NEO evidence rail · the pilot, live

Four companies, one rail, every minute sealed

Running since 29 September 2026, 17:30 UTC on the Telemach cluster: four companies' edges book their records — a thousand a second each, four thousand a second in all — fold them every minute into one 32-byte commitment, and the rail seals them every ten minutes. Everything on this page is read from the running system itself.

live · data from — · running for — · seal — s after the close, measured

The case — how 8ra becomes a cloud-edge continuum, live

Click a card for the detail behind it.

Problem

Many clouds and edges, no shared proof

In a cloud-edge continuum the record of what happened is spread over many providers and many edges, each keeping its own logs. To show a partner, an auditor or a court what was booked and when, today you copy data and trust whoever holds the log. Every copy is a leak; every log is a thing to argue about.

  • Who has to prove what: a provider that a workload ran where and as long as it says; a customer that its data stayed in its country; a consortium that the month's deliveries add up to what was paid. Each of them today holds only its own log.
  • Why copies fail: a copy of the log is a second thing to protect and a second thing to dispute; a log kept by one side is not evidence for the other side.
  • What a continuum needs: one shared, neutral time that every party can verify without opening anyone's data — and a rule for the day it is disputed.
Solution

One neutral timeline for the whole continuum — the data never leaves its owner

Every participant, a provider's server or a company's edge, keeps its own book and sends the rail only a 32-byte commitment a minute. The rail seals everyone's commitments every ten minutes with two witnesses and post-quantum signatures and keeps only the seals and a list of roots; each participant fetches its proof and keeps it. Any record is provable months later, offline, with public keys — nobody has to open a log. That shared, verifiable time is what makes many clouds and edges one continuum, at 33 bytes a minute per participant.

  • How the 8ra consortium is orchestrated: each party runs its own OpenNebula (placement by country and assurance level — German data stays on German hosts; a hook fires on every workload start, stop, loss and end) → SAP's ApeiroRA collector signs each event at the source → the NEO edge on the same server books it (128 bytes, append-only) and folds each minute into one 32-byte commitment → the door → the accounting cell folds ten minutes of everyone into one root → the DLT seals it (two witnesses, Ed25519 + ML-DSA-65) → the NEO Chamber keeps the seal and the list of roots.
  • Governance = the NEO Chamber: the consortium's neutral body. It holds the small book (48 bytes per company per period, seals kept forever, lists for 35 days), admits and suspends members, and on a dispute or a regulator's request takes the proof from the rail and hands it to the authorised party by its procedure. Its rule: the side without a receipt loses; the side that withholds evidence loses.
  • Settlement: the month closes to one amount per member from what the records show — no receipt, no payment (shown live for a month on OpenNebula, cotrugli.tech/demo/8ra/month/).
  • What each party keeps: its data, its book, its keys, its proofs — for its own legal retention; what leaves: 33 bytes a minute.
Technology

SAP's signal, Cotrugli's rail, the NEO Chamber, European iron

SAP / ApeiroRA: the audit-logging collector (otelauditcol, strict mode, source-signed) is the signal at every server — unchanged. Cotrugli / the NEO stack: the edge beside it, the door, the accounting cell, the DLT with its witnesses and seals (Ed25519 + ML-DSA-65), the NEO Chamber's small book for governance — 32-byte objects end to end. Iron: Telemach's Kubernetes cluster in Croatia, WireGuard between sites; before it, a month on OpenNebula. Everything on this page is the running system, read live.

  • OpenNebula 7.4.1 — the parties' orchestration; several providers, placement by NEO_COUNTRY / NEO_ASSURANCE, state hooks on every transition (the month demonstration, run 3, reviewed by four independent reviews).
  • ApeiroRA otelauditcol — strict verification of source-signed records (JCS canonical form, one key per party), the signal the edge books; the collector is not changed for the pilot.
  • NEO edge — 128-byte records, 60-second periods, one 32-byte commitment a minute, a kit with every proof, offline verification with public keys; about 100 MB of RAM beside the collector.
  • The door — 33 bytes per send, keeps nothing; measured 100,000 sends a second, 0 dropped.
  • The accounting cell — ten minutes of everyone into one root: 60.1 million objects per root live on this page; a company's proof answered in milliseconds from a per-period index.
  • The DLT — two independent witnesses, the terminal's Ed25519 and ML-DSA-65 (post-quantum) seal 5–11 s after each close; archives deleted 15 minutes later.
  • The NEO Chamber — governance and the small book: the seal and the roots list per period (48 bytes per company), receipts to the rail, the dispute procedure.
  • Iron — Telemach RKE2 Kubernetes, Croatia; WireGuard between sites; the rail unchanged by any load on this page.
The ask to SAP

