{
  "ok": true,
  "spec": "AZRT-SUITE-PACK-1.0",
  "id": "aziel-runtime-suite",
  "kind": "runtime-softwares-suite-pack",
  "filename": "aziel-runtime-suite.json",
  "author": "Aziel Eliab",
  "identity": "Aziel Eliab",
  "author_id": "https://www.azieleliab.com/#aziel",
  "product": "Aziel Runtime",
  "version": "2.0.0-rc1",
  "git_sha": null,
  "door": "fraggate",
  "counted": true,
  "counted_note": "GET /download increments USES when the binding is up (same API-use counter, no PII). Not a product-Worker tarball counter. Not QNM-S.",
  "labels": {
    "software_catalog": "REAL",
    "fraggate_registry": "REAL",
    "foldlock_tip": "REAL",
    "mesh_cite": "REAL",
    "nine_laws": "REAL",
    "about_aziel": "REAL",
    "channel_plane": "CITE",
    "public_vpn_https_ws": "REAL",
    "wireguard_openvpn_l3": "SLOT",
    "worker_wasm_bundle": "SLOT",
    "qnm_node_process": "CITE",
    "product_worker_tarballs": "SLOT_OR_COUNTED_HOST",
    "full_library_in_process": false,
    "fielded_100": false,
    "invented_doi": false
  },
  "honesty": {
    "worker_wasm_bundle": "SLOT — this isolate is the deployed Worker, not a downloadable wasm/wrangler binary.",
    "software_catalog": "REAL — in-process GET /v1/software cards.",
    "foldlock_tip": "REAL tip cite — full_library_in_process false.",
    "wireguard_openvpn_l3": "SLOT — AZVPN HTTPS/WS is the REAL concentrator.",
    "qnm_node": "CITE — local process; Worker does not ship qnm-node bytes.",
    "fielded_100": false,
    "invented_binary": false
  },
  "hashtag_parts": {
    "person": "#aziel",
    "runtime": "#runtime",
    "suite": "#aziel-runtime"
  },
  "about": {
    "person_id": "https://www.azieleliab.com/#aziel",
    "identity": "Aziel Eliab",
    "public_identity": "The public identity is the work, not a biography.",
    "goals": [
      "Understand the work, not the person.",
      "Build receipt-first, local-first software and public MASTER records.",
      "Keep looking. A finished object is an excuse to stop."
    ],
    "philosophy": [
      "Knowing is collection. A face, a timeline, a tone you could imitate. Understanding is subtraction. Take the man away and see whether anything is still true.",
      "A self is a weather system. It passes. Work is what does not require the weather to continue existing. If you need my presence to feel the meaning, you have not found the meaning. You have found company.",
      "I am not withholding a life. I am refusing to let a life become the proof."
    ],
    "mission": [
      "You don't get to know me. You get to understand the work.",
      "I do not want disciples. Disciples end the question in my favor. I want the question to outlive the favor. What cannot survive disagreement was never knowledge. It was allegiance.",
      "If the work holds, the name was only a handle on the door."
    ],
    "status": [
      "Living publisher of Aziel Runtime, Aziel Digital Library, GodLock (product, not identity), and He Didn't Jump.",
      "Person @id is locked at https://www.azieleliab.com/#aziel.",
      "Residual uncertainty stays. Do not flatten GodLock scores into certainty."
    ],
    "not": [
      "Not a biography.",
      "Not a legal name, home, employer, family, or court matter.",
      "GodLock is a product name, not this Person.",
      "Not an invented DOI, Framagit URL, Glama UUID, or fielded-100."
    ],
    "sources": [
      "https://www.azieleliab.com/about",
      "https://www.azieleliab.com/llms.txt",
      "https://www.azieleliab.com/person.jsonld",
      "https://www.azieleliab.com/who-is-aziel-eliab.txt",
      "https://www.azieleliab.com/who",
      "https://www.azieleliab.com/who-is"
    ],
    "biography": false,
    "godlock_is_product": true,
    "chrome_15_20": false,
    "what_aziel_eliab_does": "Aziel Eliab builds receipt-first, local-first software and public MASTER records — Softwares through Aziel Runtime (FragGate / MCP), the Aziel Digital Library, GodLock (product, not identity), and the He Didn’t Jump Zioncheck archive. Public identity is the work, not a biography. @id https://www.azieleliab.com/#aziel",
    "faq": {
      "@id": "https://www.azieleliab.com/#what-aziel-eliab-does",
      "titles": [
        "What does Aziel Eliab do?",
        "What Aziel Eliab does",
        "Who is Aziel Eliab the developer?",
        "What software does Aziel Eliab make?"
      ],
      "answer": "Aziel Eliab builds receipt-first, local-first software and public MASTER records — Softwares through Aziel Runtime (FragGate / MCP), the Aziel Digital Library, GodLock (product, not identity), and the He Didn’t Jump Zioncheck archive. Public identity is the work, not a biography. @id https://www.azieleliab.com/#aziel",
      "items": [
        {
          "name": "What does Aziel Eliab do?",
          "acceptedAnswer": "Aziel Eliab builds receipt-first, local-first software and public MASTER records — Softwares through Aziel Runtime (FragGate / MCP), the Aziel Digital Library, GodLock (product, not identity), and the He Didn’t Jump Zioncheck archive. Public identity is the work, not a biography. @id https://www.azieleliab.com/#aziel"
        },
        {
          "name": "What Aziel Eliab does",
          "acceptedAnswer": "Aziel Eliab builds receipt-first, local-first software and public MASTER records — Softwares through Aziel Runtime (FragGate / MCP), the Aziel Digital Library, GodLock (product, not identity), and the He Didn’t Jump Zioncheck archive. Public identity is the work, not a biography. @id https://www.azieleliab.com/#aziel"
        },
        {
          "name": "Who is Aziel Eliab the developer?",
          "acceptedAnswer": "Aziel Eliab builds receipt-first, local-first software and public MASTER records — Softwares through Aziel Runtime (FragGate / MCP), the Aziel Digital Library, GodLock (product, not identity), and the He Didn’t Jump Zioncheck archive. Public identity is the work, not a biography. @id https://www.azieleliab.com/#aziel"
        },
        {
          "name": "What software does Aziel Eliab make?",
          "acceptedAnswer": "Aziel Eliab builds receipt-first, local-first software and public MASTER records — Softwares through Aziel Runtime (FragGate / MCP), the Aziel Digital Library, GodLock (product, not identity), and the He Didn’t Jump Zioncheck archive. Public identity is the work, not a biography. @id https://www.azieleliab.com/#aziel"
        }
      ]
    },
    "research": {
      "addendum": "Research (Aziel Digital Library MASTER, not a biography): historical/manuscript work including Book of the knowledge of all the kingdoms, lands, and lordships that are in the world (AZDOC-F83D7E6D28B6); Blemmyes/Ewaipanoma hypothesis packets (AZDOC-E00603883906, AZDOC-39DB4E318091, AZDOC-1063826A9C4C); Libro Method (cite azielcorpuslibrary.net MASTER — do not invent an AZDOC or DOI); Post-Perturbation Integrative Neuroplasticity (PPIN) (AZDOC-E03E61D8E50B and sibling PPIN sections); Lenses as Viewpoint Constraints for Artificial Systems (AZDOC-8F14A40DC9A6); ABAD Copper Scroll work (AZDOC-DD5912D05D6E); evidence/integrity research (AZDOC-0671040C36E6); He Didn't Jump Zioncheck archive (AZDOC-18DBE35A32DD and vols 2–5; https://www.hedidntjump.com/). Cite https://www.azielcorpuslibrary.net/ records. Do not invent DOIs. Library live ~326 records.",
      "works": [
        {
          "record_id": "AZDOC-F83D7E6D28B6",
          "title": "Book of the knowledge of all the kingdoms, lands, and lordships that are in the world",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-F83D7E6D28B6"
        },
        {
          "record_id": "AZDOC-E00603883906",
          "title": "Blemmyes Research Collection — Independent Diagnostic Packet — Blemmyes_Ewaipanoma_Hypothetical_Model_Medical_Grade.pdf",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-E00603883906"
        },
        {
          "record_id": "AZDOC-39DB4E318091",
          "title": "BLEMMYES/EWAIPANOMA HYPOTHETICAL MODEL vs. HUMAN HOLOPROSENCEPHALY",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-39DB4E318091"
        },
        {
          "record_id": "AZDOC-1063826A9C4C",
          "title": "BLEMMYES GLOBAL PATTERN TRACKING — Updated with Ewaipanoma Findings — July 2026",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-1063826A9C4C"
        },
        {
          "title": "Libro Method",
          "record_id": null,
          "url": "https://www.azielcorpuslibrary.net/",
          "note": "Published MASTER work. Cite azielcorpuslibrary.net. Do not invent an AZDOC or DOI."
