A systems studio

Don't trust the number. Re-run it.

Most software hands you a conclusion and asks you to believe it — a score, a benchmark, a dashboard. We build the other kind: systems whose claims you can derive again yourself, on your machine, and get the same answer or a different one.

It starts with an operating system. T&R — FreeBSD 15 assembled from pkgbase rather than installed, no installer and no first-boot download. 626 MB carries the verifier, which is the half that lets you take the sentence above literally; a 364 MB server image without it is below.

free · no account · nothing to sign up for
sha256 7e0f027db3da721b7f0210c4d5101e2acf872e77036c088f53c1ad8fafc820f9
release v0.3 · this file is tandr-0.3.qcow2 · all files & checksums
A RuneFort layout standing as a window on the road, titled What is Runefort? · Concept — a tile grid of rooms labelled rooms, claims, neighbors and state bindings, above the shell's seven amber gauge tubes for CPU, RAM, SWAP, DISK, NET, TEMP and LOAD, a gear selector and a DRIVE gauge
a RuneFort layout standing on the road — rooms, claims, neighbors and state bindings, compiled to a grid at author time rather than laid out by an engine at run time. 2026-08-16, 16.7 ms/frame. The pane is not a process: it is a document the shell draws, so the road carries a lot of them — 10,000, measured, at the same 16.7 ms.
The thesis

Data driven keeps the result. Compute driven ships the derivation.

The name is an argument, and it is not that data-driven work is irreproducible. It often is reproducible — when the inputs, the transformations, the environment and the method have all been preserved with enough discipline. The difference is where that discipline lives: alongside the artifact, or inside it.

the common posture

Data driven

  • The result is the thing that travels.
  • Reproducing it means reassembling its context by hand.
  • That context lives outside the artifact — a README, a lockfile, a methods section, somebody's memory.
  • When any of that rots, the number outlives its derivation.
  • Reproducibility is achievable, and it is a practice.
keeps: the result
ours

Compute driven

  • The derivation is the thing that travels.
  • Canonical input, executable semantics, a derived identity and its provenance ride inside the artifact.
  • Meaning is computed, never assigned — the identity is a hash.
  • The derivation travels with the artifact rather than as assembly instructions beside it.
  • Reproducibility is a property, not a practice.
keeps: the derivation

So, stated as a test rather than a mood:

A claim is compute driven when the artifact carries enough — canonical input, executable semantics, a derived identity and its provenance — for an independent machine to derive the claim again.

And the limit, because this is the sort of page that has to state it: re-derivation proves fidelity, not correctness. A wrong computation re-runs perfectly and is still wrong. Deriving the same identity tells you that you got what we got — it does not tell you that either of us should have wanted it. What it removes is the argument about what happened, which is the argument that usually eats the room.

The shape

A road, and a window. All the way down.

This is a WRL world — the language the stack writes meaning in. Square brackets are places. Arrows are roads between them. It is a map, and the map is executable.

profile forge.world.core.v1 [pulser:p0](every 2){sig_out} [relay:r0]{sig_in, sig_out} [spinner:sp](w=16, n=8, rotor=quarter_turn_z) [orb:ob]{pose} [pulser:p0] --sig--> [relay:r0] [relay:r0] --sig--> [spinner:sp] [spinner:sp] --socket--> [orb:ob]

Now look at the shell in any photograph on this page: panes standing as signs along a road you drive through. That is the same drawing. Not a metaphor borrowed for the marketing — the language, the runtime, the evidence and the interface are all the same two things.

layerthe road — how, goingthe window — what, arrived
WRL --sig--> and ~~route~~> [actor:id] and its ports
TRVM local rewrites — a traversal the reduced term
TRAAVIIS the film, epoch by epoch the semantic identity (sem-…)
the shell Travel — road, camera, the flight in RRABBIT — signs, surfaces, the rect

The shell's own documentation puts it better than we can: “One likes going; the other likes being gone to.” Neither half is worth much alone — a hash without a film is a claim, and a film without a hash is a story.

The ladder

Five rungs. Three of them hold weight.

A world you can drive, that remembers where you went, and can be asked to go there again — under a certificate saying it was allowed to. That is the whole intention. It comes apart into five steps, and they are not equally real.

