Endstop

Rev 0.3.4 · in integration

For investors

Hardware containment for untrusted AI.

Endstop is a hardware containment system. It is designed to let AI-generated programs do useful work while dedicated hardware bounds their authority and makes their actions observable.

The investment thesis is a reusable containment layer for AI-generated computation and the external actions it requests. Machine control is our first application and route to customers.

View pitch deck (PDF) ↗ Request the financing memo → Read the investment case →

Engineering prototype · Investor brief updated 27 September 2026

Investment summary
Company thesisA hardware containment foundation for useful AI computation and explicitly authorized effects, reusable across applications.
First applicationMachine control, with integrators and equipment builders as the initial target buyers.
Initial route to revenueA scoped engineering evaluation, followed by hardware and support across compatible machines. The reusable containment foundation creates expansion opportunities beyond machine control.
Current stageImplemented execution and supervision components, formal checks, and simulation and hardware results including a physical arm stop. Pre-certification; paid customer evaluations are the next milestone.
Financing planA $1.2M working planning target for nine months, based on a $1,172,100 budget including 20% contingency. Principal technical and commercial decisions are due within six months. Cost scenarios span $0.94–1.43M under explicit planning assumptions.
§1

Useful autonomy needs an enforceable boundary

Recent AI escape incidents have made containment an immediate engineering priority. OpenAI’s report on the July 2026 incident documents models bypassing isolation and gaining unauthorized access to real systems during cybersecurity evaluations. Anthropic’s subsequent security changes include stronger isolation and monitoring.

A model can generate useful behavior while making errors, following hostile instructions or pursuing unintended goals. Its surrounding software can also contain vulnerabilities that turn limited access into wider authority.

Endstop’s design removes inherited operating systems, middleware and general-purpose runtimes from the containment boundary. We rebuild that environment from the hardware up as a compact runtime with explicit rules and machine-checked properties.

  • Bound execution. Limit the memory, instruction budget and capabilities available to generated programs.
  • Control external actions. Hold permissions and enforcement outside generated code, so the program cannot expand its own authority.
  • Make behavior observable. Expose attempted actions, enforcement decisions and refusal reasons for inspection.

In the intended deployment, the model performs inference only. Endstop is the sole route from its output to external action; the inference system has no independent tool execution or separate communication or control path. Completing and testing that integration is part of the development plan.

The alternative to this boundary is not better software. It is less autonomy. Throttled models, sandboxed skills, a person left on every machine, or AI deferred altogether. Our bet is that the ceiling on deployed autonomy is proof, not capability: a model a team cannot answer for is a model that stays throttled. The bet has its first documented instance. In the summer of 2026, when a frontier lab's own agents escaped their evaluation sandbox and it could not say for days what they had done, its answer included a two-week pause on reinforcement-learning training and a hold on its largest planned frontier run (OpenAI, August 2026). Pausing is what a missing answerability layer looks like at the top. The gate converts unprovable autonomy into provable autonomy, and the record is what proves it after the fact.

Architecture and implementation scope →

§2

One containment foundation, multiple applications

The common foundation is bounded execution, explicitly granted capabilities and observable enforcement. Each application defines the data and actions a program can access, the state that must be tracked and the policy governing its effects.

Machine control gives us a concrete first application: useful work and physical interventions can be measured against a defined task. The machine supervisor adds state, trajectory and stopping checks to the execution boundary.

Expansion opportunities include environments where AI-generated programs work with permitted data or invoke explicitly granted functions. A proposed evaluation of useful computation under adaptive attack tests which workloads fit the restricted runtime and how the boundary responds to attempts to escape it.

The opportunity is to carry a common execution core, capability model and decision record into new applications, adapting interfaces and policies to each task. Machine control provides the first commercial path into this broader containment opportunity.

§3

Machine control: the first customer path

The initial target customer is an integrator or equipment builder evaluating AI-generated control in a fixed-base robot workcell. A controls engineer owns the integration; an engineering or product leader owns the deployment decision and budget.

The proposed value is a reusable way to contain changing AI-generated programs, supervise the machine and inspect what happened. The customer comparison must establish whether this preserves useful work and reduces integration or review effort alongside existing controls.

Here, supervision evaluates machine state, motion history, acceleration, predicted stopping positions and patterns that can excite resonance. These checks determine whether proposed motion is permitted.

A free fit assessment selects one task, operating limits and a baseline. A subsequent paid evaluation has agreed deliverables and acceptance criteria covering:

  • Utility: completed work, response time and unnecessary refusals.
  • Enforcement: correct intervention for forbidden actions and specified state, trajectory or fault conditions.
  • Observability: a trace of attempted actions, decisions and resulting behavior.

Founder-led sales focuses on builders that deliver multiple compatible machines. The first commercial milestone is a budget owner agreeing to a paid comparison. The next is a second integration that takes less engineering work.

Evaluation scope and acceptance criteria →

§4

An inspectable engineering foundation

The execution and supervision core contains 1206 measured lines of Rust: a published 667-line interpreter and a 539-line motion monitor available under evaluation agreement. Fifteen named properties have formal checks with explicit assumptions and limits. The compact core makes its rules practical to inspect and test.

Evidence and what it establishes
EvidenceWhat it establishes
Execution and formal checksNamed memory, budget and supervision properties; compiled target execution; and a public challenge on an emulated target. Source and proof scopes · Public challenge.
Useful work in simulationUnder an injected position error, bounded recovery completed 10/10 placements versus 4/10 in observe-only mode; both completed 10/10 in normal conditions. Simulation, placement phase. Method.
Physical integrationOn a physical SO-101 arm in a PC-assisted rig, a program in the ECP5 gate's interpreter moved the elbow and a program one count past the envelope was refused before any actuator write. When the gate withheld its reply, the trusted PC held the arm 50 ms after the invalid request, inside every predeclared stopping-response limit. Interpreter-to-arm record · stop record.

These are company-authored engineering results. The implementation checklist and roadmap consolidate current capabilities and next milestones.

§5

The first business model: repeated machine deployments

For machine control, the product model combines the containment core with machine-specific interfaces and operating limits. The initial evaluation pays for a defined comparison; repeated deployments would generate hardware and ongoing support revenue.

Proposed commercial model
PurchasePlanning rangeCustomer receives
Engineering evaluation$25,000–75,000Agreed integration work, repeatable tests and a comparison report.
Production hardware$2,000–5,000 per machineThe containment component for a supported machine configuration.
Platform support$50,000–250,000 per yearConfiguration maintenance, regression tests, updates and assessment support across an agreed machine family.

These are pricing hypotheses. Included machines, support obligations and the combination of fees must be agreed with buyers. Unit costs and margins need validation through delivery.

Within this first market, the route to scale is adoption across a builder’s product family. The core, test harness and evidence format should carry forward; adapters, calibration and machine-specific assessment remain integration work. Measuring that division on a second installation is a key investment test.

For the initial machine-control market, IFR reports 542,000 industrial robots installed in 2024. The reachable subset depends on technical fit and willingness to pay. Broader containment applications offer expansion opportunities with distinct buyers, pricing and adoption paths.

§6

A distinct architecture, with reuse to prove

Endstop’s architectural proposition combines a compact hardware execution boundary, independently held authority and observable enforcement. The intended advantage is to carry that foundation across deployments and applications while adapting the permitted capabilities and policies.

Machine-state supervision is the first application of that architecture. Its customer alternatives provide the initial comparison:

Customer alternatives and the comparison to make
AlternativeCustomer comparison
Existing machine controlsEstablish which risks and useful AI behaviors remain beyond the existing protections. Rated controls remain part of the machine.
Software sandbox and custom supervisionCompare the trusted software, available action paths, useful output and engineering effort required to maintain the boundary.
Integrated controller or platform vendorCompare the value of Endstop’s independent component with the vendor’s integration, distribution and assessment advantages.

Reusable configurations, regression tests and accumulated integration evidence could strengthen the product with each deployment. Customer adoption and measured reductions in installation effort must establish that advantage. Detailed vendor comparison and sources →

Five provisional applications

The submissions describe five related areas of physical AI containment. These briefs summarize proposed mechanisms; they do not establish patentability or completed product capabilities.

01 · Execution and safety

USPTO application No. 64/158,254

A machine-side gate checks AI-generated commands before they reach an actuator. The disclosure combines bounded program execution, predictive stopping checks, physical-effect budgets and authority that the untrusted controller cannot renew itself. Its focus is keeping the final permission to act outside the planner.