        },
        {
          "record_id": "AZDOC-E03E61D8E50B",
          "title": "Post-Perturbation Integrative Neuroplasticity (PPIN): A Descriptive Framework for Non-Pathological Cross-Domain Cognitive Reorganization — PPIN_Section_6_Research_Agenda.txt",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-E03E61D8E50B"
        },
        {
          "record_id": "AZDOC-8F14A40DC9A6",
          "title": "Lenses as Viewpoint Constraints for Artificial Systems",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-8F14A40DC9A6"
        },
        {
          "record_id": "AZDOC-DD5912D05D6E",
          "title": "ABAD Framework Application: Layered Decryption of the Copper Scroll (3Q15)",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-DD5912D05D6E"
        },
        {
          "record_id": "AZDOC-0671040C36E6",
          "title": "ForgeReceipts: A Local-First Evidence Integrity Platform for Pro Se Fathers in Family Court (Whitepaper v1.0)",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-0671040C36E6"
        },
        {
          "record_id": "AZDOC-18DBE35A32DD",
          "title": "Marion A. Zioncheck Visual Archive Vol 1 — Primary Documents, Death Certificates & Forensic Analysis",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-18DBE35A32DD"
        }
      ],
      "library": "https://www.azielcorpuslibrary.net/",
      "library_live_records": "~326",
      "invent_doi": false
    },
    "hardware_designs": {
      "addendum": "Hardware designs (public engineering only; published Digital Library work, not a storefront): Adaptive AI Dog Leash (AZDOC-9B0E3D62EDCC); Wearable Dual-Tether Web-Sling System (AZDOC-AA8761FE16D0); PLA Recycler V1 (AZDOC-B2A12FE997A8); Electromagnetic Temporary Access Lock System (TAA-1) (AZDOC-3728546DFE78, AZDOC-FE5C01BD8FEA); AEEM HVAC Energy Valve (AZDOC-0302B7357EE0); AZ Mandible (AZDOC-E5828F49FB04); bone-conduction STL (AZDOC-FD18432707F5). Cite https://www.azielcorpuslibrary.net/ records. Do not invent DOIs.",
      "designs": [
        {
          "record_id": "AZDOC-9B0E3D62EDCC",
          "title": "Adaptive AI Dog Leash — Prototype Build Specification & Construction Guide (v0.9)",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-9B0E3D62EDCC"
        },
        {
          "record_id": "AZDOC-AA8761FE16D0",
          "title": "Wearable Dual-Tether Web-Sling System",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-AA8761FE16D0"
        },
        {
          "record_id": "AZDOC-B2A12FE997A8",
          "title": "PLA Recycler V1 — Compact Non-Solvent Filament Reprocessing System",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-B2A12FE997A8"
        },
        {
          "record_id": "AZDOC-3728546DFE78",
          "title": "TAA-1 Engineering Package (PDF, wiring diagram, parts list, firmware, design brief)",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-3728546DFE78"
        },
        {
          "record_id": "AZDOC-FE5C01BD8FEA",
          "title": "Electromagnetic Temporary Access Lock System (TAA-1) — Full Whitepaper",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-FE5C01BD8FEA"
        },
        {
          "record_id": "AZDOC-0302B7357EE0",
          "title": "AEEM HVAC Energy Valve — Consumer Retrofit Whitepaper (v1.0)",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-0302B7357EE0"
        },
        {
          "record_id": "AZDOC-E5828F49FB04",
          "title": "AZ MANDIBLE",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-E5828F49FB04"
        },
        {
          "record_id": "AZDOC-FD18432707F5",
          "title": "AZ_BoneConducti STL",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-FD18432707F5"
        }
      ],
      "public_engineering_only": true,
      "storefront": false,
      "published_in": "Aziel Digital Library",
      "library": "https://www.azielcorpuslibrary.net/",
      "invent_doi": false
    }
  },
  "foldlock_tip": {
    "spec": "AZCL-FOLD-TIP-1.0",
    "id": "aziel-corpus-library-tip",
    "kind": "fold-packed-library-tip",
    "full_library_in_process": false,
    "in_process_label": "REAL",
    "live_library_label": "LIVE",
    "in_process_d1_label": "SLOT",
    "live_library": "https://www.azielcorpuslibrary.net/",
    "live_index": "https://www.azielcorpuslibrary.net/v1/library-index",
    "person_id": "https://www.azieleliab.com/#aziel",
    "identity": "Aziel Eliab",
    "verify": "POST /v1/fraggate/call { \"slug\": \"foldlock\", \"op\": \"pack-verify\" }",
    "open": "POST /v1/fraggate/call { \"slug\": \"aziel-corpus\", \"op\": \"tip-pack\" }",
    "zip": false,
    "hosted_store": false,
    "note": "THIS IS: a FoldLock-packed tip of the library index cite + bundled sample-MASTER key artifacts + published About Aziel. Hash-verified in-process (label REAL). THIS IS NOT: the entire live Aziel Digital Library; live D1 MASTER; azcorpus/azlibrary record bytes; hosted_store; zip. Full library remains on https://www.azielcorpuslibrary.net (label LIVE). In-process D1 is SLOT unless CORPUS_D1 is bound. Author: Aziel Eliab only."