DRIVE rung one
A person moves through the world. Roads, windows, gauges — an operating system you steer rather than a desktop you tidy.
live_local the shell runs; three of the system's own programs stood as windows on 2026-08-13
TRACK rung two
The traversal is recorded — which road, how far along it, which window you were standing in, the trail behind you, and an append-only log beside the trail.
live_local 1–999 tracks, sparse, with a reel to manage them — but the recording covers 4 of about 15 verbs
REPLAY rung three
The track runs again, against a world that persisted — and refuses by name if that world moved underneath it.
live_local roads checked before anything moves; typed refusals; no silent repair — shipped 2026-08-15
GENERALIZE rung four
WRL abstracts the track into a program — the one route you drove becomes the class of routes you meant.
spec blocked on closing the op vocabulary, which is a decision and not a task
AUTONOMOUS rung five
A model proposes WRL text; the host derives the edit from it rather than running what the model wrote; the kernel rules on whether it was permitted.
spec designed in full, built not at all

live_local — run end to end, on a machine here, at least once. spec — written down, not built. There is deliberately no rung on this page meaning we are confident it works.

Our own audit had rung three at spec"no implementation found" — as recently as yesterday. It shipped on 15 August, and this table was corrected before the page went up rather than after somebody noticed. The frontier is rung four now, and rung four is not waiting on work: it is waiting on a decision about what the verbs are.

rungs 4–5 are not built · nothing on this page ships them
The surface

The window is a vehicle. It is not a browser.

The obvious way to put an operating system on the internet is to write a browser. It is also the most reliable way to spend three years and lose: Chrome is counted in billions of users, and every agent-driven browser shipped so far, added together, is a rounding error against the online population.

So the shell runs the other direction. It does not put pages inside a browser — it puts the operating system inside one. A Wayland compositor whose surfaces are ordinary native applications, encoded and carried to a canvas, standing as windows along a road you drive through.

It has carried native applications since 2026-08-14: a foot terminal, a Mousepad editor and a GTK file chooser, none of them modified to appear there, in a 4 GB guest at 3840×2160 with no GPU and no /dev/dri — software EGL, software H.264, and the frames arrive. That is a dated claim and there is no current photograph of it on this page. The one there was showed a mirror reading "R · REEL is not built", which stopped being true, and a picture that contradicts the ladder two sections above it is worse than a sentence with a date on it.

The Travel & RRABBIT shell at 5K: two BendScript documents standing as windows along a dark road — one titled All nine core predicates listing nine typed edges, one titled On the Closed Memory Loop listing five phases — with a third as a distant card. In front of the instrument panel the left document is also open flat at 1:1 in a reading pane with a delete button. Mirrors read NO REAR VIEW and NO REEL IN THE GLASS.
the same surface carrying documents instead — 2026-08-16, 5120×2880, 34.1 ms/frame at that resolution. Nothing here is a process. Two .bend documents stand where the applications stood, drawn by the shell rather than run by it, and the road does not know the difference. The left one lists nine typed edges — cites, contradicts, supersedes, transcludes — each pointing at a content address rather than a URL. A .bend document averages 1,067 bytes against the ~3 MB a native window costs in VRAM — and the road was driven with 10,000 of them on it, which is a different conversation from dozens of applications.

The pane across the bottom is the same document flattened to 1:1 — the window you were driving past, standing still under you, with the controls that act on it. That is what the vehicle is for: the thing on the road and the thing you are reading are one object at two distances, not a preview and a file. The mirrors are the current ones — the reel exists now, and the camera still does not.

That claim used to read "thousands", from arithmetic. Bytes per document do not prove that a scene can draw them, so it was measured instead — one session, panes added without clearing, frame time from 80 requestAnimationFrame deltas with the first 20 discarded.

panes on the road median ms/frame objects in the scene painted at once JS heap
016.70
116.731
1016.73010
10016.830024
1,00016.76782467 MB
3,00016.86782485 MB
10,00016.767824130 MB

2026-08-16, one machine, 1600×900, shell running from source. The same 10,000 panes while driving: median 16.7 ms, 95th percentile 40.7 ms against 37.5 stationary. Placing the last 7,000 took 4 ms.

The column that matters is the second one, because it does not move. Panes go up by four orders of magnitude and the frame time does not — the scene stops growing at 678 objects and never paints more than 24 at a time, because everything further away is a card and everything past that is not drawn at all. Cost tracks what you can see, not what exists.

