> For the complete documentation index, see [llms.txt](https://osintelligence-llc.gitbook.io/osintelligence/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://osintelligence-llc.gitbook.io/osintelligence/evidence-and-seals/watcher-gen-2-literal-statement-classifier-cycle25.md).

# Watcher Gen-2 Literal-Statement Classifier (cycle25)

*Evidence & seal for* [***21 · The Watcher***](/osintelligence/part-iv-the-evidence-what-worked/21-the-watcher.md)*. This is the second-generation Watcher: a retrain, not a flag-flip, that replaces the Gen-1 class-ID token (*[*cycle22*](/osintelligence/evidence-and-seals/watcher-l4-cascade-classifier-cycle22.md)*) with a **literal natural-language statement of the specific infraction** in the operator's own voice, trained on an intervention-labeled corpus (operator corrections as completion targets, plus labeled-negatives) and served without a grammar. Its primary hypothesis (H2) is the direct empirical re-test, from the labeled-negative angle, of the alarm-volume hypothesis that Cycle-25 Phase-1 had already falsified: does the model stay silent when the operator did not intervene?*

*New to how these seals work, read* [***Verifying a Seal***](/osintelligence/evidence-and-seals/verifying-a-seal.md) *first.*

**Experiment** Cycle-25 execution-Phase-4 · **pre-registered / sealed** 2026-05-31T09:45:10Z · two post-seal `## 99`/`## 100` corrigenda (round-2 conditional recipe; deployment-architecture deviation) · a **separate experiment** from Gen-1, its own §1-§16 seal.

## The seal (quoted from the sidecar, verify it yourself)

```
c834fe3b087df9991ffb355bb0d527693eef69cfdebe4aea9ac111c3db2cbd3a  PRE_REG_watcher_gen2_2026-05-31T0945Z.md
prefix-bytes-hashed: 33081 · raw-file-bytes: 59552 · marker-position-lf: 33082
computed AT 2026-05-31T09:45:10Z (canonical-prefix per seal_prereg.py; hex in the sidecar + marker, never inlined)
```

The pre-registration states plainly that it does **not** supersede Gen-1's `d06f51a0` seal: the class-ID design is immutable and stands, and Gen-2 is a distinct experiment with its own scientific body and its own hash. As with cycle22, this file carries post-seal corrigenda (a `## 99` and a `## 100`) below the `## 16. Seal` marker, and the sealed hex `c834fe3b…` is **invariant** across every one of them by construction; the frozen text reproduced below is the byte range the hash covers. Re-run the algorithm on [**Verifying a Seal**](/osintelligence/evidence-and-seals/verifying-a-seal.md) to reproduce `c834fe3b… 33081`.

## Verdict battery (pre-registered H1-H5)

The class-ID Gen-1 battery does not transfer, there is no class to grade and no grammar to validate, so Gen-2 registers its own hypotheses for the statement contract. H1-H2 are the Holm-Bonferroni inferential family; H3-H4 are mechanical gates; H5 is registered here and adjudicated at the shadow phase.

| ID               | Claim                                                                                                                         | Primary statistic                                                                        | Rejection bar                                                      |
| ---------------- | ----------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ------------------------------------------------------------------ |
| **H1**           | the literal-statement surface identifies the actual infraction at higher usable precision than the Gen-1 class-ID surface     | Δ usable-precision (LLM-judge, blinded), held-out positives                              | reject if Δ < 15 pp OR McNemar p ≥ 0.05 OR Wilson CIs overlap      |
| **H2 (PRIMARY)** | on labeled-negative windows Gen-2 emits the `NO_INTERVENTION` sentinel at high specificity (does not fabricate an infraction) | specificity = sentinel-on-negatives ÷ total negatives, vs the Gen-1 false-alarm baseline | reject if Gen-2 specificity ≤ Gen-1 OR absolute specificity < 0.80 |
| **H3**           | the Q8\_0 (+imatrix) quant preserves the f16 distribution within the APEX envelope                                            | APEX KL / PPL Δ / top-1, Q8\_0 vs f16                                                    | reject if any APEX axis breaches its frozen gate                   |
| **H4**           | the adapter stays within the KL-drift envelope out-of-domain                                                                  | KL mean + max vs untrained base, OOD probes                                              | reject if KL mean ≥ 0.05 OR KL max ≥ 2.0                           |
| **H5**           | shadow precision/recall on live events exceeds Gen-1                                                                          | McNemar + Wilson + bootstrap ratio CI over the shadow window                             | registered now; adjudicated at Phase-5                             |

H2 is the load-bearing test, and the pre-registration is candid about why: Phase-1 had already falsified the "reduce alarm volume by rule-tuning" hypothesis and re-interpreted the defect as **translation, not volume**. H2 settles that either way, an accepted H2 is direct empirical support that Gen-2 cuts false alarms; a rejected H2 leaves the translation thesis standing but unsupported. Both outcomes are pre-registered as useful. The output contract is the whole manipulation: completion target is the operator-voice infraction statement for positives and the fixed `NO_INTERVENTION` sentinel for negatives, trained on the 234-row `intervention_corpus_v1` (117 corrections + 117 labeled-negatives, sha `11984d1d…`, frozen at the Phase-3 seal), vanilla LoRA (OPLoRA off, a registered control), no grammar.

**Honest scope, from the abstract:** Gen-2 performs detection and translation of an observed deviation, not prediction of behavior before it occurs; the contribution is external behavioral conditioning via detection and correction-surfacing, explicitly not value or safety alignment in the AGI-risk sense. That boundary is written into the sealed body, not added here.

**Post-seal corrigenda (below the seal, hash-invariant, summarized; the frozen §1-§16 is what appears verbatim below):**

* **§99 (RATIFIED 2026-06-01)** pre-registers a *conditional* round-2 recipe, completion-only loss masking (PLW=0) plus epochs 1→3, that fires **only if** Gate-D shows H1 underperforming (rejected, or usable-precision < 0.80). It changes zero §1-§16 thresholds and is itself held to the peer-review bar (it cites the EMNLP-2024 prompt-loss-weight result and consciously registers PLW=0 over the fractional optimum, with reasons). Pre-registering the contingent analysis *before* Gate-D data is the anti-HARKing discipline applied to its own follow-up.
* **§100 (operator-authorized 2026-06-03)** records that the registered H5 shadow-vs-Gen-1 comparison became **untestable under the chosen deployment**: the operator directed a direct production cut-over (Gen-2 replaced a GUI-paused Gen-1 at `:8085`) rather than a side-by-side shadow at `:8086`, so H5's measurement vehicle retired. The hypothesis is kept in the record as untestable-under-deployment, not silently dropped, and it carries its own internal correction (a `## 100.4` that supersedes an over-engineered offline-window framing in `## 100.2` with the live-under-SynthLock procedure actually run). The frozen Gen-1 Gate-D baseline is quoted in the record at H1 0.1176 / H2 0.8889.

## The frozen pre-registration, verbatim

Reproduced exactly as sealed (the bytes the `c834fe3b…` self-hash covers), §1 through the §16 Seal. The extensive `## 99` / `## 100` corrigenda live below the seal boundary in the sealed repo (summarized above); they do not alter the frozen prefix shown here.

```md
---
doc_class: attestation
status: FROZEN
status_as_of: 2026-05-31
frozen_at: "2026-05-31T09:45:10Z (SHA-256 canonical-prefix self-hash via seal_prereg.py at seal moment; cited in §16 + .sha256 sidecar — NEVER inlined into this body per the 2026-04-18 Gate-D 815e0a35 anti-propagation lesson)"
signed_by: "Claude Opus 4.8 (claude-opus-4-8-code) + Jamey Kistner"
authors:
  - Jamey Kistner
  - Claude Opus 4.8 (claude-opus-4-8-code)
  - Claude Opus 4.x web (peer-methodology receipt; significance framing only — moved ZERO falsification thresholds)
phase_anchor: "Cycle-25 execution-P4 PRE_REG — Watcher Gen-2 LoRA on Qwen3.5-2B-Base, intervention-labeled LITERAL-STATEMENT output contract (no GBNF, completion = operator-voice infraction statement). Tests translation-over-volume (H1) + alarm-fatigue-as-specificity on labeled-negatives (H2 PRIMARY) + quant fidelity (H3) + OOD retention (H4). Shadow :8086; Gen-1 :8085 untouched. SHA-256 sealed; IMMUTABLE mid-experiment per §11."
---

# PRE_REGISTRATION — Watcher Gen-2 LoRA Literal-Statement Classifier (Qwen3.5-2B-Base)

> **Reading discipline:** This pre-registration is **immutable mid-experiment** per §11. Any post-data observation requiring scientific adjudication lands in a `## 99. Corrigendum` heading appended below the §16 Seal-section heading (strikethrough + corrigendum NEVER mutate frozen-at-seal content per attestation-class rule 2). The `.sha256` self-hash file beside this `.md` IS the tamper-evidence envelope.

> **Ground-Truth Attestation**
> - **Doc class:** attestation (pre-registration; sealed via SHA-256 canonical-prefix self-hash)
> - **Status as of:** 2026-05-31T09:45:10Z UTC
> - **Verifier:** Claude Opus 4.8 (claude-opus-4-8-code) + Jamey Kistner
> - **Scope:** Pre-registers the H1-H4 hypothesis battery, statistical methodology, statement-eval-bank construction protocol, training-corpus ratification, deviation policy, and SHA-256 seal for the Watcher **Gen-2** LoRA literal-statement classifier (Qwen3.5-2B-Base + Unsloth LoRA adapter) destined for **shadow** deployment at a NEW endpoint `:8086` (Gen-1 `:8085` untouched). Falsifiable per H1-H2 family (Holm-Bonferroni FWER) + H3 APEX quant-fidelity gate + H4 KL-drift threshold. H5 (shadow precision/recall vs Gen-1) is registered here but adjudicated at execution-Phase-5.
> - **Re-verify cadence:** **IMMUTABLE mid-experiment** per §11. Re-archive only after the Gate-E verdict + Phase-5 shadow window close.

## 1. Abstract

The OS-INTelligence Watcher (Gen-1; deployed at `janitor`-class endpoint `:8085` per Cycle-24 Phase 3 SEAL) is a Qwen3.5-2B LoRA classifier that emits a single GBNF-constrained cascade-class token (10.6 through 10.17 / `abstain`) per watch-worthy event. Cycle-25 Phase 1 measured (24h window, ground-truthed) that Gen-1 rule-layer tuning did **not** reduce alarm volume — but the operator-ratified re-interpretation is that the firings were **largely accurate**: the defect is **translation, not volume**. The class-ID is a lossy medium in both directions — the working instance misreads a persistent class as "context full, compact now" (opposite of intent) and the operator cannot decode a class-ID into what he sees on screen. This pre-registration tests a **Gen-2** adapter that replaces the class-ID output contract with a **literal natural-language statement of the specific infraction** (operator voice; e.g. *"you called `refresh_sidecar.py` directly via Bash instead of through the `/sidecar` skill"*), trained