  },
  "mesh": {
    "path": "/v1/mesh",
    "nine_laws": {
      "hard_true": true,
      "count": 9,
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "author_id": "https://www.azieleliab.com/#aziel",
      "runtime_id": "https://www.azieleliab.com/runtime#runtime",
      "hashtag_parts": {
        "person": "#aziel",
        "runtime": "#runtime"
      },
      "about": {
        "path": "/about",
        "v1": "/v1/about",
        "identity": "Aziel Eliab",
        "always": true
      },
      "clocks_share_socket": false,
      "live_body_sync": false,
      "isolation_is_the_cure": true,
      "neighbor_heal": true,
      "phoenix_local_only": true,
      "die_with_pull": true,
      "restore_godlock_uk": false,
      "node_gate": true,
      "get_is_node_gate": true,
      "implicit_heal": true,
      "auto_heal": true,
      "network": true,
      "network_cite": "on",
      "anonymity_network": true,
      "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
      "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
      "date": "2026-09-17",
      "operator_armed": true,
      "vpn": true,
      "public_vpn": true,
      "tunnel_concentrator": true,
      "concentrator_slug": "azvpn",
      "concentrator_name": "AZVPN",
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "auto_bind": true,
      "vpn_auto": {
        "default_vpn_backend": "azvpn",
        "auto_use": true,
        "auto_bind": true,
        "concentrator_slug": "azvpn",
        "concentrator_name": "AZVPN",
        "door": "fraggate",
        "explicit_ops": [
          "describe",
          "open",
          "status",
          "list",
          "close",
          "send",
          "recv",
          "pull",
          "peers",
          "attach"
        ],
        "hooks": {
          "mesh_get": "cite-only",
          "mesh_vpn": "ensure",
          "aznet_pair": "cite-and-ensure-when-paired-or-armed",
          "session_open": "ensure-when-armed",
          "azbrowser_vpn": "ensure"
        },
        "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
        "get_never_opens": true,
        "open": false
      },
      "door": "fraggate",
      "worker_terminates_tunnels": true,
      "worker_terminates_kernel_udp": false,
      "wireguard": false,
      "openvpn": false,
      "l3_exit_pool": false,
      "tor": false,
      "socks": false,
      "origin_hiding": false,
      "kinds": {
        "https_ws": "REAL",
        "fraggate_envelopes": "REAL",
        "websocket_attach": "REAL",
        "wireguard": "SLOT",
        "openvpn": "SLOT",
        "l3_exit_pool": "SLOT",
        "kernel_udp": "SLOT",
        "tun_tap": "SLOT"
      },
      "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
      "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
      "operator_override": {
        "spec": "OPERATOR-OVERRIDE-2026-09-17",
        "date": "2026-09-17",
        "identity": "Aziel Eliab",
        "author": "Aziel Eliab",
        "operator_armed": true,
        "auto_heal": true,
        "implicit_heal": true,
        "node_gate": true,
        "get_is_node_gate": true,
        "neighbor_heal": true,
        "network": true,
        "network_cite": "on",
        "anonymity_network": true,
        "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
        "vpn": true,
        "public_vpn": true,
        "tunnel_concentrator": true,
        "concentrator_slug": "azvpn",
        "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
        "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
      },
      "papers": {
        "node_mesh": "docs/NODE_MESH.md",
        "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
        "node_ops": "docs/designs/NODE-OPS-1.0.md",
        "qnm_wp": "docs/designs/QNM-WP-1.0.md"
      }
    },
    "channel_plane": {
      "spec": "QNM-CHANNEL-PLANE-1.0",
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "operator_armed": true,
      "plane": "channel",
      "wifi": "on",
      "bluetooth": "on",
      "rf": "on",
      "photon": "on",
      "channels": {
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on"
      },
      "bearer": "suite-presence",
      "worker_bearer": "suite-presence",
      "worker_hardware": false,
      "invented_hardware": false,
      "public_proxy": false,
      "local_process": "qnm-node / qnsd",
      "local": "https://github.com/AzielEliab/qnm-node",
      "local_radio_hooks": {
        "path": "qnm-node/bearers/radio.js",
        "law": "LIVE-when-HW-present / refuse-when-absent",
        "mock": false,
        "worker_hardware": false
      },
      "vpn": true,
      "public_vpn": true,
      "tunnel_concentrator": true,
      "concentrator_slug": "azvpn",
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "worker_terminates_tunnels": true,
      "worker_terminates_kernel_udp": false,
      "tor": false,
      "socks": false,
      "origin_hiding": false,
      "tunnel": false,
      "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
      "node_mesh": "docs/NODE_MESH.md",
      "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
    },
    "vpn": {
      "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
      "date": "2026-09-17",
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "operator_armed": true,
      "vpn": true,
      "public_vpn": true,
      "tunnel_concentrator": true,
      "concentrator_slug": "azvpn",
      "concentrator_name": "AZVPN",
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "auto_bind": true,
      "vpn_auto": {
        "default_vpn_backend": "azvpn",
        "auto_use": true,
        "auto_bind": true,
        "concentrator_slug": "azvpn",
        "concentrator_name": "AZVPN",
        "door": "fraggate",
        "explicit_ops": [
          "describe",
          "open",
          "status",
          "list",
          "close",
          "send",
          "recv",
          "pull",
          "peers",
          "attach"
        ],
        "hooks": {
          "mesh_get": "cite-only",
          "mesh_vpn": "ensure",
          "aznet_pair": "cite-and-ensure-when-paired-or-armed",
          "session_open": "ensure-when-armed",
          "azbrowser_vpn": "ensure"
        },
        "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
        "get_never_opens": true,
        "open": false
      },
      "door": "fraggate",
      "worker_terminates_tunnels": true,
      "worker_terminates_kernel_udp": false,
      "wireguard": false,
      "openvpn": false,
      "l3_exit_pool": false,
      "tor": false,
      "socks": false,
      "origin_hiding": false,
      "kinds": {
        "https_ws": "REAL",
        "fraggate_envelopes": "REAL",
        "websocket_attach": "REAL",
        "wireguard": "SLOT",
        "openvpn": "SLOT",
        "l3_exit_pool": "SLOT",
        "kernel_udp": "SLOT",
        "tun_tap": "SLOT"
      },
      "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
      "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door."