What this does not show, said plainly. All 10,000 panes are three sample documents recycled, so the texture atlas holds far less than 10,000 distinct documents would — it stayed flat at 48 MB throughout, and a corpus of genuinely different documents is the obvious next measurement and has not been taken. They were placed on the bench path, which skips the dash-slot rule real windows obey. One machine, one browser, and nobody else has run it.

10,000 panes · 16.7 ms · measured 2026-08-16 · 3 distinct documents

What the vehicle buys is the two things a page in a tab does not have: an address — the subject of the next section — and a boundary you can hang rules on. What it does not buy is universal compatibility, and there is a plain example. Firefox will not come aboard. It connects, opens its protocol channel, and then never maps a surface: no window, no error, no output on either stream. Reproduced 2026-08-14. Cause unknown.

A rendering engine is years of work and a race that was won by somebody else a decade ago. A vehicle is a wrapper around one — and the wrapper is where the address, the rules and the certificate live.

the shell runs · the photograph above is it
Where this is going

The road is the filesystem. The signs are where the code goes.

A window in this shell is not floating in a compositor's list. It is somewhere: on a network, on a road, on a side of that road, at a numbered dash. home:1 · left is an address, and it is the address the window is stored at.

The road map: a graph of three workspaces named home, build and watch with directed arrows between them, and a side panel listing each window with its address, side and pixel size
the same three windows, addressed — (foot) home:1 · left · 816×312. Rows are hops from the root; an arrow pointing back up a row is a loop. Photographed 2026-08-14, alongside the native-window frame it shares its addresses with.

That is already a filesystem, in the only sense that matters: a namespace with paths, in which a path is a route rather than a chain of folder names. And the signs standing along it already speak WRL:

The entrance gantry of a road: a board reading T&R and the arrow --build--> on the first row, 1:0-2 and the bracketed word [main] on the second, above three blue panels reading back to home, left open window, and right open window
the entrance. Blue panels are the things you can do on arriving: go back where you came from, or open a window to your left or your right. The board reads --build-->, a WRL arrow, into [main], a WRL place; 1:0-2 is lane : window-you-are-at - windows-total. The far board is this road's other end.
The exit gantry of the same road: the same T&R --build--> board now reading 1:2-2, above three panels reading home, back to the entrance, and plus lane new workspace
the exit, on the same road. The counter has moved 1:0-21:2-2 — you have passed both windows. Green panels are ways out: leave along --home-->, loop back to the entrance, or open a lane that does not exist yet.

Both photographed 2026-08-16 at 1920×1080, 16.7 ms/frame, on the shell running from source. Nothing here is a mock-up or a diagram — the signs are geometry in the scene, and the text on them is read out of the world graph rather than authored for the picture.

Square brackets are places and arrows are roads — the same notation as the program listing further up this page. Nobody translated the language into signage; the signage is written in the language.

So the language is already on the furniture. The next step is to let you write it there — WRL beside a window, at a dash, on a lane, on the gate itself; and programs that do not merely run on the road but read it, change it, and execute it. A shell whose layout is a program, and whose programs can rewrite the layout.

the piecestanding todaynot built yet
address network · road · side · dash, persisted resolving one as a path from a program
notation signs are rendered in WRL signs you can type WRL into
graph roads, exits, ramps, tracks — editable by hand editable by a running program
execution WRL runs in TRVM, off the road WRL that runs as the road

None of the right-hand column exists. It is written down here because a direction stated in public can be checked against what turns up, and because the left-hand column was the same kind of sentence a year ago. Everything in the left column can be driven today, on a machine you can download from this page.

the right-hand column is not built · nothing on this page ships it
Tracks

A macro repeats. A track checks.

Recording what somebody did and playing it back is an old idea and not the interesting part. The interesting part is what happens when the world has changed since — because it will have.

The shell keeps up to 999 tracks, made as you need them. Each one remembers the road it is on, how far along every road it had driven, the window it was standing in, a capped trail for retracing, and — beside the trail — an append-only log that is never truncated. The two are deliberately different objects: the trail is lossy on purpose, and a recording must not be. When the log does hit its cap, the number of steps that fell off the front is kept, so a replay can tell it is holding a tail and decline to call it the whole drive.

