SMARTHAUSThe Mathematically Governed AI Fabric
Investors ↗ Twenty minutes
SAIDGoverned inferenceIn daily use

We don't run your model. We decide whether what it says is allowed to count.

SAID is everything around the model. It chooses which model answers and records why, refuses to use a source it cannot point at, holds the answer to the evidence you supplied, and writes a record you can verify afterwards. The model itself is yours — running on your machine, or at a provider you already pay.

StatusIn daily use
SeamThe model's output
InferenceYours — local or your own provider
Sent to usNothing
EVERY CLAIM SOURCED · IT COUNTS “What notice does the supplier contract require?” yours · SAID does not run it YOUR MODEL REPAIR YOUR DOCUMENTS CHECK THE ANSWER, CLAIM BY CLAIM contract · §4 contract · §9 notices · §2 Notice is 90 days.§9 It must be in writing.§4 It goes by registered post.§2 COUNTS every claim points at a source RECORD which model answered, and why · sources §9 §4 §2 one claim repaired · sealed with a keyed hash NOTHING IN THE DECISION PATH IS A MODEL

Fluency is not correctness. A model produces a confident paragraph whether or not the thing it is describing is true, and every part of your organisation downstream of that paragraph treats it as an answer. The industry's response has largely been to ask a second model whether the first one was right — a guessing machine supervising a guessing machine, with nothing underneath to catch it.

The statistical part proposes. The deterministic part decides. Nothing in the decision path is a model.

And we are not in the model business. We do not train models, we do not host them, and we have no opinion about whose is best. Inference is a handful of thin adapters that call a library on your own machine or an interface you already have an account with. Everything that makes SAID worth having sits around that call, not inside it.

The position, in one sentence

Everyone else is competing on the model.

SAID competes on everything the model cannot do for itself: choosing, checking, sourcing, recording, and refusing.

It abstains rather than guesses

Give it the facts an answer must rest on and it holds the answer to them. When the response is not supported, it is rejected and the caller is told, rather than being handed a confident paragraph. This is on by default, not opt-in.

It refuses a source it cannot point at

When it searches your documents, the whole request fails rather than proceed on a passage with no document identity, no position, a score below the bar, or a result set that is not in strict order. Most retrieval returns its best guess and leaves you to sort it out.

The checks are predicates, never a model

Set membership, numeric range, length, pattern match, pattern reject, format, maximum count. Seven fixed types, and a violation drives a repair attempt rather than only a refusal.

Every answer carries a receipt you can verify

Sealed with a keyed hash and independently checkable: which model answered, under which weights, on which build, against which enrolled model fingerprint, and why that model was chosen.

The same request produces the same decision

A pure function of the request, the models available and your configuration — no clock, no randomness, no network — with the same 132 decisions checked across two independent implementations to twelve decimal places.

Determinism here is a property of the decision — which model, under which rules, with which sources — not of the generated prose. We say which, because a reader will otherwise assume the stronger claim.

And what SAID is not

Not a model, a hosting service, or a place your data goes.

Inference runs where you put it

An Apple Silicon machine through the standard local library, or a provider you already have an account with. SAID adds no inference of its own and has no preferred model.

Nothing is sent to us

The part of the runtime that gathers operating statistics contains no network capability of any kind — not disabled, not opt-out, absent — and the only way to read those numbers is to ask the service for them yourself. Provider keys live in the operating system keychain rather than a file.

The problem

A confident answer and a correct answer look identical.

That is the whole difficulty, and almost every response to it has been to add another model.

01

Fluency is not correctness

The paragraph reads the same whether or not the thing it describes is true, and everything downstream treats it as an answer.

02

A model judging a model has nothing underneath it

When the judge is wrong, there is no deterministic layer to catch it — the same process produced both the answer and the confidence in it.

03

Retrieval returns its best guess

A passage with no document identity, no position or a score below the bar still comes back, and the caller is left to work out that it should not have.

The test

Switch it off and the agent cannot act.

Not a gap in the record. Not a missing report. The action does not occur, because the thing that was switched off was in the path rather than beside it.

That is the whole distinction, and it is checkable in four seconds rather than argued. A system that describes who should decide produces paperwork. A system that decides produces effects — this ran, this did not, this waited for a named person.

Which is also why we are upstream of the platforms that keep the register rather than competing with them. Their file is better if we exist, because for the first time there is a system behind the assertion instead of a paragraph.

How it works

One request, six decisions, one record.

Nothing in the decision path is a model: the checks are fixed predicates, the retrieval rules raise rather than return, and the record is arithmetic.

Choose
which model answers, and why — a pure function of the request
→
Source
retrieval that aborts rather than degrades
→
Infer
your model, on your machine or your provider
→
Check
deterministic predicates — no model in the path
→
Repair or refuse
a violation drives a repair attempt, not only a refusal
→
Record
a receipt you can verify afterwards

What it governs

Four things, none of which is the model.