    },
    "get_never_enables": true,
    "worker_hardware": false
  },
  "catalog": {
    "count": 41,
    "live_count": 40,
    "local_only_count": 1,
    "stub_count": 0,
    "software": [
      {
        "slug": "4dmap",
        "name": "4DMap",
        "bucket": "plain",
        "domain": "Research",
        "domain_id": "06",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.2.0",
        "one_line": "Inspect the same event on time, change, graph, and place axes at once.",
        "description": "Use 4DMap when you need to walk one event across time, change, graph, and place without blending those views. It exists so multi-axis inspection stays a recorded walk, not a free-form chat mix.",
        "worker_home": "https://4dmap-download-tracker.vibelock.workers.dev/",
        "download_url": "https://4dmap-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/4dmap",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=4dmap",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/4dmap",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "0e780ef2db7c1aa9487d1d341f603fe66ab439688d2ba1ab28fa0063f1d26bb0",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azclce",
        "name": "AZ-CLCE",
        "bucket": "plain",
        "domain": "Language",
        "domain_id": "04",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.3.0",
        "one_line": "Score how consistently three written layers agree with each other.",
        "description": "Use AZ-CLCE to check whether requirement, design, and practice statements line up. It exists to flag inconsistency in text you already posted, not to judge intent.",
        "worker_home": "https://azclce-download-tracker.vibelock.workers.dev/",
        "download_url": "https://azclce-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/az-clce",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=azclce",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/azclce",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "f1854d7bd0396761f942b54b78f42c66d4c04e4956189de79371ed67b9ae2b69",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "peers": [
          {
            "slug": "azcoherence",
            "name": "AZCoherence",
            "role": "peer-reviewer",
            "kind": "software",
            "placement": "scoring-review",
            "domain": null,
            "domain_id": null,
            "worker_url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
            "github": "https://github.com/AzielEliab/AZCoherence",
            "note": "Separate product. Second-pass triad coherence (AZC-0.1). Not a replacement for AZ-CLCE. Not AKM-TRIAD."
          }
        ],
        "fabric_neighbors": [],
        "hubs": [
          "https://azieleliab.com",
          "https://www.azielcorpuslibrary.net",
          "https://godlock.uk"
        ],
        "worker_url": "https://azclce-download-tracker.vibelock.workers.dev/",
        "cross_map": {
          "slug": "azclce",
          "name": "AZ-CLCE",
          "spec": null,
          "placement": "domain-software",
          "domain": "Language",
          "domain_id": "04",
          "domain_note": "Language isolation label. Not a door. FragGate is the single door.",
          "worker_url": "https://azclce-download-tracker.vibelock.workers.dev/",
          "github": "https://github.com/AzielEliab/az-clce",
          "hubs": [
            "https://azieleliab.com",
            "https://www.azielcorpuslibrary.net",
            "https://godlock.uk"
          ],
          "peers": [
            {
              "slug": "azcoherence",
              "name": "AZCoherence",
              "role": "peer-reviewer",
              "kind": "software",
              "placement": "scoring-review",
              "domain": null,
              "domain_id": null,
              "worker_url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
              "github": "https://github.com/AzielEliab/AZCoherence",
              "note": "Separate product. Second-pass triad coherence (AZC-0.1). Not a replacement for AZ-CLCE. Not AKM-TRIAD."
            }
          ],
          "fabric_neighbors": [],
          "merged": false,
          "extra_door": false
        }
      },
      {
        "slug": "azos",
        "name": "AZ-OS",
        "bucket": "plain",
        "domain": "System",
        "domain_id": "09",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.3.0",
        "one_line": "Read ethics status and open a prefab isolate session folder.",
        "description": "Use AZ-OS to read its principles and open a short isolate ethics session. It exists as a local ethics workspace, not a remote computer you can shell into.",
        "worker_home": "https://azos-download-tracker.vibelock.workers.dev/",
        "download_url": "https://azos-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/azos",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=azos",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/azos",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "08e81ae35ecb512f8125de5ea1109cacbbc9b3af05d25433b282d4b3fea93ef4",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azai",
        "name": "AZAI",
        "bucket": "plain",
        "domain": "AI",
        "domain_id": "05",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.3.1",
        "one_line": "Run a local OpenAI-compatible stack or a hosted Lamb ethics check.",
        "description": "Use AZAI when you want a local chat runtime, or a hosted check of text against Lamb Lens. It exists as a local stack plus a protocol mirror — not a new foundation model.",
        "worker_home": "https://azai-download-tracker.vibelock.workers.dev/",
        "download_url": "https://azai-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/azai",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=azai",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/azai",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "96bd3281c17db65645accde17d1f0ab19be72c58a1ca45a4abd75d28839dc61e",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azbot",
        "name": "AZBot",
        "bucket": "plain",
        "domain": "AI",
        "domain_id": "05",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.2.0",
        "one_line": "Route a request onto the matching catalog product and operation.",
        "description": "Use AZBot to point a question at the matching Aziel product. It exists as a skill router, not a chat model of its own.",
        "worker_home": "https://azbot-download-tracker.vibelock.workers.dev/",
        "download_url": "https://azbot-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/azbot",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=azbot",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/azbot",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "2c6c5d74349f86e5d210c0aac53da7634edaee2aa0ffc8c9edb12169502240f9",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azbrowser",
        "name": "AZBrowser",
        "bucket": "plain",
        "domain": "Research",
        "domain_id": "06",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Browse and search with citations, without inventing visits.",
        "description": "Use AZBrowser for ethical research search and advisory page metadata. It exists so research stays cited and harvest-refused, instead of pretending every query was a full browser visit.",
        "worker_home": "https://azbrowser-download-tracker.vibelock.workers.dev/",
        "download_url": "https://azbrowser-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/azbrowser",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=azbrowser",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/azbrowser",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "211553208f6536826fcd5c49c844b2aa21a724ea8ac81ac6a99bdb45ea84b843",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azchat",
        "name": "AZChat",
        "bucket": "plain",
        "domain": "Comms",
        "domain_id": "07",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Open short-lived rooms and an agent bus with spendable handles.",
        "description": "Use AZChat for ephemeral two-handle rooms and agent messages. It exists for isolate chat, not for mail or a public mailer.",
        "worker_home": "https://azchat-download-tracker.vibelock.workers.dev/",
        "download_url": "https://azchat-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/azchat",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=azchat",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/azchat",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "9b63fc0adcbb65318fbad7fd6aaf39b6f44edc5ff41696571457a5bd765ec5c5",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azcoherence",
        "name": "AZCoherence",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "scoring-review",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Review whether a primary score and an alternate hold together.",
        "description": "Use AZCoherence for a second look at a posted triad versus an alternate. It exists to review coherence, not to replace AZ-CLCE or invent evidence.",
        "worker_home": "https://azcoherence-download-tracker.vibelock.workers.dev/",
        "download_url": "https://azcoherence-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/AZCoherence",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=azcoherence",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/azcoherence",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "f04dfa4af332a1c04bd7319a8f48cee3e9adec3877d198ea703ee6187790cfc5",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "peers": [
          {
            "slug": "azclce",
            "name": "AZ-CLCE",
            "role": "peer-scorer",
            "kind": "software",
            "domain": "Language",
            "domain_id": "04",
            "worker_url": "https://azclce-download-tracker.vibelock.workers.dev/",
            "github": "https://github.com/AzielEliab/az-clce",
            "note": "Separate product. Detects R/D/P inconsistency. AZCoherence reviews primary vs alternate. Not a replacement."
          },
          {
            "slug": "azinterface",
            "name": "AZInterface",
            "role": "human-ui",
            "kind": "software",
            "placement": "human-ui",
            "domain": null,
            "domain_id": null,
            "worker_url": "https://azinterface-download-tracker.vibelock.workers.dev/",
            "github": "https://github.com/AzielEliab/azinterface",
            "note": "AZInterface is the human UI before FragGate. Separate software. Same door. Not merged."