Replaying one happens in two phases, and the split is forced rather than chosen. Roads are checked before anything moves — a route whose third step names a road that is gone never takes the first step. Windows are checked on arrival, because surfaces cannot be asked about in advance. When a track cannot proceed it is refused by name:

// the shell's own refusal codes TRACK_EMPTY nothing recorded to drive TRACK_ROAD_GONE a step names a road that no longer exists TRACK_ROAD_CLOSED the road is there and will not admit you TRACK_WINDOW_GONE the surface it stood in has closed TRACK_BUSY something else is driving TRACK_REFUSED the step was not permitted

No silent repair. A step whose road has vanished is refused and named; it is never quietly remapped to a road that looks similar. That is the difference the whole rung exists for — a macro would have carried on and done something plausible to the wrong thing.

One consequence is worth the detail. A track records arrivals, not inputspark(road, z) rather than forty notches of a scroll wheel. So the state after step k is fully described by step k, and stepping backwards through a replay means performing step k−1 again rather than trying to reverse step k. Forty wheel deltas cannot be undone. One arrival can.

the pieceships todaystill missing
recording append-only, capped, and the loss is counted 4 of ~15 verbs — no resize, no launch, no clicks
refusal six typed codes, no silent repair the check/use race is narrowed, not closed
precondition hand-written, in JavaScript sealed into the track, so it cannot be edited to weaken its own guard
address a track is a thing on this machine somewhere a stranger could drive to — no publish path at all
The reel: a table of tracks with columns for name, the road each is parked on, trail length and recording length, and per-track buttons reading here, replay, walk, clear rec and delete. Below it a make control accepting 1 to 999. The road and its documents are dimmed behind the overlay.
the reel, in gear R — 2026-08-16. Every track says which road it is parked on, how long its trail is and how long its recording is, and those are two different numbers on purpose: "a short trail beside a long recording means you reversed out of somewhere." Up to 999 of them. This shell has one track on it — the instrument is the claim, not the count.

That last row is the one that matters commercially, and it is empty. A track you cannot hand to anybody is a personal convenience. The claim worth making is that a track refuses — and that part is standing, today, with the codes above printed by the shell rather than by this page.

no track can be published or addressed · that is not built
The certificate

Feasible ▸ permitted ▸ best. And three laws that do not hold.

"May this proceed, and is it best?" is normally answered by a person reading a diff. Underneath this stack it is answered by arithmetic, and the answer carries a certificate saying how it was reached.

The kernel is eight small algebras in a fixed order — what can happen, how to rank it, what is allowed, what stays safe over time, whether the rules may themselves change, whether we know enough, who can ensure it, and whether we can afford it. One bridge composes them, floor first and gradient second, over a safety floor that cannot be weakened. Nothing is ever chosen before it is permitted.

It carries 118 property-tested laws, two thousand random trials each. That number is not typed into this page — the suites count themselves and print it, because the last time a law count was written out by hand the published figure and the real one drifted apart without anyone noticing.

And three laws do not hold. They are declared open, they print FALSIFIED in red on every single run, and the build fails if one of them ever starts passing — because a gap that quietly closes is a gap nobody checked. All three concern the same operator, and whether the order you compose in can move the floor:

// open, and printed in red every run CP5 the |> floor is association-invariant CP6 no backward execution step survives |> CP7 &-operand order does not change a downstream |> floor

You do not have to take any of that on faith, and it costs about two minutes. There is no install step and there are no dependencies:

$ git clone https://github.com/c-u-l8er/AmpersandBoxDesign $ cd AmpersandBoxDesign/box-and-box $ node test/laws.mjs && node test/compose-laws.mjs

It prints 118 holding, three falsified, and the counterexample that broke each one — a different counterexample most runs, because the trials are random. The conformance surface is published at ampersandboxdesign.com/laws.html.

The laws hold against generators we wrote, which is the weak half of the claim: nobody outside has tried to break the kernel. The command above is the cheapest way anyone could, and a law we assert that you can falsify is worth more to us than the 118 that held.

118 enforced · 3 declared-open · re-derived 2026-08-15
What we hold to

Six rules. We break them in public or not at all.

These are not aspirations. Each one is here because it changed something we shipped — usually by making a page say something less flattering than the draft did.