SAID has no opinion about whose model is best. It has opinions about everything around the call.

Which model answered, and why

Explainable selection: the choice is a pure function of the request, the models available and your configuration, and the reason travels with the answer.

What the answer was allowed to rest on

Evidence-bounded answering, fail-closed by default, with an explicit insufficient-evidence contract and a named violation plus diagnostics on rejection.

Whether the source is real

Retrieval aborts rather than degrades: no document identity, no position, a score below the bar or a result set out of order fails the whole request.

What can be said about it afterwards

Admission control, the artifact fingerprint, the durable record, and a control plane that fails closed.

Evidence

Running today, on our own work.

RunningEvidence-bounded answeringFail-closed by default, with an explicit insufficient-evidence contract and a named violation plus diagnostics on rejection.
RunningRetrieval that aborts rather than degradesThe whole request fails rather than proceed on a passage it cannot point at.
RunningExplainable selectionWhich model answered and why, carried with the answer.
RunningAdmission control and the durable recordA control plane that fails closed, and a record that persists.

Hard questions

What a serious buyer asks.

“Isn't this just retrieval with extra steps?”

The difference is what happens when the evidence is not there. Ordinary retrieval returns its best passage and lets the model write around it. This declines.

Give it the facts an answer must rest on and it holds the answer to them. When the response is not supported it is rejected and the caller is told, with a named violation and diagnostics rather than a softer paragraph.

“You said determinism. Do I get the same prose every time?”

No, and we are careful about which claim we make. Determinism here is a property of the decision — which model, under which rules, with which sources — not of the generated text.

“Whose model do we have to use?”

Yours. An Apple Silicon machine through the standard local library, or a provider you already have an account with. We add no inference of our own and have no preferred model.

The signed, distributable build is Apple Silicon today. The library is portable and the provider adapters are platform-neutral.

“What leaves our network?”

Nothing reaches us. The part of the runtime that gathers operating statistics contains no network capability of any kind — not disabled, not opt-out, absent. The only way to read those numbers is to ask the service for them yourself.

Provider keys live in the operating system keychain rather than a file.

In the fabric

Where SAID sits, and what it hands on.

SAID is the seam where a statistical proposal becomes something the rest of your systems are asked to trust.

TAI
→
MAIA
→
CAIO
→
SAID
→
UCP
→
MGR
→
Effect

Beneath every step: RFS and NME hold state and meaning, and MAE on the Unified Calculus supplies the rules and their proofs.

The contract

What it promises the next component.

To UCP

A checked answer, and a record that joins the same ledger the action gate writes to.

To the caller

Either a supported answer, or an explicit refusal with a named violation and diagnostics.

To the auditor

Which model answered, under which weights, on which build, and why that model was chosen.

Every component is a product in its own right and works without the others. The contract is what makes them compose when you want them to, not a dependency that makes you take all of it.

The thesis

Mathematics as the nervous system of AI.

Everything here descends from one argument: that the integrating substrate for artificial intelligence should be mathematics itself — not another orchestration layer, not a better prompt, and not a policy document.

Each part of a modern AI system works. The joins between them do not. Vision, language, planning and retrieval are each remarkable and they are integrated through hand-built pipelines and brute-force scaling. The thesis proposes a shared mathematical space that components write into and read from through operations defined once and behaving the same way for all of them — a nervous system rather than a bundle of wires.

Guarantees become measurable. Every property claimed has a quantity attached. Measure it and either the implementation holds or it is broken; there is no third answer.

The foundation is reusable across customers. The calculus, the construction engine, the control plane and the receipts are common. Your rules, connectors, integrations and authority model are yours.

The ladder, in order

Each rung was built from the one before it.

Rung 01
The thesis
The origin.
Rung 02
Mathematical Autopsy
The method.
Rung 03
MAE
The engine that runs it.
Rung 04
Unified Calculus
The foundation it builds on.
Rung 05
The components
What you actually deploy.

That order is why the components share a foundation instead of being a suite assembled after the fact, and it is why a refusal at the action boundary can be traced back through a proof to a sentence somebody wrote.

The paper

Openly licensed, so you can check the argument.

Open

Mathematics as the Nervous System of AI: A Unified Field Operator Framework for Distributed Cognition. Philip Siniscalchi, v9, 27 August 2026, CC-BY-4.0.

Falsifiable

It separates conformance — does the implementation obey the mathematics it claims — from superiority over alternatives, and refuses to let the first stand in for the second.

Bounded

No claims about consciousness or sentience. The biological analogies are engineering inspiration, not identity claims. Theoretical extensions are labelled as a roadmap, never as capability.

Start at one seam

Bring one question your documents should answer, and one they should not.

Watch it answer the first from your evidence, and decline the second rather than improvise.

Book the twenty minutes