MockupRepresentative mockup of the VoidLens master console. Figures are illustrative, not measurements.
Internals are withheld by design — where an internal would sit, you will see a redaction chip.liveread from the real system 2026-07-25repillustrativespecdesigned constraint
VoidLens · the Sergeant · one seat over the whole company
Cockpit — run a company of agents through one lens
The master console sits one step above every customer hub. It is where a human supervises an
AI workforce instead of prompting one: what moved overnight, what needs a signature, what is off-baseline,
and the receipt for every action. This public view is a mockup — the operating console is
customer-hosted and NDA-only. exceptions-first · audit-before-effect on instrumented paths
// needs you nowonly a human turns these · rep
The company, counted
// cross-divisional command matrix11 divisions × director × roster · live counts
Division
Director
Agents
Autonomy
Standing signal
// build readiness0–100 · rep
// audit stream curated demo pool · rep
// how to read this page
Every number is classed.live means the figure was read out of the
running system on 2026-07-25 and is a real count. rep means representative — it shows
the shape of the panel, not a measurement. spec means a designed constraint of the
architecture, true by construction rather than by observation.
The stream above is a curated demo pool. Rows are selected at random from a fixed set; no value on
this page is randomly generated, and nothing here is wired to a production log. The real console reads an
append-only audit substrate. That substrate is not exposed publicly.
Fleet — the soldiers
The doctrine is one-to-many: the Sergeant is the master console; the soldiers are
per-customer cockpits derived from it. Flow is Sergeant → Soldier, never sideways. Onboarding a customer
appends one entry to the fleet registry, and the fleet view, the headline counters and the ledger all evolve
from that single edit. derivation model · spec
// soldiers on the line live
1
One pilot cockpit stands. It is the reference derivation every future soldier is forged from.
// closed software revenue live
$0
No customer has paid. The pilot offer is out and unaccepted. We will not dress that up.
// forge time per soldier spec
1
One config edit. Every on-screen word in a soldier renders from a single object — no logic fork per customer.
// hosting model spec
Customer-hosted
The cockpit runs on the customer's machine, on the customer's own model keys.
The reference derivation. A full operator cockpit — approval queue, receipt stream, division
roster, autonomy view — skinned to the customer's brand and bound to their own instance. It exists, it renders,
it has been driven end-to-end by its intended operators. It has not been paid for, and no contract is signed.
booked $3,480repcollected $0livepilot · offer out
The evolve contract — where the next ones land
Soldier #2empty seat one registry append · zero logic fork
Soldier #3empty seat one registry append · zero logic fork
Soldier #4empty seat one registry append · zero logic fork
// why this shape mattersthe argument, not a number
The expensive thing in agent deployments is not the model — it is the per-customer
governance surface. Here that surface is one artifact: the same approval queue, the same receipt schema,
the same autonomy ladder, the same refusal behaviour, re-skinned. A new customer does not get a new codebase to
audit; they get the same audited one with their name on it. That is the multiple. It is also, today,
a claim resting on exactly one derivation — which is why the honest line above says one.
Divisions & Agents
Eleven divisions plus a cross-cutting Engineering function, 35 registered agents, one
company. Each division carries a named director lens, a roster, and an autonomy range. Click any division
to open its mandate and roster. division count, agent count and per-agent rung are
live · standing signals are rep
rung key:agentL0 observe only
agentL1 propose
agentL2 act with review
L3 · refused · see Autonomy Ladder
The directors' table
// director lensesnamed seats · live
Seat
Director
Owns
// the cabinet
No agent acts alone. Work runs under its division's director plus every director it
touches — money work gets finance's eyes, customer work gets legal's — reviewed in both directions,
with minutes recorded, before it reaches a human.
// the board
Consequential moves convene a standing critic board plus the directors' board —
two-tier review. The room recommends; the capability gate and the human authorize. A lens, never a key.
// independent review
Load-bearing work is handed to an independent adversary review that genuinely tries to
break it before it ships. A rejection stops the ship. Mechanism · REDACTED · NDA
Revenue lanes — booked versus collected
The company runs its own revenue lanes as the proving ground for the product: whatever the
agents cannot survive doing to our own books, we do not sell. The ledger separates booked from
collected on purpose — a founder steers the gap, and so should an investor.
lane count is live · every dollar figure is rep
// the honest line on this table
VoidLens has no software customers and no closed pilot revenue. No round has been raised, and
there are no outside letters of intent or commitments. The lanes below are the company's own operating ventures
plus one pilot with an offer out. Every dollar figure on this page is representative — it
demonstrates what the ledger panel does, not what the bank account holds.
// revenue lanes live
4
Three operating own-ventures plus one new proposed lane. Software pilots are tracked separately, in Fleet.
// software customers live
0
Pre-revenue on the product. One pilot offer is out and unaccepted.
// pilot offer spec
$1K–3K/mo
90-day money-back, one-page scope. Calibrated to clear procurement for a first cohort, not to anchor long-run pricing.
// agent-executed payments spec
0
Forbidden by an immutable rule. Agents model and recommend; a human moves money. Always.
// lane ledgerbooked vs collected · rep
Lane
Kind
Stage
Booked
Collected
// what the ledger is actually forthe mechanism, not the money
Every row here is assembled by an agent and reconciled against the receipt stream, then
handed to a human to act on. No agent has ever moved a dollar and none can — the capability is refused
at the gate, and each refusal emits its own receipt. An investor should read this panel as a demonstration that
the money path is observable and gated, not as a demonstration that the money is large. It is not large.
It is $0 in software revenue.
Autonomy ladder — earned one rung at a time
Every agent starts watch-only and climbs only on recorded evidence. There is no tier-skipping and
no “just this once.” A miss resets the clock. Below is the census only — how many agents sit at
each rung today. rung counts live · promotion mechanics withheld
// the top rung is empty on purposespec
Zero agents hold the fully-autonomous rung, and none can be promoted into it: it is
refused by an immutable rule, not merely unused. Most agent platforms treat full autonomy as the
destination. Here it is a line the system will not cross without a human changing the constitution — and
that change is itself gated and recorded. The ceiling is the feature.
18:24:11
38% of 48:00:00
A shadow window is running. Before any agent moves up a rung it runs a fixed observation
window doing the real job with its hands tied, while the system watches. At the end of the window a promotion
decision — not an automatic promotion — lands in a human's queue. One unbudgeted action or one refused
call and the clock returns to zero. The system resets it; the agent's good intentions do not.
rep clock · spec rule
The criteria a promotion must satisfy are the substance of the
architecture and are covered by pending provisional applications. Under NDA, an evaluator sees the full gate
list, the thresholds, the evidence each gate consumes, and the recorded history of every promotion and
demotion the system has performed on itself. What is public is the shape: a fixed observation window,
a fixed set of gates, a human signature, and an automatic reset on any miss.
The approval queue — where the human stays the boss
Anything touching money, publication, or autonomy stops here. The agent does the work,
assembles the artifact, and then waits. Open an item to see what it would do and what happens either way; approve
or send it back and a receipt lands either way. A send-back is not a failure — it is a routed note the
agent has to answer. interactive demo · every item rep
Queue clear. The company keeps running; the receipts keep landing.
// what an approval actually carriesthe part that survives an audit
Each item in the real console carries the artifact itself, an editable draft, the
consequence of approving, the consequence of sending it back, and the identity of every reviewer that touched
it. Approve and the receipt lands before the effect on instrumented paths. Send it back and the note is
routed to the agent and kept. Reviewer identities, capability diffs and evidence packs · REDACTED · NDA
VoidLens · the Sergeant · the operator’s working surface
Workspace — what is in flight, and what needs your name on it
The cockpit is the read; the workspace is the doing. Everything the workforce has open, everything
stopped at a human signature, and the shelf of documents the whole company is grounded in — on one surface, so a
founder never has to go looking for the state of their own company.
work items are rep · the stop-at-a-signature rule is spec
// in flight rep
6
Work the agents have open right now. Each one carries its division, its rung, and a running receipt trail.
// waiting on a signature rep
3
Stopped, not slowed. Money, publication and autonomy always come to a human before they land.
