FailStop · a Regulayer surface
FailStop is a fail-closed brake in the action path. Before an action runs it must receive a positive yes. No permission means stop. Silence means stop. It latches, and it stays stopped until a person, not the system, re-arms it.
Software now takes actions it cannot take back. A payment, a deletion, a send. The window between decision and consequence has closed to nothing, and the only control standing in it is the judgement of the system that is acting.
A brake that lives inside the system it stops is a feature, and features answer to the product. FailStop sits outside, where the governed system has no way to disable it, reconfigure it, or forge its records. Disguised instructions, lookalike characters and slow multi-turn escalation are checked before the decision, not after the damage.
The kernel binds the loopback interface and refuses any client that is not local. The signing key is generated on your own machine on first run and never leaves it. In the default mode there is no outbound call of any kind. Where independent time is required, a single cryptographic digest goes to a public timestamp authority, never the file and never its contents. The source ships readable, so your own security function can satisfy itself line by line.
Every answer your security function will ask for, on one page you can forward
Describe the system, what it decides, and what it would cost you to be unable to prove it. A written scope follows before any call.
Ways to begin: