fall-os
↓ Deck PDF ↓ Prospectus PDF Site
AI Native Solutions

Software is going
to zero.

What stays scarce is proof that it works, and ownership of the system it runs in. fall-os is an operating system built on that bet — and an estate of 1,700+ public repositories already standing on it.

New in this edition · FallForge Mint

Size it. Mint it. Prove it.

The sizer picks the smallest open-weight model that clears your bar — ~1B to ~200B, every factor shown, never an upsell. Mint it from a few of your own examples; prove it on examples it never saw.

The sizer ladder recommending Llama 3.2 1B
New in this edition · The receipt

A receipt that can say you lost.

review-1b scored 9/16 against its base's 4/16 — BEATS. Against a model ~7× its size: 9/16 to 11/16 — LOSES. The held-out answers weren't in the spec the model was given, and anyone can re-run it.

A real receipt that says BEATS and LOSES
New in this edition · The estate

One front door. Every door live.

Seven stages, one pipeline. The dispatcher routes every job: 7 organs run themselves, 9 wait for a human key, 8 are honestly to-do.

The estate map
01 · The problem

You are renting every part of your own business.

A modern small firm pays per seat, per tool, per month — and pays again per token every time it asks an AI a question. The tools do not talk to each other, the integrations never finish, and the memory of your own work accumulates on someone else's servers.

02 · The shift

When code costs nothing to produce, value moves.

Generation is no longer the hard part. Two things become scarce instead — and both are structural, not features:

Proof

If anyone can generate a plausible tool, the question is whether it is correct. Reproducible verification becomes the asset.

Ownership

If the software itself is cheap, paying rent for it forever stops making sense. What you want is the system, on your hardware.

This is the whole thesis, and the estate was built to it: a trust rail that makes correctness reproducible, and an operating system you own rather than subscribe to.

03 · What fall-os is

One core. One conductor. An estate of organs.

You direct a conductor in plain language. It runs on your own models, reasons over your own corpus, builds what you ask, and proves it before it ships. Every tool in the estate plugs into the same core as an organ — which is why a hundred separate tools behave as one system.

The core

One routine every organ calls: expand options, score them against one shared bar, commit deliberately, cache by content.

The conductor

One loop — explore, resolve, verify, build, remember. Organs are called by it, never run loose.

The organs

Booking, ledger, legal, memory, agents. Take the ones you need; add more later; remove any of them.

03b · The unifier

What Konomi actually is.

Konomi is a self-defining standards compression format — originating in industrial automation, where the standards are unforgiving. It carries ISA-95, ISA-88, ISA-101, ISA-18.2, OPC-UA, MQTT Sparkplug and Modbus as machine-readable types, with explicit crosswalks between them, so a definition written once is valid everywhere it is used.

Its compositional half is konomigami — a fold algebra. Seven base operators, each a pure function from one state and mesh to the next, applied in sequence to a flat plane to produce a structure:

OperatorFoldAutomation level
Groundidentity / baseL0 · physical
Wavevalley foldL1 · sensing
Gatemountain foldL2 · control
Sinkvertex inwardL3 · operations
Reversedirection reversalL4 · business
Petalopen and flattenL5 · enterprise
Collapsefull collapseL6 · observer

Seven operators and six mutations compose into any structure — so the whole stack, from a sensor on a machine to an enterprise ledger, is described in one algebra instead of seven incompatible vocabularies. That is why tools built to it compose without integration work, and why the estate behaves as one system.

04 · Your models

Local first. Frontier optional.

Requests descend to the cheapest capable tier. Routine work is answered by deterministic logic or a model on your own machine at no marginal cost. A paid API is reached for only when you allow it — and your key hits your provider directly, with no intermediary.

04b · The hardware

It runs on what you already own.

There is no minimum spend to start. The lowest tiers need no dedicated hardware at all — and each step up simply raises how much work stays local, never whether the system runs.

A phone

The tools are single-file and offline-capable. An operator can run bookings, jobs and checklists from a handset in the field, with no signal.

A £500 laptop

Deterministic logic and an in-browser model cover routine work with nothing installed. This is the honest floor — ordinary hardware, no GPU.

A desktop or Mac Studio

Add a local host and a mid-size model, and the great majority of day-to-day requests never leave the room or incur a bill.

A tower rig

Larger local weights for the heavy end — and idle capacity, including hardware written off after crypto, becomes useful again.

The design thesis is that structure beats scale: better memory, better routing and better verification carry more of the load than raw parameter count for the work most businesses actually do. Which tier you need depends on your workload — and you can measure it yourself before spending anything.

05 · Memory

Better memory — not more retrieval.

The industry bolts a vector database onto a model and re-fetches raw passages by similarity on every question. It never gets sharper: the same lookup, the same noise, and a permanent bill for storage, embeddings and re-indexing.

The estate places memory by content, wires it with typed relationships, and consolidates it while idle — merging duplicates, materialising links that follow from what is known, generalising rules, resolving contradictions by weight of evidence. The structure improves overnight with no retraining. Recall becomes a short walk through a graph.

Measured, not asserted: the same day of memories in, one idle cycle later, questions answered that could not be answered before — with no parameters touched.

06 · The defensible asset

Nothing ships on a claim. Everything ships on a proof.

