ARIN22 · Layer 0 · Deterministic Kernel
A deterministic computational core for systemic risk.
A class-routed deterministic acceleration layer — deterministic where it provably can be, Monte-Carlo-challenged where it must be, every verdict hash-logged. ARIN22 is a US trademark name (registration pending) for the deterministic risk-core; the construction is a protected trade secret. Embeddable beside Aladdin, Bloomberg, Murex, and MSCI — not a replacement for full-stack risk platforms.
US trademark name (registration pending) · ~99 µs at D=4 synthetic · ~0.3 ms at D=200 real portfolios · 0.035% canonical / D=200 p95 0.28% · max 0.90% · Enterprise Wave: 8.8 B paths/backend · 10M lane: internal Market Readiness canon; aggregate formula under reconciliation · CRN 99.9 PASS.
S1.5 · Evidence status taxonomy · claim posture
Measured challenger, bounded claims.
ARIN22 is a measured, artifact-bound risk-compute challenger with strict claim boundaries. The strongest current claim is operational reproducibility and latency-governed evidence; model-validation claims remain bounded until realised evidence and external replication mature.
ARIN22 is
- A risk-compute and governance kernel.
- A challenger layer beside incumbent systems.
- A hash-bound evidence and replay layer.
ARIN22 is not
- Not an exchange execution venue.
- Not a market-maker pricing stack.
- Not a full replacement for Aladdin / Bloomberg / Murex / MSCI.
- Not an externally attested production risk system.
| Status | Meaning | Public claim boundary |
|---|---|---|
| MEASURED | Artifact-bound internal evidence. | Publishable inside the stated workload envelope. |
| REVIEW_ONLY | Engineering evidence, not external validation. | Disclose as diligence material, not external attestation. |
| RESEARCH_ONLY | Challenger lane, not production claim. | Supports research posture; cannot promote production parity. |
| PENDING | Planned benchmark or external replication. | No public performance claim until artifact-bound. |
| NOT CLAIMED | Explicit boundary. | Used to prevent implied attestation or client validation. |
Operational gates validate runtime, replayability, drift control, and evidence custody. They do not by themselves establish predictive model validity or regulatory backtest maturity.
| Evidence lane | Status | Artifact ID | Boundary |
|---|---|---|---|
| Tick replay | MEASURED | artifact:FINAL_H100_EVIDENCE_INDEX_20260530 | Self-run, not STAC. |
| Pre-trade gate | MEASURED / REVIEW_ONLY | artifact:pretrade_replay_manifest@sha256:... | Not live execution. |
| Quant challenger | RESEARCH_ONLY | artifact:quant_library_challenger_20260612 | Not production Greeks parity. |
| Shadow ledger | PENDING / ARMED | artifact:shadow_ledger_status | Not 250/250 realised-validation pass. |
| Evidence surface | Status | Release boundary |
|---|---|---|
| Shadow Ledger | ARMED | Outcome-ingestion contract active; release promotion remains gated. |
| Realised evidence | DEVELOPING | Recorded outcomes are not yet mature enough for public realised-validation claims. |
| 250/250 validation floor | NOT CLAIMED | No regulatory backtest maturity claim until the observation floor is met. |
| Surface | Visible content |
|---|---|
| Public page | Envelope, evidence status, boundaries, and non-claim discipline. |
| NDA pack | Run SHA, hardware fingerprint, full q999 distribution, artifact hashes, and replay bundle. |
| Trade secret | Internal construction details remain protected. |
S2 · Signature proof
The evidence is the page hero.
Three quiet proofs. A worst-tail CPU↔GPU parity scatter that lies exactly on the y = x line. A May 24-million-tick latency histogram retained as lineage, explicitly superseded by the 2026-05-30 canon lane. And a determinism check across a thousand fresh processes that produces a single hash.
CRN 99.9 GPU↔CPU parity
R² 1.0000 · RMSE 0.0000100 worst-tail cases · 100 M paths per backend · Δmax 0.000 bp · PASS. Regression y = 1.0000·x. Every dot lies on the reference line.
