Every claim is scoped
Source snapshots, parameters, assumptions, named bad outputs, reset policy and bounded horizon travel with the result.
Powered by CQ-SAT
Guarded Continuation Checker is an evaluation-ready platform for embedded firmware and RTL. It records the model, assumptions, property, horizon, result and replay evidence, then fails closed to an exact backend outside CQ-SAT's validated regime.
Platform architecture
Guarded Continuation Checker authenticates the model and obligation, governs resources before solving, and selects CQ-SAT only when a static structural gate admits it. Every other supported case stays on an exact fallback. Both routes must produce evidence that a separate checker can recompute, prove or replay.
Evidence, not assertion
Source snapshots, parameters, assumptions, named bad outputs, reset policy and bounded horizon travel with the result.
Deterministic certificates and replayable counterexamples are checked independently of the specialised producer path.
A static, explainable gate selects CQ-SAT only in its measured structural regime and otherwise uses persistent CDCL.
A product-shaped example
Check whether configuration and control logic can reach a declared hazardous delivery state within a reviewed startup and operating horizon, under explicit environmental assumptions.
property over_delivery
result SAFE ยท bounded
evidence model + assumptions + horizon
review independently replayable
Illustrative workflow only, not a medical-device certification claim.
Independent evaluation
Run the published workflow on a partner-owned ephemeral Linux worker. Return only a non-confidential outcome and suitability assessment.
Read the self-service pathVersioned public reference