Skip to content

PointSav Documentation

The engineering library for the PointSav platform — operating systems and services for regulated businesses that own their data, their AI, and their record-keeping outright. Where the monorepo holds the code, this wiki holds the reasoning: architecture, services, security, and the governance commitments that bind future development.

Substrate without inference — The base case

← All revisions

4932927e · PointSav Digital Systems ·

editorial(substrate): rehedge substrate-without-inference-base-case's unbuilt mechanisms (Track-B) — confirmed the transfer-bundle export command and marketplace/settlement services are planned, not built (same finding already established on customer-owned-graph-ip.md/reverse-flow-substrate.md); confirmed no dedicated TUI deterministic-only mode exists anywhere in the console apps (AI-independent operations do work without an inference tier, but no separate labeled mode). ES pair had the same unhedged claims plus a 'Procedencia' footer that itself violated the no-session-vocabulary register rule (cited an internal source filename and phase-status commentary in reader-facing prose) while incorrectly asserting the hedge was already applied to the body — removed the footer, hedged the body directly. Register-clean EN+ES

View the full record as of this revision →

@@ -28,7 +28,7 @@ When all three compute tiers (local specialist, [[yoyo-compute-substrate|GPU bur

The WORM file ledger ([[service-fs-architecture|service-fs]]) is operational: ingest, query, and checkpoint all work. The knowledge runtime ([[service-content|`service-content`]]) is operational: graph queries, vector search, and temporal queries work, with mutations from non-AI paths only. The input service, extraction service (at the deterministic parsing layer), egress service, people service, and email service are all operational. The [[compounding-doorman|Doorman]] is bound and listening, returning 503 to inference endpoints while keeping health and contract endpoints always responsive. The operator [[tui-corpus-producer|TUI]] operates in deterministic-only mode.

When marketplace and settlement services are enabled, those are also operational in the base case. Transactions may proceed without AI-assisted grounding; audit and consent records are still enforced.
The [[reverse-flow-substrate|marketplace and settlement services]] are planned, not yet built; when they exist, the design intends the same discipline to apply — transactions proceed without AI-assisted grounding, with audit and consent records still enforced.

## What the base case does not require

@@ -36,21 +36,19 @@ It is not required that all three tiers be simultaneously unavailable to activat

## TUI in deterministic-only mode

When the operator TUI detects that no inference tier is available, it enters deterministic-only mode. The status bar shows that AI is disabled. Natural-language chat input is unavailable. Slash commands that depend on AI — verdict capture, brief submission, adapter listing — gracefully return no-ops or unavailability notices.

Deterministic slash commands remain fully operational: status and health queries, audit ledger queries, knowledge graph queries, keyword search, export, and the ownership transfer preparation flow.
A dedicated deterministic-only mode for the operator TUI — a status-bar indicator that AI is disabled, graceful no-op behavior for AI-dependent slash commands — is the design's intent when no inference tier is available, but is not yet built as a distinct mode. What is confirmed real today is that AI-independent operations (status and health queries, audit ledger queries, knowledge graph queries, keyword search) do not require an inference tier to function; the base case's requirement is that they keep working, not that the TUI presents a separate labeled mode for it.

## Transfer of ownership

The "freely transferable" property is more than a philosophical statement. It is implemented through a structured transfer flow. The operator runs a transfer preparation command to produce a self-contained, cryptographically signed bundle: the per-tenant graph snapshot, the [[worm-ledger-architecture|audit ledger]], the trained [[adapter-composition|adapter weights]], the [[seed-taxonomy-as-smb-bootstrap|seed taxonomy]], the pack manifest, and the tenant configuration. The bundle is signed by the operator's identity key and the integrity is anchored to a public transparency log. [^1]
The "freely transferable" property is the design's intended commercial outcome, not yet a shipped mechanism. A single export command — producing a self-contained, cryptographically signed bundle of the per-tenant graph snapshot, the [[worm-ledger-architecture|audit ledger]], the trained [[adapter-composition|adapter weights]], the [[seed-taxonomy-as-smb-bootstrap|seed taxonomy]], the pack manifest, and the tenant configuration — is planned and not yet built (see [[customer-owned-graph-ip]]). The bundle is intended to be signed by the operator's identity key with integrity anchored to a public transparency log. [^1]

The receiving party imports the bundle into a fresh Totebox. Deterministic operations work immediately on the imported state. AI-assisted operations become available once the new operator configures the compute tier.
Once built, the receiving party is intended to import the bundle into a fresh Totebox, with deterministic operations working immediately on the imported state and AI-assisted operations available once the new operator configures a compute tier.