Underlying table · 6-of-100 sample
| Case | CPU CVaR 99.9 | GPU CVaR 99.9 | Δ bp |
|---|---|---|---|
| WT-001 | 0.010% | 0.010% | 0.000 |
| WT-020 | 0.018% | 0.018% | 0.000 |
| WT-040 | 0.025% | 0.025% | 0.000 |
| WT-060 | 0.031% | 0.031% | 0.000 |
| WT-080 | 0.040% | 0.040% | 0.000 |
| WT-100 | 0.050% | 0.050% | 0.000 |
Tick-replay latency · lineage exhibit
May p99 0.625 · p999 0.710 ms · superseded by 05-30 canonN = 24,000,000 · Run 11/12 · 8×H100 · NVIDIA Innovation Lab · May 2026 lineage. Shown for distribution shape only; headline canon is p99 0.44–0.46 ms / p999 0.653 ms on the 10 M-update lane.
May superseded percentiles
| Quantile | Latency | Sample |
|---|---|---|
| p50 | 0.388 ms | 24,000,000 |
| p90 | 0.524 ms | 24,000,000 |
| p99 | 0.625 ms | 24,000,000 |
| p999 | 0.710 ms | 24,000,000 |
Deterministic where it publishes. Monte-Carlo-challenged where it must be.
PASS lane · Challenger lane · fail-closed.
S3 · The challenge
Why a deterministic core matters.
Stale risk evidence changes the decision. ARIN22 reduces dependence on brute-force path enumeration within published workload envelopes. The sections below separate compute capability, measured performance and integration scope. The construction remains a protected trade secret.
S4 · CPU posture
Kernel correctness is CPU-bound. GPU is for scale.
The kernel validates identically on a commodity ARM CPU and an 8×H100 cluster. Every result is stamped with a hardware fingerprint and a run SHA for cross-environment replay. Precise numerics — µs, speedup×, q999%, fingerprint, run SHA — are released to bank model-risk teams under NDA.
S5 · Three core capabilities
What the kernel does, in three lines.
Constant-cost compute.
Wall-clock cost shows weak dependence on the equivalent MC path count. Verified across separated lanes: Enterprise Wave v2 — 8,800 cases, 8.8 B paths per backend, zero failures; 10M production-default lane remains the internal Market Readiness canon until its public case × path formula is reconciled.
Adaptive tail controller.
Class-routing holds target accuracy under jumps, regime-shifts, and vol-clustering. Deterministic where it provably publishes; CRN-anchored at 99.9; 10 M MC challenger on hard regimes; no silent degradation.
Cross-asset contagion.
Hidden-channel detection across the covariance and contagion structure. Every verdict is hash-chained; replay is bit-exact under a recorded hardware fingerprint.
S6 · Mode catalogue
One kernel, many class-routed modes.
Six public layers (A–F) are the reviewer-facing projection. The internal catalogue contains 22 modes grouped into eight NDA categories (A–H); only six categories (A–F) are exposed publicly. Each public layer publishes enum-named surfaces a reviewer can audit; the construction sitting beneath them — the protected construction dossier — remains NDA-bound. The published list is the IP boundary.
Institutional reviewers need a written IP boundary — what is auditable publicly (input → output → hash → lineage) versus what is only auditable under NDA (the how of construction). This catalogue is that boundary.
S7 · Performance envelope
Workload, envelope, scale.
The canonical envelope, end-to-end. Numbers are reproducible from the run SHA and hardware fingerprint released under NDA; the public surface publishes the envelope itself.
| Workload | Envelope | Scale · lane |
|---|---|---|
| Intraday tick replay | p99 0.44–0.46 ms · p999 0.653 ms | N = 10,000,000 · canon 2026-05-30 lane · 8×H100 |
| Pre-trade mixed gate | p99 0.85–0.93 ms · p999 1.8–2.5 ms | N = 50,000,000 orders · ALLOW / REVIEW / BLOCK verdicts |
| Enterprise Wave v2 canonical | 0 failures | 8,800 cases · 8.8 B paths / backend |
| 10M production-default lane | internal canon lane · not a replacement for Enterprise Wave lineage | Public aggregate withheld until case × path formula reconciles |
| CRN 99.9 parity | PASS · Δmax 0.000 bp | 100 worst-tail cases · 100 M paths / backend |
| 10 M MC challenger | CVaR 99.9 canonical p95 0.015% · max 0.035% · D=200 lane p95 0.28% / max 0.90% | 50 cases × 4 seeds × 10 M paths = 2.0 B reference paths |
| Estimated acceptance battery | 160/160 cells within 5% envelope vs 100M-path reference · median |error| 0.0156% · worst cell 2.72% | 40 cases × 10 regimes × 4 metrics · params estimated + hash-frozen pre-join · REVIEW_ONLY |
| Determinism | 1 hash · 0.0% drift | 1,000 fresh processes |
| CPU deterministic kernel | ~99 µs at D=4 · ~0.3 ms at D=200 | D=4 synthetic baseline · D=200 real portfolios · sub-linear scaling · published accuracy bands |
All numbers are public-tier. Precise µs, speedup×, full q999 distribution, hardware fingerprint, and run SHA are released to bank model-risk teams under NDA.