  1. Re-derive, don't trust. If a claim cannot be computed again by someone who does not work here, it is a rumour with good typography.
  2. Say what is not built. Every status on every page is measured, sourced, or marked not built. The absent things are listed beside the present ones, at the size they actually are.
  3. Subtraction is the feature. 364 MB is not an optimisation. It is 200 MB of test suites, every debug package and every 32-bit library, decided against.
  4. A claim carries its date and its machine. “It works” is not a result. “Measured on a pristine image, 10 August 2026, and here is the string it printed” is one.
  5. Quote the unflattering half. The verifier costs 14 MB. The interpreter it needs costs another 250. A page that mentions only the first number is lying with a true fact.
  6. Never fake a success. A control that reports something it did not do is worse than one that plainly fails. We deleted our own before writing this down.
Get it

Two downloads, one build.

One release, v0.3, holding two images. The file names carry the image version, not the release version — so tandr-0.2.qcow2 and tandr-0.3.qcow2 are both current, and 0.2 is the smaller build rather than the older one. If you want to check anything this page claims, take 0.3: it is the one with trvs in it.

Server

364 MB
50 packages · T&R 0.2

sshd, cron, a serial console. The whole operating system and nothing arranged around a screen.

sha256 9e8767be0140ac5515fedafabdd156e5c9323619285ec12790e29557c422023e

Server + verifier

626 MB
56 packages · T&R 0.3

The same system carrying TRVM and trvs — a runtime and a verifier that turn a run into a bundle somebody else can replay. The extra weight is almost entirely the python interpreter.

sha256 7e0f027db3da721b7f0210c4d5101e2acf872e77036c088f53c1ad8fafc820f9

Desktop

~5.2 GB
~350 packages · build it yourself

X.org, icewm, a vertical cockpit panel, Firefox, and the Travel & RRABBIT road shell in the picture above. Too large for the release host, so this one is a build rather than a download.

Run it

Three ways in. One of them is proven.

Every T&R boot on record is a virtual machine. Writing the image to real hardware should work — it is a GPT image with a UEFI partition — but nobody has done it, so those two routes are marked untested rather than supported.

This is the route we run constantly. The image boots to a serial console, so you can drive and log it without a display. Needs UEFI firmware — the path below is Arch; Debian uses /usr/share/OVMF/OVMF_CODE.fd.

# one command, straight from the download above qemu-system-x86_64 -m 2048 -smp 2 -cpu host -enable-kvm \ -drive file=tandr-0.3.qcow2,if=virtio \ -bios /usr/share/edk2/x64/OVMF.4m.fd \ -nographic

That is the 626 MB image, the one the button at the top of this page hands you and the only one with trvs aboard. Running the 364 MB server image instead is the same command with tandr-0.2.qcow2 in it.

Prefer something that manages instances for you? PARKVPS runs these images rootless and daemonless, one process per guest, every disk a copy-on-write overlay on one shared image.

Why it is small

Subtraction, done once, at build time.

FreeBSD's own cloud image enables firstboot_pkg_upgrade, so every instance re-downloads its base packages the first time it starts — forever. We patch at build time instead, and leave out the ~200 MB of test suites, every debug package and every 32-bit library a server guest will never open.

T&R server image364 MB
FreeBSD cloud image2.51 GB
written on first boot — T&R55 MB
written on first boot — stock cloud image~3 GB
Measurement record. First-boot figures measured 10 August 2026 on this workstation, as the size of a copy-on-write overlay after one boot and no other use: two independent bare instances wrote 58,064,896 and 58,130,432 bytes (55.4 MB); the image carrying the verifier wrote 59,637,760 bytes (56.9 MB). Image sizes are qemu-img on-disk, same day, same tree.
The two FreeBSD cloud-image figures are carried from the T&R build notes rather than measured here — they are the weakest numbers on this page and they are the ones that flatter us, which is exactly why they are labelled.
The stack

Six parts. Not all of them are software.

T&R is the distribution and the shell; the five beneath it are the reason the distribution exists. They are not the same kind of thing, so each card says what role it plays and where it actually is — because "part of the stack" and "in the image you just downloaded" are different claims. ComputeDriven is not a seventh box. It is the discipline the six are held to.

