Governed Cognitive Infrastructure

AI that does regulated work under human authority — with cryptographic evidence for decisions processed through the governed evidence path and fail-closed control. The governed core that every TF Group product is built on.

Built in the Republic of Moldova

The Problem

Regulated AI has a trust gap

Organizations are adopting AI faster than they can prove what those systems actually did.

In finance, energy, agriculture, healthcare, and public administration, after a decision is made, it is hard to demonstrate which model produced it, on what data, under which rule — and whether the record was altered afterward. When a regulator, an auditor, or a court later asks why a decision was made — and whether the record is intact — most AI deployments cannot answer with cryptographic certainty. They have logs — but logs can be edited, and a log is not proof.

The EU AI Act, DORA, and transparency mandates require traceability, version control, integrity guarantees, and human oversight. Most AI systems were never built with this at the infrastructure level. Governance is bolted on after the fact — a dashboard beside the work, not a gate on the path of the work. That gap is exactly where liability, regulatory exposure, and loss of trust accumulate.

Regulatory context: official EUR-Lex texts. Requirements depend on the system, sector and applicable provisions; these references are not a certification of SoulGCI compliance.

SoulGCI is that infrastructure: a governance layer that lets AI act under human authority, proves every governed decision cryptographically, and fails closed by design. Instead of asking institutions to trust the AI, it lets them verify it — independently, after the fact, without access to our systems.

The Proof Plane

Cryptographic evidence for decisions processed through the governed evidence path

At the core of SoulGCI is a proof plane: structured event recording, cryptographic signing, an append-only hash-chained ledger, and self-contained evidence. Every governed decision becomes independently verifiable — its provenance reconstructable and checkable by any third party, without access to our infrastructure.

Signed decision receipts

Every governed decision produces a cryptographic receipt — independently verifiable, carrying its own proof of authenticity and integrity with no exposure of private keys or personal data.

Tamper-evident ledger

An append-only, hash-chained journal with Merkle roots. Any single-byte alteration breaks the chain and is detected.

Self-contained audit packs

One shareable evidence bundle — signed receipt, public key, verification result, ledger excerpt, tamper proof — reproducible by a third party.

WORM-anchored storage

Write-once-read-many storage with KMS-signed Merkle roots (RSA-PSS-SHA256) anchors the record against retroactive change.

Architecture

Five layers, one governed system

SoulGCI is built as five integrated architectural layers. Together they take an AI decision from request to cryptographically provable, human-governed action — and refuse to act when governance cannot be satisfied.

01

Constitutional runtime

Decision governance

A constitution compiled into the executable evaluates every request before any autonomous action. An event validator, idempotency engine, quarantine path, contradiction-detection engine, and deterministic state compiler enforce it. A constitutional reflex engine classifies each action into three governance classes.

S — safe automatic execution D — prepared, not executed H — mandatory human approval
02

Cryptographic trust fabric

Proof & integrity

An append-only event journal forms a cryptographic hash chain, sealed by a Merkle tree whose roots are digitally signed via KMS (RSA-PSS-SHA256). Events written to WORM storage are held create-only under a locked retention policy, and their inclusion receipts are independently checkable.

Append-only journalMerkle inclusion proofsWORM storage

Technical references: RSA-PSS — RFC 8017 and Google Cloud Bucket Lock. These describe the signature and retention mechanisms, not evidence that a particular deployment has passed verification.

03

Policy-as-code engine

Versioned rules

Each event is evaluated against a versioned policy bundle (OPA/Rego), producing versioned decision logs. Rules are explicit, auditable, and reproducible — and every decision references the exact policy version that governed it.

OPA / RegoVersioned policy bundlesReproducible decision logs
04

Decision Proof Object

Independent verifiability

A cryptographic Decision Proof Object can be verified by third parties without access to our infrastructure. It contains references to input events, the policy version, a state hash, the approval chain, a determinism attestation, and a Merkle inclusion proof — the complete provenance of a decision in one object.

