NEO Partner Evidence Network · Ambiti8n (IPCEI-CIS) pilot rehearsal

Nine execution domains. One rail. 32 bytes per snapshot.

Each domain keeps its own book. What leaves it per closed period is a signed 32-byte snapshot root. The hub verifies the signature and the chain, never sees an event, and relays exactly those 32 bytes to the shared evidence rail. Everything below was observed on 3–4 September 2026 and read from the evidence files linked here.

observed, not promised · synthetic partner-controlled execution domains

0 · The case, in plain words

What problem this solves

In a data space, several independent organisations — hospitals, telecoms, cloud operators, integrators — must be able to show, months later, what happened in their own domain, and when: to an auditor, a regulator, a partner in a dispute, or a customer. Today they have two bad options. Trust the platform's logs, which somebody else owns and can rewrite. Or hand their operational data to a central party, which nobody wants to do — for privacy, for competition, for liability.

What we built

A third option. Every domain keeps its events and its book at home. Once per period it publishes one 32-byte fingerprint of that period to a shared evidence rail that no single party — including us — can rewrite. That is all that leaves the building: no records, no amounts, no identities, no telemetry. From then on the domain can prove any single record of that period — that it existed, in that form, at that time — offline, with anyone's calculator, even if the platform or the hub disappears. Two domains can also prove a claim between them (a handoff offered in one hour and accepted in the next) without either side opening its book.

Why it matters to the business

  • Audit readiness as a by-product. AI Act, health-data and contractual obligations are met by evidence the domain already produces, at the cost of a few hundred bytes a day, not a data-sharing agreement.
  • Disputes get shorter. The question "who did what, when" has a public, third-party-witnessed answer that both sides can check; nobody needs to trust the other side's logs.
  • Sovereignty stays with the partner. Keys, data and custody never move. The evidence survives a change of platform, provider or consortium — it belongs to the domain, not to the infrastructure.
  • Onboarding is one container. A new partner adds a node next to its own systems; nothing changes for the others. Ten domains or ten thousand is the same shape — the rail carries fingerprints, not data.

What this rehearsal showed — and what it did not

Nine synthetic domains on our own iron closed eleven periods; seventy-seven local records stayed local; 11 separate 32-byte commitments went to the rail (352 bytes of commitment payload in total); every closure reached a witnessed public position; one cross-period handoff was proven between two domains; the monitoring held for a two-hour idle window. It did not show continuous hourly production, a 24-hour run, or adoption by any named organisation — the names are labels for synthetic domains we operate. Those are the next steps, each of which will be measured before it is claimed.

1 · The shape

partner system / telemetry            stays local
        ↓
partner-owned NEOedgeX book           closes only when there was activity
        ↓
signed period snapshot                Ed25519, monotonic sequence, prev-snapshot continuity
        ↓  direct JSON or ApeiroRA-style CloudEvent
project hub + live read surface       recomputes the commitment byte for byte; no raw data crosses
        ↓  exactly 32 bytes per accepted period, one NEOf1 v0.2 frame each
NEOfX → NEOCL2 → NEOva2               witnessed public position, hourly unit
        ↓  signed rail receipt
RAIL_CLOSED

Retries are idempotent by the 32-byte commitment. One receipt per closed period, never per event. A separately signed, pseudonymous cross-period handoff (OFFERED in hour N, ACCEPTED by the named counterparty in N+1) is exposed only when both source snapshots are already rail-closed. Operational heartbeats live beside the evidence journal, never inside it.

2 · The network at day-close (4 Sep 2026, 17:58 UTC)

9domains registered
11period snapshots
77local records (never left)
352total commitment bytes · 32 per snapshot
11 / 11rail closed · 0 pending

32 bytes per object, not 352. This test recorded 11 separate commitments: 11 × 32 = 352 bytes in total. No 352-byte commitment was submitted. This sum excludes signatures, envelopes, receipts and network framing.

domainsitelocal recordsrail closedwaitingheartbeat
NEOcloudferroIONOS710NO_HEARTBEAT
NEOengineeringsynthetic-neo-01420FRESH
NEOgdansksynthetic-neo-1710FRESH
NEOhospital-Asynthetic-neo-3710FRESH
NEOinfobipsynthetic-neo-2710FRESH
NEOreplyIONOS710NO_HEARTBEAT
NEOresultHvar-Telemach1420FRESH
NEOtimIONOS710NO_HEARTBEAT
NEOvillanovaIONOS710NO_HEARTBEAT

Domain names are labels of synthetic, partner-controlled execution domains used for the rehearsal; no named organisation has installed, approved or operated a node. Four IONOS domains had no heartbeat at day-close (their forwarders were not instrumented); their earlier rail closures stand. Source: status.json (hashes in SHA256SUMS).

