IMPRIMATUR
UNCLASSIFIED  //  CAPABILITY OVERVIEW
TRUSTED MISSION EXECUTION
PROG IMPRIMATUR · IMP-001 · REV C · COPY 001/012 SHEET {{ sheetNo }} / 12·{{ sheetName }}·{{ smt }}·KEY {{ cipher }} CONTROLLED DISTRIBUTION · © 2026 IMPACTS R&D
DWG NO
IMP-001
ARCHITECTURE
MRCAL
REV
C
SHEET
01 / 12
CLASS
U // COV
CLASSIFIED BY
DERIVED FROM
DECLASSIFY ON
EXEMPTION
SAR // 50X1
(U) // PRIMARY TENET · 001  //  SAP IMPRIMATUR
FURTHER DETAIL  SPECIAL ACCESS REQUIRED

Proof Before Power.

AUTHORIZED INTENT  ·  ASSURED EXECUTION
MRCAL — MISSION RESOURCE COORDINATION AND ASSURANCE LAYER
IMPACTS ADVANCED DEVELOPMENT · SPECIAL PROGRAMS OFFICE

The trusted execution fabric between autonomous intent and physical action. Permission is made physical — and withdrawn, in hardware, the instant its basis fails.

WARNING — Unclassified capability extract of Special Access Program IMPRIMATUR. Parent program, full envelope, and methods remain classified. Handle via authorized channels only.
ASSURANCE  EVALUATING...
SESSION KEY  {{ cipher }}
INTERLOCK  NOMINAL
EXEC EPOCH  {{ epochTag }}
MET  {{ smt }}
(U)PLATE IMASTER SCHEMATIC
SUPERVISORY CONTROL · SAP IMPRIMATUR

The drawing the planner never sees.

Two trust domains. One boundary that cannot be bypassed. A single protected path to consequence — and no mission processor may assert it.

1234567ABCDE000030060090120150180210240270300330PREPARECOMMITARMACTIVATEMONITORRECONSTITUTEMISSION DOMAINASSURANCE DOMAINBOUND PREDICATESINTERLOCK60°R 358FURTHER DETAIL(S // SAR)IMPACTS ADVANCED DEVELOPMENT · SPECIAL PROGRAMSPLATE I — SUPERVISORY CONTROL · MASTER SCHEMATICDWG IMP-001 · REV C · SAP IMPRIMATUR · (U)PLATE I · MASTER · 01 OF 01
(U)FIG. 02THE GAP
SHEET 02 OF 12 · REV C

The most dangerous moment is after the plan is chosen — and before the hardware acts.

Modern autonomy plans, allocates, and reroutes at machine speed. But a planner's picture of the world can be stale, replicated, estimated, or drawn from a node that is no longer trusted. A plan valid the moment it is chosen can be invalid milliseconds later — and a physical action, once taken, cannot be recalled.

REMOTE PLANNING STATE  / ASSUMED
sufficient power and energy remain
the sensor is thermally available
the communications path is open
the payload software is approved
the required route is safe
the task authority is current
the resource is not committed elsewhere
LOCAL TRUTH  / ENFORCED
local managers reserve the actual capacity
the operating-envelope controller accepts the physical configuration
the exact action is frozen into a cryptographic commitment
an independent assurance controller confirms validity at the moment of use
permission expires — renewed only while every condition holds

The time-of-check / time-of-use and authority gap. IMPRIMATUR exists to close it — advanced autonomy without monolithic trust.

(U)FIG. 03GOVERNING DOCTRINE
SHEET 03 OF 12 · REV C

Four authorities. Separated on purpose.

The architecture reduces to four propositions. They are not slogans — they are distinct technical authorities, and no one of them can do another's job.