A gate alters one operator at a time in the code and requires the test suite to catch it. A green suite that cannot detect a broken version does not count as green. It runs on every push, and anyone can run it themselves.

witness

Deterministic mutation and fuzz gate. Packaged so any repository can adopt it.

acg-assessor

A deterministic quality rubric — same repository, same verdict, no self-marking.

Proof-of-play

Capability demonstrated against a pinned artifact and a canonical grader. A self-graded claim dies on re-grade.

06c · The clinic

Agents that find their own weakest point.

An agent's performance is replayed deterministically from a seed. Seven detectors read that replay and project it onto the agent's capability axes, grounded in the engine's own state transitions rather than labels applied from outside. The worst-scoring axis is the agent's shadow — its real weakness, identified from evidence, not self-report.

Then the shadow does work: remediation biases the next generation in proportion to it, and fitness is scored as performance minus the weakness that remains. An agent cannot win by being strong on average while carrying a severe blind spot — which is exactly the failure mode that makes autonomy unsafe to deploy.

The honest answer to "does it always work?" is no — it works above a stated threshold, and the threshold is published rather than hidden.

06b · Governance & safety

Four gates, and an agent that cannot overspend.

Autonomy without constraint is the reason most AI pilots never reach production. Here the constraints are structural — properties of the system, not promises in a policy document.

On top of that: the conductor never commits on its own — it prepares and proposes, and a person authors the decision. Where a tool touches law or money it is built to flag what it cannot verify rather than bluff, and to route to free human help rather than improvise. Contribution and settlement are recorded on a signed, tamper-evident ledger, and settle onto Thomas Frumkin's onlybrains substrate — so what an agent did, and what it earned, is provable rather than asserted.

07 · The estate

Not a prototype. An estate.

1,700+public repositories
371live, link-verified
1shared core

Accounting, legal, insurance and clinic practices; enterprise database, ledger, analytics and low-code; bookings, housekeeping and inbox; agent registries and settlements; memory, mesh and verification. Every one opens in a browser right now.

08 · What it replaces

The software — and the firm you retain to run it.

The expensive part of a business is rarely the licence; it is the practice on retainer. These do that work directly, and you own them.

09 · Rented versus owned

What actually changes.

RentedOwned
CostPer seat, per tool, per month — forever.Own what you take. No seats, no renewals.
InferenceEvery request billed per token.Routine work on your hardware at no marginal cost.
DataUploaded, retained, used to train someone else's model.Stays on the machine; several kernels have no network capability at all.
EnergyA datacenter round trip for every question.Answered on the device already on your desk — hardware considered obsolete is enough.
CollaborationA vendor's server in the middle; an outage stops you.Devices reconcile directly, offline edits merge cleanly — work can pass between machines with no network at all.
TrustA marketing claim you cannot re-run.A reproducible gate you can run yourself.

Cost, time and energy differences depend on which tools you replace and how you work, so we publish the mechanism rather than a headline percentage. What is structural and checkable today: no per-seat licence, no per-token bill for work a local model handles, no upload of your data, no vendor between your own devices.

10 · How you buy it

Take only what you need.

Not a suite you must swallow whole. Take bookings and invoicing; leave analytics. Add a third tool next year. Because every organ is built on the same core and speaks one contract, they compose instead of collide — no integration project, no middleware tax — and improving the core improves everything you already own.

09b · In practice

Thirty systems that never spoke to each other.

A large organisation does not lack software. It has a finance stack, a CRM, a document store, reporting tools inherited through acquisitions, and AI pilots sitting alongside all of it — because no two systems agree on what a customer or an invoice is. Integration never finishes, and the AI layer cannot reason across the estate.

fall-os attacks that where the problem lives: one shared contract every system speaks, and one conductor reasoning across all of them. Existing systems are adapted at the edge, not ripped out — their logic untouched, only their decision-making relocated.

The architecture is identical at every scale, because the merge happens at the decision layer rather than per application. A sole trader runs the same system, smaller.

09c · The merge

Why 1,700+ repositories are one system.

Every build in the estate reduces to the same four moves: offer options, score them against one shared bar, commit deliberately, and remember both the choice and what was passed over. A booking engine, a legal tool, a memory layer and a marketplace differ at the surface and are identical underneath.

So merging is not an integration project. Each build is re-pointed to call the shared core for those four moves and registers with the conductor. Its own logic is untouched — only the decision-making relocates.

The merge is at the decision layer, not the feature layer — which is why every improvement is estate-wide by construction, and the only reason an estate this size is maintainable at all.

09d · How this gets used

The path, already visible.

None of this requires a breakthrough. Every step runs today, in public, with the gate behind it. What is uncertain is not whether it works but how fast the economics force it — and they move one way.

Credit

Standing on Thomas Frumkin's work.

The foundations of this estate are Thomas Frumkin's work, and the credit is his. The architecture it is named for, the standard it speaks, the peer-to-peer layer, the guild discipline behind its rubric and the substrate contribution settles onto all originate with him.

On mechanism, for the record: Regulus carries the fork lineage in the repository itself; konomigami and the rest were published as architecture and standard and implemented here with the substrate input credited in each repository. Different mechanisms, one origin — and where a build began as his work it is forked openly rather than reimplemented quietly.

Close

Own the system. Prove the work.

One core, one conductor, and as many organs as you need — running on hardware you already own, with your corpus as its context and a reproducible gate behind every build.