Governed Execution Infrastructure
Authority before protected action.
Evidence-backed authority, continuity, execution control, and proof.
KAVACH 2.0 Β· Architecture Β· Quickstart Β· Security Β· License notice
TRANSCRIPT is governed execution infrastructure for software actions that should not proceed on trust alone.
Its first public subsystem is KAVACH β a continuity-bound authority and protection substrate that turns context into an explicit execution decision:
Trust β Authority. Authority β Execution. Execution requires current continuity.
KAVACH evaluates trust context, issues bounded authority, revalidates continuity at execution time, and records authenticated evidence of what happened.
KAVACH 2.0 is the first publicly admitted subsystem of TRANSCRIPT.
| Capability | Public software reference |
|---|---|
| Decision semantics | OPEN / HOLD / REFUSE |
| Authority binding | Project, workload, resource, operation, provider, policy, continuity |
| Continuity | Project / workload / provider / policy / recovery generations |
| Execution control | Revalidation before protected execution |
| Replay behavior | One-use authority and consumption semantics |
| Recovery behavior | Recovery invalidates stale recovery-dependent authority |
| Evidence | Authenticated append-oriented execution receipts |
| SDK surface | Bounded reference client; no direct βset OPENβ authority |
| Provider assurance | SOFTWARE_REFERENCE |
Release: KAVACH 2.0 β Software Reference
Many systems collapse trust, authorization, execution, and logging into one decision boundary. KAVACH separates them.
A request can be trusted yet still lack authority. Authority can be valid yet become stale before execution. Recovery can invalidate earlier authority. A receipt should prove the execution lineage rather than merely report that an action happened.
That separation is the engineering idea behind KAVACH:
- Appraise context.
- Decide explicitly.
- Bind authority to current continuity.
- Revalidate before execution.
- Emit evidence after execution.
git clone https://github.com/XMECK-LAB/TRANSCRIPT.git
cd TRANSCRIPT
$env:PYTHONPATH = "$PWD\KAVACH\src"
python -m unittest discover KAVACH\testsgit clone https://github.com/XMECK-LAB/TRANSCRIPT.git
cd TRANSCRIPT
PYTHONPATH="$PWD/KAVACH/src" python -m unittest discover KAVACH/testsFor the architecture and module map, start with KAVACH/README.md.
The repository includes a real public reference demo, not a screenshot-only mock.
$env:PYTHONPATH = "$PWD\KAVACH\src"
python KAVACH\examples\protected_action_demo.pyIt demonstrates:
TRUSTED β OPEN β protected execution β recovery continuity change β REFUSE(STALE_CONTINUITY) β verified evidence chain
See KAVACH/examples/README.md.
TRANSCRIPT/
βββ README.md
βββ SECURITY.md
βββ LICENSE-NOTICE.md
βββ CHANGELOG.md
βββ CITATION.cff
βββ assets/
β βββ transcript-kavach-hero.svg
β βββ authority-flow.svg
β βββ demo-authority-lifecycle.svg
βββ docs/
β βββ ARCHITECTURE.md
β βββ PUBLICATION.md
β βββ REPOSITORY_MAP.md
βββ KAVACH/
βββ README.md
βββ PUBLIC-MANIFEST.json
βββ contracts/
βββ docs/
βββ sdk/
βββ src/
β βββ kavach_semantic/
β βββ kavach_runtime/
β βββ kavach_substrate/
βββ tests/
See the annotated map: docs/REPOSITORY_MAP.md.
Public maintenance and governance: docs/OPERATIONS.md.
Current public engineering line with software-reference authority semantics, SDK surface, public tests, contracts, provenance, and source manifest.
Historical Windows engineering line with a runnable unsigned Windows installer.
The public repository is intentionally narrower than the private engineering lineage.
Public today: the KAVACH 2.0 software reference, its contracts, SDK surface, tests, documentation, and the KAVACH 1.0 historical release line.
Not asserted by this release: hardware-backed authority, TPM/TEE/HSM assurance, independent security certification, formal verification, or production certification.
The exact statement is maintained in KAVACH/docs/CLAIM_BOUNDARY.md.
Security issues should be reported privately before public disclosure. See SECURITY.md.
This repository is public for engineering review, research communication, and product evaluation. Public visibility is not an open-source license grant. See LICENSE-NOTICE.md.
Designed and built by Raaj Mandale.
Published under XMECK-LAB.
The work represented here comes from an independent systems-engineering program focused on a single question:
What should exist between βwe trust thisβ and βthe system is allowed to execute thisβ?
KAVACH is the executable answer currently published from that program.