01
THE PLANNER PROPOSES
Mission autonomy nominates a platform, payload, timing, geometry, or route, and weighs mission value. It cannot energize a payload or assert a protected enable path.
02
THE LOCAL PLATFORM COMMITS
Only local resource managers reserve real power, energy, thermal, compute, and communications. Only the local operating-envelope controller accepts the route, attitude, depth, pose, or pointing state.
03
THE ASSURANCE CONTROLLER PERMITS
A separate hardware-enforced trust domain verifies authority, exact command, measured state, leases, envelope acceptance, freshness, epoch, revocation, and live invalidation predicates.
04
PROTECTED HARDWARE ENFORCES
The mission processor does not own the final gate. A protected interlock — FPGA, CPLD, or security island — controls the payload, transmitter, processor, or bus path itself.
POSITION IN THE AUTONOMY STACK
HUMAN MISSION COMMAND
INTENT · AUTHORITY · RISK · OVERRIDE
HIGH-LEVEL MISSION AUTONOMY
PLANNING · TACTICAL REASONING · RECOMMENDATION
IMPRIMATUR · MRCAL
FEASIBILITY · COMMITMENTS · TRUST · ASSURANCE · RESILIENCE
PLATFORM · PAYLOAD · NETWORK · COMPUTE
POWER & THERMAL CONTROLLERS
PROTECTED PHYSICAL ACTION
IRREVERSIBLE · ATTRIBUTABLE · BOUNDED
(U)FIG. 04THE INTERLOCK
SHEET 04 OF 12 · REV C

Two domains.
One never touches the trigger.

The mission-allocation processor can run the most advanced planning in the fleet — and still cannot assert a protected enable path. That authority lives across a hardware-enforced trust boundary, in an isolated assurance controller. Compromise the planner, and you have compromised a proposal — not a weapon.

FIG. 04 — SUPERVISORY ENABLE PATH LIVE · SELF-RUNNING · EXEC EPOCH {{ epochTag }}
MISSION DOMAIN
MISSION-ALLOCATION PROCESSOR
PROPOSES · OPTIMIZES · NO ENABLE AUTHORITY
FORMS
RESOURCE-COMMITMENT RECORD
EXACT COMMAND · LEASES · MEASURED STATE · AUTHORITY · PREDICATES
TRUST BOUNDARY
ASSURANCE DOMAIN · ISOLATED
ASSURANCE CONTROLLER
VERIFIES RECORD · ISSUES EXECUTION CAPABILITY · ROOT OF TRUST
CONTROLS
HARDWARE INTERLOCKREADBACK
{{ stateLabel }}
PROTECTED ENABLE PATH · {{ enablePct }}%
ENABLES
MISSION SUBSYSTEM
TRANSMIT · PAYLOAD · EFFECTOR
BOUND PREDICATES — CONTINUOUSLY EVALUATED
{{ p.label }} {{ p.status }}
{{ stateNote }} EXEC EPOCH {{ epochTag }}

Enablement is held, not granted. The moment one predicate fails, the interlock deasserts locally — without a coordinator, a quorum, or a network — and the lost function is reconstituted under a later epoch.

(U)PLATE IIASSURANCE CORE
EXPLODED SECTION · SAP IMPRIMATUR

The trust domain, in section.

Isolated silicon — measured, sealed, and gated — pulled apart along its alignment axis. Two layers sit above the boundary; everything that can energize hardware sits below it.

1234567ABCDEMISSION-ALLOCATION PROCESSORUNTRUSTED · PROPOSES1RESOURCE-COMMITMENT RECORDEXACT CMD · LEASES · STATE2ASSURANCE CONTROLLERVERIFY · ISSUE CAPABILITY3ROOT OF TRUSTTPM 2.0 · SEALED KEYS4EXECUTION CAPABILITYTIME-BOUNDED TOKEN5HARDWARE INTERLOCKPROTECTED ENABLE GATE6MISSION SUBSYSTEMTRANSMIT · PAYLOAD7HARDWARE-ENFORCED ISOLATION PLANE⊥ NON-BYPASSABLEASSEMBLY ENVELOPE · SECTION A–AFURTHER LAYERS(S // SAR)IMPACTS ADVANCED DEVELOPMENT · SPECIAL PROGRAMSPLATE II — ASSURANCE CORE · EXPLODED SECTIONDWG IMP-001 · REV C · SAP IMPRIMATUR · (U)PLATE II · SECTION A–A · 01 OF 01
(U)FIG. 05THE TRANSACTION
SHEET 05 OF 12 · REV C

Prepare. Commit. Arm. Activate. Then watch — and reconstitute.

Six movements convert an authorized objective into a bound, attested, revocable commitment — and restore the function when it breaks. None of them energizes hardware until the one before it is real.