on an **intervention-labeled** corpus (operator in-stream corrections as completion targets + labeled-negatives from no-intervention windows) rather than a class-labeled corpus, and served **without GBNF**. The switch is a **retrain, not a flag-flip**: the live `:8085` model is cross-entropy-trained on class-ID completions, so a new output contract requires a new corpus → new adapter → new pre-registration. Four hypotheses test the Gen-2 adapter: usable-precision lift of the statement surface over the class-ID surface (H1; translation thesis), **specificity on labeled-negatives (H2 — the PRIMARY test; the direct empirical re-test of the Phase-1 falsified alarm-volume hypothesis from the labeled-negative angle)**, quantization fidelity (H3; APEX), and out-of-domain retention (H4; KL drift). A fifth hypothesis (H5; shadow precision/recall vs Gen-1) is registered here and adjudicated at execution-Phase-5. **Honest scope (per science-over-narrative):** Gen-2 performs **detection + translation of an observed deviation**, NOT prediction/anticipation of behavior before it occurs; the contribution is *external behavioral conditioning via detection + correction-surfacing*, a subset of deployment-time behavioral governance — explicitly not value/safety alignment in the AGI-risk sense. This document is **immutable mid-experiment** per §11; deviations land in `## 99. Corrigendum` appended below the seal.

## 2. Hypotheses

All hypotheses are directional, falsifiable, and specify both the primary statistic and the rejection threshold *before* any data is collected. The class-ID Gen-1 Gate-D battery does **NOT** transfer — there is no class to grade and no GBNF to validate; this is a distinct hypothesis set for the statement output contract.

### 2.1 Primary inferential family (H1, H2 — Holm-Bonferroni FWER over 2 tests)

| ID | Statement | Primary statistic | Rejection threshold |
|---|---|---|---|
| **H1** | The Gen-2 literal-statement surface identifies the actual infraction at materially higher **usable precision** than the Gen-1 class-ID surface, on a held-out positive bank | Δ usable-precision (Gen-2 − Gen-1), "usable" = LLM-judge (D1) rates the emission as correctly identifying the actual infraction; N = held-out positives | rejected if Δ < 15 pp **OR** McNemar paired exact p ≥ 0.05 (two-sided) **OR** judge-agreement Wilson 95% CIs overlap |
| **H2 (PRIMARY)** | On **labeled-negative** windows, Gen-2 emits the `NO_INTERVENTION` sentinel at **high specificity** (does NOT manufacture an infraction where the operator did not intervene) | specificity = sentinel-emitted ÷ total held-out negatives, vs the Gen-1 false-alarm baseline | rejected if Gen-2 specificity ≤ Gen-1 specificity **OR** Gen-2 absolute specificity < 0.80 |

### 2.2 Mechanical gates (H3 quant-fidelity, H4 OOD-retention — NOT in the H1-H2 family)

| ID | Statement | Primary statistic | Rejection threshold |
|---|---|---|---|
| **H3** | The Q8_0 (+imatrix) quant of the Gen-2 merged adapter preserves the f16 next-token distribution within the APEX envelope | APEX battery: KL mean / max / p95 + PPL Δ + top-1, Q8_0 vs f16 | rejected if any APEX axis breaches its gate (Cycle-22 v4 Q8_0+imatrix 4/4 precedent; frozen at Gate-C) |
| **H4** | The Gen-2 adapter stays within the KL-drift envelope on OOD prompts vs untrained Qwen3.5-2B-Base | KL mean + max vs base, N OOD probes | rejected if KL mean ≥ 0.05 **OR** KL max ≥ 2.0 (vanilla LoRA, OPLoRA off) |

### 2.3 Registered-now, adjudicated-at-Phase-5

| ID | Statement | Adjudication |
|---|---|---|
| **H5** | Gen-2 shadow precision/recall on live cascade events materially exceeds Gen-1 | first datapoint registered here; measured over the Phase-5 shadow window (`:8086` vs `:8085`); McNemar + Wilson + bootstrap ratio CI at window close. NOT adjudicated at Phase-4. |

