Codex OS
The architecture that proves control.
Dual Trust Paths
Codex OS separates the execution path (what the runtime attempted) from the governance path (why the disposition occurred). These paths converge only at the evidence plane, never at the gate, preventing circular assurance chains.
Enforcement Surfaces
Every consequential action passes through a Freeze Gate, which validates authority, governing conditions, admissibility, applies disposition, and emits receipts. The Freeze Gate is the only admissibility surface — there is no second path.
Consequence Boundary
Crossing consequence requires a scoped, unforgeable, freshness‑bound capability issued only through the Freeze Gate and validated at the consequential sink. If the capability is absent, the action did not occur.
Evidence Plane
The evidence plane is append‑only, non‑runtime‑writable, non‑admin‑writable, and externally attestable. It stores execution receipts, governance receipts, structural violations, and diagnostic events.
Causal Guarantees
Codex OS enforces a one‑way causal chain: authority → state change → admissibility → disposition → consequence capability → evidence. This chain is externally reconstructable and proves what was allowed, narrowed, refused, crossed consequence, or never occurred.
Codex OS + Founder OS
Founder OS is the operating system for founders. Codex OS is the substrate that proves it works. Together they create clarity, structure, evidence, control, and scale.