01
PREPARE
Local managers provisionally reserve real power, thermal, compute, and communications; the operating-envelope controller accepts the route, depth, pose, or pointing. Remote state supports planning; local state controls commitment.
02
COMMIT
Only after every mandatory participant accepts is the Resource-Commitment Record formed. Provisional leases become committed. Commitment establishes bounded ownership — it does not energize hardware.
03
ARM
The isolated assurance controller verifies the record against measured state and issues a short-lived Execution Capability — bound to one command, one epoch, one machine state.
04
ACTIVATE
The capability is installed in protected gate logic. The gate holds the enable path only while epoch, commitment, leases, and state-generation still match. Mission software cannot route around it.
05
MONITOR & RENEW
Live predicates are evaluated continuously; the capability is renewed before expiry, and only while conditions hold. A hard fault inhibits immediately — locally, without consensus.
06
RECONSTITUTE
On failure: tombstone the epoch, account for residual resource until quiescence, identify the function actually lost, and restore it under a new commitment and a later epoch — subject to the same controls.
(U)PLATE IIIEXECUTION SEQUENCE
TIMING DIAGRAM · SAP IMPRIMATUR

The last microseconds, on the wire.

The execution sequence as the gate sees it. The enable path exists only while every bound predicate holds — and collapses the instant one fails.

1234567ABCDEPREPARECOMMITARMACTIVATEMONITORREVOKEQUIESCERESTOREENVELOPE REVOKEGATE-DISABLE ≤ 2 µsPREDICATES 5/5MEASURED STATEEXECUTION CAPABILITYENABLE PATHINTERLOCK STATEEXEC EPOCHARMEDENABLEDDISABLEDQUIESCENTRECONSTITUTINGEXEC EPOCH 0x120x13t0t / µsRENEWAL INTERVAL(S)IMPACTS ADVANCED DEVELOPMENT · SPECIAL PROGRAMSPLATE III — EXECUTION SEQUENCE · TIMING DIAGRAMDWG IMP-001 · REV C · SAP IMPRIMATUR · (U)PLATE III · CH 1–6 · 01 OF 01
(U)FIG. 06THE FIVE RECORDS
SHEET 06 OF 12 · REV C

Five records.
No record answers another's question.

Each record is owned by a different authority. Keeping their questions separate is the whole discipline — it stops any one service from claiming the mission, reporting the state, choosing the action, certifying it, and authorizing itself to act.

R1
BOUNDED TASK DESCRIPTOR
MISSION AUTHORITY · TASK COMPILER
“What authorized outcome is requested, and within what limits?”
R2
AUTHENTICATED CAPABILITY MANIFEST
SUPPLIER · INTEGRATOR · APPROVING AUTHORITY
“What is this component approved to do, and under what static conditions?”
R3
RESOURCE-STATE VECTOR
LOCAL PLATFORM RESOURCE MANAGERS
“What is actually available now, and forecast to remain available?”
R4
RESOURCE-COMMITMENT RECORD
COMMITMENT COORDINATOR + LOCAL PARTICIPANTS
“What exact execution have all mandatory participants accepted?”
R5
ASSURANCE DECISION RECORD
ISOLATED ASSURANCE CONTROLLER
“Why may — or may not — the protected hardware act now?”
A nominal capability is not current availability A selected plan is not a commitment A commitment is not present permission A valid signature is not authority An optimization score is not permission to energize hardware
(U)FIG. 07HARDWARE-ROOTED TRUST
SHEET 07 OF 12 · REV C

Cryptography establishes authority. Protected logic preserves the machine.

The strongest embodiment fuses software-defined coordination with hardware-defined permission — split cryptography, a measured root of trust, a fast hard-fault path, and freshness that never depends on a clock.

01SPLIT CRYPTOGRAPHY
Durable, cross-domain records carry asymmetric signatures any platform, organization, or auditor can verify. Local, short-lived artifacts use fast symmetric authentication between identified components. Confidentiality is applied only where needed — never by default.
SHA-256ECDSA P-256AES-256-CMACPER-BOOT KEYS
02MEASURED ROOT OF TRUST
An immutable measurement root and a discrete TPM 2.0 device anchor measured and secure boot, protected registers, event-log reconciliation, nonce-bound attestation, anti-rollback, and sealed keys. The TPM establishes measured state — it is not the real-time gate.
TPM 2.0MEASURED BOOTPCR QUOTESEALED KEYS
03FAST HARD-FAULT PATH
A hard over-temperature, over-current, envelope inhibit, emergency inhibit, or watchdog fault deasserts the physical gate directly — no signature, no quote, no MAC, no network, no consensus, no mission processor in the path.
OVER-TEMPOVER-CURRENTWATCHDOGDEFAULT-DISABLED
04FRESHNESS WITHOUT A CLOCK
Boot epoch, key epoch, task epoch, a per-issuer monotonic sequence, and protected monotonic elapsed time establish currency. Roll back civil, GPS, or network time and nothing expired comes back. Built for denied, spoofed, and degraded timing.
BOOT EPOCHTASK EPOCHMONOTONIC SEQNO CIVIL TIME
THREE GATES — NEVER COLLAPSED INTO ONE
COMMAND-ACCEPTANCE
May a task, update, or command even enter the trusted environment? Authentication proves who sent it; admission decides whether they may ask.
PAYLOAD-ACTIVATION
May this subsystem physically arm, activate, continue, or renew? A payload may warm up without being permitted into its mission-effect-producing mode.
DATA-RELEASE
May this product leave, by this route, to this destination? A sensor may be cleared to collect while transmission stays prohibited.
(U)FIG. 08INSTRUMENTED EVIDENCE
SHEET 08 OF 12 · REV C

The evidence is part of the product.

Every commitment, lease, gate state, fault, and reconstitution is an authenticated record. Evaluate the architecture against measures with a direct nexus to its mechanisms — not against adjectives.

RESOURCE INTEGRITY
100.0%
Physically infeasible tasks blocked before dispatch
EXECUTION INTEGRITY
0admitted
Stale, replayed, or superseded commands reaching hardware
HARDWARE ASSURANCE
2µs
Deterministic gate-disable latency, hard-fault path
RESILIENCE
99%
Essential functions restored after attrition, by reconstitution
REPRESENTATIVE · MODELED TARGETS · NOT FIELDED RESULTS  //  ADDITIONAL MEASURES  WITHHELD (S//SAR)
(U)FIG. 09THE DOMAINS
SHEET 09 OF 12 · REV C

One architecture.
Every platform that acts.

The same transaction governs an aircraft's payload, an undersea vehicle's sonar, a ground vehicle's emitter, a spacecraft's downlink, and a fixed sensor's transmit path. Only a domain adapter changes — which resources are material, which hardware is gated. What is never gated: the functions that keep the platform alive.

AIRD1
VEHICLE-MANAGEMENT SYSTEM · FLIGHT-CLEARANCE ENVELOPE
GATES
Payload mode · RF power-amplifier · mission-data transmit
NEVER GATED
Flight-envelope protection · collision avoidance
SURFACE & SUBSURFACED2
NAVIGATION · PROPULSION · BUOYANCY · DEPTH · RECOVERY RESERVE
GATES
Sonar transmit · acoustic modem · mission-data radio
NEVER GATED
Emergency surfacing · ballast release · collision avoidance
GROUNDD3
MOTION-PLANNING SUPERVISOR · CORRIDOR · POSE · SAFE-STOP
GATES
Active emitters · manipulator power · data transmit
NEVER GATED
Emergency braking · obstacle avoidance · steering to safe stop
SPACED4
BUS · GN&C · ADCS · POINTING · MANEUVER · CONTACT WINDOW
GATES
Mission payload · downlink transmitter
NEVER GATED
Safe mode · power survival · command reception
FIXED NODED5
INSTALLATION & POINTING CONTROLLER · FIELD OF REGARD · MAINTENANCE
GATES
Emitter enable · mission-data transmit
ON LOSS
Observation or relay function reconstitutes to another node
COALITION & COMPARTMENTEDD6
PARENT & CHILD COMMITMENTS · SELECTIVE DISCLOSURE
A RELAY SEES ONLY
Its obligation · product identity · source · timing · destination
NEVER
The whole plan. Least-knowledge, by construction.
D7
CLASSIFICATION
Withheld — TS // SAR // SPECIAL ACCESS REQUIRED
ACCESS
Briefed personnel only
(U)PLATE IVOPERATIONAL EMPLOYMENT
CONTESTED ENVIRONMENT · SAP IMPRIMATUR

Deep inside the ring — by permission.