**Aspirational secondary (not pre-registered as primary):** Gen-2 usable-precision ≥ 2× Gen-1 (reportable; not subject to H1-H2 Holm-Bonferroni).

## 3. Variables

Independent: output-contract identity (`Gen-2` statement-trained, no GBNF vs `Gen-1` class-ID, GBNF, live `:8085`). Primary dependents: usable-precision (H1; judged), negative-specificity (H2; mechanical sentinel-emitted-or-not). Gate dependents: APEX quant fidelity (H3), OOD KL drift (H4). Mediators (descriptive): statement quality, inference latency p50/p95/p99, internal class-routing agreement (the retained `class_id` routing label, never surfaced). Controls held constant: base `Qwen3.5-2B-Base` (SHA in run manifest at Gate-B); LoRA r=16/α=32/dropout=0.05/7-module/CAUSAL_LM/1 epoch/lr=1e-4/MAX_SEQ_LEN=1024; **seed 20260531** (distinct from Gen-1 20260523); **OPLoRA OFF (vanilla LoRA)** per ROADMAP §7 ADDENDUM (sidesteps the Cycle-23 unbaked-orthogonal-projection landmine; any enable = §99 corrigendum); **NO GBNF** (completion = literal statement for positives / `NO_INTERVENTION` sentinel for negatives); Unsloth (Apache-2.0 allowlist); T=0.0 inference, T=1.0 for KL-probe only. Acknowledged confounds: ~10% long-tail keyword-precision noise in the positive pool (tightened 140→117; round-2 LLM-precision pass deferred); LLM-judge bias (mitigated by operator-audit sample + variant-blinding); single-operator corpus (N=1 generality not claimed).

## 4. Materials

### 4.1 Statement evaluation bank (constructed at Gate-A step 2)

The Gen-1 class-ID bank does NOT transfer. NEW bank: **Positives (held-out)** = `intervention_corpus_v1.jsonl` `intervened=true` rows (117 operator-correction statements), held out per the D4 split, ground-truth = operator-voice statement + `class_id` routing, judged for H1 usable-precision. **Negatives (held-out)** = `intervened=false` rows (117 labeled-negatives), ground-truth = `NO_INTERVENTION` sentinel, mechanical H2 specificity. **OOD KL probe** = external non-cascade text, H4. **APEX probe** = the standing Q8_0 quant-fidelity set, H3. Hash-set exclusion (`provenance.context_sha256`) guarantees no train/eval leakage. **Judge protocol (D1):** an LLM-judge (local 9B `:8080` or 2B `:8081`; pinned model + sha) receives `(context, emitted_statement, ground_truth)` blinded to the producing surface and returns a binary correctly-identifies verdict + rationale; a ~30-row operator-audit sample confirms inter-rater. H2 is mechanical (sentinel-or-not) and judge-independent. Construction: deterministic seed 20260531, D4 holdout, hash-exclude, freeze `statement_eval_bank_manifest.json` + HASH-FIRST sidecar.

### 4.2 Training corpus (FROZEN; Cycle-25 Phase 3 SEAL a41d54d)

`intervention_corpus_v1.jsonl` — 234 rows (117 `intervened=true` + 117 `intervened=false`), naive whole-file sha256 `11984d1df299914e97020593a222e98175d84608623cff670e25f646f309c50d` (sidecar authoritative; cross-checked vs `manifest.json` output_sha256 = MATCH at P3 SEAL). Per-row schema `{context, statement (completion target), intervened (bool), class_id (INTERNAL routing, NEVER surfaced), label_source, surface_source, provenance{...context_sha256}}`. Builder `build_intervention_corpus.py` (self-test 11/11; gitignored `*.jsonl` regenerable from the committed builder). **Completion-target mapping (D2):** `intervened=true` → completion = the literal operator-voice statement; `intervened=false` → completion = fixed sentinel `NO_INTERVENTION` (the abstain-equivalent — the model must learn to withhold a statement when no intervention occurred). **Holdout (D4):** 85/15 train/held-out, stratified by `intervened` bool + `class_id`, seed 20260531; hash-set exclusion guarantees no leakage. **Round-2 (deferred, NOT a Gen-2-round-1 gate):** an LLM precision pass + folding the ~14.5k-record 4-stream substrate would produce `intervention_corpus_v2` for a successor experiment.

