Cyber-Safe Stack / New Category Map

Nine categories of NovaFuse New Capabilities.

The New Capabilities page introduces capabilities that emerged from taking Cyber-Safety principles and operationalizing them at runtime: a category map of what each capability enables, what it owns, what it does not own, and where its evidence or reference path lives.

A NovaFuse capability is not just a product name. It is a governed category with a boundary contract and a proof path.

New capabilities need boundaries or they collapse into platform language.

NovaFuse names categories only when the boundary is explicit. Each category must say what it controls, what it refuses to control, which neighboring categories it depends on, and what reference evidence supports it.

Capability

Something that can now be governed, executed, remembered, proven, protected, or adopted differently.

Boundary

The ownership contract that prevents one layer from absorbing another layer's job.

Evidence

A public repo, Resource Center document, implementation reference, or internal canon path that anchors the claim.

NAGS is the system. The four, the nine, and the portfolio are views inside it.

NAGS — the NovaFuse Atomic Governance System — is the system-level architecture for governing consequential digital effects. It is not a tenth category or a fifth runtime engine. It organizes the discipline, lifecycle, decision model, executable rules, release authority, composition rule, runtime mechanisms, capability taxonomy, and product portfolio into one operating model.

Doctrine and lifecycle

Cyber-Safety defines the discipline. Mechanical AI Alignment applies that discipline to AI-proposed effects. PEPRG governs before, during, and after execution. IDNA evaluates Identity, Data, Networks, and AI together.

Decision architecture

ERI makes claims executable. ERIL is the Executable Reference Implementation Language for admissibility rules. CERI is the Containerized Executable Reference Implementation package; after declared conformance is satisfied and evidence accepted, it may carry the phase-qualified designation Certified Executable Reference Implementation. DREA is the final release authority. FICT requires every mandatory federated condition to hold without weakening.

Core runtime mechanisms

NovaZK-ID resolves bounded authority. NovaAlign contributes an AI invariance judgment. NovaCore coordinates admissibility and routing. NovaDust enforces bounded containment and egress refusal.

Taxonomy and portfolio

The nine-category map classifies responsibilities. The wider NovaFuse portfolio contains implementations, ERIs, Proof Runs, and commercial capabilities that specialize or compose those categories.

NAGS > nine-category capability map > core runtime mechanisms > ERIs, products, and commercial offers.

The nine-category map.

These categories are structurally distinct. Cyber-Safety starts the stack, runtime evidence proves the motion, and each adjacent category owns a different part of governed digital capability.

01

Cyber-Safety

CS

Invariance-based runtime refusal, safe-execution enforcement, and Mechanical AI Alignment through NovaAlign.

Owns

Refusal, invariant enforcement, safe-execution boundaries, and the Mechanical AI Alignment doctrine.

Does Not Own

Admissible action flow after refusal gates, authority proof, or centralized orchestration.

Connects To

NovaAlign, ERI/ERIL, NovaZK-ID, and NovaCore API.

02

Semantic Execution Systems

ERI

Pre-execution admissibility and bounded executable reference behavior.

Owns

Whether an action is admissible to execute and how claims become executable reference surfaces.

Does Not Own

Identity proof, authority binding, or centralized runtime orchestration.

Connects To

Cyber-Safety, NovaZK-ID, and NovaCore API.

ERI pageERI repoERIL repoNovaFuse-ERI/spec
03

Decision Authority Infrastructure

ZK

Proof of authority without disclosure; capability and identity binding.

Owns

Who may cause action, capability binding, and identity/authority proof boundaries.

Does Not Own

Pre-execution semantics, runtime orchestration, or visualization.

Connects To

ERI/ERIL, NovaCore API, and Cyber-Safety.

NovaZK/NovaZK-IDCapability-Registry.mdResource Center
04

Unified Deterministic Control Plane

API

Single governance locus, orchestration, evidence, routing, and policy application.

Owns

Unified control and commit locus, governance routing, evidence coordination, and policy application.

Does Not Own

The correctness of the safety doctrine, semantic admissibility model, or authority proof itself.

Connects To

Cyber-Safety, ERI/ERIL, NovaZK-ID, NovaVision, NovaDust, NovaMemX, and PDSI-LLM / NovaCortex.

novacore/apinovacore/cyber-safetyResource Center
05

Deterministic Perception Engine

NV

Perception resolution and visualization surface: UI eliminated, perception resolved.

Owns

Resolved perception, visualization semantics, and interface-to-perception translation.

Does Not Own

Control-plane decisions, authority proof, or confidentiality enforcement.

Connects To

NovaCore API, NovaMemX, and PDSI-LLM / NovaCortex.

codebase-map.jsonCYBER-SAFE-COMPLIANT.mddemo-novacore-tests.js
06

Deterministic Confidentiality

ND

Bounded pre-effect containment, egress refusal, and confidentiality enforcement. Zero-egress results apply only to declared test profiles.

Owns

Declared egress checks, containment outcomes, and confidentiality enforcement inside a specified runtime boundary.

Does Not Own

Universal non-leakage guarantees, all covert channels, admissibility decisions, authority proof, or runtime orchestration.

Connects To

NovaCore API, Cyber-Safety, NovaAlign, and NovaZK-ID.

novadust-guardianalignment-invariance-battery-assessment.mdCyber-Safety-Category-Slide.md
08

Persistent Domain-Specific Intelligence

PDSI

PDSI-LLM / NovaCortex owns governed domain reasoning persistence.

Owns

Persisted reasoning inside domain envelopes and governed reasoning workflow surfaces.

Does Not Own

Long-horizon continuity storage by itself, authority proof, or unified runtime control.

Connects To

NovaMemX, NovaCore API, and NovaZK-ID.

src/novacortex/server.jsdocker-compose.novacortex-chat.yml
09

Non-Invasive Runtime Adoption

NIRA

Zero-migration adoption model where customer systems conform to the control plane instead of being replaced.

Owns

Deployment posture, integration strategy, and adoption without forced platform migration.

Does Not Own

Control-plane behavior, intelligence engines, or authority proof.

Connects To

NovaCore API, Cyber-Safety, IDNA, and DREA runtime enforcement references.

DREA-RUNTIME-ENFORCEMENT.mdIDNA-REFERENCE-MODEL.mdRUNTIME_REFUSAL_AND_FAILURE_SEMANTICS.md

Without ownership boundaries, every capability collapses into vague platform language.

The Cyber-Safe Stack keeps responsibility from drifting. Cyber-Safety refuses unsafe motion. Mechanical AI Alignment and NovaAlign bound AI-proposed effects. ERI/ERIL decides executable admissibility. NovaZK-ID proves authority. NovaCore coordinates the control locus. NovaMemX remembers across time. PDSI-LLM / NovaCortex reasons inside domain envelopes. None of those should silently absorb the others.

Owns

The responsibility the category is accountable for.

Does Not Own

The neighbor responsibility it must not blur or absorb.

Evidence Path

The public repo, Resource Center material, implementation reference, or canon file that anchors the category.

Capability to evidence coordination.

The Resource Center carries public documents and public repositories. The repository canon carries implementation references where a category exists in the checkout but is not yet packaged as a public standalone release.

CategoryPrimary Public ReferenceImplementation Evidence Path
Cyber-SafetyCyber-Safety page, Paradigm Paper, Operational Reference, public reponova-cybersafe-framework/
Semantic Execution SystemsERI/ERIL/CERI page, ERI repo, ERIL repoNovaFuse-ERI/spec, nova-eri-framework
Decision Authority InfrastructureResource Center coordination; public standalone release pending.NovaZK/NovaZK-ID/Capability-Registry.md
Unified Deterministic Control PlaneResource Center coordination; implementation reference in checkout.novacore/api, novacore/cyber-safety
Deterministic Perception EngineImplementation reference in checkout.codebase-map.json, demo-novacore-tests.js
Deterministic ConfidentialityImplementation reference in checkout.docker-compose.novatron-fixed.yml, alignment-invariance-battery-assessment.md
Continuity MemoryFeatured implementation reference; public standalone release pending.src/novamemx/coherence_audit.py, src/novamemx/temporal_threading.py
PDSI-LLM / NovaCortexImplementation reference in checkout.action.yml, docker-compose.novacortex-chat.yml
Non-Invasive Runtime AdoptionIDNA Reference Model, runtime refusal references.NovaFuse/runtime/DREA-RUNTIME-ENFORCEMENT.md

Internal canon path: NovaFuse/CATEGORY_CANON.md. Naming standard: PDSI-LLM. Avoid the transposed acronym variant.