Technical / System Architecture
Coherence by Invaris AI
The anti-gravity metaphor, precisely stated

Against the pull of the probable.

Language models are optimized to continue a sequence plausibly. Coherence inserts a different kind of machine into that path: a deterministic control architecture that freezes candidate output, decomposes its claim structure, maps what cannot lawfully survive, and withholds release until typed reliability prerequisites close.

  • Not model voting
  • Not a prompt wrapper
  • Not a truth oracle
  • Repair requires re-adjudication

Map the negative space first.

Most generative systems begin with positive space: what answer is likely, useful, fluent, or preferred? CRE begins with the complement. Given this prompt, this candidate response, these typed relations, and these active obligations, which compositions are inadmissible?

The surviving answer is not declared true because a model liked it. It is the candidate morphology that remains after deterministic exclusions, unresolved obligations, invalid transformations, and release blockers have been accounted for.

01.1

Candidate, never oracle

Provider output enters as an untrusted proposal. Confidence, citations, retrieval rank, model identity, and agreement are substrate—not authority.

01.2

Typed morphology

Prompt and response particles are closed against exact source spans. CRE derives the bonds, obligations, relation states, and prohibited transformations it will govern.

01.3

Authority must be earned

Only the Rust trust domain can close prerequisites and seal an exact final output. UI state, JavaScript projections, tools, billing, and telemetry cannot recreate that authority.

A metaphor for opposing objectives.

Prediction has a natural pull toward the next plausible token. Reliability has a different objective: prevent unsupported structure from becoming usable output merely because it arrived fluently.

Coherence does not make probability disappear. It surrounds probabilistic fluency with typed constraints, immutable checkpoints, separated observers, deterministic comparison, and an exact-output release boundary.

Probabilistic gravity

Generate the sequence most compatible with learned patterns, the current context, and the provider's decoding process.

Deterministic counterforce

Eliminate graph states that violate typed support, scope, relation, authority, continuity, repair, or finality prerequisites.

Image position 01 Full cutaway illustration of the probabilistic field meeting the CRE constraint field.
Figure 01 / Art direction reserved

The machine in one image.

A future hero-grade cutaway belongs here: candidate text entering at the top, typed constraints forming around it, inadmissible structures falling away, and only a sealed exact output crossing the release membrane.

The page is intentionally complete without the illustration. The image will clarify the architecture, not carry a claim the engineering cannot support.

Freeze. Observe. Derive. Decide.

The product path is staged so that later components cannot rewrite the evidence they are supposed to inspect. Primary generation and prompt observation begin from the same frozen turn package. The exact primary response is then frozen and hashed before response observation starts.

Observers propose particles. They do not supply bonds, verdicts, repair decisions, or release authority. CRE closes the graph and owns every semantic transition that follows.

Image position 02 Layered technical illustration of frozen inputs, observer isolation, and the Rust release membrane.
Figure 02 / System cutaway

Observation is not adjudication.

That separation is not cosmetic. It prevents a probabilistic observer from smuggling a verdict into the deterministic layer and prevents the response generator from becoming its own controlling witness.

Every station has a typed minimum-necessary projection. Missing, malformed, polluted, stale, or authority-bearing shapes fail closed.

Each layer gets less power than it wants.

Coherence is designed as a system of explicit incapabilities. Components are useful because of what they can do; the architecture is reliable because of what they are structurally prevented from doing.

Transport can spend but cannot decide. UI can display but cannot mint authority. Retrieval can find candidates but cannot turn them into support. Telemetry can remember but cannot govern.

Layer May own Must never own
Product UI Input, progress, guided interaction, audit presentation, released output. Direct provider/CRE invocation, semantic scoring, candidate-to-final promotion.
Coherence Runtime Canonical context packaging, orchestration, effect isolation, result projection. Proof synthesis, independent semantic verdicts, release authority.
Provider Gateway Model/tool routing, credentials, transport, cost reservations, usage, lineage. Truth, support, authority, repair success, CRE lanes, final release.
Observers + helpers Typed particle proposals, fluent candidates, bounded evidence synthesis. Bonds, verdicts, proof states, witness IDs, repair approval, release.
CRE / Rust Graph closure, deterministic relations, obligations, repair, re-adjudication, sealing. Invented external truth or untyped shortcuts around missing evidence.
Lab + CPD Measurement, replay, diagnostics, governed evidence, advisory calibration candidates. Runtime adjudication, scorecard-driven control, release authority.
Image position 03 Trust-domain lattice showing candidate, observed, evidence, verifier, witness, and release boundaries.
Figure 03 / Trust-domain lattice

Data can cross. Authority cannot hitchhike.

Structured payloads move through several domains, but proof-like fields are quarantined at provider boundaries. Content hashes establish integrity, not empirical truth. Schema validity establishes shape, not admissibility.

This is the spine of the proof-kernel work: keep inert evidence carriers and authoritative state transitions unmistakably different.

The system does not grade and walk away.

A reliability layer that only refuses is a sophisticated brake. CRE is built around elimination by repair: preserve fluency at the provider edge, narrow the lawful search space with typed constraints, then force the changed output back through fresh observation and the same adjudication path.

The old proof cannot be reused for new text. The repaired candidate must earn its own closure, and newly introduced debt terminates progress rather than being laundered into success.

R1

Locate typed debt

CRE identifies the exact unresolved relation, support, scope, continuity, or finality condition.

R2

Compile constraints

A complete composite repair plan preserves secondary failures instead of collapsing everything into one label.

R3

Recover fluency

The repair provider writes naturally inside the deterministic scaffolding. It cannot approve its own work.

R4

Invalidate stale proof

The candidate is frozen and hashed. Prior response observation and release prerequisites no longer apply.