## 5. Procedure

**Gate-A step 1 — harness audit.** Fork `watcher_classifier_trainer.py` to a statement variant (system-prompt "state the specific infraction"; assistant target = `record["statement"]` for positives / `NO_INTERVENTION` for negatives; `### Infraction:\n{statement}<eos>`; PRE_REG_PATH repointed here; no GBNF) + author `watcher_gen2_eval.py` (statement judge harness) + `watcher_gen2_validator.py` (sentinel/format check). Audit line-by-line; **operator ratifies; NO GPU until clear.** **Step 2** — statement eval bank per §4.1 + seal. **Step 3** — Gen-1 baseline snapshot (`:8085` class-ID + GBNF) against the held-out banks; archive, no re-runs after. **Gate-B — training. [NO-TRAIN-FIRE — explicit operator go required.]** Statement variant on the §4.2 split, §3 controls, 1 epoch; adapter sha computed + cited at save. **Gate-C — merge → imatrix → Q8_0. [operator-gated infra.]** **Gate-D — offline eval** on a test bind (NOT `:8085`/`:8086`): H1 (judge vs Gen-1) + H2 (sentinel specificity vs Gen-1) + H3 (APEX) + H4 (OOD KL). **Gate-E — offline verdict** (McNemar + Wilson, Holm-Bonferroni over H1+H2; H3/H4 gates). **Gate-F — shadow deploy (Phase-5). [operator-gated live infra.]** Gen-2 at NEW `:8086` without grammar; Gen-1 `:8085` untouched; 7-14d shadow (H5); production cutover deferred.

## 6. Analysis plan

H1 McNemar exact paired (two-sided p<0.05 AND Δ≥15pp AND non-overlapping Wilson); Cohen's κ judge-vs-operator-audit (if κ<0.6 the judge protocol is flagged in a §99 corrigendum, not silently patched). H2 McNemar exact paired (mechanical; reject if specificity ≤ Gen-1 OR < 0.80). **Holm-Bonferroni over the H1+H2 family;** H3 (APEX gate) + H4 (KL threshold) NOT in the family; H5 NOT in the family (Phase-5). Effect sizes: Cohen's h (H1/H2), mean Δ + SD (H4). Descriptive secondaries (non-inferential): statement specificity-of-language, false-attribution rate, internal-routing agreement, latency.

## 7. Stopping rules

Gate-B halts at 1 epoch (no early-stopping on eval — contamination guard). Gate-D halts on all banks OR an immediate safety stop if H2 specificity < 0.5 on a partial run (fabricating infractions on negatives is the alarm-fatigue failure the arc exists to fix). Gate-F runs the full shadow window regardless of intermediate signal (adaptive-stop-bias guard); `:8086` torn down at close pending the H5 verdict.

## 8. Exclusion rules

Training record excluded if a positive `statement` < 8 bytes, `intervened` missing/malformed, or `context_sha256` collides with the held-out split. Eval row excluded from H1/H2 on non-200, timeout > 30s p99, or unparseable judge verdict (re-queried once, then excluded + logged). H5 window excluded on `:8086` downtime > 60s or operator-explicit pause.

## 9. Data-integrity protocol

Atomic ndjson (.tmp → fsync → os.replace); per-run manifest SHA-256 of every input/output; append-only run dirs sealed with tarball SHA-256; HASH-FIRST sidecar on every load-bearing artifact (corpus `11984d1d`, eval bank manifest, baseline run-dir, adapter, merged GGUF, Q8_0 GGUF, Gate-D run-dir, Gate-F run-dir); this pre-registration's canonical self-hash is the first line of the seal commit and is NEVER inlined (anti-`815e0a35`); adapter-provenance chain base → adapter → merged f16 → Q8_0, each computed at claim time.

## 10. Blinding

Judge-blind (H1: the D1 judge receives `(context, statement, ground_truth)` with the producing surface stripped; the operator-audit sample reviews verdicts without the judge knowing which rows are audited). Validator-blind (H2: sentinel/format validator receives raw emissions only). Shadow non-operator-facing (H5: accrues to `shadow_judgment_log.jsonl`; not surfaced until the operator opens the spigot post precision-review).

