Skip to main content
Protocol Wealth

System of systems

Public contracts around a private host.

Six repositories publish different boundaries: how to learn, describe agent intent, apply governance patterns, call analytical capabilities, render planning workflows, and protect selected recovery artifacts. They can be composed, but none is a complete operating environment by itself.

Source review: 2026-07-25 · static page · no runtime calls

Read it as

A contract map

Arrows describe information, control, or optional adoption boundaries—not package imports or proof of live integrations.

Do not read it as

A production topology

Public source cannot establish private configuration, authentication, monitoring, retention, deployment, or runtime behavior.

The invariant

The host owns authority

Models and repositories do not grant themselves tools, credentials, approval, signing authority, or permission to deliver advice.

Reference architecture

Follow the boundary, not the brand name

The visual order is also the reading order on small screens. Relationship labels are written into the page so the map does not depend on color or connector lines alone.

Human boundary

Operator, reviewer, or learner

Chooses scope, selects a host and model, grants or denies approval, reviews output, and remains accountable for deployment and use.

Human → pw-learnai · education + source inspection

Learning entry

pw-learnai

Build a first path, practice locally, and follow claims into primary sources.

Human → private host · scope + policy + approval

Private deployment boundary

Human-controlled host and agent runtime

The adopter supplies the model loop, process and filesystem isolation, credentials, network policy, authentication, monitoring, retention, and runtime configuration.

Not an open-source repository and not described as public infrastructure.

Human-controlled host → pwcli-core · control + evidence contract

Control envelope

pwcli-core

Describe intent, side effects, approval, redaction, provenance, and receipts around the host.

Adopting application → pwos-core · explicit control adoption

Governance rail

pwos-core

Adopt PII, audit, tool, workflow, document, and related packages where the host needs them.

Private host → nexus-core · capability request

Analytical tools

nexus-core

Return documented research and analytical material through compatible APIs or MCP tools.

Planning interface

pwplan-core

Render a planning workflow across an explicit request contract and defined direct-identifier tripwire.

pwplan-core → compatible planning engine · configured contract

Adopter-selected destination

Compatible planning engine

Public or private deployment; verify the request contract and runtime configuration.

Adopter-selected origin

Selected recovery artifact

A deliberately scoped secret and operator-designed recovery ceremony.

Selected artifact workflow → shard-core · optional protection

Cryptographic primitive

shard-core

Apply authenticated encryption and threshold recovery to the selected artifact.

Published contract

Inspect a schema, package, route, test, or module in public source.

Adoption boundary

A private host must intentionally configure and verify the connection.

Human decision boundary

Approval and accountability remain outside model output.

Layer inventory

Six repositories, six bounded responsibilities

01 · Learn and inspect

pw-learnai

Self-contained modules, exercises, references, labs, and browser-only tools help humans and agents learn the public boundaries before adopting them.

Boundary: Learning material and source links. It does not grant runtime authority or prove that a learner followed the material.

02 · Express intent and control

pwcli-core

Portable schemas and reference adapters make intent, policy, approvals, redaction decisions, runtime boundaries, provenance, and minimized receipts explicit.

Boundary: A control envelope around a host-selected agent runtime. It is not the model loop, an operating-system sandbox, or a credential source.

03 · Apply governance patterns

pwos-core

Reusable TypeScript packages and reference patterns cover PII tripwires, audit evidence, gated tools, workflows, documents, and related safeguards.

Boundary: Adoptable governance primitives. Publication does not prove that a private host imported, configured, or operated every control.

04 · Call analytical capabilities

nexus-core

Python APIs and MCP-compatible tools expose financial research and analytical capabilities for a compatible human-facing application or agent runtime.

Boundary: Analytical inputs for review. Outputs are not recommendations, predictions, trade authority, or control over client assets.

05 · Render bounded planning workflows

pwplan-core

A React interface uses an explicit planning contract and a defined direct-identifier tripwire before calling a compatible planning engine.

Boundary: A public UI with an explicit request contract and named-key tripwire. Client identity, advice, authentication, and books-and-records systems remain outside it.

06 · Protect selected recovery artifacts

shard-core

Authenticated encryption and threshold recovery can protect a deliberately selected secret or recovery artifact when an adopter needs that workflow.

Boundary: An optional cryptographic primitive. It is not general storage, key custody, deployment security, or a required dependency of the other repositories.

Contract matrix

Every arrow needs a failure condition

A relationship is credible only when an adopter can identify the public contract, observe the private integration, and state what evidence would disprove the claim.

Relationship types, statements, and falsification conditions for the open-source architecture
From → toContractWhat the arrow meansClaim fails whenInspect
Human or agentpw-learnaiEducationChoose a learning path, inspect primary sources, and practice against public examples.If a module cannot be traced to its lesson, exercises, references, and cited source, the learning edge is not inspectable.Module triads ↗
Human-controlled hostpwcli-coreControl and evidenceTranslate a requested task into declared intent, policy, approval decisions, redaction outcomes, and minimized receipts.If the host can silently elevate side effects or retain raw prompt, output, tool, file, or credential content in a receipt, the control edge fails.Runtime-adapter schema ↗Run-receipt schema ↗
Adopting applicationpwos-coreGovernance adoptionSelect and configure PII, audit, workflow, tool-registration, document, or related governance packages at explicit boundaries.If a claimed control is not imported, configured, tested, and observed in the adopter, repository publication proves nothing about that deployment.Package workspace ↗
Compatible hostnexus-coreCapability requestCall a typed research capability and return analytical material to a human-facing application or governed agent workflow.If a listed API or MCP tool has no typed implementation or its output is treated as autonomous advice or trade authority, this edge is misstated.MCP implementation ↗
pwplan-coreCompatible planning enginePlanning contractSend only variables allowed by the explicit planning contract and named-key tripwire across a configured engine boundary.If the browser contract accepts blocked direct-identifier keys or embeds private identity mapping or credentials, the boundary has drifted.Planning contract ↗Identifier tripwire ↗
Selected artifact workflowshard-coreOptional cryptographic protectionEncrypt a chosen artifact and use threshold recovery only when the operator has designed an appropriate recovery ceremony.If recovery accepts corrupted or incompatible shares as valid plaintext, or if an integration implies custody or protects nothing in practice, the edge fails.Cryptographic source ↗

Trust boundary

What the public map cannot establish

Production wiring

A repository, schema, package, or example does not prove that a private deployment imports, configures, or observes it.

Compliance outcome

Controls can support a process; they do not make an adopter compliant or replace legal, regulatory, security, or supervisory review.

Client identity and records

Client identity mapping, authentication, private data, retention, and books-and-records systems are outside the public repositories.

Custody or signing authority

The map grants no model or repository access to client assets, private keys, transaction signing, or unrestricted execution.

Security guarantee

Open source improves inspectability but does not establish secure configuration, patching, monitoring, isolation, or incident response.

Commercial relationship

Permissive licenses do not create a support, hosting, implementation, advisory, or software-vendor agreement with Protocol Wealth.

Choose an entry point

Learn the boundary, then inspect the implementation

New to the stack? Start with the learning guide. Evaluating an integration? Start with the control contract, choose one capability, and require deployment evidence before calling the connection real.