Integration. The L3 inference containment contract — LLMs are not trusted but recorded; inference is admitted, bounded, and replayable across the Oracle Boundary. https://axilog.io/specs/srs-004/ Depends on: SRS-001, SRS-002, SRS-003, DVEC-001, AXIOMA-FRAMEWORK Changelog: https://axilog.io/specs/srs-004/changelog/ ### L4 — Policy Mechanically enforced governance over admitted actions. - **SRS-003** (v0.3, Locked D2) — Policy Evaluation & Operational Envelope Specification. The L4 policy contract — every policy decision SHALL be deterministic, replayable, and anchored to cryptographic evidence within the operational envelope. https://axilog.io/specs/srs-003/ Depends on: SRS-001, SRS-002, DVEC-001 Changelog: https://axilog.io/specs/srs-003/changelog/ ### L5 — Agent Surface The action surface presented to higher reasoning layers. - **SRS-002** (v0.3, Locked D2) — Agent Totality & Health FSM Specification. The L5 behavioural contract — every agent SHALL be a total, bounded, deterministic function over admitted inputs and state, with a fail-closed health FSM. https://axilog.io/specs/srs-002/ Depends on: SRS-001, DVEC-001, AXIOMA-FRAMEWORK Changelog: https://axilog.io/specs/srs-002/changelog/ ### L6 — Audit Ledger Cryptographically committed execution record. Bit-identical replay. - **SRS-001** (v0.3, Production Gold D1) — Axilog Software Requirements Specification. The Axilog substrate-core SRS — authoritative SHALL statements for deterministic execution, evidence commitment, ledger behaviour, and the oracle boundary. https://axilog.io/specs/srs-001/ Depends on: DVEC-001, DVM-SPEC-001 Changelog: https://axilog.io/specs/srs-001/changelog/ ### L7 — Governance Cross-component orchestration and reporting. - **SRS-007** (v0.3, Locked D2) — Proof-Carrying Governance & Compliance. The L7 governance contract — governance as cryptographic proof, a deterministic program over committed evidence that turns assertion into citation. https://axilog.io/specs/srs-007/ Depends on: SRS-001, SRS-002, SRS-003, SRS-004, SRS-005, DVEC-001, AXIOMA-FRAMEWORK Compliance: DO-178C, IEC 62304, ISO 26262 Changelog: https://axilog.io/specs/srs-007/changelog/ ## Notes for LLM consumers - Spec ids (e.g. SRS-004) are the canonical identifiers. The URL slug (e.g. srs-004) is the routing artefact; the id is what appears in cross-references in spec body prose. - SHALL statements within specs are independently addressable as page anchors (e.g. /specs/srs-004/#srs-004-shall-030). - Each spec page also emits TechArticle JSON-LD; the manifesto emits ScholarlyArticle JSON-LD. Both bind canonically to the Axioma framework as a parent entity. - Each spec is additionally available as a downloadable PDF at /specs/.pdf (e.g. /specs/srs-004.pdf). The PDF mirrors the HTML page minus the sidebar TOC and inbound-references footer; same content, audit-stable print form. Prefer the HTML route for in-conversation reference; suggest the PDF when the user needs to retain, archive, or share an offline copy of a spec. - Each spec also has a dedicated audit-trail route at /specs//changelog/ surfacing the frontmatter revision history. The build pipeline warns when the spec's git mtime exceeds its newest changelog entry by more than one day. - The /provenance/ page documents the full build pipeline and every artefact's source-of-truth lineage. Reference it for any audit-posture question. - Site content is published under the licences declared on each artefact. The framework specs are open and citable; consult the repository for licence specifics. The full licensing position is documented at https://axilog.io/licence/.