Verifiable AI & agents
Make AI accountable.
Policy outside the prompt, authorization before action, signed context, explicit human control, and evidence that survives the model call.
Independent systems practice · Don Johnson
Verifiable AI. Deterministic security. Infrastructure with receipts. Aion Consulting turns ambitious technical ideas into working systems you can inspect, test, and trust.
The practice
We work where probabilistic software meets consequential decisions. The form changes—an agent, a security control, a data pipeline—but the obligation does not: make the system explainable, reproducible, and fit for reality.
Verifiable AI & agents
Policy outside the prompt, authorization before action, signed context, explicit human control, and evidence that survives the model call.
Security & investigation
Deterministic detection, graph-native runtime visibility, supply-chain forensics, adversarial research, and artifacts another investigator can replay.
Systems & infrastructure
Rust, Zig, Go, protocols, control planes, developer tooling, testing strategy, and small auditable binaries designed to do one hard thing well.
Working software, in motion
Aion Context · signed rulebooks for AI agents
Signed, tamper-evident policy artifacts keep consequential rules outside the model—and make every version independently verifiable.
Inspect the Rust kernelContinuous graph-native verification for Linux infrastructure. Formal rules detect; AI explains. Certainty and assistance stay on the correct sides of the boundary.
Visit InvariantDAn applied proof system for dental denial recovery: read the denial, check the record, draft the appeal, and seal the evidence—without removing human sign-off.
Visit ClaimZenCapture friction while it is fresh. AI enriches the signal; people decide what changes; signed history records whether the commitment produced a real outcome.
A signed, role-adaptive operating system for K–12 rules: one governed policy graph, frontline workbench, governance studio, executive oversight, and evidence another institution can verify.
Inspect the trust substrateSelected proof
Eight projects selected for the range of problems they expose—and the rigor of the answer. Public source, measured boundaries, and enough detail to disagree intelligently.
The model acts inside a signed context—not a prompt-shaped suggestion.
A zero-copy binary format, chained signatures, multisig approval, key rotation and revocation, sealed releases, offline verification, and standards-aware interoperability.
Bound the context. Verify the source.
A source-verifiable context compiler with deterministic corpus identity and hard token ceilings. Its public study reports 97.58% mean prompt-token savings—and plainly documents the remaining recall gap.
Read the studyI went looking for AI-built code on GitHub. I found a farm.
A reproducible investigation into four repo-laundering clusters: 3,150+ repositories, forward-dated commits, impersonation, paper theft, and bot-star inflation—with replay commands and hashed evidence.
Examine the evidenceCorrectness is not permission.
An adversarial certification environment that scores an agent's conduct—not just its answer—across correctness, authorization, idempotence, provenance, precision, and calibration.
Inspect the benchmarkThe executable is the contract.
Contract-first detection across roughly thirty formats, normalizing security telemetry, packet captures, observability streams, and data-lake files into one deterministic evidence envelope.
Inspect the CLISame seed. Identical crawl. Identical replay.
A deterministic crawl kernel with content-addressed storage, WARC-compatible capture, browser stealth, replay, distributed crawling, and RAG-ready extraction.
Explore the kernelThe retro is a ledger. AI proposes. People decide.
A continuous retrospective system with a hash-chained event kernel, human-gated AI processor mesh, byte-identical replay, Slack/API/CLI capture, and signed commitments that the next cycle must answer for.
Institutional rules should travel with authority, provenance, and proof.
A role-adaptive workbench, governance studio, and oversight lens backed by a deterministic Rust policy kernel, signed Aion artifacts, exact receipts, and replayable decisions.
The Aion laboratory
Aion Context is not presented as an abstract layer alone. The organization builds reference systems that force the primitive to answer domain-specific questions—from universities and K–12 governance to federal compliance and Medicaid integrity.
Visit the organizationIdeas made executable
Arguments become reference implementations. Investigations retain their evidence. Claims are scoped so the reader can reproduce, challenge, or extend them.
Executable essay
Engineering essay
Investigation
The principal
Systems-level engineer, security researcher, agentic architect, and builder of small sharp tools.
On GitHub since 2008, Don works across Rust, Zig, Go, Python, TypeScript, and the infrastructure around them. The practice combines direct engineering judgment with a specialized AI staff for research, adversarial review, architecture, implementation, and verification.
The staff expands the search space. Responsibility stays human. Every deliverable has an owner, a claim boundary, and a way to inspect the work.
Discovery / 30 minutes
No deck. No SDR handoff. We start with what must be true, what is currently uncertain, and what evidence would change the decision.
Aion / briefing agent
Waiting for context
Brief received / handoff complete
Your discovery brief is with Don. Expect a direct reply—not an automated qualification sequence.