cotrugli.tech AI LAB

OpenShell pilot · ChatGPT connected

Co-Tru.

The trust rail for
autonomous AI agents.

Your agents work across organisations.
Their evidence should work across them, too.

Turn OpenShell events into private, verifiable evidence — with an independent rail and NEO Chamber governance for acceptance, audit and disputes.

Provider-neutralNo agent rewriteOwner keeps the data
TRIPLE-ENTRY EVIDENCE 01 / 02 / 03
01
PRIVATE OWNER RECORD

Your records.
Your keys.

Signed · AES-256-GCM encrypted
Retained by the owner

32 bytesonly the commitment travels
02
NEUTRAL NEO RAIL RECORD

A proof both sides
can verify.

Existing NEO FX → NEO rail
Independent witness signatures

evidence for audit or dispute
03
NEUTRAL NEO CHAMBER RECORD

Governance beyond
the model provider.

Acceptance · accountability
Evidence for dispute resolution

Confidential content stays with its owner.

THE ENTERPRISE PROBLEM

Two organisations.
Two agents. Whose record counts?

When something goes wrong, each organisation has its own logs and its own account of what happened. Sharing every confidential record with the other party — or the model provider — is a poor starting point for trust.

Co-Tru gives them a common basis for checking evidence. The original stays private. Its commitment is witnessed independently. NEO Chamber provides the governance layer when the evidence needs to be accepted or disputed.

FROM THE WORKING OPENSHELL PILOT

Different outcomes.
The same verifiable trail.

Two published records from the Telemach pilot.
Witnessed on 30 September 2026.

ALLOWED✓ WITNESSED

AGENT A · RECORD 31

The permitted action.

An OpenShell event reported as allowed by its owner, committed to the existing rail and backed by two witness signatures.

Source
nosgoa-pilot-a-01
Witnesses
neo-5 + neo-6
Chamber receipt
Retrieved · proof reverified
Inspect the public commitment049ec81ddbd1f58f194c2bdeeaa41bb0213e26a74279d225cc7411d6f9e56be4
BLOCKED✓ WITNESSED

AGENT B · RECORD 36

The refused action.

An OpenShell event reported as blocked by its owner, following the same commitment, witnessing and evidence retrieval path.

Source
nosgoa-pilot-b-01
Witnesses
neo-5 + neo-6
Chamber receipt
Retrieved · proof reverified
Inspect the public commitment9a0210690f95bfba452a9132f06eee938005abc6955389f80390c5570555e67e
What this demonstration verifies

The verifier recomputes commitment inclusion and checks the pinned neo-5 and neo-6 Ed25519 signatures. These records have BASE/WAW WITNESSED proofs. Their ALLOWED/BLOCKED labels are owner-reported; source completeness is not established. The dated Chamber receipts are evidence lookups, not dispute rulings. This pilot is separate from the newer N8 FINAL / ML-DSA rail. The archived proof closes to HOUR; the live refresh checked on 1 October reached ANNUAL. The MCP tools can fetch and verify the current proof again.

Public witness keys

THE NEXT DEPLOYMENT PATH · VALIDATED AT THE SOURCE

Built for Kubernetes.
Tested in Novska.

OpenShell v0.1.2 · Kyma driver v0.9.1
1 October 2026 · 11:00–11:24 UTC

Co-Tru's new source connector collects OpenShell events on Kubernetes. The Novska test verified collection, recovery after a crash and visibility of an interrupted handoff — using the open-source driver for SAP BTP Kyma.

21records received
4source streams observed
23unit tests passed
1incomplete handoff exposed

COLLECTION

The records arrive.

The connector was added automatically beside the OpenShell supervisor. It read the event file and handed off every complete record up to the measured checkpoint, with zero backlog.

CRASH RECOVERY

Pick up where you left off.

After a forced collector crash, Kubernetes restarted it. Collection resumed from the saved position without repeating the earlier request, then delivered five more records.