15 of your servers now, 150 by the end of the year

Put the edge beside your collector on 15 servers of a test landscape: a container of about 100 MB, six configuration values, a WireGuard peer — your collector unchanged, your data never leaves your server. From the first minute every server holds a proof per minute that anyone verifies offline. One engineer, one day for the first site; then 150 by December, and the continuum's evidence rail shown together at the 8ra General Assembly in Paris, March 2027.

  • What we ask: 15 servers of a test landscape now — their ApeiroRA collector already there, our edge beside it; 150 by December; one engineer for one day at the first site; a joint demonstration at the 8ra GA, Paris, March 2027.
  • What it costs you: one container (about 100 MB of RAM), six configuration values, a WireGuard peer per site; nothing changes in the collector; nothing of your data leaves your server.
  • What you get from minute one: a proof per server per minute — your record, its minute's commitment, the cell's root, the sealed period — verifiable offline with public keys, kept on your own volume for your own retention; and the NEO Chamber's procedure when a regulator asks.
  • What stays open, honestly: your servers' path to the door (WireGuard or a public door), which servers and parties, and the Chamber's key ceremony — decisions for the pilot, not blockers.

Capacity — live

—objects folded into roots on this rail, running total since 26 Sep
—of them since the live run began, 29 Sep 19:30 UTC
—objects a second through the door, last cell period
—objects folded into one root, last cell period
—simulated companies, one send a minute each
—of their sends refused
—bytes in the Chamber's list, last DLT period

Beside the four real edges, two loads run through the same door into the same cell around the clock: a paced source at 100,000 33-byte objects a second — sixty million objects folded into one root every ten minutes, 8.6 billion a day — and a fan of — simulated companies, each opening a connection, sending its one object and closing, once a minute. The cell folds everything of ten minutes into one root; the DLT seals it; the rail deletes the archives fifteen minutes later. The fan's own counters: sent — · refused — · mean — ms · slowest — ms · rounds —.

The running total is the sum of the cell's own period counts: every period the cell folded since 26 Sep, read from its period files, plus every period closed since, read once from its receipt service as it closes; a period this watch could not read while its archive existed is left out, so the figure is exact or an undercount. Objects a second = the last closed cell period's count over its 600 seconds, read from the cell's own receipt service. Measured on this rail on 29 Sep: at 100,000 a second the cell folded 59.7, 60.1 and 60.1 million objects into one root each, nothing dropped at the door or the cell, every root sealed within nine seconds of the close. A company's proof is one block of 4,096 leaves and the block hashes — 26 hashes among 60 million, answered in milliseconds from an index the cell writes once per period and deletes with the archive — so every real edge's proof lands inside the fifteen-minute window at this pace. The rail's shape is the same at any pace: one root per period whatever comes in, 48 bytes per company in the Chamber's list.

How it flows — six steps, one shape end to end

1 · the company's server

Their collector, our edge

ApeiroRA's audit collector, in strict mode, passes only source-signed records to the edge on the same machine. The edge books each record (128 bytes, append-only) and every 60 seconds folds the period's records into one 32-byte commitment.

the book, the keys and the kit stay on the company's disk
2 · the door

33 bytes a minute, nothing kept

The commitment and one flag byte, over one TCP connection. The door checks the shape, forwards, and keeps nothing: no journal, no signatures, no configuration per edge. A new edge is enrolled by being on the trusted network.

100,000 sends a second measured, 0 dropped
3 · the accounting cell

Ten minutes → one root

The cell folds every edge's commitments of the ten-minute period into one root and sends that one object to the DLT. The cell's archive lives 15 minutes after the root is final, then it is deleted.

four companies = four objects a minute here
4 · the DLT

Sealed every ten minutes

Two independent witnesses sign the period, the terminal seals it with Ed25519 and ML-DSA-65 (post-quantum). Seals chain from the genesis. The archive is deleted 15 minutes after the seal — only with the Chamber's receipt.

seal 4–11 s after the close, measured
5 · the Chamber's small book

The seal and the list of roots

The Chamber takes each seal and the period's list of roots, checks that the list reproduces the sealed root, keeps it, and gives the rail its receipt. Seals are kept forever, lists for 35 days: any path is recomputed from the list.

