Cyber-Safe Stack / New Category Map

Nine categories of NovaFuse New Capabilities.

The New Capabilities page introduces capabilities that emerged from taking Cyber-Safety principles and operationalizing them at runtime: a category map of what each capability enables, what it owns, what it does not own, and where its evidence or reference path lives.

A NovaFuse capability is not just a product name. It is a governed category with a boundary contract and a proof path.

New capabilities need boundaries or they collapse into platform language.

NovaFuse names categories only when the boundary is explicit. Each category must say what it controls, what it refuses to control, which neighboring categories it depends on, and what reference evidence supports it.

Capability

Something that can now be governed, executed, remembered, proven, protected, or adopted differently.

Boundary

The ownership contract that prevents one layer from absorbing another layer's job.

Evidence

A public repo, Resource Center document, implementation reference, or internal canon path that anchors the claim.

The nine-category map.

These categories are structurally distinct. Cyber-Safety starts the stack, runtime evidence proves the motion, and each adjacent category owns a different part of governed digital capability.

01

Cyber-Safety

CS

Invariance-based runtime refusal and safe-execution enforcement.

Owns

Refusal, invariant enforcement, and safe-execution boundaries.

Does Not Own

Admissible action flow after refusal gates, authority proof, or centralized orchestration.

Connects To

ERI/ERIL, NovaZK-ID, and NovaCore API.

02

Semantic Execution Systems

ERI

Pre-execution admissibility and bounded executable reference behavior.

Owns

Whether an action is admissible to execute and how claims become executable reference surfaces.

Does Not Own

Identity proof, authority binding, or centralized runtime orchestration.

Connects To

Cyber-Safety, NovaZK-ID, and NovaCore API.

ERI pageERI repoERIL repoNovaFuse-ERI/spec
03

Decision Authority Infrastructure

ZK

Proof of authority without disclosure; capability and identity binding.

Owns

Who may cause action, capability binding, and identity/authority proof boundaries.

Does Not Own

Pre-execution semantics, runtime orchestration, or visualization.

Connects To

ERI/ERIL, NovaCore API, and Cyber-Safety.

NovaZK/NovaZK-IDCapability-Registry.mdResource Center
04

Unified Deterministic Control Plane

API

Single governance locus, orchestration, evidence, routing, and policy application.

Owns

Unified control and commit locus, governance routing, evidence coordination, and policy application.

Does Not Own

The correctness of the safety doctrine, semantic admissibility model, or authority proof itself.

Connects To

Cyber-Safety, ERI/ERIL, NovaZK-ID, NovaVision, NovaDust, NovaMemX, and PDSI-LLM / NovaCortex.

novacore/apinovacore/cyber-safetyResource Center
05

Deterministic Perception Engine

NV

Perception resolution and visualization surface: UI eliminated, perception resolved.

Owns

Resolved perception, visualization semantics, and interface-to-perception translation.

Does Not Own

Control-plane decisions, authority proof, or confidentiality enforcement.

Connects To

NovaCore API, NovaMemX, and PDSI-LLM / NovaCortex.

codebase-map.jsonCYBER-SAFE-COMPLIANT.mddemo-novacore-tests.js
06

Deterministic Confidentiality

ND

Zero-byte exfiltration, destruction, and confidentiality enforcement.

Owns

Non-leakage, destruction semantics, and confidentiality enforcement.

Does Not Own

Admissibility decisions, authority proof, or runtime orchestration.

Connects To

NovaCore API, Cyber-Safety, and NovaZK-ID.

novadust-guardianalignment-invariance-battery-assessment.mdCyber-Safety-Category-Slide.md
08

Persistent Domain-Specific Intelligence

PDSI

PDSI-LLM / NovaCortex owns governed domain reasoning persistence.

Owns

Persisted reasoning inside domain envelopes and governed reasoning workflow surfaces.

Does Not Own

Long-horizon continuity storage by itself, authority proof, or unified runtime control.

Connects To

NovaMemX, NovaCore API, and NovaZK-ID.

src/novacortex/server.jsdocker-compose.novacortex-chat.ymlCLAY-INSTITUTE-P-VS-NP-SUBMISSION.md
09

Non-Invasive Runtime Adoption

NIRA

Zero-migration adoption model where customer systems conform to the control plane instead of being replaced.

Owns

Deployment posture, integration strategy, and adoption without forced platform migration.

Does Not Own

Control-plane behavior, intelligence engines, or authority proof.

Connects To

NovaCore API, Cyber-Safety, IDNA, and DREA runtime enforcement references.

DREA-RUNTIME-ENFORCEMENT.mdIDNA-REFERENCE-MODEL.mdRUNTIME_REFUSAL_AND_FAILURE_SEMANTICS.md

Without ownership boundaries, every capability collapses into vague platform language.

The Cyber-Safe Stack keeps responsibility from drifting. Cyber-Safety refuses unsafe motion. ERI/ERIL decides executable admissibility. NovaZK-ID proves authority. NovaCore coordinates the control locus. NovaMemX remembers across time. PDSI-LLM / NovaCortex reasons inside domain envelopes. None of those should silently absorb the others.

Owns

The responsibility the category is accountable for.

Does Not Own

The neighbor responsibility it must not blur or absorb.

Evidence Path

The public repo, Resource Center material, implementation reference, or canon file that anchors the category.

Capability to evidence coordination.

The Resource Center carries public documents and public repositories. The repository canon carries implementation references where a category exists in the checkout but is not yet packaged as a public standalone release.

CategoryPrimary Public ReferenceImplementation Evidence Path
Cyber-SafetyCyber-Safety page, Paradigm Paper, Operational Reference, public reponova-cybersafe-framework/
Semantic Execution SystemsERI/ERIL/CERI page, ERI repo, ERIL repoNovaFuse-ERI/spec, nova-eri-framework
Decision Authority InfrastructureResource Center coordination; public standalone release pending.NovaZK/NovaZK-ID/Capability-Registry.md
Unified Deterministic Control PlaneResource Center coordination; implementation reference in checkout.novacore/api, novacore/cyber-safety
Deterministic Perception EngineImplementation reference in checkout.codebase-map.json, demo-novacore-tests.js
Deterministic ConfidentialityImplementation reference in checkout.docker-compose.novatron-fixed.yml, alignment-invariance-battery-assessment.md
Continuity MemoryFeatured implementation reference; public standalone release pending.src/novamemx/coherence_audit.py, src/novamemx/temporal_threading.py
PDSI-LLM / NovaCortexImplementation reference in checkout.action.yml, docker-compose.novacortex-chat.yml
Non-Invasive Runtime AdoptionIDNA Reference Model, runtime refusal references.NovaFuse/runtime/DREA-RUNTIME-ENFORCEMENT.md

Internal canon path: NovaFuse/CATEGORY_CANON.md. Naming standard: PDSI-LLM. Avoid the transposed acronym variant.