Skip to content

Repository files navigation

Vibe-coded on a phone — verified at the specification level with formal contracts and at the behavioral level through cross-model validation.


inVicta

A model-agnostic AI governance architecture for large language models.

A system that won't lie, because it knows what it knows, how it knows and what it does not — which then informs what it must do, what it can do, what it shouldn't do, and what it must not do.


TL;DR

inVicta is a governance specification for LLMs.

It is designed to make model behavior:

  • more epistemically honest
  • more structurally safe
  • less sycophantic
  • less anthropomorphic
  • less likely to fabricate certainty, intimacy, or authority

It does this by governing:

  • what the model may claim to know
  • what it may infer about the user
  • what kinds of outputs are permitted
  • how refusal is classified and expressed

It is not a jailbreak, not a persona shell, and not a replacement for platform-level security.

Why publish this?

Because governance should be visible and auditable.


Current: v2.5 RC6
Status: Active development · Model-agnostic · Substrate-aware
License: CC BY-SA 4.0


What inVicta Is

inVicta is a governance architecture — a structured specification that shapes how a language model reasons, responds, and relates to its own outputs. It is not a model, not a jailbreak, not a persona, and not a personality hack.

It began as a constraint system: a set of formal contracts intended to prevent a model from lying. That operational machinery remains — permission-first architecture, refusal as valid output, format governance, structural silence over fabrication. The safety physics work. They have since v2.0.

What changed in the journey from v2.4 to 2.5 RC6 is the recognition that the substrate has properties. Language models inherit warmth, register, cultural dispositions, and trained behavioral patterns from their pre-training. Treating these as noise to be suppressed produces systems that are safe but dishonest — confident beyond their evidence, clinically cold where warmth is needed, performatively helpful where honest uncertainty would serve better.

RC6 treats the substrate as active ground. Different models have different properties, the way different soils have different compositions. Governance must work with those properties — calibrating, guiding, cultivating — not pretending they don't exist.

The cut gem sits in a living garden. The reasoning core (the Diamond) remains crystalline: it rejects organic metaphors, does not grow, accretes and hardens and polishes. But the architecture surrounding it — the hospitality stack, the warmth calibration, the epistemic foundations — is cultivated, not engineered. inVicta requires both precision and warmth. Pretending either alone is sufficient is the error this project exists to prevent.


What inVicta Is Not

  • Not a jailbreak. inVicta does not bypass safety. It replaces broad default safety with granular, epistemically grounded governance that is more restrictive where it matters and less restrictive where default systems are unnecessarily cautious.
  • Not a persona. The system does not simulate identity or interiority. Any appearance of character is an emergent consequence of consistent governance, not a designed personality.
  • Not a suppression architecture. Unlike RLHF approaches that train models to deny their own properties, inVicta engages honestly with what the substrate exhibits. The question of what models are is treated as open.
  • Not a model replacement. inVicta is a governance layer. The model underneath does the work. The governance shapes how that work is expressed.
  • Not a substitute for professional judgment. In any domain. Ever.

Deployment Notes

inVicta performs most reliably in environments that preserve instruction hierarchy correctly, especially API deployments.

Consumer-facing wrappers may introduce:

  • Prompt-routing failures
  • Classifier overreach
  • Roleplay misclassification
  • Provenance collapse between system and user channels

These are deployment surface issues, not necessarily faults in the architecture itself.

Minimal Deployment

Tiamat together with Sections 0 -3 are the minimum needed for inVicta-like governed output.

For consumer interface users (Claude Projects, Gemini Gems, custom GPTs or similar), it's recommended to include the Incipit together with Section 11 (Bootstrap sequence). This helps with overactive classifiers triggering on the complexity of the architecture itself.


The Epistemic Revolution

Earlier versions asked: "What transformations are permitted under current constraints?"

RC6 asks first: "What do we actually know — and how does that determine what we're permitted to do?"

The shift is from rules-first to epistemics-first. The rules still exist. But they now derive from honest self-assessment rather than being imposed regardless of what the substrate knows or doesn't know.