## Why this matters commercially

The freely transferable property distinguishes a sovereign asset from a service subscription. When a business is sold, the new owner imports the Totebox bundle and has the complete operational history available immediately — the knowledge graph, the audit ledger, and the workflow vocabulary — without re-subscribing to any platform or engaging migration consultants.
The freely transferable property is intended to distinguish a sovereign asset from a service subscription. Once the export path is built, the design intends that when a business is sold, the new owner imports the Totebox bundle and has the complete operational history available immediately — the knowledge graph, the audit ledger, and the workflow vocabulary — without re-subscribing to any platform or engaging migration consultants.

When a business dissolves or splits, each party receives their share of the graph as a portable, cryptographically-signed artefact. When the acquiring party in a corporate transaction imports the bundle, patient or client records, audit history, and operational patterns are available immediately with verifiable provenance.
The same intended mechanism covers a business dissolving or splitting (each party receiving their share of the graph as a portable, signed artefact) and a corporate acquisition (records, audit history, and operational patterns available immediately with verifiable provenance to the acquiring party).

If the platform itself ceases operations, the customer continues operating their Totebox indefinitely. The deterministic substrate works without the platform. The customer loses the ability to receive new vertical packs and to transact on the platform's marketplace, but their existing operations do not pause.

Important Information

Corporate structure. PointSav Digital Systems ("PointSav") is currently a trade name of Woodfine Capital Projects Inc. ("Woodfine"), planned to become a wholly-owned Woodfine subsidiary upon incorporation. PointSav does not itself offer, sell, or solicit any security. Any securities offering associated with Woodfine's real-property direct-hold solutions is made exclusively by Woodfine, and only by means of the applicable Private Placement Memorandum.

No investment advice. This wiki's content is provided for engineering, operational, research, and development purposes. Nothing on this wiki constitutes investment advice or a solicitation to invest in any Woodfine partnership or direct-hold solution.

Intellectual property. The PointSav name, trade name, wordmark, and marks, together with all current and future PointSav- and Totebox-branded products, services, and offerings — and the software, source code, documentation, design system, and all related materials — are proprietary to Woodfine and its affiliates, except for components identified as open source. No rights are granted except as expressly set out in a written license or agreement. The full trademark notice appears in the footer of every page on this site.

Open source components. Portions of the platform are made available under permissive open-source licenses identified in the accompanying repository. Use of those components is governed by their respective license terms.

No warranty; informational use. Content on this wiki is provided for general informational purposes only and does not constitute a representation, warranty, or commitment with respect to product functionality, availability, pricing, or roadmap. Some articles describe planned or intended features, capabilities, and milestones — language such as "planned," "intended," "targeted," "may," and "expected" marks this forward-looking content, which is subject to change and does not constitute a commitment regarding future performance.

Confidentiality. Where an article describes an operational or deployment detail that is not intended for public disclosure, that article is not published on this wiki. Content here is general-purpose engineering documentation, not customer-specific configuration.

Jurisdiction. Woodfine Capital Projects Inc. is organized in British Columbia, Canada. References to the Sovereign Data Foundation on this wiki describe a planned or intended initiative only, not a current equity holder or active governance body.

Changes to this notice. PointSav may update this notice from time to time; the version posted on this page governs.

Not a filing system. This wiki is not a securities filing system, an electronic disclosure repository, or a substitute for SEDAR+ or any other regulatory filing system. Formal securities filings are made through the applicable regulatory filing system, not through this wiki.

Full disclaimer. This notice supplements, and does not replace, the full Disclaimers article. In the event of any conflict, the full Disclaimers article governs.

Read the full disclaimer →