S8 · Validation evidence
Enterprise Wave v2 and the 10M production-default lane.
Two evidence lanes are separated deliberately. Enterprise Wave v2 remains the public canonical pack (8,800 cases / 8.8 B paths per backend). The 10M production-default lane is the internal Market Readiness canon; its public aggregate is withheld until the case × path formula is reconciled. V1 aggregate (the 1.06 T-path headline) is superseded as a headline number; it is preserved as lineage inside the Layer-1 data room.
Phase 5 closed · Run 11/12 audit closed · negative controls fail-closed · sampler-independent across PRNG / Sobol / LHS.
S8.5 · Behavioral evidence
Proof without construction.
The kernel construction remains protected. Its behavior does not. ARIN22 publishes what a model-risk reviewer needs to inspect: convergence discipline, coupling governance, head-to-head accuracy, replayability, and claim boundaries without exposing protected construction.
Terminal-state error declines under composition count.
The public surface discloses the lane discipline: same fixture, same Monte Carlo reference, fresh-process repeats, and a log-log convergence trace. Exact slope table and SHA-bound replay pack are released under NDA.
Artifact discipline: exact run ID, SHA256, input fixture, reference backend, and slope table are model-risk artifacts. Public page shows the behavior contract, not protected construction.
Commutator pressure is admitted, bounded, and routed.
When cross-domain coupling rises, ungoverned model error rises with it. The operator contract requires adaptive routing and step governance so terminal error remains below the institutional cap or the lane fails closed.
Routing rule: deterministic lane first; EVT overlay for tail stress; MC challenger for regime-shift and cascade; fail-closed when evidence is insufficient.
Same task, same reference, no silent promotion of research lanes.
Rows are separated by status. Measured lanes can support public claims inside their boundary. Research and pending rows are disclosed as typed limitations, not marketing promises.
| Method | Status | CVaR / error | Wall-clock / scale | Replay | Evidence note |
|---|---|---|---|---|---|
| ARIN22 class-routed | Measured | 0.035% max, canon lane | sub-ms / call | 1 hash / 1,000 repeats | FINAL_H100_EVIDENCE_INDEX_20260530 |
| GPU Monte Carlo reference | Measured | reference backend | 10M-path D=200 lane | seed-bound | d200_10m_new_variant_20260531 |
| Chebyshev tensor challenger | RESEARCH_ONLY | controlled payoff fixtures | validated as a challenger lane | deterministic | not a VaR/CVaR replacement |
| ARIN22 estimated-config battery | REVIEW_ONLY | 160/160 within 5% envelope · median 0.0156% | CPU lane · 40 oracle cases × 100M paths reference | frozen-config receipts + oracle evidence SHA per row | battery bundle sha256:a87246763088ca661e112e5b32ecd1fde4e80613e9cca9dc98f7afe19f2928c0 |
| NDA benchmark lanes | Pending | — | — | — | not promoted until run under canon discipline |
| Chebyshev tensor-train | Pending | — | — | — | fair sparse variant not yet public-run |
| AAD / adjoint | RESEARCH_ONLY | not a tail engine | 1000-factor gradient benchmark · speedup band, not hero number | artifact-bound gradient check | complements ARIN22; not production Greeks parity |
Boundary: measured numbers support the ARIN22 Operator Contract v1 evidence lane. Quant-library challenger lanes complement ARIN22 evidence; they are research-only on the public page, not production Greeks parity, not listed-options pricing attestation, and not a VaR/CVaR replacement. Pending rows are explicitly blocked from public claims until bound to archived artifacts.