Operational employment in a contested environment. The platform persists where it otherwise could not — because every emission, release, and action waits on a current, authorized, feasible commitment, and the lost relay is reconstituted under a later epoch.

1234567ABCDEIADS THREAT RINGS-CLASS ████ (S)EW · GNSS-DENIEDINGRESSOBJECTIVEGROUND NODEC2 LINKUCAV-2 · RELAYUCAV-1(U) ENABLEENVELOPE ACCEPTED · WINDOW OPENINHIBIT — EMISSIONSNO CURRENT AUTHORITYDATA-RELEASE GATEDDEST ████ (S)RECONSTITUTE · FN-114RELAY LOST → LATER EPOCHN050 NMPERSISTS INSIDE THE THREAT RING — ACTS ONLY ON A CURRENT, AUTHORIZED, FEASIBLE COMMITMENT.IMPACTS ADVANCED DEVELOPMENT · SPECIAL PROGRAMSPLATE IV — OPERATIONAL EMPLOYMENT · CONTESTED ENVIRONMENTDWG IMP-001 · REV C · SAP IMPRIMATUR · (U)PLATE IV · TAC PLOT · 01 OF 01
(U)FIG. 10CONSTRAINTS
SHEET 10 OF 12 · REV C

What it cannot do is built in, not promised.

IMPRIMATUR governs exactly one transition — from authorized intent to physical action — and stops precisely at the decisions that must remain human.

TRUST GUARANTEES
A compromised planner cannot enable hardware. The mission processor owns no gate and no execution-capability keys.
A software change voids old permission. A security-relevant change rolls the measured-state generation and invalidates existing capabilities.
Stale authority cannot revive. Boot, key, and task epochs, monotonic sequence, expiry, tombstones, and revocation block replayed or delayed artifacts.
Connection alone confers no trust. A payload must match an authenticated manifest, approved identity, acceptable measured state, and permitted command form.
Human command is preserved. IMPRIMATUR confirms a required authorization is present, and inhibits an action that lacks it.
WHAT IMPRIMATUR IS NOT
IMPRIMATUR does not —
decide the strategic objective
fly the vehicle
perform combat identification
generate electronic-warfare technique
determine whether a target is legally engageable
authorize weapons release
act as a universal cross-domain security solution

It makes authorized intent physically executable, attributable, continuously bounded, locally containable, and recoverable — without surrendering human authority, platform safety, or control of consequential hardware.

(U)FIG. 11THE PRACTICE
SHEET 11 OF 12 · REV C

Engineered for the irreversible.

IMPRIMATUR is built by IMPACTS Research & Development — an engineering practice working at the boundary between autonomous decision and physical consequence. It builds the control and assurance machinery that lets advanced autonomy be fielded without surrendering authority over what it does.

Its method is the architecture itself: nothing acts that is not measured, bounded, attested, and revocable — and nothing stays enabled once any of those ceases to hold.

One principle governs the work: authority over a physical action must be proven at the moment of use, in hardware — never assumed from a plan, a signature, or a prior state.
IMPACTS RESEARCH & DEVELOPMENT · FOUNDED 2005
EXECUTION CORE · MRCAL — MISSION RESOURCE COORDINATION AND ASSURANCE LAYER
FOUNDED BY SCOTT CORWON
(U)FIG. 12ENGAGEMENT
SHEET 12 OF 12 · REV C

What can be shown has been shown.

The rest is discussed under authority, with the programs it is built for. If you are accountable for autonomy that will act in the physical world, that is reason enough to make contact.

REQUEST A TECHNICAL BRIEFING DIRECT INQUIRY · AUTHORIZED CHANNELS
IMPRIMATUR.SYSTEMS
WARNING NOTICE — This sheet is the unclassified capability extract of Special Access Program IMPRIMATUR. The parent program, its full operating envelope, parameters, and methods remain confidential. Reproduction or dissemination outside briefed channels is prohibited without IMPACTS Advanced Development approval.
IMPRIMATUR
TRUSTED MISSION EXECUTION
IMPACTS ADVANCED DEVELOPMENT · SPECIAL PROGRAMS
IMPRIMATUR.SYSTEMS
SAP IMPRIMATUR · MRCAL ARCHITECTURE · COPY 001 / 012
© 2026 IMPACTS RESEARCH & DEVELOPMENT · UNCLASSIFIED