Skip to content

Investor Brief

SZL Holdings is building governed-AI infrastructure around a simple operating discipline: make the decision boundary inspectable, preserve the evidence that informed it, and state plainly what is proven, modeled, unavailable, or still on the roadmap.

This is a public, evidence-first orientation. It is not a financial model, a customer claim, or a representation of current service availability. Those questions have their own sources of truth.

The investment thesis

The opportunity is not to add another opaque AI control layer. It is to make consequential AI workflows easier to inspect and govern: policy-bounded decisions, receipt-oriented evidence, and a formal-methods corpus whose open assumptions remain visible.

SZL's public product story begins with two flagship source surfaces:

  • a11oy, a governed agentic execution fabric.
  • killinchu, a counter-UAS decision-support surface.

The product pages describe implementation and intended behavior. They do not upgrade source availability into runtime availability, formal-methods scope into a universal safety proof, or a hash chain into a signed receipt without exact signature verification evidence.

Current public posture

QuestionPublic postureWhere to verify
What source products are documented?REAL source surfaces: a11oy and killinchuFlagships
Are public runtimes available now?Check the dated observation; a source label is not an uptime claimRuntime status
What is formally proved?MIXED: the locked corpus identifies proven formulas and open sorry-tagged obligationsProof and Evidence
Is Lambda a theorem?CONJECTURE 1, not a theoremDoctrine register
What is the receipt-signature posture?Consult the exact artifact and central compliance postureCompliance
What certifications are held?FedRAMP, SOC 2, IL5, and CMMC are not claimedCompliance

Read status on two axes

REAL, MEASURED, MODELED, ROADMAP, and UNAVAILABLE classify an artifact or claim. Operational availability is separate and must be read from the dated Runtime status observation. A repository or published revision is not evidence that a public service is running.

Why the architecture is differentiated

The documented architecture is designed to bound action before execution and preserve the decision trail afterward. Its components include policy evaluation, evidence references, a Khipu receipt model, and a Lean corpus. The strongest public claim is not that every system property is formally proved; it is that proof status and implementation limits are intended to remain inspectable.

Start with the Architecture for the component map, then use the Evidence index to inspect pinned artifacts and the Compliance page for the current supply-chain and certification posture.

Product map and roadmap discipline

The public product map distinguishes flagships from roles that are implemented in-process, documented as frontier capabilities, or not separately deployed. In particular, Provenance Anchor, Operator, and Policy are not represented as independent live services. Their standalone status is stated in the flagship product and role map; Runtime status remains authoritative only for the named hosted surfaces it actually reports.

That distinction matters in diligence: design intent, local source, an in-process capability, a published image, and a currently reachable runtime are different kinds of evidence.

Evidence before adjectives

Diligence and contact

Public materials contain no financials. Confidential financial model and cap-table materials, if appropriate, are shared directly with qualified investors on request. The public Diligence index records the evidence boundary and the questions that can be answered from this site today.

Request investor diligence

For company background and partnerships, see About SZL. For security reports, use the relevant repository's SECURITY.md process rather than the investor contact.

Public claims link to source and evidence. SLSA L1 is the current stated supply-chain posture.