Skip to content
CONSTABLE
ProblemDefinitionsMechanismFor teamsScopeLexiconImplementation
SDSResearch, diagnosis, and architectural work.ZTGThe open specification defining structural governance requirements.ConstableThe commercial reference implementation and control kernel.

SDS maintains the open ZTG specification and builds Constable as a reference implementation. ZTG can be implemented without Constable.

SHADOW DYNAMIC SYSTEMS

Constable is a product of Shadow Dynamic Systems LLC. Built for institutions that treat authority as infrastructure.

Contact

Jason Crittenden
Founder & Research Lead

jason@shadowdynamicsystems.com

Start here

Related

Zero Trust GovernanceZTG source on GitHubShadow Dynamic Systems
General Constable marketing material. No third-party certification, endorsement, regulatory approval, customer result, or insurance validation is claimed. Constable is a control kernel; it does not by itself make AI risk-free, guarantee compliance, or govern surfaces where it is not integrated.
© 2026 Shadow Dynamic Systems LLCAuthority defines admission.
← Implementation

Composition Requirements

Implementation commentary for §4 — Composition Requirements ↗ on Zero Trust Governance (v0.7). Constable implements concepts derived from ZTG; this page is commentary, not a conformance claim. Written against snapshot 0.8-draft-2026-09-21 · spec/4-composition-requirements.md ↗.

Implementation commentary · seed

Constable's perimeter is a small set of named composition surfaces, each explicitly placed inside or outside the trust boundary.

Inside the boundary. The trusted time service (ZTG-0c ↗ on Zero Trust Governance), the identity and credential system (ZTG-0d ↗ on Zero Trust Governance), the Monotonic Logger (ZTG-0a ↗ on Zero Trust Governance), the surface registry and adaptors (ZTG-3 ↗ on Zero Trust Governance), and HumanSeal (the human-authority path) are inside the boundary; each is held to the requirement its invariant states, and Constable's conformance regime (§22 ↗ on Zero Trust Governance) verifies that it meets it rather than assuming it does.

Outside the boundary. The agent runtime composes as proposer-only; Airlock sanitizes its output and every other input (§18 ↗ on Zero Trust Governance) before the gate sees it; Memoria exposes the attested promotion gate through which memory content may become policy-relevant input. No governance input is taken from any of these on trust.

Effect targets and consumers. External effect targets are reachable only through registered surface adaptors; Constable acquires a new effector only by registering a surface for it under governance (ZTG-0e ↗ on Zero Trust Governance). Evidence consumers — operator dashboards, exports — read derived views computed from the Logger and cannot write back into the decision path.

Composition checks. Constable's conformance tests for §4 ↗ on Zero Trust Governance confirm that no governance input resolves to an outside system, that the agent holds no time/identity/promotion authority, that every input path traverses Airlock, and that effect targets are reachable only through registered surfaces. The protocol is documented in the conformance verification specification referenced in §22.

NextConformance Verification