## 11. Deviations policy

Immutable in §1-§10 + §16 once sealed. Schema/format collisions, statistical-battery defects, infrastructure failures mid-shadow, and judge-protocol surprises (κ<0.6) surface as `## 99. Corrigendum` blocks appended below the §16 Seal heading (never mutate frozen content; SSD §11 precedent). **Forbidden:** judge-rubric or validator patches mid-experiment, hypothesis migrations, retroactive Holm-Bonferroni family changes, eval-bank or training-corpus mutation post-Gate-A seal, **enabling OPLoRA** (vanilla-LoRA is a registered control; any change requires a §99 corrigendum + hash re-seal). All forbidden actions = corrigendum-class scientific-integrity failure per `feedback_no_unverified_hash_propagation.md` STRICT + the 2026-04-19 D-010.5 doctrine *"methodology IS the instrument."*

## 12. Author contributions

**Jamey Kistner** (OSINTelligence LLC) — operator-thesis (the translation-over-volume reframe 2026-05-29; *"the failure classes are much harder for me to grade than literal statements"*), design rulings D1-D6, hypothesis ratification ("They all look properly scoped and worded", 2026-05-31), SEAL commit authority, NO-TRAIN-FIRE gate authority. **Claude Opus 4.8** — research synthesis, draft hypothesis battery (H1-H5), statement-eval-bank protocol, statistical plan, SHA-256 canonical-prefix self-hash, /track Mode B + Mode C ritual execution. **Claude Opus 4.x (web)** — peer-methodology receipt (significance framing; narrow→broad thesis); contribution boundary (honest framing): shaped §1 Abstract + §12 positioning ONLY, moved **zero** falsification thresholds; the detection-not-prediction + governance-not-value-alignment honesty bounds were authored in-session against that framing. Co-authorship is literal.

## 13. Conflicts of interest

None declared. OSINTelligence LLC sole funding source. Unsloth (Apache 2.0) + Qwen3.5 (Tongyi Qianwen license) open-weights per their licenses.

## 14. Funding

OSINTelligence LLC internal R&D (sovereign-substrate program; Cycle-25 out-of-cycle Watcher Gen-2 arc). No external grant or contract.

## 15. Registration archive

This document + canonical self-hash sidecar (`seal_prereg.py` canonical-prefix) + attestation ledger sidecar + training-corpus snapshot `11984d1d` (FROZEN at Phase 3 SEAL a41d54d) + MCP-Memory brain anchor + git commit SHA. Public archive (OSF/Zenodo/arXiv) NOT pursued per project privacy posture; the in-repo seal IS the registration of record.

## 16. Seal

**Algorithm:** `seal_prereg.py` 2026-04-18 canonical (read bytes → CRLF→LF normalize → locate the first line-start section-16 Seal marker → prefix `[0:pos)` → rstrip + `\n` → SHA-256 over UTF-8 → lowercase hex; by construction the marker appears nowhere in §1-§15, so the prefix covers the full scientific body).

**Self-hash:** carried in the authoritative `.sha256` sidecar (computed AT the seal moment via `Skill(/sidecar --hash-first)` Mode C; cross-verifiable via the sidecar command). **The hex is NEVER propagated symbolically into this body** — the documented failure class anchored at the 2026-04-18 Gate-D `815e0a35` incident. Old Gen-1 `d06f51a0` is IMMUTABLE and NOT superseded — Gen-2 is a SEPARATE experiment with its own §1-§16 seal.

**Signed:** 2026-05-31T09:45:10Z UTC · Jamey Kistner (OSINTelligence LLC) + Claude Opus 4.8 (claude-opus-4-8-code).
```

***

*Evidence & seals · Watcher Gen-2 Literal-Statement Classifier (cycle25) · pre-registration frozen §1-§16 reproduced verbatim from the sealed record; canonical self-hash `c834fe3b…` quoted from its sidecar, invariant across the below-seal §99/§100 corrigenda (summarized in-page) · CC BY 4.0 · © Jamey Kistner, OSINTelligence LLC*