T&R
distribution · proof artifact
Travel & RRABBIT — the distribution, and the shell it is named after. Travel navigates: the road, the camera, the flight into a window. RRABBIT is the windows: the sign on the road, the surface that flattens to 1:1 under you. Two personalities, not two layers.
shipping · shell in the desktop image
RAVIO
interface lineage · visual system
The drivable sky road the shell was forked from, re-missioned from rendering a build harness to managing an operating system's windows. What reaches the image is its palette — the amber, the cyan, the bronze rims this whole page is wearing.
upstream · theme, not a package
WRL
topology language
WallRiderLang. A topology language whose meaning is a canonical graph, so a world's identity is a hash rather than a filename. Reformat it freely; change what it claims and the identity moves.
in the 626 MB image
TRVM
reduction runtime
The term-rewrite runtime that reduces it. Interaction-net reduction is confluent by construction, and it is confluence — not locality on its own — that licenses schedule-independence: the order redexes fire cannot change the result. That is what makes "run it yourself" an offer rather than a hope.
in the 626 MB image
TRAAVIIS
evidence · verification
trvs — seals a run into a bundle somebody else can replay, and derives the same identity when they do. Boot the 626 MB image and type trvs doctor; it answers status ready having set nothing up.
in the 626 MB image
[&]
composition protocol
The protocol the other five are designed to compose under — how a capability declares what it is and what it may touch. It is not enforced as a conformance boundary across all five today. It is a specification, so it is not installed anywhere; it is the shape the rest agree to.
a protocol · nothing to install
The Travel & RRABBIT login screen: a checkered planet over an interchange of glowing roads, with a small instrument panel reading T & R, Travel & RRABBIT, and fields for USER and KEY above an IGNITION button
the login screen — the cockpit, before you are in it. Provenance not recorded: the background art predates this page and nobody wrote down whether it was drawn, rendered or generated. The panel, the fields and the IGNITION button are the real greeter.
The full instrument cluster: a FRAME gauge reading 16.7 ms/frame, a lane panel reading build, seven amber gauge tubes for CPU RAM SWAP DISK NET TEMP and LOAD, a steering wheel, a P-R-C-D gear selector, and a DRIVE gauge. Two mirrors read NO REAR VIEW and NO REEL IN THE GLASS.
the instruments, 2026-08-16 — seven gauges reading the real machine, and two mirrors that say what they cannot show you: the road behind is not rendered, and the camera gear is not built. The red lines are this box, right then: swap at 64% against a 25% threshold, one sensor at 95.6 °C. Swapping is a fault, not a level — so the instrument says so rather than drawing a longer bar.
T&R Cloud

Your world is a graph. Back up the graph, restore the world.

Not your files — your roads, your windows, your dashboards, your tracks, your park-mode collages, and the machine they all live on. Restore onto different hardware and drive the same routes. None of it is built. What follows is the design and its arithmetic, published before there is anything to sell, because the arithmetic is the part you can check.

RESTORE the product
Backup is the boring half. The thing being sold is the restore: a clean machine, a manifest, and the same world standing back up on it — the same roads, the same windows, the same tracks, and they still replay. It is step six of the loop this studio already runs, sold as a feature rather than bolted on beside one.
spec the chunker, the store and the rehydrate path are all designed and none are written
FREE RESTORES at every tier
Unlimited restores, including on the free tier. That sounds like a concession and costs nothing: the store charges $0.00 for egress at any volume. Pulling ten terabytes back down is free to serve. The same restore is $204.80 a shot on block volumes and about $922 on S3.
vendor rate provider list rates read 2026-08-14 — not our measurement, and not cyan for that reason
THE WORLD IS FREE 0.21% of the bill
The differentiated part — the graph, the provenance, the tracks, the thing nobody else sells — measures 247 KB for a realistic world and 212.70 MB at the shell's own enforced ceiling. Against 100 GB of machine data that is about a fifth of one percent at the ceiling, and two ten-thousandths of it in practice. You are charged for the machine; the world rides along.
live_local measured 2026-08-15 from the shell's own persistence, on our machine. This said "a tenth of one percent" for one day; 212.70 MB against 100 GB is 0.21%, and the error flattered us — corrected 2026-08-16
Free
$0
10 GB
costs $0.00 to serve
the store's own free tier
Genuinely free, not subsidised.
Driver
$6/mo
100 GB
costs $1.35 · 78% margin
One person's machine.
Fleet
$19/mo
500 GB
costs $7.35 · 61% margin
Several machines, or one with media on it.
Factory
$69/mo
2 TB
costs $30.57 · 56% margin
A working shop.
Enterprise
price not set
10 TB and up
storage alone costs $153.45
Not more gigabytes — dedicated infrastructure. Your own machine, your own database, data residency if you need it. A number here would be guessed, so there isn't one.