Input + policy + state hashApproval chainDeterminism attestation
05

Evidence, drift & trust budgeting

Self-regulation

An evidence-pack compiler with selective disclosure (SD-JWT, RFC 9901) shares only what is needed. A governance drift detector monitors degradation of governance discipline, and an operational trust-budgeting engine forces automatic de-escalation when a risk budget is exhausted — the system tightens its own autonomy under stress.

Selective disclosure (SD-JWT)Drift detectionTrust budgeting

How a governed decision flows

RequestEvaluated by the constitution first
ClassifyS / D / H governance class
GovernPolicy-as-code + human gate
ProveSigned, hash-chained, Merkle-anchored
VerifyDecision Proof Object, independently

The Control Plane

Constitutional governance of autonomous decisions

SentientROUTER is the control plane: it governs autonomous AI decisions before they act, evaluating a statically-compiled constitution ahead of any external query and gating execution fail-closed.

Constitution-first evaluation

A constitution compiled into the executable is checked before any autonomous action — and before any external source is queried. Class-H requests never reach external sources autonomously.

Multi-source consensus

Decisions are aggregated across at least three independent sources, with a Merkle hash per vote and an ArgMax decision function — no single source decides alone.

Governance drift detector

Router-specific drift detection watches S/D/H escalation frequency, divergence trend, and control-state variance to catch governance degradation early.

Offline-capable

A connectivity-loss mode keeps governance operating with guaranteed batch synchronization when links are unavailable.

SoulGCI Master

One governed architecture, eleven layers

SoulGCI Master is the umbrella architecture — a closed control loop that binds eleven architectural layers and four cross-cutting components into a single governed system.

A cognitive decision cannot produce a legal, economic, medical, or operational effect on a human subject without crossing a technical effectuation boundary. The proof plane (ProvableCORE), the control plane (SentientROUTER), and the medical vertical (T.E.H.N.O.F.A.R.M. OS) are preferred realizations of individual layers within this master architecture.

Layer 01Cryptographic proof

Merkle-chained, WORM-stored, offline-verifiable proof objects for governed decisions.

Layer 02Constitutional control & routing

Every request evaluated against a machine-versioned constitution before action.

Layer 03Governed execution

Execution under verified multi-field session and a controlled-phase engineering protocol.

Layer 04Human authority

An authority layer structurally independent of the cognitive layer.

Layer 05Planning

Structured planning of work ahead of governed execution.

Layer 06Judgment gate (CPE)

A judgment gate enforcing the Controlled Product Engineering protocol.

Layer 07Persistent memory

A durable memory layer feeding context into later decisions.

Layer 08Procedural skills

Reusable procedural skills available to the governed system.

Layer 09Edge inference

Inference at the edge with data-sovereignty preservation.

Layer 10Vertical workspaces

Domain workspaces carrying unified proof, control, and human-protection semantics.

Layer 11Authority control panel

A control panel for the human authority over the system.

+ Four cross-cutting components

Component 50

Human Protection Layer

A pre-flight gate between FINALIZED and EFFECTUATED states, a polarity engine, and a deterministic set of at least eighteen pre-flight rules.

Component 60

Anti-degradation core

A self-governance core with a default-DENY disposition and dual attestation against governance degradation.

Component 70

Evidence compiler

A selective-disclosure evidence-pack compiler using SD-JWT (RFC 9901).

Component 80

Durability gate

A durability gate with restore-tested parity.

The effectuation boundary

FINALIZED → EFFECTUATED

A central mechanism: the architectural separation between a decision being internally determined by the cognitive layer, and that decision being applied to a subject. The cognitive decision, by itself, is never sufficient to act.

FINALIZED

The decision is internally determined by the cognitive layer — but not yet applied to any subject or actuator.

Pre-flight gate
  • Pre-flight receipt
  • Human-authority artifact
  • Polarity class
  • Persistent proof object
EFFECTUATED

The decision is applied to the subject or consumed by an actuator — only after every gate check passes. The result feeds back into the trust budget and future governance.

The inventive step is not in any single component — a Merkle chain, a policy engine, a signature, a human-oversight mechanism can each be known on their own.