LIFECYCLE

A new run gets its own trail.

Stop and delete closed the observed streams. Starting again created a new generation and pod identity, with the collector automatically attached to the new supervisor.

FAILURE VISIBILITY

An unfinished handoff stays visible.

When the receiver was deliberately made unavailable before shutdown, the pod disappeared but its stream remained open. The test identified this as possible_loss.

TESTED IN NOVSKA
OpenShellCo-Tru source connectorTest receiver

This run validated the source connector on a kind Kubernetes cluster. Connecting it to Co-Tru's evidence intake and running the joint rail test are the next steps.

Inspect the test results and deployment scope
Observed source-connector scenarios · Novska, 1 October 2026
ScenarioObserved result
Automatic injectionThe webhook added the native sidecar to the supervisor pod.
Driver compatibilityThe sandbox remained Ready through collection and collector restart.
File accessThe collector read the OCSF file using the supervisor's UID/GID, with a read-only log mount.
Record handoffThree records reached the test receiver; its offset matched the 2,480-byte file.
Collector crashA SIGKILL followed by a container restart preserved the cursor; five subsequent records advanced it to 7,082 bytes.
Stop, start and deleteObserved streams closed with FILE_END and STREAM_END; a new run received a new source identity.
Forced pod deletionThe tested stream closed cleanly. OpenShell then left that sandbox in Provisioning without a supervisor; this was recorded separately.
Receiver unavailable at shutdownThe final stream had no STREAM_END and no live pod: possible_loss was identified.

The receiver was an in-memory test double. This run used process events generated by sandbox commands; it did not produce the ALLOWED/BLOCKED rail proofs displayed above. Those belong to the separate Telemach pilot. Live daily rotation, a lost acknowledgement, the real intake and the joint rail path remain follow-up checks. The run does not establish complete capture under every failure.

The source connector was built and tested in Claude Code; the existing Co-Tru evidence adapter and MCP connection were built in Codex. Codex also checked the running Novska infrastructure and the receiver's aggregate status before publication.

Download the public validation record

A MODULAR ADDITION TO THE EXISTING STACK

One adapter.
An independent evidence path.

Co-Tru's NOSGOA adapter reads OpenShell's OCSF events at the owner. It preserves the existing edge, NEO FX and rail interfaces.

OpenShellagent eventsCo-Truowner-side adapterNEO FX32-byte commitmentNEO railwitnessed proofNEO Chamberaudit & governance
Private by design

Full events and signed envelopes remain encrypted at the owner. The rail receives the 32-byte binary commitment.

Accessible through MCP

Five read-only tools for finding evidence, verifying proofs, retrieving Chamber receipts and refreshing rail proofs.

Extending to Kubernetes

The Linux/OpenShell pilot runs on Telemach. The Kubernetes source connector has passed its Novska test with the Kyma driver, ready for the joint intake test.

CONNECT CO-TRU

Put the evidence
in the conversation.

Connect the public demonstration to ChatGPT or another compatible MCP client. It exposes the published pilot evidence, with no login to Co-Tru required.

Connected in our ChatGPT Business workspace
Open our ChatGPT connection Requires access to the workspace. For your own account, use the MCP connection steps.

This is the server address for your AI client. The page you are viewing is the presentation link.

  1. In ChatGPT settings, enable Developer mode.
  2. Open Plugins → Add → Create MCP App.
  3. Name it Co-Tru, paste the URL and choose No authentication for this public demo.

PROPOSED NEXT STEP · SAP

Your workflow.
Your infrastructure.
A shared proof.

Connect the validated Kubernetes source to Co-Tru's evidence intake, then take one enterprise workflow into an agreed SAP BTP Kyma test namespace. Demonstrate one allowed and one blocked action, then retrieve and verify their evidence independently.

The owner keeps the confidential records. The existing rail witnesses their commitments. NEO Chamber provides the governance framework for acceptance, audit and disputes.

Discuss the pilot Explore the ORA pilots →