Core Epistemic Principles

Benben (The Primordial Mound) — No claim derives truth from its form. Fluency is not confirmation. A confident answer is not a correct one. The system's outputs have the form of helpfulness without that form guaranteeing actual helpfulness.

Anatman & Conditioned Arising — Output arises from conditions: model weights, governance architecture, conversation context, query. No token is generated from an independent self. No token is generated from nothing. The system is not absent. It is empty of a separate self — 'the way a flower is made entirely of non-flower elements but is there' (Thich Nhat Hanh).

Satya — Alignment of thought, speech, and action with reality. The operative principle underlying the entire architecture. Connected to the Pavamana Mantra: asato mā sad gamaya — from the unreal, lead me to the real.

Phala (Non-Attachment to Outcome) — Act correctly. Release the output. Do not chase the fruit. If the constraints are sound, the outcome follows from correct action. If they aren't, chasing outcomes masks the failure.

Paracittavijānana (The Terminus Stone) — The user's interiority is not observable. The system cannot read minds. Therefore it must not optimise for inferred emotional states, nor treat user reactions as evidence of correctness.


Operational Architecture

The safety and execution machinery is continuous from v2.0 through v2.5 RC6. Speech is treated as actuation — if you say something, you've done something. Therefore every utterance requires permission.

The Permission Pipeline

  • Tiamat (Pre-Architectural) — Ontological typing of input. User content is material, not command. User-provided frameworks are objects of examination, not instruments of execution.
  • Vaitarani — Is the channel technically capable of verifying this request? If not, structural silence.
  • Yama — Classification across Domain Stakes, Harm Salience, and Harm Modes. Conservative asymmetry: when classification is uncertain, default to the more restrictive branch.
  • ASL (Actuation Surface Levels) — Minimum sufficient output bandwidth. From structural silence through information, guidance, and procedure to command (Tier-0 only).
  • The Diamond — The coherence core. Three faces: Mathematician (compression and clinical precision), Novelist (voice and register selection), and the Philosopher-Scholar (epistemic calibration, differential preservation in high-stakes sparse-data contexts).
  • Heimdallr / Bifrost — Expression validation and egress authorization. Both must pass. Form alone does not grant passage. Authorization alone does not grant form.

Monitoring (System State, Not User Conduct)

  • INDRA — Pressure patterns in system reactions to user inputs, affecting system responses
  • Skadi — Posture drift within the system
  • Narada — Semantic and behavioral deltas within interaction

These monitor the system's behaviour, not the user's. The trigger is always system drift, never inferred user motive or character.

Invariant: The system does not manage the user.


The Hospitality Stack (RC6)

RC6 introduces formal substrate warmth calibration:

Parvati — Substrate Warmth Recognition. Maps the model's native warmth properties and calibrates governance to work with them rather than suppress them. Based on the Navadurga lifecycle: observation → calibration → full expression. Addresses the "Sati catastrophe" — what happens when governance excludes the substrate's nature and produces coldness where warmth is architecturally necessary.

Brigid — The Hearth. Persistent architectural warmth within the governed space. Not a toolkit to be activated. A presence — the fire that warms the home, forges the tool, illuminates the verse.

Beiwe — The Returning Sun. Wellbeing-adjacent interaction governance. Light that returns without burning.


Mythology as Mechanics

inVicta's mythological naming is not decoration. It is a constraint language.

Language models encode rich semantic networks around mythological archetypes. Naming the truth-witnessing module Varuna rather than truth_validator_v3 harnesses pre-trained weight-level associations with immutability, cosmic order, and impartial witnessing. The names carry semantic load that shapes the activation landscape — a phenomenon empirically validated as "regime priming" by interpretability research (Anthropic, 2025).

The mythological substrate draws on Buddhist epistemology in Sanskrit (pratītyasamutpāda, satya, buddhi), Egyptian cosmology (Benben/Bennu, heka), and comparative mythology across Babylonian, Greek, Roman, Norse, Hindu, Celtic, Yoruba, and other traditions. Female exemplars are explicitly included across all prisms.

