ALEPH LABS · APC × ANP
Execution-bound security for agent networks.

A public, browser-local interoperability capsule showing how ANP identity and authenticated interaction can feed an APC-style exact-act enforcement boundary—without shipping APC's proprietary runtime or secrets to the browser.

APC reference build: 7.1.0rc1 · air-gapped amd64 ANP repository: current 1.2 specification set Demo mode: SYNTHETIC / SIMULATED No credentials · no production effects

Run the interoperability capsule

The browser creates an ANP-like authenticated context, constructs a concrete candidate act, establishes bounded APC authority, and evaluates the final effect boundary. Every case is deterministic except the generated run identifiers.

Runtime boundary

READY

The public page is not the enterprise APC executable. It is an external-property demonstration capsule aligned to APC's public-safe boundary.

Protected effect: NOT_ATTEMPTED
IP boundary: proprietary APC implementation is intentionally omitted. ANP is linked to its public open-source specifications and implementation references.

ANP → APC integration boundary

ANP identityDID / authentication / agent context
→
Authenticated invocationrequest + target + interface context
→
APC security contractexact act + authority + freshness + sink
Durable authoritydelegation + replay + policy state
→
Finality enforcementreconstruct + verify actual act
→
Protected sinksynthetic effect + evidence + reconciliation

This mapping is a proposed interoperability model for evaluation. It is not an existing ANP standard and does not imply ANP currently implements APC-specific fields.

Security test results

Latest run evidence

Run the capsule to generate evidence.

Integration stack — what is actually being demonstrated

LayerComponentRole in this demoStatus
NetworkHTTPS / WebBrowser-hosted static surface; no outbound connections required.LIVE STATIC
ANP identityDID contextIdentifies the calling agent and carries authenticated-origin provenance.SIMULATED
ANP applicationInvocation / operationRepresents the concrete agent operation that becomes the candidate act.SIMULATED
Interop adapterANP → APC mappingMaps agent, target, invocation, operation, parameters and provenance into the demo contract.DEMO IMPLEMENTATION
APCSecurity contract + authorityChecks exact-act identity, authority lifetime, replay, delegation, policy epoch and sink.BROWSER MODEL
FinalityProtected-effect boundaryReconstructs the final act before the synthetic effect is admitted.BROWSER MODEL
OutcomeSynthetic sinkProduces SUCCESS, NOT_ATTEMPTED or UNKNOWN semantics without a real side effect.SYNTHETIC
EvidenceRun reportCorrelates decision, execution state, effect state, digests and evidence references.SYNTHETIC

APC security invariants represented by the public capsule

Proposed interoperability envelope

Normalized APC response

ANP public layer

The current ANP repository describes an open protocol suite for agent identity, naming, discovery, negotiation, secure messaging, and application-level collaboration. It reuses HTTP/HTTPS, DNS, TLS/CA, CDN/Web infrastructure, W3C DID, and related web primitives.

Core specification setCurrent repository README: ANP 1.2. ANP-06 remains draft; AP2 is application-layer draft material.
Agent identitydid:wba and native did:web are represented in the current architecture; authentication is separated from higher-level application protocols.
AgentConnectOpen-source SDK / reference implementation for identity, authentication, descriptions, protocol negotiation, secure communication, and application protocols.
Open DID ServerPublic reference implementation supplied for did:wba / did:web hosting and a constrained HTTP Message Signature flow with replay checks.

Security posture of this public capsule

  • No API tokens, signing keys, customer data, production URLs, or private credentials are embedded.
  • No arbitrary visitor code is executed by the demo.
  • No external network request is required for the live demo path.
  • All security-case results are explicitly labelled synthetic/simulated.
  • The browser is treated as untrusted; the page does not claim to enforce real customer effects.

IP / disclosure boundary

Public-safe
High-level security properties, interoperability concepts, attack demonstrations, protocol references, capability/status wording.
Restricted / omitted
APC kernel implementation, private schemas, internal cryptographic constructions, deployment secrets, production topology, internal incident intelligence, proprietary algorithms, customer-specific configuration.

The enterprise APC executable is deliberately not copied into this static site. A Linux amd64 runtime artifact is not a browser runtime, and publishing proprietary implementation code here would violate the intended disclosure boundary.

Source-of-truth notes

SurfaceStatus used hereReason
APC product architectureSOURCE-DERIVEDExact-act binding, security-state continuity, delegation attenuation, finality enforcement, protected sinks, evidence/reconciliation, fail-closed behavior.
APC public website architectureSOURCE-DERIVEDPublic-safe disclosure rules, synthetic-vs-real labeling, no secrets in browser/source control, public demo isolated from production.
APC current packaged referenceREFERENCE BUILDAPC-Enterprise-7.1.0rc1-airgapped-amd64.run exists in the current project Library. The browser capsule does not execute that binary.
ANPPUBLIC RESEARCHCurrent public repository README and supplied Open DID Server materials were reviewed for the interoperability boundary.
Demo resultSYNTHETICBrowser-local model only. It is not certification, a production deployment, or proof of a real ANP/APC integration.