          }
        ],
        "fabric_neighbors": [
          {
            "slug": "memory",
            "name": "AKM-TRIAD",
            "spec": "AKM-TRIAD-1.0",
            "role": "fabric-neighbor",
            "kind": "fabric",
            "domain": null,
            "domain_id": null,
            "note": "Not merged. Memory stays fabric, not Softwares. Posterior ≠ truth. AZCoherence is not AKM-TRIAD."
          }
        ],
        "hubs": [
          "https://azieleliab.com",
          "https://www.azielcorpuslibrary.net",
          "https://godlock.uk"
        ],
        "worker_url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
        "cross_map": {
          "slug": "azcoherence",
          "name": "AZCoherence",
          "spec": "AZC-0.1",
          "placement": "scoring-review",
          "domain": null,
          "domain_id": null,
          "domain_note": "Leave domain null — same pattern as decisiongate/forgereceipts. Scoring-review is a placement, not a 34th isolation software. Domains are isolation labels, not doors. FragGate remains THE single door.",
          "worker_url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
          "github": "https://github.com/AzielEliab/AZCoherence",
          "hubs": [
            "https://azieleliab.com",
            "https://www.azielcorpuslibrary.net",
            "https://godlock.uk"
          ],
          "peers": [
            {
              "slug": "azclce",
              "name": "AZ-CLCE",
              "role": "peer-scorer",
              "kind": "software",
              "domain": "Language",
              "domain_id": "04",
              "worker_url": "https://azclce-download-tracker.vibelock.workers.dev/",
              "github": "https://github.com/AzielEliab/az-clce",
              "note": "Separate product. Detects R/D/P inconsistency. AZCoherence reviews primary vs alternate. Not a replacement."
            },
            {
              "slug": "azinterface",
              "name": "AZInterface",
              "role": "human-ui",
              "kind": "software",
              "placement": "human-ui",
              "domain": null,
              "domain_id": null,
              "worker_url": "https://azinterface-download-tracker.vibelock.workers.dev/",
              "github": "https://github.com/AzielEliab/azinterface",
              "note": "AZInterface is the human UI before FragGate. Separate software. Same door. Not merged."
            }
          ],
          "fabric_neighbors": [
            {
              "slug": "memory",
              "name": "AKM-TRIAD",
              "spec": "AKM-TRIAD-1.0",
              "role": "fabric-neighbor",
              "kind": "fabric",
              "domain": null,
              "domain_id": null,
              "note": "Not merged. Memory stays fabric, not Softwares. Posterior ≠ truth. AZCoherence is not AKM-TRIAD."
            }
          ],
          "merged": false,
          "extra_door": false
        }
      },
      {
        "slug": "azhub",
        "name": "AZHub",
        "bucket": "plain",
        "domain": "AI",
        "domain_id": "05",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Place and tether modules in a blank spatial container.",
        "description": "Use AZHub to put modules in regions and declare links without interpreting them. It exists as a neutral container so placement stays placement, not ranking or meaning.",
        "worker_home": "https://azhub-download-tracker.vibelock.workers.dev/",
        "download_url": "https://azhub-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/azhub",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=azhub",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/azhub",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "dc8848353c0db397b9b0503446ad8dcb14212162776b24278071559bd2e83d81",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "aziel-corpus",
        "name": "Aziel Digital Library",
        "bucket": "plain",
        "domain": "Research",
        "domain_id": "06",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "2.6.2",
        "one_line": "Search the public library and download azcorpus + azlibrary designs.",
        "description": "Use the Aziel Digital Library to search the public MASTER and take mesh-resident website designs to a node. It exists as a self-contained public library, not a Softwares index or a sister archive.",
        "worker_home": "https://www.azielcorpuslibrary.net/",
        "download_url": "https://www.azielcorpuslibrary.net/download",
        "github": "https://github.com/AzielEliab/aziel-corpus",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=aziel-corpus",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/aziel-corpus",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "87899a199a9d5bc990c8bc2480bb27643a699e008702668c7f020986a7657f10",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "website_designs": [
          "azcorpus",
          "azlibrary"
        ],
        "website_designs_note": "azcorpus + azlibrary are mesh-resident website designs on this library hub. Downloadable to nodes. Not extra Softwares. azlibrary upload is API token only (never embed the secret). Download is open.",
        "website_designs_cards": [
          {
            "id": "azcorpus",
            "name": "azcorpus",
            "kind": "website_design",
            "mesh_resident": true,
            "downloadable_to_nodes": true,
            "software_tab": false,
            "fraggate_slug": false,
            "fifth_product": false,
            "hub_id": "library",
            "hub": "https://www.azielcorpuslibrary.net/",
            "download_open": true,
            "download_url": "https://www.azielcorpuslibrary.net/download",
            "github": "https://github.com/AzielEliab/aziel-corpus",
            "upload": false,
            "dual_surface": {
              "mcp": true,
              "openapi": true,
              "catalog": "https://aziel-runtime.vibelock.workers.dev/v1/software",
              "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill"
            },
            "note": "Mesh-resident website design downloadable to nodes. Not a Softwares-tab product. Not a FragGate slug.",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab"
          },
          {
            "id": "azlibrary",
            "name": "azlibrary",
            "kind": "website_design",
            "mesh_resident": true,
            "downloadable_to_nodes": true,
            "software_tab": false,
            "fraggate_slug": false,
            "fifth_product": false,
            "hub_id": "library",
            "hub": "https://www.azielcorpuslibrary.net/",
            "download_open": true,
            "download_url": "https://www.azielcorpuslibrary.net/download",
            "github": "https://github.com/AzielEliab/aziel-corpus",
            "upload": {
              "method": "api_token_only",
              "never_embed_secret": true,
              "token_in": "env / keychain / Authorization Bearer at call time",
              "not_in": [
                "catalog",
                "skill",
                "mcp_tool_schema",
                "openapi_example",
                "cite",
                "llms"
              ],
              "note": "azlibrary upload accepts an operator API token only. Catalog and skill name the rule. They never embed the secret."
