Skip to content

Latest commit

Β 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

TRANSCRIPT / KAVACH β€” Governed Execution Infrastructure

TRANSCRIPT

Public Reference CI

Governed Execution Infrastructure

Authority before protected action.
Evidence-backed authority, continuity, execution control, and proof.

KAVACH 2.0 Β· Architecture Β· Quickstart Β· Security Β· License notice


⚑ What TRANSCRIPT is

TRANSCRIPT is governed execution infrastructure for software actions that should not proceed on trust alone.

Its first public subsystem is KAVACH β€” a continuity-bound authority and protection substrate that turns context into an explicit execution decision:

Trust β‰  Authority. Authority β‰  Execution. Execution requires current continuity.

KAVACH evaluates trust context, issues bounded authority, revalidates continuity at execution time, and records authenticated evidence of what happened.

KAVACH authority lifecycle

πŸ›‘οΈ KAVACH 2.0 β€” current public software reference

KAVACH 2.0 is the first publicly admitted subsystem of TRANSCRIPT.

Capability Public software reference
Decision semantics OPEN / HOLD / REFUSE
Authority binding Project, workload, resource, operation, provider, policy, continuity
Continuity Project / workload / provider / policy / recovery generations
Execution control Revalidation before protected execution
Replay behavior One-use authority and consumption semantics
Recovery behavior Recovery invalidates stale recovery-dependent authority
Evidence Authenticated append-oriented execution receipts
SDK surface Bounded reference client; no direct β€œset OPEN” authority
Provider assurance SOFTWARE_REFERENCE

Release: KAVACH 2.0 β€” Software Reference

🧠 Why this architecture exists

Many systems collapse trust, authorization, execution, and logging into one decision boundary. KAVACH separates them.

A request can be trusted yet still lack authority. Authority can be valid yet become stale before execution. Recovery can invalidate earlier authority. A receipt should prove the execution lineage rather than merely report that an action happened.

That separation is the engineering idea behind KAVACH:

  1. Appraise context.
  2. Decide explicitly.
  3. Bind authority to current continuity.
  4. Revalidate before execution.
  5. Emit evidence after execution.

KAVACH protected action reference demo

πŸš€ Run the public software reference

PowerShell

git clone https://github.com/XMECK-LAB/TRANSCRIPT.git
cd TRANSCRIPT

$env:PYTHONPATH = "$PWD\KAVACH\src"
python -m unittest discover KAVACH\tests

Bash

git clone https://github.com/XMECK-LAB/TRANSCRIPT.git
cd TRANSCRIPT

PYTHONPATH="$PWD/KAVACH/src" python -m unittest discover KAVACH/tests

For the architecture and module map, start with KAVACH/README.md.

▢️ Executable protected-action demo

The repository includes a real public reference demo, not a screenshot-only mock.

$env:PYTHONPATH = "$PWD\KAVACH\src"
python KAVACH\examples\protected_action_demo.py

It demonstrates:

TRUSTED β†’ OPEN β†’ protected execution β†’ recovery continuity change β†’ REFUSE(STALE_CONTINUITY) β†’ verified evidence chain

See KAVACH/examples/README.md.

🧩 Repository map

TRANSCRIPT/
β”œβ”€β”€ README.md
β”œβ”€β”€ SECURITY.md
β”œβ”€β”€ LICENSE-NOTICE.md
β”œβ”€β”€ CHANGELOG.md
β”œβ”€β”€ CITATION.cff
β”œβ”€β”€ assets/
β”‚   β”œβ”€β”€ transcript-kavach-hero.svg
β”‚   β”œβ”€β”€ authority-flow.svg
β”‚   └── demo-authority-lifecycle.svg
β”œβ”€β”€ docs/
β”‚   β”œβ”€β”€ ARCHITECTURE.md
β”‚   β”œβ”€β”€ PUBLICATION.md
β”‚   └── REPOSITORY_MAP.md
└── KAVACH/
    β”œβ”€β”€ README.md
    β”œβ”€β”€ PUBLIC-MANIFEST.json
    β”œβ”€β”€ contracts/
    β”œβ”€β”€ docs/
    β”œβ”€β”€ sdk/
    β”œβ”€β”€ src/
    β”‚   β”œβ”€β”€ kavach_semantic/
    β”‚   β”œβ”€β”€ kavach_runtime/
    β”‚   └── kavach_substrate/
    └── tests/

See the annotated map: docs/REPOSITORY_MAP.md.

Public maintenance and governance: docs/OPERATIONS.md.

πŸ“¦ Public release lines

KAVACH 2.0 β€” Software Reference

Current public engineering line with software-reference authority semantics, SDK surface, public tests, contracts, provenance, and source manifest.

Open KAVACH 2.0 release β†’

KAVACH 1.0 β€” Engineering Preview

Historical Windows engineering line with a runnable unsigned Windows installer.

Open KAVACH 1.0 release β†’

πŸ”¬ Engineering boundary

The public repository is intentionally narrower than the private engineering lineage.

Public today: the KAVACH 2.0 software reference, its contracts, SDK surface, tests, documentation, and the KAVACH 1.0 historical release line.

Not asserted by this release: hardware-backed authority, TPM/TEE/HSM assurance, independent security certification, formal verification, or production certification.

The exact statement is maintained in KAVACH/docs/CLAIM_BOUNDARY.md.

πŸ” Security

Security issues should be reported privately before public disclosure. See SECURITY.md.

πŸ“œ Publication and license

This repository is public for engineering review, research communication, and product evaluation. Public visibility is not an open-source license grant. See LICENSE-NOTICE.md.

πŸ‘€ Independent engineering

Designed and built by Raaj Mandale.
Published under XMECK-LAB.

The work represented here comes from an independent systems-engineering program focused on a single question:

What should exist between β€œwe trust this” and β€œthe system is allowed to execute this”?

KAVACH is the executable answer currently published from that program.

About

πŸ›‘οΈGoverned execution infrastructure with KAVACH continuity-bound authority, protected execution, and authenticated evidence.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages