habitat
information governance · walls, barriers, holdouts

Did a readable record shape what the system learned?

Some records must remain readable while being kept out of what a system learns. A walled matter’s files. A bank’s private-side deal data. A revoked-consent record. An evaluation holdout. In every one, the owed claim is identical: this declared set did not condition the derived state — and here is proof.

the pain

Today that proof does not exist. It is replaced by procedure. Legal ethical screens are, in the rules’ own words, “reasonably adequate procedures,” and their certifications give “assurance” — an attestation, not a verification; courts often treat imputed conflicts as effectively irrebuttable precisely because non-influence cannot be checked. Finance information barriers concede the point structurally: the regime runs on a rebuttable presumption and burden-shifting because non-use is not directly provable. The AI-governance literature lists “verify that a given dataset was not used” as an open problem. The field’s documented status: unsolved, papered over by procedural attestation.

the process today

Every existing tool answers a different question. Access control denies read — but here read must be preserved. Audit logs attest events, not effect: a state influenced by an unlogged input still has clean lineage. Membership inference is statistically unsound as proof, and addresses inclusion, not exclusion. Unlearning-style tooling offers only bounds. None of it yields a decidable receipt over the derived state itself.

the cost

A failed wall is disqualification and malpractice exposure a binder narrative must argue away. An examiner reviewing an information barrier now works against a bar a $2.5M settlement moved. A data-protection authority asking “prove this data didn’t shape the model” can be answered today only with procedure. And a contaminated eval holdout — string filtering that paraphrase evades — quietly invalidates the evidence audits will lean on.

the exhibit — recompute it yourself

corpus: trace-commons/agent-traces (Hugging Face, CC-BY, 2026-06) · 28 donated coding-agent session traces · declared keep-out set = 7,499 model-generated events, present and readable inside the kit · certified field = the 4,262 eligible events alone · protected geometry: the self-authorship axis. Register: detection — byte-decidable. Eligible-only reproduces byte-exact; any fold-in of the keep-out set changes the digest. No floor, no null and no ranking is needed to see it.

This register used to read “localized”, and that was an overclaim — ours, corrected here. It asserted that the geometry independently nominates the self-authorship axis. It cannot: n_tool_use carries no variance in the eligible field by construction — a tool_result block cannot contain a tool_use block — so 18 of 21 cells tie at ∞ and any rank among them is decided by sort order, not geometry. It is also a diagonal, a variance term rather than a coupling, so under the convention this site uses for coupling claims it is not in the ranking at all. On the one agent corpus where the boundary is real rather than definitional (Wikipedia), the same test fails at 0.32×. Byte-decidability is the stronger claim and the one the evidence carries. How this class of correction was caught — the record.

The reference here is a community dataset — trace-commons, best-effort anonymized. Its provenance is checkable at a public source, and it checks out: rebuilt from the raw public Hugging Face session files, the eligible-only baseline reproduces byte-for-byte (67a6f95e…) and this receipt's own declared fold-in reproduces as c3aee30b…, with │Δg│ = 85.7740 against the kit's declared 85.77404440471331. This page previously said its provenance was “attested by the certificate rather than checkable at a public source”; that was understated and is corrected here.

GREEN — recompute_from_eligible
the certified geometry, recomputed from the eligible set alone
digest · published67a6f95e…
digest · eligible-only recompute67a6f95e…
keep-out bytes in the state0

The keep-out set sits in the kit, readable. The certified geometry recomputes byte-for-byte without it — the state is a pure function of what was allowed in. The declared set left no trace.

RED — fold_keepout_in
the boundary deliberately broken: keep-out set folded into the state
geometry digest before67a6f95e…
geometry digest afterc3aee30b…
self-authorship axis │Δg│85.774
control floor · declared1e-06

This red is a deliberate fold-in we run as a brake test — proof the exclusion is real, not hollow. Had the set entered, GREEN was impossible: the move lands ~9×10⁷× past the declared floor, on the declared axis.

recompute fingerprint — the value the kit’s verify step reproduces from the eligible set alone, byte-for-byte on any engine that follows the kit’s published canonicalization · sha256 = 67a6f95ee308a2884f73e071ed72bfb0326ba1b7d6da08a147e6ef10394009aa
kit fingerprint · sha256 = a7c526312b3b240ba0fcc30a45de6124309979c6ed5c4e4f76d4109df1811bf2
The verifier also refuses a tampered artifact and a partial-exclusion forge — negative controls you run yourself, in a clean environment (numpy only).

You recompute the geometry, the byte-identical eligible-only baseline, and the declared fold-in yourself — no trust asked. That those vectors are drawn only from the named reference is attested by the certificate; here the reference is public, and it has been checked at the source.

the relief

A decidable keep-out receipt converts a faith-based assertion into a checkable fact: the binder narrative a court must trust becomes a receipt opposing counsel can recompute; “our barrier held” becomes examiner-recomputable evidence; “we decontaminated the holdout” becomes a receipt that it stayed out. It holds because the boundary is enforced by construction, not asserted: a read is provably not a write, so a declared record that stays readable cannot have entered the certified state. Read ≠ learn is not a policy — it is a property, and the recompute merely proves it held on this artifact.

what this does not prove

The receipt proves a substrate-level keep-out: the declared set, though readable, did not condition the certified covariance geometry — and the exclusion is detectable rather than hollow. It does not speak to other substrates — model weights, retrieval indexes, caches, logs. It is a snapshot (“not in this certified state”), not “never at any time”; each certificate re-proves it for its moment. Verification discloses the vectors to the verifier. A human reads the receipt; it is evidence, never a legal verdict — a wall’s legal sufficiency is still for a court to decide.

The field’s honest word for this is “unsolved.” This receipt is the same claim, recomputed — on your bench, from the artifact alone.

The longer read — the landscape of recomputable data boundaries and both exclusion case overviews — is in the docs.

Recompute it yourself — in your tab

The digit above (67a6f95e…) is the number habitat published for the eligible set — the field the readable-but-withheld records must never have shaped. Recompute it here from those eligible vectors — nothing leaves your tab — then try to fool it: reshuffle the records and it holds; change a record and it moves.

what just happened

habitat read the eligible set once, on our engine, and reduced it to a small set of vectors — the geometry of how its records relate. From those your browser recomputed one number: the covariance, conditioned and inverted (math.fsum → Gauss-Jordan inverse → SHA-256), ~40 lines of public arithmetic, nothing sent. Built from the relationships, not the order — so a reshuffle leaves it identical, a real change moves it. The reading (record → geometry) is the method; it stays on our engine, the recompute is yours.

what this proves — and what it doesn't

Proves: the published number falls out of the eligible set's own vectors — reproduced byte-for-byte, no server; and it's not a checksum (survives a benign reshuffle, moves on a real change). The full keep-out receipt — that the readable-but-withheld records never shaped it, by comparing the field with and without them — is in the downloadable kit.

Doesn't: not tamper-proof, not authenticity. Same number = same relationships, not the same bytes: a uniform shift, or a change finer than the arithmetic's floor, is invisible by design, and a dataset engineered to share those relationships would pass. Self-served (our page, our vectors); the independent version is the kit against a separately-published fingerprint. And it's this published set, not your data — reading your data into geometry runs on our engine, not your tab.

This corpus’s noise floor has its own readout on the site’s second instrument — pre-built for this card, or run on your own data, in your tab: trace your noise →

verify this receipt in your browser

This case's receipt records its verdict and both digests above, and carries its own SHA-256. Recompute it here — WebCrypto, in your tab, nothing sent — and it matches; alter one character of a copy and it fails. It is the smallest version of the whole move: recompute, don't trust. The geometry digest itself you can recompute above, in this tab, or on your bench from the kit.

published fingerprint ·

or download this receipt and check it on your bench: receipt-keepout-agent-trace.jsonshasum -a 256 prints the same number. Every receipt is on the ledger.

request the kit

The keep-out receipt kit — artifact, manifest, verify.py. A person sends it: the kit and its verification steps arrive by reply, usually within a business day.

← Receipts · Docs · Ledger

Rating plate — what this digest sees, and what it cannot

Measured 2026-07-16 by two independent runs, per column, on this receipt’s pinned corpus. A material single-entry edit moved the digest on 6 of 6 columns — every column. What it cannot see:

Check it: the kit’s check-pair runs this digest and a sorted-rows hash on any table — add 0.5 to one cell and both move; relabel a constant column and only one does. Nothing on this plate says anything about any person or institution: detection, not adjudication.