Cost of goods is storage at the provider's list rate. The enterprise line is the storage floor only — a dedicated machine and a dedicated database sit on top of it, which is exactly why that tier is not priced by the gigabyte and is not priced on this page.

The unit economics are printed here for the same reason the failing laws are printed on this page and the missing rungs are printed above: a margin you cannot see is a claim you cannot check. If the arithmetic is wrong, it is wrong in public.

nothing in this section exists · no store, no chunker, no account, nothing to buy
Untested & unfinished

The parts we have not earned yet.

A download page that only lists wins is asking you to install on faith. These are the holes at the size they actually are.

Never booted on real hardware

Every boot on record is QEMU/KVM. USB and internal-disk installs should work and have not been demonstrated by anyone.

No installer

You write an image to a disk. There is no partitioner, no dual-boot path and no way to keep what was already there.

The console is the front door

The serial console is marked secure and root has no password. Fine for a disposable local VM, wrong the moment one listens on a real address.

The desktop is not downloadable

At ~5.2 GB it exceeds the release host's per-file limit, so the most visual part of this page is the part you have to build yourself.

One implementation

The verifier's identity claim rests on a single codebase agreeing with itself across two operating systems — not on two implementations agreeing.

Nothing leaves the machine

A track can be recorded, refused and replayed here, and there is no way to publish one or point anybody at it. The rung the whole ladder is built for has no implementation.

A guard that can be edited

What a track requires before it runs is hand-written JavaScript sitting beside it, not something sealed into the track's identity. Nothing yet stops a track being edited to weaken its own precondition.

Nobody has attacked the kernel

The 118 laws hold against generators we wrote ourselves. An adversary we did not write is a different test and it has never been run. That one takes two minutes.

The cloud is a price list

T&R Cloud has a design, a store picked and margins worked out, and not one line of code. No chunker, no manifest format, no account, nothing to buy. A tier table is not a product.

The loop has never run in one pass

Seven of the seven steps that take work from intent to verified result run on a developer machine. None of it has ever run end-to-end across deployed machines as a single pass.

Nobody else has run it

These are the first published images. Every measurement on this page comes from our machines, which is the weakest kind of evidence there is. That one is yours to close.

Boot reports

Be the machine that isn't ours.

Every number on this page was measured here, on hardware we own. No amount of care fixes that — a claim only becomes a result when somebody else's machine derives it too. So joining ComputeDriven is not a subscription. It is running an image and saying what happened.

What a boot report is

  1. The machine. CPU and firmware, or the hypervisor and its version — enough that somebody could try the same thing.
  2. The image, and its sha256. Whether the sum you got matches the one quoted above.
  3. Whether it reached a login prompt. Yes, no, or yes-but.
  4. What trvs doctor printed, verbatim. On 0.3 it should answer status ready having set nothing up. If trvs id hands you a different sem- identity than ours, that is the most interesting thing you could possibly send us.

A boot that fails is the better report. Success confirms what we already published; a failure is a measurement we do not have. USB and bare metal have never been booted by anyone — the first person to try is doing the experiment, whichever way it goes.

Three ways, and one of them isn't built.

Boot it

~20 minutes · the form above

Run an image and say what happened. This is the only rung on the list we are structurally unable to climb ourselves, which is why it gets the whole section above.

Break it

~2 minutes · no install

Run the law suites and try to falsify something we assert holds. The command is up the page. It already prints its own three failures — a fourth, found by you, would be worth more to us than the 118 that passed.

Drive it

does not exist yet

Publish a track and have somebody else replay it. This is what the whole ladder is for and there is no publish path at all. It is listed here so the shape of the thing is honest, not because you can do it.

There is no mailing list, and this page will not pretend there is one. If you only want to know when an image ships, watch the repository for releases, or take the feed. Anything that is not a boot report goes here instead:

What this page loads from other people, in full. Two things. The form below posts to formspree.io when you press the button, carrying what you typed. And the host injects an analytics beacon from static.cloudflareinsights.com on every visit — that one is not in this page's source and is not ours to switch off from here. Being hosted is a dependency too, which is why the download button no longer promises no telemetry: that was a claim about a file, printed on a website, and the website could not keep it. Everything else — fonts included — is served from this domain.