It is in binding them into a closed control loop where proof, authority, human protection, durability, and verification feed back into the system's future limits. Remove any layer, and the system collapses into known primitives without the synergistic effect. The system's future authority is mechanically limited by the verified quality of its past decisions — and cannot be unilaterally widened by the cognitive layer.

One family, four layers

How the layers fit together

The four components are not separate products. SoulGCI Master is the umbrella architecture; the other three are preferred realizations of individual layers within it. Each can stand alone — together they form one governed system.

SoulGCI Master

The umbrella — eleven layers + four cross-cutting components, bound into a closed control loop. Binds the layers below together with human authority, durability, memory, edge inference, and selective-disclosure evidence.

Layer 01 · Proof plane

ProvableCORE™

Preferred realization of the cryptographic proof layer — Merkle-chained, WORM-anchored, independently verifiable Decision Proof Objects.

Layer 02 · Control plane

SentientROUTER™

Preferred realization of the constitutional control & routing layer — multi-source consensus, drift detection, fail-closed, offline-capable.

Layer 10 · Vertical

T.E.H.N.O.F.A.R.M. OS™

Preferred realization of a regulated vertical — constitutionally-limited medical autonomy for isolated environments.

Each prior application is referenced for technical context as a preferred embodiment of a layer; its internal mechanisms are not re-claimed by the master application.

TFH TRACE · Interoperability programme

Evidence that can travel.
Trust that can be checked.

TFH TRACE extends the SoulGCI vision beyond a single system: a common representation of evidence that lets institutions follow where a decision came from, what authorised it, and what an independent reviewer can actually verify.

Our TRACE integration programme is being developed around ProvableCORE, which remains the source of cryptographic evidence and provenance. The goal is to express that evidence as interoperable Trust Records — without replacing its original proof or confusing a recorded event with a verified result.

Connect the evidence

Verifiable Trust Records

A target representation linking source references, decisions, approvals and evidence so a reviewer can reconstruct the relevant chain without relying on a narrative alone.

Keep responsibilities distinct

Proof, routing and authority

ProvableCORE supplies the evidence foundation. SentientROUTER supplies routing and decision-trace context. SoulGCI brings these together with human authority; a routing trace is not, by itself, proof that an action was executed.

Make verification portable

Adapters and compatibility

The planned path includes a TRACE-format adapter, version-pinned compatibility tests and independent conformance review, followed by a public mapping of what the evidence proves and what it does not.

TRUST / TRACE / PRE-TRACE. These connected tracks address provenance, evidence exchange and verification prerequisites. The design principle is simple: missing evidence must remain unknown, not become a successful verification.

This section describes the integration programme and its intended capabilities, not completed TRACE conformance, external certification or an endorsed partnership.

Upstream source: TRACE — Trust, Runtime Attestation, and Compliance Evidence. The external project defines the format and verification rules; TFH TRACE names our integration programme. The Linux Foundation announcement concerns the upstream project, not an endorsement of TF HOLDING or SoulGCI.

The working architecture · Development direction

From a human request
to an accountable result

SoulGCI is being built to connect planning, execution, memory, evidence and human control into one working environment. The ambition is not just to explain a decision afterwards, but to organise how work is admitted, carried out, reviewed and remembered.

Planning & continuity

WorkGraph

A connected view of tasks, dependencies and responsibility, intended to keep the original request linked to the work needed to complete it and the evidence supporting the result.

Oversight

Watch Plane

An oversight direction for making progress, unresolved conditions and items requiring human attention visible alongside the work — with observation kept distinct from permission to act.

Institutional memory

Memory with sources

Persistent context tied to its sources, so later work can revisit the documents and decisions behind a conclusion rather than inherit an unsupported summary as fact.

Human authority

Control consoles

A working surface for people to inspect evidence, review drafts and decide what may proceed. Preparing an action and approving its execution remain separate responsibilities.

Independent review

Model A

A review-and-release approach that separates producing a change from independently checking it. Acceptance is tied to the specific version examined, not just to the author's confidence.