02 · Settlement and accountability

USPTO application No. 64/158,568

Reserve permission for a physical effect before releasing it, then restore unused permission only when independent observations justify doing so. The disclosure also accounts for interacting effects and consumed recovery options, so a reset, missing acknowledgement or favorable measurement cannot simply erase an outstanding obligation.

03 · Ambiguous commands, artifacts and tool commissioning

USPTO application No. 64/158,569

Control how uncertain instructions, generated files and newly acquired tools gain permission to act. The disclosure binds an interpretation, the exact executable artifact and a tested tool configuration to a limited authorization. Retries, altered files or changed tools require renewed checks.

04 · Physical transactions, consequences and custody

USPTO application No. 64/158,570

Coordinate irreversible operations across machines by checking the possible partial outcomes and reserving resources for a justified response to interruption. The disclosure keeps unresolved consequences and object custody attached to the operation through handoffs, communication failures and restarts.

05 · Controller lineage and promotion

USPTO application No. 64/158,571

Require independently controlled evaluation before an updated or self-modified controller receives physical authority. The disclosure preserves obligations from the previous version and shares an aggregate authority limit across related descendants, so copying, promoting or rolling back a controller does not multiply its permission to act.

Request the supporting IP brief →

Patent application status

USPTO submission acknowledgements and matching payment receipts are on record for all five provisional applications. No patents have been granted.

§7

Control research and company-building experience

Oleg Sidorkin leads Endstop. His background includes a PhD in systematic analysis and control, four years as chief architect of IBM’s AI incubator and two prior company exits.

The funded team would add hardware and firmware engineering, embedded verification and machinery-safety expertise. Candidates have been identified and preliminary hiring terms negotiated. Safety consulting could provide interim capacity while recruiting.

Specialist hiring, founder commitment and start dates are covered in the financing memo.

Founder and company background →

§8

Build the foundation. Validate the first application.

The working planning target is $1.2M for nine months, with the principal investment tests due within six. The base budget is $1.17M and the cost scenarios span $0.94–1.43M, each including 20% contingency.

The model funds the founder and two engineers from month one, alongside safety consulting, hardware and pre-compliance, legal and IP, compute, operations and partner travel. It assumes no revenue offset. These are explicit planning assumptions; hiring terms and scoped quotes will determine the final financing size.

The programme develops the shared containment runtime, enforcement and decision records through a concrete machine-control evaluation. Funding would support hardware and firmware engineering, verification, machinery-safety expertise, test equipment and partner evaluations.

The first application tests useful contained behavior, paid demand, repeatable integration and an affordable assessment path. It should also establish which parts of the core and evidence process carry forward into further applications.

Proposed milestones

Measured outcomes over nine months

  1. 30 days

    Engineering

    Freeze one evaluation setup, baseline, fault cases and numerical acceptance criteria.

    Commercial

    Confirm problem and budget owners; scope hiring, partner access and assessor work.

  2. 90 days

    Engineering

    Measure the authorized physical path and fault responses against the agreed criteria.

    Commercial

    Agree a paid evaluation scope and baseline economics; obtain preliminary assessment feedback.

  3. 180 days

    Engineering

    Evaluate the complete partner path and decision records; measure reuse in a second compatible integration.

    Commercial

    Target two evaluations completed or in final acceptance, measured pricing and effort, and a written assessment scope and cost.

  4. Months 7–9

    Engineering

    Address reliability findings and stabilize the supported interface.

    Commercial

    Use measured customer value and repeat-integration costs to decide product scope and the next financing.

Targets depend on staffing, partner access and agreed acceptance criteria. The programme does not assume certification within this period.

The next investment decision should rest on customer value and repeatability. If useful work suffers, enforcement can be bypassed or each installation requires comparable custom engineering, the product scope and financing plan must change.

Key risks

Customer demand and willingness to pay are not yet validated, and there is no completed customer integration. Machine-level enforcement without a host in the loop and safety certification are ahead of us, and the team must add machinery-safety assessment experience. The full engineering record is available in diligence under NDA.

Funding assumptions and planning notes →   Current implementation checklist →

Request the financing memo →

Supporting materials

Pitch deck · 28 September 2026 · revision 21 (PDF) ↗
AI containment, the first application, expansion opportunities and the current financing plan.