48 bytes per company per period — 150 companies = 7 KB
6 · the company's kit

Proof in hand, verifiable offline

Inside the window the edge fetches the proof of its period — from the record to the sealed root — and keeps it in its kit. Anyone with the public keys verifies a record, a day or a year offline. No server has to be alive.

the company's own legal retention, 5–11 years
What leaves the company

33 bytes a minute per edge. Not the records, not their content, not who did what — one commitment per period.

What stays with the company

Everything: the records, the book, the keys, the kit with every proof. The rail keeps only seals — 3.7 KB every ten minutes.

What happens, minute by minute

  1. :00the edge closes its 60-second period: the records folded, one commitment written to the kit as SENT, 33 bytes to the door.
  2. :00 – :10the cell collects the four companies' commitments of the ten-minute period — ten per edge — and closes the period with one root.
  3. +10 sthe root enters the DLT; at the end of the DLT's ten-minute period the witnesses sign and the terminal seals — 4 to 11 seconds after the close.
  4. +1 sthe Chamber's book takes the seal and the list of roots and gives the rail its receipt (HELD).
  5. secondseach edge asks the rail where its commitment is, fetches the proof and the seal, and marks the period FINAL; the proof is durable in the kit about 12 seconds after the DLT period's end.
  6. +15 minthe rail deletes the period's archive; the cell deletes its file 15 minutes after the root is final. What is left: the seal, the Chamber's list, the company's kit.
  7. 00:25 UTCday-close (next): seven checks on the day's packs — every transition recorded, every book sealed without a gap, every proof in the kit, the pack verifies, no alarm, no hand, a verified copy — and the counter of days without an error.

If the door is unreachable, the edge holds its closed periods in its outbox and sends them all in the first tick after the door returns; if the rail loses a commitment, the edge re-sends it in the next period. Measured on 28 September: the door killed for three periods, every period proven afterwards; the DLT down for seven periods, nothing accepted lost; the Chamber unreachable until the DLT's quota — every refused object re-sent and found.

Measured before the pilot

100,000 / s33-byte sends through the door, 15 min, 0 dropped
100,167 / son this rail: the cell's own count for 29 Sep 19:40–19:50Z, 60.1 million objects in one root
10,000edges through one door, once a minute, 0 refused
1.44 billionobjects in 4 hours, sealed, archives deleted hourly
0 lostdoor killed 3 periods · DLT down 7 periods · Chamber gone until the quota

The numbers and their evidence: NEO8ra-GA · NUMBERS.md. Every figure names the box it was taken on, the objects per send and the connections.

What a company installs — 15 servers or 150

  • Their collector, unchanged. ApeiroRA's otelauditcol in strict mode, with one signing key per company; it already runs on the audit-logging path.
  • The edge beside it. One small container: about 100 MB of RAM with the collector, 11 GB of book a day at a thousand records a second (1.1 GB at a hundred, 18 MB at a hundred a minute), six configuration values (the door, the two receipt services, the cell's identity, the pinned genesis, the rail's public keys). Its book and kit live on the company's own volume.
  • A path to the door. The company's site joins the rail's trusted network as a WireGuard peer. Nothing at the door changes for a new edge — 150 edges are 150 connections and 150 × 33 bytes a minute.
  • Verification in their hands. The same strict verify this page's edges run, with the public keys; the day's pack on a phone comes with the counter.

On the rail's side a company costs 48 bytes per ten-minute period in the Chamber's list; the DLT's budget holds about 125,000 companies per period. Capacity is not the question; staying correct and unattended is — which is what this page shows.

Next

  • The counter. Day-close at 00:25 UTC with the seven checks, and the count of days without an error — the clock of the programme to the 8ra General Assembly, Paris, March 2027.
  • Guardians. Copies of the Chamber's small book at several sites, so the seals and lists outlive any one box.
  • More sites. A second and third real site over WireGuard; the first companies' own servers.

← the demonstrations for ApeiroRA / 8ra the architecture