Institutional workflows

Reviewable dossiers

A target workflow for bringing source documents, missing information, drafts, approvals and evidence into a coherent case that a responsible person can review before a response or action is issued.

These capabilities form the target working architecture. Their development and integration connect to Conductor, CDI and trust budgeting below; deployment is evaluated for each bounded workflow.

Vertical · Isolated environments

Constitutionally-limited autonomy

T.E.H.N.O.F.A.R.M. OS governs autonomy in isolated environments — where the human authority who would normally approve a decision is intermittently or temporarily unavailable. Its first and most demanding application is medicine.

Field and humanitarian medicine, space, maritime, polar, and rural settings, and secondary hospital decision support. It is organized as a closed loop of seven functional modules that dynamically limit autonomy by the verified quality of past decisions — the same principle applies wherever a system must act under uncertainty with delayed human review.

Axis 1 — Clinical urgency class

  • SSafe autonomous action.
  • DDraft for human review.
  • HMandatory human escalation.
  • PPalliative / expectant — no autonomous curative or invasive action; documentation, comfort, monitoring, and escalation only.

Axis 2 — Temporal availability mode

  • NORMALPhysician available within the stability window.
  • OFFLINERoutine offline operation.
  • BRIDGEPhysician exists but response time exceeds the stability window — stabilization only, no autonomy expansion.
  • NECESSITYDelay is more dangerous than action under uncertainty — temporary, auto-verified expansion only.
Module A

Two-axis classification

Every clinical request gets an urgency class (S/D/H/P) and a temporal mode — processed orthogonally, together setting the autonomy perimeter.

Module B

Mission Medical Twin

A cryptographically-linked state object — Patient, Operator, Resource, Environment — comparing the patient to population, personal, and environment-adjusted norms.

Module C

Degradation-sensitive perimeter

Recalculated every action from classification, operator capacity, sensor degradation, knowledge freshness, and resources. Cannot be widened unilaterally by the operator.

Module D

BRIDGE / NECESSITY transitions

Conditional autonomy expansion through two modes, enterable only via automatically-verifiable triggers. NECESSITY cannot be activated retroactively.

Module E

Probabilistic Medical Decision Object

Per inference: inputs, statistical model + version, probability with confidence interval, rejected hypotheses, cost-asymmetry, consent status, and resource limits — cryptographically linked.

Module F

Retrospective verification queue

Mandatory, non-self-closing. Two layers: independent automated re-analysis, then licensed-physician review. A case closes only after physician sign-off.

The system does not issue a final medical diagnosis and does not autonomously initiate prescriptions. It produces probabilistic decision objects, action drafts for operator co-signature, stabilization within the calculated perimeter, or structured physician-review packages. Cases generated in a physician's absence never close autonomously: the system signs the calculation, the operator signs the action, and a licensed physician signs the mandatory retrospective review. Accumulated verification debt mechanically contracts the system's permitted autonomy until cases are closed.

Application domains — each with its own constitution

Space

Orbital stations and long-duration missions. Orbital constitution, BRIDGE-to-Earth, mission medical officer integration.

Field & military

Field and humanitarian medicine. Field constitution, multi-patient processing, scarcity allocation by hierarchical rank.

Maritime

Cargo and passenger vessels. Maritime constitution, IMO Medical Guide, coast-guard transmission queue.

Polar

Extended-isolation stations. Polar constitution, psychological profile integrated into the operator component.

Rural

Remote clinics far from a physician. Non-action discipline, antibiotic-prescription limits, multilingual localization.

Where SoulGCI is going

From governed proof to enforced governance

The proof plane and the layered architecture are in place. The active research direction is to move governance from a verifiable record alongside the work to an enforced gate on the path of the work.

These are directions in active design and development — the next layers of the system, shown to make our trajectory clear.

In design

Conductor — the recognition gateway

A mutability gateway, not an agent: a mechanism through which any change to canonical state must pass a complete, witnessed path — owner intent → admission → lease → work zone → witness → evidence → independent verification → frontier transition → closeout — or the system does not recognize it as canonical. Human authority remains the only power over the irreversible.

