Independent systems practice · Don Johnson

We build systems
that can answer
for themselves.

Verifiable AI. Deterministic security. Infrastructure with receipts. Aion Consulting turns ambitious technical ideas into working systems you can inspect, test, and trust.

AI governanceRuntime securityAgent architectureForensic researchDeveloper infrastructure

The practice

Wide spectrum.
One standard of proof.

We work where probabilistic software meets consequential decisions. The form changes—an agent, a security control, a data pipeline—but the obligation does not: make the system explainable, reproducible, and fit for reality.

01

Verifiable AI & agents

Make AI accountable.

Policy outside the prompt, authorization before action, signed context, explicit human control, and evidence that survives the model call.

Aion ContextTaxis BenchSymgliph
02

Security & investigation

Find signal. Preserve truth.

Deterministic detection, graph-native runtime visibility, supply-chain forensics, adversarial research, and artifacts another investigator can replay.

InvariantDLong ShadowAnomalyX
03

Systems & infrastructure

Ship the difficult substrate.

Rust, Zig, Go, protocols, control planes, developer tooling, testing strategy, and small auditable binaries designed to do one hard thing well.

PalimpsestOxide CISMESH

Working software, in motion

Not a capabilities deck.
A body of evidence.

Aion Context · signed rulebooks for AI agents

01 / Verifiable AI

Aion Context

Signed, tamper-evident policy artifacts keep consequential rules outside the model—and make every version independently verifiable.

Inspect the Rust kernel
02 / Runtime security

InvariantD

Continuous graph-native verification for Linux infrastructure. Formal rules detect; AI explains. Certainty and assistance stay on the correct sides of the boundary.

Visit InvariantD
03 / Applied product

ClaimZen

An applied proof system for dental denial recovery: read the denial, check the record, draft the appeal, and seal the evidence—without removing human sign-off.

Visit ClaimZen
04 / Engineering intelligence

Solv

Capture friction while it is fresh. AI enriches the signal; people decide what changes; signed history records whether the commitment produced a real outcome.

05 / Institutional governance

Cailara

A signed, role-adaptive operating system for K–12 rules: one governed policy graph, frontline workbench, governance studio, executive oversight, and evidence another institution can verify.

Inspect the trust substrate

Selected proof

Claims are cheap.
Artifacts travel farther.

Eight projects selected for the range of problems they expose—and the rigor of the answer. Public source, measured boundaries, and enough detail to disagree intelligently.

01AI context infrastructureRust

Aion Context

The model acts inside a signed context—not a prompt-shaped suggestion.

A zero-copy binary format, chained signatures, multisig approval, key rotation and revocation, sealed releases, offline verification, and standards-aware interoperability.

02Context compilationRust

Symgliph

Bound the context. Verify the source.

A source-verifiable context compiler with deterministic corpus identity and hard token ceilings. Its public study reports 97.58% mean prompt-token savings—and plainly documents the remaining recall gap.

Read the study
03Forensic investigationEvidence corpus

Operation Long Shadow

I went looking for AI-built code on GitHub. I found a farm.

A reproducible investigation into four repo-laundering clusters: 3,150+ repositories, forward-dated commits, impersonation, paper theft, and bot-star inflation—with replay commands and hashed evidence.

Examine the evidence
04Agent evaluationTypeScript

Taxis Bench

Correctness is not permission.

An adversarial certification environment that scores an agent's conduct—not just its answer—across correctness, authorization, idempotence, provenance, precision, and calibration.

Inspect the benchmark
05Anomaly detectionRust

AnomalyX

The executable is the contract.

Contract-first detection across roughly thirty formats, normalizing security telemetry, packet captures, observability streams, and data-lake files into one deterministic evidence envelope.

Inspect the CLI
06Deterministic crawlingRust

Palimpsest

Same seed. Identical crawl. Identical replay.

A deterministic crawl kernel with content-addressed storage, WARC-compatible capture, browser stealth, replay, distributed crawling, and RAG-ready extraction.

Explore the kernel
07Engineering intelligenceRust

Solv

The retro is a ledger. AI proposes. People decide.

A continuous retrospective system with a hash-chained event kernel, human-gated AI processor mesh, byte-identical replay, Slack/API/CLI capture, and signed commitments that the next cycle must answer for.

08K–12 organizational governanceRust + Aion

Cailara

Institutional rules should travel with authority, provenance, and proof.

A role-adaptive workbench, governance studio, and oversight lens backed by a deterministic Rust policy kernel, signed Aion artifacts, exact receipts, and replayable decisions.

The Aion laboratory

One trust primitive.
Many real worlds.

Aion Context is not presented as an abstract layer alone. The organization builds reference systems that force the primitive to answer domain-specific questions—from universities and K–12 governance to federal compliance and Medicaid integrity.

Visit the organization

Ideas made executable

The writing is part of the engineering.

Arguments become reference implementations. Investigations retain their evidence. Claims are scoped so the reader can reproduce, challenge, or extend them.

Research is not a mood board. It is a method.

The principal

Don Johnson

Systems-level engineer, security researcher, agentic architect, and builder of small sharp tools.

On GitHub since 2008, Don works across Rust, Zig, Go, Python, TypeScript, and the infrastructure around them. The practice combines direct engineering judgment with a specialized AI staff for research, adversarial review, architecture, implementation, and verification.

The staff expands the search space. Responsibility stays human. Every deliverable has an owner, a claim boundary, and a way to inspect the work.

Discovery / 30 minutes

Bring the problem that does not fit neatly in a category.

No deck. No SDR handoff. We start with what must be true, what is currently uncertain, and what evidence would change the decision.

01
Technical conversation with the builder
02
Clear claim and authority boundaries
03
A concrete next experiment—or an honest no

Aion / briefing agent

Waiting for context

  1. 01 Context
  2. 02 Synthesis
  3. 03 Handoff

Where does the problem live?

Describe the outcome, not the vendor or implementation you think you need.

Only the problem context is sent for synthesis. Your name and email stay out of the model request.

Sent directly to Don. Prefer email? [email protected]