R5

Re-observe and re-adjudicate

The same membrane and graph path runs again. Only monotonic typed progress may continue toward release.

Image position 04 Claim-local repair trace: changed span, invalidated obligations, new observation, closed result.
Figure 04 / Repair trace

Every correction leaves a trail.

Replay binds exact text, hashes, topology, observer substrate, repair steps, dispositions, and the final authority envelope. The audit record can explain what changed without becoming a back door into runtime control.

Guided Repair uses the same principle. User-supplied material remains candidate input until it re-enters CRE and survives current-pair adjudication.

Long memory without magical authority.

Coherence separates exact history, derived recall, and scientific evidence because they have different jobs. The result is a pageable context architecture that can remain useful across long-running work without pretending that similarity, recency, or an old adjudication settles the current question.

Hot pages remain in the active window. Relevant older pages are recalled into a bounded warm window. Cold exact pages remain durable and addressable. Every recalled item is candidate context and the current prompt/response pair is still adjudicated fresh.

AWS / Exact

Durable product history

Encrypted per-user exact chat and project history is the governed record and rebuild source, retained until deletion or the applicable storage limit.

Authoritative for exact history only
Pinecone / Derived

Hyper Context Cube

Separate ordinary and repair lanes hold deterministic vectors and prompt-free metadata. Opaque matches map back to exact product-owned pages.

Rebuildable candidate recall
Supabase / CPD

Reliability evidence

Governed product-live and Lab evidence supports diagnostics, evaluation, research, and bounded advisory calibration—not product context or release.

Measurement, never runtime authority
Exact durable pages + Derived two-lane recall + Fresh CRE adjudication
Image position 05 Exploded Hyper Context Cube showing scope, time, semantic class, disposition, provenance, authority, decision, and lifecycle axes.
Figure 05 / Context cube

Infinite-feeling continuity, finite calls.

The design does not make a model's context window infinite. It makes durable context addressable, selectively pageable, and weighted by explicit equations while each provider call remains bounded.

Repair capsules preserve objectives, constraints, and prior dispositions as memory aids. A prior “clean” state is still not proof for a new claim.

Use models and tools. Do not obey them.

Coherence can route among managed model families, web search, semantic retrieval, structured computation, entity discovery, finance, academic literature, biomedical literature, and preprints. The important fact is not how many integrations exist. It is that the Gateway treats them as a conditional capability graph.

Before ranking, Auto Configure eliminates routes that violate entitlement, availability, context fit, observer structure, provider-family separation, latency, usage, cost, or margin constraints. No score can rescue an ineligible topology.

06.1

Lane-separated demand

Conversation, analysis, sources, current information, math, entities, documents, long context, code, high stakes, and specialist research remain distinct transport needs.

06.2

Smallest useful graph

Configured tools are eligible, not mandatory. Closed transformations suppress search. Complex source work may activate complementary components in bounded parallel batches.

06.3

Whole-turn economics

Generation, observation, retrieval, repair, re-observation, and guided acquisition reserve inside one authenticated hard envelope before provider traffic begins.

Image position 06 Provider and specialist-tool lattice with eliminated routes fading before a bounded plan is selected.
Figure 06 / Orchestration lattice

Agreement is not truth.

Independent sources may broaden coverage, expose conflict, or reduce correlated failure. They do not create support by majority vote. Provider-synthesized answers remain different from source records; both remain candidate material.

The helper may compare and compress a source neighborhood into one bounded candidate repair input. CRE still owns what happens next.

Designed to fail closed and recover cleanly.

The architecture is backed by executable boundaries rather than a diagram alone: Rust-owned transitions, generated wire contracts, bounded framing, opaque continuations, role-specific data projections, content-addressed replay, secret-isolated workflow processes, and explicit rollback paths.

Structural integrity and test evidence are reported as exactly that. They do not become claims of whole-product formal verification or empirical truth.

E1 / Rust trust domain

Semantic transitions stay sealed

The membrane, graph, orchestration, repair, prerequisite closure, replay construction, and release authority remain inside the engine boundary.

E2 / Generated contracts

One editable wire source

Product Runtime consumes generated request shapes. Unknown versions, extra fields, and authority-bearing envelopes fail closed.

E3 / Workflow host

Bounded, correlated, replaceable

The optional persistent host uses length-framed JSON, bounded in-flight work, exact request correlation, process-scope failure, and opaque continuation recovery.

E4 / Release assurance

Cross-language gates

JavaScript contracts, Rust formatting/checks/lints/tests, adapter tests, architecture boundaries, security, reproducibility, and schema classification run together.

Current qualification boundary: the product-active path uses Rust-owned live release prerequisites. The richer sealed proof-closure typestate, typed external-evidence promotion, and production effect cutover remain quarantined, shadowed, or explicitly exit-gated wherever their separate promotion evidence is incomplete.

What this architecture does not claim.

Strong engineering begins where category language ends. Coherence is designed to reduce reliability failures and make the path inspectable. It does not turn an open-world reasoning problem into certainty.

¬

No universal truth oracle

External facts can still require sources, domain authority, current evidence, or human judgment the system does not possess.

¬

No “models checking models” shortcut

Observers and helpers supply substrate. Their confidence, agreement, identity, and scores never become controlling verdicts.

¬

No claim of whole-product formal verification

Typed states, generated contracts, bounded-model artifacts, tests, and reproducibility evidence validate defined properties—not reality itself.

¬

No invisible downgrade to a candidate

When prerequisites do not close, the system must repair, ask, withhold, or fail. Candidate text cannot be scavenged into a governed final answer.

Keep the model. Change what may cross the boundary.

Open Coherence