In development

Enforced trust budgeting & drift

Moving the trust-budget and governance-drift mechanisms from specification onto the enforcement path — so that the system's future autonomy is mechanically, not advisorily, limited by the verified quality of its past decisions.

In design

Deliberative consensus (CDI)

An iterative deliberative-consensus track feeding admission decisions — structured multi-step deliberation before a change is admitted to the governed path.

Concept

Native context compression

An opt-in compression layer inside the control plane, governed by a hard denylist: never on commitment, evidence, legal, or enforcement context — only on volatile cost context, audit-mode first.

These items describe our development roadmap and architectural direction. They are stated as forward-looking work, distinct from the proof plane described above.

Intellectual property

Four patent applications.
One governed architecture.

Official AGEPI correspondence identifies four patent applications filed by TF HOLDING S.R.L. in the Republic of Moldova, with Alexandr Șcecaliuc named as inventor.

Proof plane

ProvableCORE

a 2026 0010 · Filed 14 April 2026
Constitutional cognitive governance for verifiable and reproducible decisions in regulated environments, with cryptographic evidence.
Documented in AGEPI correspondence dated 16 July 2026.

Control plane

SentientROUTER

a 2026 0011 · Filed 17 April 2026
Constitutional governance of autonomous artificial-intelligence decisions.
Documented in AGEPI correspondence dated 20 July 2026.

Isolated-environment vertical

T.E.H.N.O.F.A.R.M. OS

a 2026 0014 · Filed 15 May 2026
Constitutionally limited medical autonomy in isolated environments, with a dynamic clinical-autonomy perimeter and mandatory retrospective verification.
Registration confirmed by AGEPI on 8 June 2026.

Umbrella architecture

SoulGCI Master

a 2026 0020 · Filed 28 May 2026
Governed cognitive infrastructure for constitutional, cryptographically provable, human-protected and independently verifiable execution of decisions in regulated environments.
Registration confirmed by AGEPI on 15 June 2026.

These are application filing references, not numbers of issued patents. The dates above identify the official correspondence supporting this disclosure; they do not certify the current procedural status, a grant of protection, or patent protection outside Moldova.

Evidence reviewed: AGEPI letters 9787 (16 July 2026), 9894 (20 July 2026), 7794 (8 June 2026) and 8294 (15 June 2026), respectively. AGEPI official website identifies the issuing authority; it is not a direct public record for these filings. Request redacted supporting correspondence. Private documents are not published here.

Institutional Standing

Inside Moldova's AI governance agenda

The project contributed a formal advisory opinion to Moldova's Ministry of Economic Development, feeding the National AI and Data Governance Program 2026–2030.

The submission positions verifiability as a cross-cutting principle and resident, exportable intellectual property as a national asset — placing SoulGCI inside the formation of national AI policy, not observing it from outside.

Company submission references: AVIZ 04-05-2026/TF-IA and CERERE 04-05-2026/TF-SCIA, dated 4 May 2026. Particip.gov.md is the public-consultation portal, not an independent confirmation of our submission or its acceptance. Request the supporting submission record. Participation does not imply government endorsement.

Applications

Built for accountability-critical sectors

The proof plane is domain-agnostic. SoulGCI's verticals apply governed cognitive infrastructure where decisions must be defensible.

Agri-finance

ACS Bank OS

A governed credit-risk workspace for agricultural lending — the first instantiation of the proof plane, built on the Agro Capital Standard platform.

Land

TerraScore™

Land-intelligence scoring for financing and risk decisions, live at terrascore.eu.

Farmer

ACS FARMER™

A farmer-facing assistant for regulated agricultural workflows.

Medicine

T.E.H.N.O.F.A.R.M. OS™

Constitutionally-limited clinical decision support for isolated environments — field, space, maritime, polar, and rural medicine. The system signs the calculation, the operator signs the action, and a licensed physician signs the mandatory retrospective review.