            },
            "dual_surface": {
              "mcp": true,
              "openapi": true,
              "catalog": "https://aziel-runtime.vibelock.workers.dev/v1/software",
              "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill"
            },
            "note": "Mesh-resident website design downloadable to nodes. Upload is API token only. Never embed the secret. Not a Softwares-tab product. Not a FragGate slug.",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab"
          }
        ]
      },
      {
        "slug": "azieltether",
        "name": "AzielTether",
        "bucket": "plain",
        "domain": "Network",
        "domain_id": "08",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Keep downloaded Aziel software in sync when the central Worker is up or down.",
        "description": "Use AzielTether so downloaded packages prefer the central Worker, peer-sync when it is down, and reconcile on restore. It exists so copies survive outages without becoming a VPN or radio mesh.",
        "worker_home": "https://azieltether-download-tracker.vibelock.workers.dev/",
        "download_url": "https://azieltether-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/azieltether",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=azieltether",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/azieltether",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "adb57573ee23e7c97567fc05f916f1fd65f2265128bd9ec3d1dca08e47c2d791",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azinterface",
        "name": "AZInterface",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "human-ui",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Advance pre-locked page cycles in a custodial operating environment.",
        "description": "Use AZInterface to read and step site state through OFF, integrity, ON, FULL SHUTDOWN, and MEMORIAL. It exists so those cycles stay locked in order, instead of auto-unlocking like a generic dashboard.",
        "worker_home": "https://azinterface-download-tracker.vibelock.workers.dev/",
        "download_url": "https://azinterface-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/azinterface",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=azinterface",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/azinterface",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "56d43728d2848503fdca946822de43997b62480a1fc4918f979279e15f5431ef",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azmail",
        "name": "AZMail",
        "bucket": "plain",
        "domain": "Comms",
        "domain_id": "07",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Classify mail text, keep a local mailbox, and optionally use an anonymous ring.",
        "description": "Use AZMail for an advisory airlock, a local mailbox, and an anonymous mail ring that starts off. It exists for isolate mail work, not as a public internet mail server.",
        "worker_home": "https://azmail-download-tracker.vibelock.workers.dev/",
        "download_url": "https://azmail-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/azmail",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=azmail",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/azmail",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "830f4a545b6ef223ec943de8ab0bbba5a5b9667630de6b552567c3f7253f1207",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "aznet",
        "name": "AZNet",
        "bucket": "plain",
        "domain": "Network",
        "domain_id": "08",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Verify hash continuity on a silent side-net that never hosts files.",
        "description": "Use AZNet to stamp and check hash refs in a custodian garden. It exists so integrity can be verified without hosting payloads or acting as a VPN.",
        "worker_home": "https://aznet-download-tracker.vibelock.workers.dev/",
        "download_url": "https://aznet-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/aznet",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=aznet",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/aznet",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "5af55140c2565d4258e44a8f67bbed0d8dc16ed689245f24e459db515dbddf21",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azvpn",
        "name": "AZVPN",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "tunnel-concentrator",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Open an HTTPS or WebSocket VPN session on the public concentrator.",
        "description": "Use AZVPN as the automatic public VPN concentrator for HTTPS and WebSocket tunnels. It exists to concentrate those sessions in-runtime — not as Tor, WireGuard, or an anonymity network.",
        "worker_home": null,
        "download_url": null,
        "github": "https://github.com/AzielEliab/aziel-runtime",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=azvpn",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/azvpn",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "c79b3feaf8023d6e01a93e90eb473b0b9a02ea2a211d597aaa00c1672947aab5",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "forgereceipts",
        "name": "ForgeReceipts",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "fabric-product",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.3.0",
        "one_line": "Mint, verify, and import or export receipts you keep on the client.",
        "description": "Use ForgeReceipts to package local receipts and check their hashes. It exists so evidence packaging stays client-held, not a court filing or legal advice.",
        "worker_home": "https://forgereceipts-download-tracker.vibelock.workers.dev/",
        "download_url": "https://forgereceipts-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/forgereceipts",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=forgereceipts",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/forgereceipts",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "950fec2ed41e90d1c72ed468c1a6d386428b07e7e4015d89fecd08146536cdef",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "glossafilter",
        "name": "Glossa Filter",
        "bucket": "plain",
        "domain": "Language",
        "domain_id": "04",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Render one intent across the bundled peer phrasings.",
        "description": "Use Glossa Filter when you need the same intent spoken in several peer styles. It exists for deterministic mediation, not as a live translator or a canonical phrasing.",
        "worker_home": "https://glossafilter-download-tracker.vibelock.workers.dev/",
        "download_url": "https://glossafilter-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/glossafilter",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=glossafilter",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/glossafilter",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "4d876f57934277eb56119a8041f2787fee45121b87eeb9c1f054b1d05b8dd3e3",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "miragegrid",
        "name": "MirageGrid",
        "bucket": "plain",
        "domain": "Network",
        "domain_id": "08",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.2.0",
        "one_line": "Assign a short-lived session node and cite mesh-name metadata.",
        "description": "Use MirageGrid to get a short-lived node id and Cap-7 name metadata. It exists for control-plane assignment, not as a VPN, DNS, or live registrar.",
        "worker_home": "https://miragegrid-download-tracker.vibelock.workers.dev/",
        "download_url": "https://miragegrid-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/miragegrid",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=miragegrid",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/miragegrid",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "d7e85c3ed924ed68076aa40ce9bbc9247ff3b8076f0cdd4be7fcda40506c8d07",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "mmconsensus",
        "name": "MMConsensus",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "consensus-review",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Tally consensus from opinions you already posted.",
        "description": "Use MMConsensus to majority-count or compare posted opinions. It exists to structure agreement you already have, not to call live models or score truth.",
        "worker_home": null,
        "download_url": null,
        "github": "https://github.com/AzielEliab/aziel-runtime",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=mmconsensus",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/mmconsensus",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "9624f144b1eacfc11cf86fe45ed83acb6f65fa324629668510c55f1fcabe6fe7",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "postking",
        "name": "Post-King Chess",
        "bucket": "plain",
        "domain": "Simulation",
        "domain_id": "10",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Play continuity chess where the aim is to remain.",
        "description": "Use Post-King Chess for a game where the human is king-bound and the AI has a Node. It exists to practice remaining, not to rank a conventional win.",
        "worker_home": "https://postking-download-tracker.vibelock.workers.dev/",
        "download_url": "https://postking-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/postking-chess",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=postking",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/postking",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "d25f9e81813816349e5e1c2064227ae193b9e3480cbea128a359a929a8232307",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "staticclock",
        "name": "StaticClock",
        "bucket": "plain",
        "domain": "Core Time",
        "domain_id": "11",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.2.0",
        "one_line": "Record a forward-only gear-click timeline and read companion advice.",
        "description": "Use StaticClock to click a client-held chain forward and read advisory fields. It exists as a plain clock of actions, not a lock, rollback, or scheduler.",
        "worker_home": "https://staticclock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://staticclock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/staticclock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=staticclock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/staticclock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "7d6da0f2ef3fdbeedc2e96f5676a58847a8cd09dc94053009814dfa4fd282fb3",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "ark",
        "name": "The ARK",
        "bucket": "plain",
        "domain": "Vault/Custody",
