ARDYN OS

One instance.
Your continuity.

ARDYN OS keeps identity, approved knowledge, applications and authority in a customer-governed instance. Providers change. The instance remains yours.

Architecture
THE DURABLE FOUNDATION

Your governed instance

IdentityAuthorityApproved knowledgePoliciesEvidenceRecovery
REPLACEABLE DEPENDENCIES
Agents & applicationsSupported packages
Models & runtimesTested configurations
Devices & infrastructureQualified environments
ACTA

Cognition

Governed cognition, context, intelligence and node fabric.

ACTA
ADS

Release

Protected state, release condition and assurance.

ADS
Marketplace

Applications

Admit packages into the same instance.

Marketplace
Developer Platform

Publish

Contracts for building inside the OS.

Developers
Authority

Admission and release
stay with the instance.

Policy evaluation returns allow, block or escalate before execution proceeds. Delegated authority, obligations and fail-closed defaults belong to the governed instance—not to a replaceable application or model.

Evaluate first

An action is authorized only after policy evaluation. Missing identity, expired delegation or a configuration error defaults to deny.

Named obligations

Allow can still carry obligations. Block stops admission. Escalate records the hold for a named approver.

Who may change what

Who admits applications, changes policy, exports state or authorizes a protected-result release is explicit.

Recorded decisions

Authority decisions become part of the inspectable record when cognition evidence is in scope. ACTA →

Execution

Work runs inside
a declared boundary.

Governed workloads execute in tamper-evident cells with identity, registry and handoff under instance policy. Execution is a capability of ARDYN OS, not a separately sold runtime product.

Declared boundary

Workloads run inside the policy scope the instance authorized. A blocked decision never proceeds to execution.

Identity adapters

Runtime identity is bound to the instance. Cross-runtime handoff carries authority context with the work.

Protected results

When an ADS profile is in force, a protected result stays held until required reversion evidence is accepted. ADS →

Qualified destinations

Hardware and infrastructure are replaceable only when the destination meets the named deployment profile.

See Marketplace → · Read the claim boundary →