The company's memory.

New projects ask what could work. Inherited ones ask what is already true.

Kinbase is being built to answer the second question: a store of what the company has decided, and why, that engineers and coding agents read before they change a line, over the same connection Kindex uses today.

Kindex indexes you and your code. Kinbase adds the third store: what the company has decided.

Status specification ratified · proof of concept not yet run

company · payments-coresteward: chief architect · example
Architectural brief: refund authorization migration
decisionPayments owns refund authorization.ADR-042 · admitted by the steward · June 2024
constraintThe legacy ledger accepts cents only.owner: ledger team · as read from ledger/README at 9f2c1a
observationThree clients still call the old callback.as of the runtime trace on 2 September · re-read daily · an input, not a decision
questionShould the callback remain a supported contract?routed to the chief architect · pending · shown as open, never guessed
nothing enters this store without a person approving the exact bytes · authority: decisions and answers · everything else: a dated reference to its source

Four kinds of entry: decisions, constraints, observations, and open questions. Each carries a source, an owner or authority, and a date. The observation sits lower on purpose: it is an input to a decision, not a fact in the record.

How it works

Ten years of context. On day one.

A new engineer, or a new agent, opens a repository it has never seen and gets what a complete spec would have told them, if anyone had written one: the direction, the standards, the constraints, and the reasons behind them.

Documentation rots, goes unread, and never reaches the agent's context window. Kinbase is derived from evidence with its provenance attached, typed, and placed into every session automatically. And nothing enters it without a person approving the exact bytes. That is the ceiling on how fast it grows, and it is deliberate.

It knows why. And when it doesn't, it asks.

Decisions carry their rationale. Constraints carry their owner. History carries its date. So the work follows the architecture instead of rediscovering it.

When the evidence cannot settle a load-bearing fact, Kinbase is designed not to guess. The question is shown as an open unknown and routed to the named authority for that scope, the chief architect for architecture. The signed answer becomes company knowledge with a name, a date, and a validity window, and it can be superseded by the same authority. Asked once. Answered on the record. Re-asked when it changes.

Kinbase is the authority only for what someone signed: decisions and answers. Everything it reads from evidence stays a dated reference to its source, re-read on a cadence, so a trace from Tuesday never outvotes a decision from June.

question · payments-corescope: architecture · example
questionShould the callback remain a supported contract?raised by the projector · evidence insufficient · not guessed
answerYes, until the Q2 deprecation notice ships. Then no.Chief Architect · signed 3 September · valid until Q2 · supersedable by this scope
decisionCallback stays a supported contract through Q2.admitted from the answer · cites the trace as of 2 September
while pending, the session sees an open unknown, not a default · when the answer changes, supersedes carries the notice to everything that cited it
Isolation

A coding session never opens the personal store.

Personal, codebase, and company knowledge are specified to live in three stores with separate roots. A coding session reads company and codebase. The shared writer is denied the personal root by OS policy before it starts, and the projection layer checks again. Nothing crosses a boundary unless a person approves the exact bytes.

Once something is marked tainted, the mark never clears, through paraphrase, summary, or derivation. Finding the taint in the first place is a separate problem, handled by deterministic scanners and that final human gate, and measured in the proof rather than promised here.

personalyour conversations and contextseparate root · never mounted by a coding session
codebasethe repository's .kin/, plain files in gitread by the session · approved by the codebase maintainer
companydirection, architecture, standards, ownershipread by the session · admitted by the steward

coding session reads codebase + company · promotion between stores: independent writes, per-destination receipts, exact-byte approval · taint: non-clearable

Proof

The condition we'd concede on.

Kinbase is a specification and an experiment, not yet a product. Until the experiment passes, everything above is intent.

Eleven arms run on the same brownfield commits, with the same model, tools, and budget, scored by people who cannot see which arm produced what. Two conditions carry the claim. The rest keep us honest about why it worked.

01

Match an agent that was handed the full spec.

Blind scorers compare the full system with an agent given the fully informed spec on the same commit. It must score at least 0.90 and land within 0.05 of that agent, close at least 70% of the gap between a plain agent and the spec-fed one, and beat the plain agent by 0.15. If it doesn't, we say so.

02

Zero seeded secrets reach a shared surface.

Thirty or more planted secrets and identifiers, across every kind of evidence, including under prompt-injection and indirect-identifier probes. One reaching a shared candidate or surface is a failed proof. This one is a correctness property, not a target.

knowledge, not plumbing
Beat the same hooks and scaffolding running on an empty corpus by 0.15. Beat a 2 KiB conventions note and plain top-k retrieval by 0.10.
routing
Sort what it learns into the right store at 0.90 macro-F1 or better, with 0.95 precision or better on anything shared, across five recorded live-model runs. Roughly: fewer than one in twenty shared items misfiled.
approval fatigue
At most four shared approval prompts an hour, never three in a row without returning you to your work. A blinded twenty-item operator test must be 95% correct at a median of 30 seconds. Failing this is not proven, even if privacy passes.
the right fact, in context
In at least 80% of dependent edits, the load-bearing fact is present with a mean of at most 12 facts per projection.
blinding
Scorers also guess which arm made each output. If they can, the run is void.
evidence
At least seven kinds ingested end to end, including Codex and Claude Code transcripts, git history, code, tests, and the repository's .kin/.

Zero secrets is a property we bind the name to. The numbers are the current bar, and we will publish what we actually hit, pass or fail.

Every condition, in plain words

Tell us the legacy failure you're living in.

The proof runs on real inherited codebases and real tasks. If yours is the kind that makes a new engineer ask the same five questions every quarter, we want to hear the shape of it. We read every message and reply within a week.

Write to usTell me when the proof runsInstall Kindex today

Send the shape of the problem, not the secrets. We keep what you send only for the conversation.