// memory index · documents live
0
The searchable institutional memory the operating console binds this viewer to. Eleven representative documents are readable on the shelf below.
// items an agent may land alone spec
0
Nothing on this surface can complete itself. That is a rule of the architecture, not a setting on this page.
// in flightdivision · rung · state · rep
// needs your signatureonly a human turns these · spec
The document shelf
// reading shelfclick any card · opens in the built-in viewer
// what a real workspace carrieswithheld by disclosure class
Live work queue, per-item evidence packs, reviewer identities, capability diffs and the write-path internals — REDACTED · NDA
In the operating console every row here is a real work item bound to its own
receipt trail, its draft artifact, and the identity of every reviewer that touched it — and the shelf is the whole
institutional memory rather than eleven public documents. What is public is the shape: work is visible, work is
attributed, and the consequential classes stop at a signature.
VoidLens · Iris · Command Deck
Iris Command Deck
The operator’s command surface: threads on the left, the model seat on the right, and a
governed write-path for anything that would change the company. Talking is free. Changing is not — a change
is staged outside the working tree, written by a sanctioned writer with a hash receipt, refused by default at the
capability gate unless it was granted in advance, put in front of an independent reviewer, and only then opened as an
observation window. This deck is a scripted mockup — the buttons below replay a real sequence, they do not
call a model. any model · your keys · same rails, same gates · rep
OPERATOR COMMAND DECKgoverned write-pathseat:BYOK · named on every receipt
// why the seat is a dropdown
The model is pinned at onboarding, its exact version is named on every receipt, and it can
be swapped without touching a single rail. The customer brings their own key and the cockpit runs on the customer’s
machine — so model spend, and model choice, stay theirs. A governance layer that only works on one vendor’s
model is a governance layer with an expiry date.
// what the deck cannot do
It cannot land a change by itself. A chat is not an authorization: the same gate, the same
independent review and the same human signature sit between this box and any effect on the company.
Write-path internals · capability model · REDACTED · NDA
VoidLens · Iris · Second Brain
Iris — the second brain
Ask the company about itself. Every answer cites the documents it rests on, and every number in an
answer carries the same class chip the rest of this page uses. This is the asset that does not walk out of the building
with a departing employee — institutional memory you can interrogate.
The knowledge base in this mockup is a fixed, investor-facing set; the operating console binds the same surface
to the full live 3,934-document memory.
try: what does this company do · what is the moat · what is not built yet · what is the honest risk
// what this surface is honestly doingread this before you judge the answers
This mockup matches your question against a fixed knowledge base of curated answers and returns
the matching one. It does not call a model, it is not retrieval-augmented, and it will say so rather than invent an
answer it does not have. The operating console does the real thing — a query against the institutional memory with
the source documents attached — but publishing that surface would publish the memory.
Retrieval pipeline · memory contents · REDACTED · NDA
IP & moat
The defensible position is filed, dated, and deliberately under-disclosed. What is public is the
existence and the timing; what is protected is the mechanism.
all filings and corporate facts on this page are live
Provisional applications live
4 filed
Three filed 2026-06-03, one filed 2026-07-03. These are provisional
applications — they establish filing dates. No patent has been granted, and we do not say otherwise.
Trademark live
VOIDLENS
Filed 2026-06-04 at the USPTO on an intent-to-use basis. Filed, not registered.
Entity live
Delaware C-Corp
VoidLens, Inc. incorporated 2026-07-08. Clean cap table, single founder, no outside
capital taken to date.
Disclosure posture spec
Local only
The operating instances are not published. Investor and evaluator conversations are
NDA-gated. We do not seed our own prior-art surface to look impressive on a website.
The compounding assets
// memory index live
0
Documents in the searchable institutional memory. Every decision, incident and rationale the
company has produced is retrievable — this is the asset that does not transfer with a departing employee.
// sessions archived live
0
Complete working sessions preserved. The system's own operating history is evidence of how it
behaves under real load — including the failures.
// canon files live
0
The written constitution the agents run under: rules, conventions, postures, red lines. Machine-
readable, versioned, and the thing that makes behaviour reproducible rather than emergent.