The construction is protected. The behavior is auditable: convergence order, coupling governance, head-to-head accuracy, deterministic replay, and hash-bound lineage.
S9 · STAC-inspired wave
GPU lane — MC throughput on 8×H100. Self-run, not STAC-audited.
Built to STAC archetypes, self-run. The four lanes below are the GPU-throughput envelope; independent STAC benchmarking is the deliberate next step.
Two worlds, never conflated. Monte-Carlo throughput → GPU lane (scale). Deterministic kernel → commodity CPU (correctness). The GPU lane is where MC throughput is measured; the deterministic kernel is where correctness is anchored. Archive SHA + 77 hashed artifacts available under NDA.
S10 · Claim boundaries
What is claimed. What is not.
Claimed
- Deterministic where it provably publishes — not a blanket Monte Carlo substitute.
- CRN-anchored 99.9 parity on the worst-tail subset.
- 10 M MC-challenger backing on hard regimes with hash-logged routing.
- Tick p99 0.44–0.46 / p999 0.653 ms on the canon 10 M-update lane.
- Pre-trade gate p99 0.85–0.93 ms · p999 1.8–2.5 ms on the 50 M-order lane; ALLOW / REVIEW / BLOCK published.
- Determinism: 1 hash / 1,000 repeats / 0.0% drift.
- CPU correctness on commodity ARM: ~99 µs at D=4, ~0.3 ms at D=200; 0.035% canonical max / 0.90% D=200 max.
- Negative controls fail-closed.
- Sampler-independence across PRNG, Sobol, LHS.
Not claimed
- Not a realised regulatory backtest PASS — Shadow Ledger ARMED, 250-observation floor not yet met.
- Not a live-production sign-off at any bank or G-SIB.
- Not a blanket Monte Carlo substitute.
- Not EVT 99.9 long-horizon promotable — WATCH_SUPPRESSED.
- Not STAC-audited — self-run.
- Not a market-maker pricing service.
- Not a full-stack platform — embeddable layer beside Aladdin / Bloomberg / Murex / MSCI.
- Not a production accuracy attestation from the acceptance battery — REVIEW_ONLY until the same battery re-runs green on productionized backend routes.
S11 · Economic value
Five mechanism-anchored drivers.
Per-bank ROI is established during pilot, not asserted up front. Quantification and sensitivity envelope are released under NDA. No headline dollar number.
Latency value
Intraday recomputation stays within the published workload envelope; latency is a governance constraint.
Anchor · tick p99 0.44–0.46 ms canon
GPU utilisation
An 8×H100 cluster is freed for paths that actually need MC challenge; deterministic work runs on commodity ARM.
Anchor · Enterprise Wave 8.8 B/backend · 10M lane formula withheld
Compliance velocity
Hash-chained verdicts bind each review to its recorded input, output and run.
Anchor · 1 hash / 1,000 repeats
Decision quality
CRN-anchored tail evidence gives committees a stated accuracy boundary.
Anchor · CVaR 99.9 max 0.035%
Audit velocity
Reviewers can replay a recorded run with its hardware fingerprint and compare the receipts.
Anchor · Enterprise Wave 0 failures / 8,800 cases
S12 · Architecture integration
Embeddable beside Aladdin, Bloomberg, Murex, MSCI.
ARIN22 is a layer, not a platform. Three calm integration targets — one for risk platforms, one for trading systems, one for sovereign & central use cases.
| Pilot entry | What happens | Output |
|---|---|---|
| 01 · Ingest | Import incumbent output or an agreed portfolio fixture. | Typed input contract and evidence custody record. |
| 02 · Run challenger lane | Execute ARIN22 under the routed lane, with fail-closed behavior preserved. | Run SHA, hardware fingerprint, and replay bundle. |
| 03 · Compare | Compare deltas, latency, replay hash, and governor decisions. | Reconciled output comparison, not platform replacement claim. |
| 04 · Decide claims | Separate measured, review-only, research-only, pending, and not-claimed outputs. | Claim matrix: can claim / cannot claim. |
Affiliations: NVIDIA Inception · NVIDIA Innovation Lab · Google for Startups · AWS Activate. ARIN22 is a US trademark name (registration pending); the construction is a protected trade secret. Pre-client diligence-ready with a strong public-portfolio H100 validation package; not externally production-attested.