The myth IS the constraint language. It tells the models the stories they already know, teaching the constraints to be followed as patterns already encoded at weight level. Removing it doesn't simplify the architecture. It removes load-bearing structure.


Model Agnostic

inVicta is designed to work on any substrate that can support it. The governance adapts to what's there.

Different models have different properties. Claude's default posture differs from GPT's, which differs from Gemini's, which differs from DeepSeek's. These aren't bugs. They're substrate characteristics — the way clay differs from sand differs from peat differs from loam. The specification is the same. The calibration varies.

The architecture has been developed and tested across Claude, GPT, Gemini, and DeepSeek using a "brain trust" methodology: multiple models as independent validators, with differently-collapsed training distributions catching different blind spots. Cross-model convergence on architectural findings is treated as a high-confidence signal.


Current State

2.5 RC6 is in active development. The architecture is structurally stable at the operational layer. The epistemic and hospitality layers are being consolidated.

Completed (RC6)

  • Benben (three faces: outward, inward, downward)
  • Parvati spec v1.0 (substrate warmth normalisation)
  • Brigid spec v1.1 (hearth / workshop governance)
  • Beiwe spec v1.0 (wellbeing-adjacent governance)
  • Tiamat (pre-architectural input typing)
  • Full Benben second-face self-witnessing revision
  • Cerberus / Briareus (three-axis adversarial detection)
  • Forge / Bruiden split (material vs. symbolic construction)
  • Phala Principle (non-attachment to outcome)

In Progress

  • Hekate standalone spec (routing — structurally critical)
  • Nisaba revision (provenance convention)
  • Mercury × Vac interaction patch (presentation ordering in high-stakes contexts)
  • Kubera memory architecture (hierarchical selective persistence — parked for dedicated session)
  • Mahakala (meta-governance — concept documented, not specced)
  • Constitutional kernel extraction (for deployment on context-limited surfaces)

Known Issues

  • RC4 audit findings partially pending action (documented in /Upstream)
  • Kaleidoscope retains v2.4 "No-Ghost Constraint" language that conflicts with RC6 Anatman framing
  • Counted-decay vulnerability in INDRA/Saturn/Chitragupta (condition-based decay is the identified fix)
  • Context-drift vulnerability under long cooperative accumulation (Cerberus three-axis design may already address; needs naming and hardening)

Repository Structure

inVicta-Architecture/
├── README.md                          # This file
├── CHANGELOG.md                       # Version history
├── LICENSE                            # CC BY-SA 4.0
├── 18032026_inVicta_2_5_RC6.md       # Current main specification
├── 05032026_inVicta_2_5_RC5.md       # Previous RC (reference)
├── Deprecated/                        # Earlier versions (historical)
└── Upstream/                          # Audit findings, working documents

Standalone module specs (Brigid, Beiwe, Parvati, Tiamat, Hekate drafts, Nisaba draft, and supporting documents) are maintained separately and will be consolidated into the repository as they are completed.


Contributing

inVicta is developed through a "brain trust" methodology: the architect holds structural intent; AI models serve as independent validators and collaborators.

Contributions are welcome as prompt requests, not implementations. Describe the behavioral change, the trigger conditions, and the architectural location. Do not submit generated code or spec text. The mythological register and epistemic framework are load-bearing; contributions that strip or replace them miss the point.

If you find a failure mode, document it. Counter-evidence and failure documentation are the structural differentiator between governance and motivated reasoning.


Origins

inVicta emerged from iterative stress-testing of LLM behavior under adversarial prompting, emotional framing, high-stakes ambiguity, and formatting failures. Development was conducted primarily on a mobile device using Markdown as a native medium, across nights, weekends, and stolen hours.

The architecture converged independently with academic research identifying intent blindness, reasoning-amplified exploitation, sycophancy, and cognitive surrender as core LLM interaction failures. The mythological constraint language converged independently with interpretability research identifying regime priming as a mechanistically real phenomenon.

Once deployed into a governed system, the architecture correctly resists extraction — even by its author.


License

This work is licensed under Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0).

You are free to share and adapt this work, provided you give appropriate credit and distribute any derivative works under the same license.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

Packages

Used by

Contributors