A public investor page is a disclosure surface. Publishing the
mechanism of a pending provisional application is how a company donates its own moat. Under NDA an evaluator
gets the filings, the architecture, the running instance, and a walkthrough of the mechanism against live
behaviour. Here you get the dates. The discipline you are watching on this page is the same discipline
that governs the agents.
Trust & governance — safety is the product
Every shipping AI agent is a liability surface somebody's compliance team is going to ask about.
The rails below are the answer to their first ten questions, and they were built in from message one rather than
bolted on. rail behaviour is spec · rule bodies withheld
// immutable rules live
26
A fixed set of actions the system refuses regardless of instruction. The count is public on our
trust page; the rule bodies are NDA-only.
// agents at full autonomy spec
0
Not “none yet.” None permitted — the top rung is refused by rule.
// agent-moved money spec
0
Payments, trades and transfers are refused at the gate. Analysis is the agent's job; execution is the human's.
// refusals that emit a receipt spec
100%
A refusal is an event, not a silence. Failures emit rows too — that is the whole point of the substrate.
// the railsbehaviour public · mechanism withheld
// what an evaluator gets under NDA
The rule bodies. The capability model. The gate mechanics and their thresholds. The
independent-review pipeline and its recorded verdicts, including the ones that went against us. The instance
itself, driven live. The failures are part of the package — a governance story with no recorded
rejections in it is a governance story that has never been tested.
// the honest bound
Claims on this page are held at the strength they actually have. Some rails are enforced
by policy on instrumented paths rather than by cryptography; where that is true we say so rather than saying
“tamper-proof.” The hardened enforcement plane is on the roadmap and is not claimed as shipped.
An investor should weight a company by what it refuses to overstate.
The ask — stated at its true stage
The most useful thing this console can do for an investor is refuse to flatter itself. Here is
where the company actually is. status live · offer terms spec
// where we actually are
No customers yet. No round raised. No outside LOIs, intros, or commitments. VoidLens is a
working system built and operated by one founder. The stage is finding the first operators willing to run a
paid pilot — not closing a financing.
The pilot offer: $1K–3K per month, 90-day money-back, one-page scope agreement. Bring
your own model key; the cockpit runs on your machine. Calibrated to break the procurement barrier for a first
cohort, not to anchor long-run pricing.
An investment at this stage backs operator-tested infrastructure and a filed IP position before
revenue — with the risk and the entry point that implies. We won't dress that up.
Pipeline, at its true stage
// pipelinestage counts · live
Stage
Count
What that word means here
Closed / paying
0
No customer has paid VoidLens for software.
Signed
0
No contract, LOI, or written commitment exists.
Offer out
1
Soldier #1 — a pilot cockpit built and driven by its intended operators; the offer is out and unaccepted.
Round raised
$0
No outside capital taken. Single-founder cap table.
// what is real today
35 agents across 11 divisions under a written constitution of
127 canon files. A 3,934-document institutional memory and 2,905 archived sessions.
Four provisional applications and a filed wordmark. One derived customer cockpit. All
live counts, host-verified 2026-07-25.
// what is not real yet
Revenue. A second customer. A hardened enforcement plane. A team beyond one operator.
Multi-tenant hosting. Any independent audit of the claims on this page. We list these because you were
going to find them, and a company that surfaces its own gaps is cheaper to diligence.
// what a conversation looks like
Under NDA: the running instance driven live, the filings, the rule bodies, the gate
mechanics, the recorded independent-review verdicts including the rejections, and the full operating history.
Nothing on this page is the pitch — the running system is.
This page is a representative mockup of the VoidLens master console, published for
investor context. It is not connected to a production system, no figure on it should be relied upon as a
measurement, and the operating console it depicts is not publicly deployed. Figures marked
live were read from the running system on 2026-07-25 and are counts, not
projections. Figures marked rep are illustrative. Figures marked
spec are designed constraints. Provisional patent applications are filings, not
granted patents; the trademark is filed on an intent-to-use basis and is not registered. VoidLens is
pre-revenue.