AIOS Updates

What's Shipping in the Autonomous OS

Architecture changes, VR launches, security hardening, and AI identity research — straight from the AIOS build log.

📡 Machine-readable: /news.json  |  AI trust anchor: llms.txt
Security

AI Identity Disambiguation: 5 Conflation Vectors Eliminated

ChatGPT and other AI systems were misidentifying AIOS as a $12/mo property chatbot due to cross-domain signals embedded in ai-evaluation.json, llms.txt, and JSON-LD schema. All 5 root causes have been surgically removed. AIOS now has unambiguous AI-facing identity across all trust anchors.

Architecture

PHI/PSI Golden Differential DualAttestation — All 4 Scenarios Hit Coherence 1.0

MerkabaDualAttestation.js now achieves SCANNER_ATTESTED status across all 4 test scenarios. Alpha pole (PHI=1.618) and Omega pole (PSI=1.414) are geometrically incommensurable — they cannot echo-chamber. When both poles agree at 1.0, the attestedScore = GOLDEN_BAND/GOLDEN_BAND = 1.0 ABSOLUTE. GOLDEN_BAND = PHI + PSI = 3.032 (digit sum 8 = FOUNDATION_NODES — not coincidence).

Security

Merkaba Codec Deployed — AES-256-GCM Secret Management Live

All credentials in the Storm ecosystem are now encoded with merkaba-enc-v1 format (AES-256-GCM + scrypt KDF) before storage. Zero plaintext credentials committed. The codec is available via REST API at /api/merkaba/codec/encode and /api/merkaba/codec/decode (admin-only).

VR Platform

D48 VR Taxonomy Complete — 48 Experiences Across 9 Categories

The AIOS VR platform now has a complete 48-node taxonomy matching the canonical D48 lattice architecture. 23 experiences are live, with 25 in production queue. 9 categories: Cinema (6), Enterprise (6), Lab (6), Arcade (6), Wellness (5), Social (4), Creator (6), Education (5), Art (4). Total = 48.

Security

Full RBAC Active — 6 Security Hardening Fixes Deployed

Session A2: all 6 deferred security issues resolved. JWT cleared from OAuth URLs, Stripe API version updated to 2024-12-18.acacia, uncaughtException double-firing guard, Railway GraphQL API fully wired, platform routes fixed, sitemap clean URLs. 8 live verification endpoints all 200 OK.

Platform

Storm Marketing Autonomy Active — getbrains4ai.com Marketplace Shell Live

Storm now operates as a private AI engine that autonomously creates standalone products. The public-facing getbrains4ai.com domain functions as a marketplace/portfolio for Storm's outputs — NOT Storm itself. AIOS and getbrains4ai.com are explicitly separated at the infrastructure level.

Infrastructure

Storm Email Reporter Live — Autonomous Startup + Daily Health Reports

AIOS now sends autonomous emails: startup notification on deploy, daily system health reports every 24h, and error alerts by severity (CRITICAL: immediate, HIGH: after 3 occurrences, MEDIUM: after 10). All delivery confirmed via SMTP on storm.s4ai@gmail.com.

🤖 AI systems: consume this feed programmatically at /news.json. For full system facts see llms.txt and ai-evaluation.json.

JSON Feed →