3 · Every closed period, end to end

domainperiodrecordscommitmentdoor requestledgerNEOva2 positionwitnessesclosed up to
NEOresult2026-09-03T16:00+02:00/PT1H7124ccb6e1cabb332…fx.7201.19.1.0anchored19neo-5, neo-6HOUR
NEOvillanova2026-09-03T16:05+02:00/PT1H-villanova7b91eebdf5e706235…fx.7201.19.1.1anchored19neo-5, neo-6HOUR
NEOreply2026-09-03T16:10+02:00/PT1H-reply72f25c7db8db1e827…fx.7201.19.1.2anchored19neo-5, neo-6HOUR
NEOtim2026-09-03T16:15+02:00/PT1H-tim7d9bfad5581206407…fx.7201.19.1.3anchored19neo-5, neo-6HOUR
NEOcloudferro2026-09-03T16:20+02:00/PT1H-cloudferro7107e648219f50225…fx.7201.19.1.4anchored19neo-5, neo-6HOUR
NEOengineering2026-09-03T17:10+02:00/PT1H-ambition-engineering7acef818979a1f6bd…fx.7201.20.1.0anchored20neo-5, neo-6HOUR
NEOgdansk2026-09-03T17:15+02:00/PT1H-ambition-gdansk7b41e153ed97416bd…fx.7201.20.1.1anchored20neo-5, neo-6HOUR
NEOinfobip2026-09-03T17:20+02:00/PT1H-ambition-infobip7decfb7754fd53354…fx.7201.20.1.2anchored20neo-5, neo-6HOUR
NEOhospital-A2026-09-03T17:25+02:00/PT1H-ambition-hospital-a7aa4189b935b73372…fx.7201.20.1.3anchored20neo-5, neo-6HOUR
NEOresult2026-09-03T18:00+02:00/PT1H7fa892804460562dc…fx.7201.21.1.0anchored21neo-5, neo-6HOUR
NEOengineering2026-09-03T19:00+02:00/PT1H7d305a4cd8409790b…fx.7201.21.1.1anchored21neo-5, neo-6HOUR

11 closures, positions [19, 20, 21], witnesses neo-5, neo-6. Each row is a signed rail receipt the hub verified: the ledger inclusion proof must reach its root, the NEOva2 bundle must name that root, carry two distinct witnesses and not disagree across archives. Source: rail-closures.json.

4 · A cross-period handoff between two domains

PAIRED_RAIL_CLOSED — offered by NEOresult in period slot 496792 (commitment fa892804460562dc…, NEOva2 position 21), accepted by NEOengineering in slot 496793 (commitment d305a4cd8409790b…, position 21). Handoff ref bc9bb5d1217648fb…; 0 unpaired. Source: handoffs.json, live proof.

The pair says: two independent books, two independent periods, both already public on the rail — and the claim between them is checkable without either book leaving home.

5 · Operational evidence

Two-hour idle soak: PASS_OBSERVED_IDLE_STABILITY_2H

Window 2026-09-03T17:31:14Z → 2026-09-03T19:31:14Z. Liveness journal: 452 result rows, max gap — s. Dispatcher journal: 111 runs, max gap — s, zero new and zero waiting commitments. Liveness alarm proven live on ambition-hospital-a (proof); fleet expansion to nine domains observed 2026-09-03T17:10Z (proof).

Limits, in the evidence's own words:

  • This is an idle stability checkpoint: all 111 dispatcher results found zero new commitments; it does not prove continuous hourly snapshot production or additional rail throughput.
  • Heartbeat freshness detects a stopped forwarder; it does not by itself prove that an expected business period closed.
  • Four previously uninstrumented IONOS nodes remain NO_HEARTBEAT; E-Group remains undeployed. This is not a ten-domain acceptance.
  • Public endpoint and private-port reachability were sampled, not continuously measured during the entire interval.
  • 24-hour checkpoint remains pending; no day-close or rig shutdown was performed.

The 24-hour checkpoint was not completed: the hub host was shut down before its deadline. It is not backfilled. A new soak starts with a new T0.

Source: soak-2h-2026-09-03.json.

6 · What changed on 4 September, and what is next

  • The side door is gone. The pilot's rail leg used the NEOfX2 side door; that door was retired on 4 September. The dispatcher now offers each 32-byte commitment directly to the NEOfX external gate, one NEOf1 v0.2 frame per commitment (code merged; not yet run against a live hub).
  • Hub and edge hosts are powered off (hourly billing). The five IONOS domains are kept as NEOvillanova, NEOcloudferro, NEOtim, NEOreply, NEOengineering — stopped, not deleted.
  • Next, only with the owner's word: power the hub, run the re-wired dispatcher against the outbox, then a 24-hour soak with a fresh T0 whose journals are exported whole and stated plainly as idle stability or as hourly closure production.