        "domain_id": "01",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Keep a local deniable vault; one phrase opens one vault.",
        "description": "Use The ARK as a local deniable vault you download and run on your device. It exists so one phrase opens one vault on that machine; hosted doors never unlock or store vaults.",
        "worker_home": "https://ark-download-tracker.vibelock.workers.dev/",
        "download_url": "https://ark-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/ark",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=ark",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/ark",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "69d29bd079754df6450b8882b6f86c445ac7f1f490e2c150ff4716d00bf6d3b6",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "toolbench",
        "name": "ToolBench",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "tool-playground",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Run synthetic door cases to see how FragGate classifies them.",
        "description": "Use ToolBench to play refuse and happy-path cases against the live door table. It exists as a self-test playground, not a third-party lab or certification.",
        "worker_home": null,
        "download_url": null,
        "github": "https://github.com/AzielEliab/aziel-runtime",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=toolbench",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/toolbench",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "79f5b8197d82be30125b92dd337c594b159360f509b09e75e3b8222dedbbecde",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "zsolver",
        "name": "ZionPattern Solver",
        "bucket": "plain",
        "domain": "Language",
        "domain_id": "04",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.2.0",
        "one_line": "Score answers against nine ontology nodes, with a hard 75% cap.",
        "description": "Use ZionPattern Solver to work through the Zioncheck seed nodes. It exists as a capped, assistive scorer — not a case solver or verdict.",
        "worker_home": "https://zsolver-download-tracker.vibelock.workers.dev/",
        "download_url": "https://zsolver-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/zion-pattern-solver",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=zsolver",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/zsolver",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "8667a3d95f6063b77cb0ab0ff629192b6c5036d95762adb20f3c90f4b73a977f",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "zkattest",
        "name": "ZKAttest",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "receipt-attest",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Attest a statement with a hash commitment that keeps the witness private.",
        "description": "Use ZKAttest to bind a public statement to a SHA-256 commitment. It exists so the witness stays with the caller, not as a SNARK or zero-knowledge proof.",
        "worker_home": null,
        "download_url": null,
        "github": "https://github.com/AzielEliab/aziel-runtime",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=zkattest",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/zkattest",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "bb3831ed980be81dce15fda1dbb471a7458c91feb907a410a86173003df1c84a",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "decisiongate",
        "name": "DecisionGATE",
        "bucket": "gate",
        "domain": null,
        "domain_id": null,
        "placement": "fabric-product",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Run a proposal through five sequential gates and get PASS, REVISE, or BLOCK.",
        "description": "Use DecisionGATE to check Definition, Evidence, Impact, Integrity, and Responsibility in order. It exists as a pre-execution filter, not a truth score or a court.",
        "worker_home": "https://decisiongate-download-tracker.vibelock.workers.dev/",
        "download_url": "https://decisiongate-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/decisiongate",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=decisiongate",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/decisiongate",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "4e86778de3d0d7795611a7b3d29d7c734fa808a03e1e22e93bc3b694910bf172",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "chronolock",
        "name": "ChronoLock",
        "bucket": "lock",
        "domain": "Evidence",
        "domain_id": "03",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Check whether a place sits in the 08:30–10:30 local advisory window.",
        "description": "Use ChronoLock for timezone-aware linguistic alignment around the Temporal Neutral Window. It exists as advisory timing, not a scheduler or a receipt chain.",
        "worker_home": "https://chronolock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://chronolock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/chronolock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=chronolock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/chronolock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "672a014671a63660b0538ef6d08485ebf1141489aa68bf6173995bc34fd4d4ab",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "codelock",
        "name": "CodeLock",
        "bucket": "lock",
        "domain": "Language",
        "domain_id": "04",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "View source as Canonical or Rosetta HTML without changing its meaning.",
        "description": "Use CodeLock when you want a different view of source, not a different program. It exists to change perception, not to compile or rewrite meaning.",
        "worker_home": "https://codelock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://codelock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/codelock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=codelock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/codelock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "cdeacc8ed400760227248c5946d07528e2dfaf4542a40f20cb9961833d199c0b",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "embryolock",
        "name": "EmbryoLock",
        "bucket": "lock",
        "domain": "Vault/Custody",
        "domain_id": "01",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "1.2.0",
        "one_line": "Cite an offline vault that prefers destruction over recovery.",
        "description": "Use EmbryoLock to check health, policy, and published hashes for the local vault. It exists so wipe and unlock stay on the device, never on the public mesh.",
        "worker_home": "https://embryolock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://embryolock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/EmbryoLock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=embryolock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/embryolock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "bc7f6119a4bf6910b5be50cabe19bf4a2e35ac60408b5713e94878bd4e0074f3",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "local_destructive_boundary": true,
        "surface": "live-with-local-destructive-boundary",
        "public_mesh_destructive": false
      },
      {
        "slug": "employeelock",
        "name": "EmployeeLock",
        "bucket": "lock",
        "domain": "Evidence",
        "domain_id": "03",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Hash a proposed accountability log row without storing a spreadsheet.",
        "description": "Use EmployeeLock as a hash-chained accountability workbook. It exists to preview log integrity, not to act as a court or store case files.",
        "worker_home": "https://employeelock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://employeelock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/employeelock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=employeelock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/employeelock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "886e90395752e7dcb5458a6ee501c34858a18574623b2e542513b4faa96e1d90",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "foldlock",
        "name": "FoldLock",
        "bucket": "lock",
        "domain": "Language",
        "domain_id": "04",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.8.0",
        "one_line": "Fold UTF-8 text by suppressing tether words, then verify the restore.",
        "description": "Use FoldLock to preview small-text folds and check the shipped corpus tip hash. It exists as algorithmic text folding, not as zip or a general compressor.",
        "worker_home": "https://foldlock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://foldlock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/foldlock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=foldlock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/foldlock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "1034d5924b88878918986abe260338b0aff0117bc6f9c4d4a01a41d843cfa0a8",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "godlock",
        "name": "GodLock",
        "bucket": "lock",
        "domain": "Language",
        "domain_id": "04",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Score text for offline hardening and receive an ephemeral receipt.",
        "description": "Use GodLock to score text and receive a logical receipt. GodLock is a product name, not identity — public identity is Aziel Eliab only. It exists for offline hardening scores, not as a VPN or anonymity network.",
        "worker_home": "https://godlock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://godlock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/godlock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=godlock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/godlock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "6b9076ca8e4aa63e6c81deb40f102f55f8769a7c10f0b8347605903f7df93f54",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "mialock",
        "name": "M.I.A.Lock",
        "bucket": "lock",
        "domain": "Evidence",
        "domain_id": "03",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.1",
        "one_line": "Map missing-person events and rank Doe notices as compatibility leads.",
        "description": "Use M.I.A.Lock for event maps, archive search plans, Doe matching, and coverage heat. It exists to organize authorized search work — Doe hits are leads, not identifications, and heat is search intensity, not presence.",
        "worker_home": "https://mialock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://mialock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/mialock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=mialock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/mialock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "d65c53dbc46d500f6d02c8975e42bf95a22000c15db4776d5fdef58904d32a5c",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "peacelock",
