The control layer for product safety

Safety that
shows its work.

Turn customer-owned activity into explainable Findings, authorised Decisions, and verified reversible action.

Detection is only the beginning.

Evidence · authority · outcome

Why Jouleyard

Consequential systems should be able to account for every consequence.

Most safety tools stop at a score or an API response. Jouleyard is built for the consequential work in between—and after.

01

Explain what happened

Trace each warranted outcome to exact inputs, release, rationale, authority, and evidence.

02

Keep authority explicit

Signals inform. Findings explain. Only an authorised path can decide and act.

03

Verify the real result

Acceptance is not confirmation. Reconcile each requested effect against customer state.

Two dangerous leaps

Keep the boundary.
Lose the guesswork.

Automation becomes unsafe when an observation quietly becomes authority, or a delivery receipt quietly becomes truth.

01 · AuthorityBoundary held
Detector outputSignal
Authorised pathDecision

Detection can inform an accountable judgement. It cannot make one by side effect.

02 · TruthBoundary held
HTTP 202Accepted
Customer stateConfirmed

A provider receipt is evidence of delivery. Only authoritative observation can establish the result.

One accountable loop

From activity to observed outcome.

Five distinct stages. Four visible boundaries. One causal chain an operator can actually follow.

01

Customer source

Read customer-owned activity.

Typed adapters consume the customer’s durable stream. Clean streamed Events are evaluated transiently and leave no Jouleyard product-domain row.

1 / 5
Causal record
Observemessage.sent@1

p03 · offset 884,201

Current stateevaluated transiently
Exact release2026.08.24.3

Proof, not posture

Built for the failure modes that happy-path demos erase.

01

One exact release

Every evaluation, replay, shadow comparison, and historical record stays pinned to one immutable EnvironmentRelease.

No floating “latest”
02

Replay without multiplying harm

Stable identities, idempotency, checkpoints, and version preconditions make at-least-once work converge safely.

One intended effect
03

Customer-owned by default

The customer remains the source of truth. Clean streamed content stays in customer storage and worker memory.

0 clean-event domain rows
04

Uncertainty stays visible

Unknown, contradicted, stale, failed, and unconfirmed are preserved as different operational facts.

No certainty theatre

Data restraint by design

Your product.
Your data.
Clear authority.

Jouleyard coordinates the safety loop without becoming the system of record for your product. Governed evidence begins only when a suspicious claim warrants it.

Clean streamed activity0

Jouleyard product-domain rows

Customer sourcedurable Event
transient evaluation
Cleancheckpoint only

When a Finding is warranted, exact governed evidence and causal links begin—deliberately, not indiscriminately.

Current alpha

One real safety loop, proved end to end.

The first complete workflow is message safety: evaluate a customer-owned Event against one exact release, retain a Finding only when warranted, authorise a reversible quarantine request, and verify the customer’s real state.

Discuss a design-partner workflow
01Customer Event
02Finding
03Decision
04ActionIntent
05Observation

Common questions

Ask the hard questions before the first consequence.

Good safety architecture should get clearer under scrutiny.

Is Jouleyard an AI moderation model?

No. Jouleyard is the governed control layer around detectors and other capabilities. A model may emit a typed Signal; it cannot silently issue a Decision or ActionIntent.

Does Jouleyard store every customer Event?

No. Clean streamed Events are evaluated transiently and create no Jouleyard product-domain row. Governed durable evidence begins at Finding unless an earlier bounded purpose is explicitly declared.

Who is allowed to decide and act?

Only an authorised deterministic policy or human path may create a Decision. A consequential ActionIntent can follow only from an eligible Decision; detectors, connectors, Joules, and agents hold no hidden authority.

What does “confirmed” mean?

It means an authoritative observation of the customer’s product state matches the requested effect. A successful delivery response alone remains accepted—not confirmed.

Where is the product today?

Jouleyard is in alpha. The current delivery phase is proving one replay-safe message-safety loop from deterministic authority through reversible quarantine and reconciliation.

Build with boundaries

Every consequence,
accounted for.

Bring one real product-safety workflow. We’ll help you make the evidence, authority, effect, and outcome inspectable.