NEO evidence rail · the pilots for SAP · the first

Their audit-logging signal, 10,008 companies, two hours — every company its own book, one seal a minute leaves

The first pilot for SAP: ApeiroRA's audit-logging signal — their Go SDK, their collector, their wire format, unchanged — into a NEO audit sink that keeps every company's records in that company's own book and answers each on the wire with a receipt. Once a minute each book seals into one 32-byte commitment that leaves for a door; nothing else leaves. 10,008 companies, 58.6 million records, none failed — and the sinks were stopped mid-work and came back without a record lost.

measured 20 September 2026, 10:46–12:46 UTC · rig-1, 16 vCPU · evidence linked below

What ran — measured 20 September 2026, one box, their SDK and collector as published

Every company keeps its own book; one 32-byte seal per company per minute leaves for a door

What this is. A provider here is one company of the consortium — a cloud, infrastructure or service provider in the 8ra sense — emitting its own audit records (who did what, to which resource, with what outcome) as ApeiroRA's audit-logging signal describes them. No company trades with another in this demonstration; no message passes between them. 150 companies is the consortium's size today; 10,008 is the network it describes. The marketplaces demonstration further down is the other case — two companies, one deal, two books.

What was built. ApeiroRA's audit-logging signal is OpenTelemetry: their Go SDK emits audit records, their collector forwards them, on their wire format. We put a NEO audit sink behind that wire. Every record lands verbatim in its company's own book and is answered with a receipt on the wire (record id, integrity hash, sink time); once a minute each book seals into one 32-byte commitment that leaves for a door. What the door sees is 10,008 objects a minute — whatever the record rate. Nothing else leaves a company: no record, no content, no counterparty.

10,008companies, each its own book and door session
58,623,047 / 0audit records answered 200 / failed, in 2 hours
8,140/srequests per second, one record each
1,200,960 → 1,200,960seals → admitted at the doors · 10,008 × 120, 0 unadmitted
10,008 / 10,008companies whose book holds exactly the records they were told 200 for
116,547 / 116,547periods of one door cross-checked: commitment in the door's journal, receipt's admission number, kit verified
112,366 / 0records through their collector (20 companies), 0 integrity failures at the collector
12.4records per disk sync (group commit)

How it was reached. First the small test that is the consortium's shape today: 150 companies × 0.5 audit records/s each × 3 minutes → 13,535 records, 0 failed, 74 requests/s, p50 1.7 ms; 2,249 seals admitted at the door, every one of them cross-checked against the door's journal and its kit verified (ALL OK, 2,249 periods — fleet150-3min.json · cross-check). Then the ladder at 10,008 companies with one disk sync per record: 3,577 / 4,235 / 4,719 requests/s at 0.5 / 1 / 1.5 records per company per second, 0 failed at every step (run 9). Then the sink's group commit — one disk sync per window of records, every request still answered only after the sync that covers it — and the two-hour run above at 8,140 requests/s (SUMMARY.json · completeness.json · crosscheck-summary.json).

And it survives its sink. Right after the run the twelve sink processes were stopped in the middle of their work — 26,793,445 records answered 200 but not yet in their books — and restarted. The sink's intake log replayed 26,628,445 records into the books, every company sealed and every seal was admitted — 10,008 → 10,008, 0 unadmitted — within 31 minutes of the stop, no operator in the loop (state-after-drain.json). A receipt a company holds is valid before, during and after. Three minutes at the same rate on the restarted sinks: 6,648 requests/s, 0 failed, 36,853 seals admitted (after-restart-smoke-SUMMARY.json).

Bounded on purpose: the twelve doors on this box are test doors with their own journals — the leg from those doors to the production ledger was not part of this run. Verified here means: the record is in its company's book, under a commitment the door admitted, with a kit that recomputes record → snapshot → commitment; it does not mean the record's business content is true, and a record never sent cannot be missed by any bookkeeper. Their SDK and collector were used as published; one box (16 vCPU, 62 GB) carried all of it.

What it showed SAP

  • Their signal needs no change. The SDK and the collector were used as published; the sink sits behind their wire and answers on it.
  • Every company keeps its own book. No record, no content and no counterparty leaves a company — one 32-byte seal a minute does.
  • It survives its sink. Twelve sink processes stopped mid-work and restarted; every answered record reached its book, every seal was admitted, no operator in the loop.
  • 10,008 is the network 8ra describes; 150 is the consortium today. Both were run; both cross-checked to the last period.
All the pilots for SAP Next: the pilot, live The demonstrations page