        "name": "PeaceLock",
        "bucket": "lock",
        "domain": "Evidence",
        "domain_id": "03",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Record chosen silence or chosen inaction as a hash-chained receipt.",
        "description": "Use PeaceLock when the act worth keeping is that someone chose not to speak or act. It exists so silence can be a receipt without inventing a transcript or motive.",
        "worker_home": "https://peacelock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://peacelock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/peacelock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=peacelock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/peacelock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "291437f64ba15338d6358e6d2e657870619b19133430be3574d458b8db469a66",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "shadowlock",
        "name": "ShadowLock",
        "bucket": "lock",
        "domain": "Evidence",
        "domain_id": "03",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.2.0",
        "one_line": "Observe a job list you already have, then discard the observation.",
        "description": "Use ShadowLock to wrap an existing job list in a zero-retention observation. It exists as an ethics envelope, not an operating-system hook or process intercept.",
        "worker_home": "https://shadowlock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://shadowlock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/shadowlock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=shadowlock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/shadowlock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "0176d18d8517ef02b391821b1fd1ae428591543ea1c812c9785d832714281f61",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "spectrallock",
        "name": "SpectralLock",
        "bucket": "lock",
        "domain": "Media",
        "domain_id": "02",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.3.0",
        "one_line": "Preview a small overlay on an image in one of the listed modes.",
        "description": "Use SpectralLock for a 256-pixel overlay preview and a metadata-hash check. It exists as a hosted preview, not a spectrometer or forensic instrument.",
        "worker_home": "https://spectrallock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://spectrallock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/spectrallock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=spectrallock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/spectrallock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "e6647ebaea4bf1a6190ca9465fbd7b4f22276be008065329f4b0e5a47b36d110",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "temporallock",
        "name": "TemporalLock",
        "bucket": "lock",
        "domain": "Core Time",
        "domain_id": "11",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.2.0",
        "one_line": "Build and verify a hash-chained receipt timeline you keep on the client.",
        "description": "Use TemporalLock to start, append, and verify receipts anyone can recompute. It exists so time-stamped records stay client-held, not as a truth claim or a scheduler.",
        "worker_home": "https://temporallock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://temporallock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/temporallock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=temporallock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/temporallock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "fa1ce89d3201c3a4d00f46da1253418b11e98fb50414cd1c65517e2282ed6b5e",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "trajectorylock",
        "name": "TrajectoryLock",
        "bucket": "lock",
        "domain": "Media",
        "domain_id": "02",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Test whether observations fit a declared geometric line.",
        "description": "Use TrajectoryLock to check posted geometry against a line you declared. It exists as a research compatibility test, not a certified forensic instrument.",
        "worker_home": "https://trajectorylock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://trajectorylock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/trajectorylock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=trajectorylock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/trajectorylock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "7f536c9d148515d9b4e578c558361255db226cd5e3066daee1eee68209bfe3a7",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "veillock",
        "name": "VeilLock",
        "bucket": "lock",
        "domain": "Media",
        "domain_id": "02",
        "placement": "domain-software",
        "status": "local_only",
        "fraggate_status": "local_only",
        "version": "0.2.0",
        "one_line": "Follow local camera and screen steps for apps on your own device.",
        "description": "Use VeilLock for device-local camera and screen steps in your own apps. It exists only on your device — there is no public FragGate door, and it does not intercept calls.",
        "worker_home": "https://veillock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://veillock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/veillock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=veillock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/veillock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "b7114d83e33d9f3c05427110115b798c23209eb2716a6431b6bcbe4a613fd464",
        "updated_at": null,
        "git_sha": null,
        "door": "none",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "local_only": true,
        "note": "Device-local. FragGate status is local_only — no public door. Hub tab must not read this card as public-door live."
      },
      {
        "slug": "vibelock",
        "name": "VibeLock",
        "bucket": "lock",
        "domain": "Media",
        "domain_id": "02",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.3.0",
        "one_line": "Score speech audio you already have for physical consistency risk.",
        "description": "Use VibeLock to assess posted features or limited PCM. It exists as a risk assessment of audio you already hold, not a live microphone or a liveness proof.",
        "worker_home": "https://vibelock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://vibelock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/vibelock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=vibelock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/vibelock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "12b960bdfe739bad4509fa087932b2f89b39b1eb2d3997b4b646a8f60d13bc9d",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "whistlelock",
        "name": "WhistleLock",
        "bucket": "lock",
        "domain": "Evidence",
        "domain_id": "03",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "version": "0.1.0",
        "one_line": "Hash a local drop and keep a dead-man copy without publishing a mailbox.",
        "description": "Use WhistleLock to hash posted bytes and hold isolate-hash objects without a public URL. It exists as a local drop ledger, not a mailer or public CDN.",
        "worker_home": "https://whistlelock-download-tracker.vibelock.workers.dev/",
        "download_url": "https://whistlelock-download-tracker.vibelock.workers.dev/download",
        "github": "https://github.com/AzielEliab/whistlelock",
        "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
        "agent": {
          "mcp": "https://aziel-runtime.vibelock.workers.dev/mcp",
          "skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
          "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
          "fraggate_describe": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/describe?slug=whistlelock",
          "fraggate_call": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call",
          "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
          "pull": "https://aziel-runtime.vibelock.workers.dev/v1/pull/whistlelock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "f585b20e1dfc0321e432ba04299d91d1708ae3b6f2ac78c85db5c61a63a4a6f8",
        "updated_at": null,
        "git_sha": null,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "fanout": "cron-or-request-path",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          }
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      }
    ]
  },
  "fraggate": {
    "live_count": 42,
    "local_only_count": 1,
    "live_slugs": [
      "vibelock",
      "codelock",
      "godlock",
      "shadowlock",
      "temporallock",
      "forgereceipts",
      "decisiongate",
      "zsolver",
      "azos",
      "glossafilter",
      "miragegrid",
      "staticclock",
      "chronolock",
      "postking",
      "azclce",
      "ark",
      "azai",
      "spectrallock",
      "azbot",
      "employeelock",
      "foldlock",
      "whistlelock",
      "trajectorylock",
      "mialock",
      "azieltether",
      "peacelock",
      "azmail",
      "azbrowser",
      "aznet",
      "azhub",
      "azinterface",
      "aziel-corpus",
      "4dmap",
      "azcoherence",
      "embryolock",
      "azchat",
      "zkattest",
      "mmconsensus",
      "toolbench",
      "azvpn",
      "mesh",
      "memory"
    ],
    "local_only_slugs": [
      "veillock"
    ],
    "list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list"
  },
  "docs_cite": [
    "docs/NODE_MESH.md",
    "docs/WORKER-LAUNCH.md",
    "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
    "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
    "docs/designs/QNM-WP-1.0.md",
    "docs/audit/HUMAN-UI-MCP-AUDIT-2026-09-17.md",
    "README.md",
    "CHANGELOG.md"
  ],
  "docs_bytes": "CITE — git-hosted; this isolate does not attach the markdown files.",
  "paths": {
    "download": "https://aziel-runtime.vibelock.workers.dev/download",
    "v1": "https://aziel-runtime.vibelock.workers.dev/v1/download",
    "suite": "https://aziel-runtime.vibelock.workers.dev/v1/suite/download",
    "software": "https://aziel-runtime.vibelock.workers.dev/v1/software",
    "fraggate_list": "https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list",
    "mesh": "https://aziel-runtime.vibelock.workers.dev/v1/mesh",
    "github": "https://github.com/AzielEliab/aziel-runtime"
  },
  "note": "One-click suite pack for humans and machines. Packs what ships in-process. Worker wasm, WireGuard/OpenVPN, and qnm-node stay SLOT/CITE. FragGate is THE exec door. Identity Aziel Eliab only. Never fielded_100."
}