Carbon & ESG

Provable sustainability

Provable traceability of sustainability data and reporting.

Critical infrastructure

Auditable operations

Auditable governance of decisions in energy and regulated infrastructure.

Available for design-partner pilots with regulated institutions.

The Ecosystem

One governed core, many verticals

SoulGCI is the governed core that every TF Group product is built on — the proof, control, and human-authority engine beneath the group's verticals.

The TF Group is a privately held group of companies in Dondușeni, Republic of Moldova. A parent holding owns the intellectual property and licenses it to operating companies; each vertical is an application of the same governed core.

The core

SoulGCI — Governed Cognitive Infrastructure

Cryptographic evidence for decisions processed through the governed evidence path, constitutional control of autonomous action, and irreducible human authority — the engine on which every vertical below is built.

ProvableCORE™ · proof planeSentientROUTER™ · control planeHuman authority · effectuation gate

The verticals — built on the core

Agro Capital Standard

The institutional agricultural credit-risk platform — "Bloomberg/Moody's for agricultural lending." The first instantiation of the proof plane.

ACS Bank OSagrocapitalstandard.eu

TerraScore™

Land-intelligence scoring for financing and risk decisions.

Live · terrascore.eu

ACS FARMER™

The farmer-facing assistant for regulated agricultural workflows.

agrocapitalstandard.org

CORN PLATFORM

Corn-vertical structured financing.

cornplatform.capital

OILSEEDS PLATFORM

Oilseeds-vertical structured financing.

oilseedsplatform.capital

T.E.H.N.O.F.A.R.M. OS™

Constitutionally-limited autonomy for isolated environments — the medical vertical.

The group

Parent · IP holder

TF HOLDING S.R.L. IDNO 1025604010126

Parent holding. Owns and licenses the group's intellectual property, brand assets, domain portfolio, and trademark applications.

Technology operator

TF INTELLIGENCE PLATFORM S.R.L. IDNO 1026604000661

Develops and runs SoulGCI and the Agro Capital Standard platform.

Est. 1992 · tehnofarm.md

TEHNOFARM S.R.L. IDNO 1005600002358

Pharmaceutical, biotech, medical, and IT operations — active since 1992. The group's three-decade heritage behind the medical vertical.

Agricultural vertical

NORD NUC S.R.L. IDNO 1021604001777

Agricultural production, processing, forestry, and biotech R&D.

Construction vertical

TF ASSETS S.R.L. IDNO 1026604000041

Real estate, construction, and equipment-leasing operations.

Sources & evidence

Inspect the source.
Understand what it supports.

References are placed beside the relevant statements so technical reviewers, institutions and partners can distinguish a standard, a documented filing and a product-level verification result.

Public primary sources

Standards & context

TRACE documentation, IETF RFCs, official EU legislation and provider documentation explain the referenced mechanisms and requirements. They do not, on their own, establish our implementation's conformance.

Document-backed statements

Filings & submissions

The IP disclosure identifies dated official correspondence. The institutional section identifies company submissions. Supporting materials can be requested for review with personal and confidential information protected.

Implementation evidence

Version-specific verification

A product-level assurance claim needs the implementation version, test scope, results and independent review. The upstream TRACE suite is not a SoulGCI test report; planned capabilities remain development directions until supported by their own evidence.

References checked on 19 September 2026. Request evidence or report a source issue.

Contact

Governed cognitive infrastructure, today

  • Proof plane
    Cryptographic decision receipts, independently verifiable, with tamper-evident audit packs.
  • Architecture
    Eleven-layer governed cognitive infrastructure bound into a closed control loop, with four cross-cutting components.
  • Standing
    Contributing to Moldova's national AI governance program.

Let's talk

Built by TF INTELLIGENCE PLATFORM S.R.L. (Republic of Moldova) — part of the TF HOLDING group. EU-hosted infrastructure.

Addressstr. Independenței, 4, of. 40, MD-5101 Dondușeni, Republic of Moldova
EntityTF HOLDING S.R.L. · IDNO 1025604010126
AdminAlexandr Șcecaliuc