PROJECT H.
A longitudinal behavioural inference engine with cryptographic audit properties.
Not “who should this child become?” but “what is this child already remembering?”
One boundary. Everything hashes at the door.
Every producer writes to POST /api/reflections: a human in a text box, an AI tutor after a chat, a voice note. The engine never branches on source. Two hashes are stamped at write time, never retrofitted. The content hash lands before any non-deterministic processing, the dedupe key before the LLM vision read. A partial unique index makes double-taps race-safe, so a duplicate can never mint a second moment.
Forty small evidenced decisions. Not one giant guess.
No mega-prompt scores forty metrics, because that hallucinates and drifts. A cheap, recall-biased candidate detector narrows each reflection to the three-to-eight dimensions actually present. Each candidate tenet then gets its own narrow judge answering one question, and it fires only on a direct quote of the child's own words. No quote, no signal. Below the confidence floor a signal is dropped, never recorded weakly.
An open vocabulary, canonicalised by meaning.
Skills and values are living dimensions, not a fixed list. The engine names what it observes in the learner's own language, then collapses synonyms into canonical concepts, so persistence and perseverance become one node. A new concept mints as provisional and promotes to stable at three distinct observations. Embeddings run locally, in-process, 384 dimensions: nothing leaves the box.
Design-spec canonicalisation: attach when cos(e_new, e_existing) ≥ 0.86, else mint provisional. As-built, an LLM matcher performs the collapse by meaning.
25 tenets. Zero scores.
The deepest layer is a curated set of exactly 25 tenets, flat, none inferring another. Growth is pure closed-form math over an immutable log: replay every reflection in order and reproduce live state exactly. Outward, only qualitative bands and a direction word ever surface. A projector wall strips every internal number from every response, and a leaked weight fails the build.
growth.ts: 30-day half-life decay toward floor 0.1, never zero. Decay begins only after 7 days of silence, and a node quiet for a full half-life that returns reads as reawakened.
One root. Change a byte, break the proof.
Hers for life. Verifiable offline, forever.
Learner-owned. Private. Exportable.
The issuer identity is a did:key, where the Ed25519 public key IS the identifier, so a signed export verifies forever with no DNS and no certificate authority. Credentials mint deterministically as OpenBadges 3.0 and CLR 2.0, only from mastery confirmed across two or more distinct content hashes. Signature-ready by design, signed when an issuer key is configured. Export, wipe, import: the record and its Merkle root reproduce byte-identically. Family-held in stewardship, with custody transferring to her at majority in a key ceremony.
The engine knows no tenet names.
A build constraint from day one, not a future refactor: the engine is domain-agnostic inference machinery. It does not know it is measuring children, or that Curiosity exists. The entire methodology lives in a versioned, forkable YAML pack. Change the pack, change the philosophy, no code change. What a pack can never do is break integrity: a conformant engine must reject any pack attempting a numeric or ranking surface.
One engine. Any philosophy.
Today one pack runs live: harper-home, authored by two parents for one learner. The rest is the point of the architecture. A forest school, an adult relearning to paint, a civic project: illustrative forks, until someone writes the YAML. The spec's adoption metric is a stranger with the repo and the demo pack rendering a valid conformant record in under an hour. That hour is the pitch.
Bring your own pack.
booting…