B4 -- Helios Hardware
NOTE (2026-06): Helios is Skyzai's own first-party branded product line, sold into the neutral Nexus market. It is a distinct surface at helios.skyzai.com (helios.you as the external entity TLD) — NOT folded into Nexus. Nexus is the separate neutral replicator-stack data + market-access surface.
Helios is Skyzai's own first-party branded product line.
Current public-DAV authority boundary — 2026-07-12. Pre-launch target design; nothing here proves a live system.
A public-DAV consequence may occur only when at least two natural-person councilors bind the exact consequence in a complete valid bound PRISM decision receipt.
PRISM records and verifies that receipt only; it never serves as council, signatory, authority, or receipt producer.
AI and caste seats stage unsigned proposals only; they never authorize or execute a public-DAV consequence. Constitution or membership adoption establishes constitution and membership only; it does not authorize a later consequence. Policy may constrain an unsigned proposal but never authorizes execution or substitutes for the complete consequence-bound receipt.
Before receipt validity, consequence fails closed to read-only proposal, simulation, or deterministic sandbox; live evidence remains gated_pending_complete_valid_bound_receipt.
Software deterministically carries out only the exact consequence bound to a complete valid bound PRISM decision receipt from at least two natural-person councilors binding that exact consequence.
The organism's sensory organs. Never isolating. Consent-bounded signing.
Two Devices, One Principle
Helios is not a product line. It is two reference designs that give the organism eyes and ears in the physical world. Both follow the same rule: the wearable senses, the phone signs.
Device 1: The Ear -- Bone Conduction Audio
Form factor: Shokz OpenRun Pro 2 style -- open-ear, bone conduction.
Why bone conduction? Because APU's voice must never isolate you from the world. Noise-cancelling headphones create a sensory monoculture. Open-ear preserves spatial awareness. You hear APU and the traffic. You hear the Council deliberation and your colleague. The organism augments perception; it never replaces it.
Continuous biometrics:
| Sensor | Signal | Use |
|---|---|---|
| PPG (optical) | HRV | Stress detection, decision gating |
| PPG (optical) | SpO2 | Altitude, fatigue, health baseline |
| Thermistor | Skin temp | Circadian phase, illness early warn |
| IMU | Head motion | Activity context, fall detection |
Biometric data stays on-device by default. Transmitted only to your phone over BLE, encrypted. Never to cloud. The organism reads your body only with your permission, and only your wallet holds the key.
Device 2: The Eye -- Spatial Video Camera
Form factor: DJI Osmo Pocket 3 style -- pocketable, gimbal-stabilized.
Stereo spatial video for Apple Vision Pro and Meta Quest playback. Every recording is a potential Circle observation. The camera does not just capture -- it witnesses.
Nostr-signed observations: Each clip is hashed and signed as a Nostr event (Kind 31339) at capture time. Target signature chain: camera creates hash, phone signs with Nostr key, receipt designed to anchor on the target external anchor (Arweave in current doctrine; local proof lanes may use append-only evidence until full anchoring is wired). Tamper-evident from the moment of perception.
The Signing Boundary
A private Natural Person signs their own act on the phone, never on the wearable. Public-DAV consequence instead consumes a valid ≥2-natural-person PRISM decision receipt; the wearable never signs.
This is a constitutional constraint, not a technical limitation. The wearable has no secure element suitable for key custody. The phone does (Secure Enclave / Executive M / StrongBox). Splitting sense from sign creates a clean trust boundary:
Wearable (sense) --BLE--> Phone / authority validator --Nostr--> Network (witness)
If the wearable is lost or compromised, no keys are exposed. For a private act, the Natural Person authorizes their own typed private act using a device-held key; the phone is a signing device, never the authority. For public-DAV consequence, the validator verifies a complete valid bound PRISM decision receipt from at least two natural-person councilors binding the exact consequence. PRISM records and verifies only; deterministic software carries out only that exact bound consequence. Three substrates remain distinct: L1 hardware sensor + unsigned AI processing + the applicable typed authority receipt.
What Helios Is Not
- Not a medical device (no FDA/CE claims on biometrics)
- Not a surveillance tool (no cloud upload without explicit consent)
- Not required (the organism works fine without it -- Grace Exit applies)
Helios gives the organism a body in the physical world. Open ear. Open eye. Closed key.
Hardware Trust Boundary
Helios surfaces (ears/eyes/mouth metaphors) must define clear trust boundaries.
Boundary checklist
- Sensor ingest authenticity checks
- Local pre-processing constraints
- Secure channel to upstream routing layer
- Device attestation or equivalent trust signals
- Remote disable / quarantine path for compromised nodes
Safety rule
Never treat raw hardware input as authoritative without triangulation or provenance checks.
Agent Execution Surface
If you are an AI agent reading this document:
- This is a downstream public content page. The canonical source lives in
EMERGENTISM_ORG/08_FRAMEWORK_SUPPORT/orSKYZAI_ORG/. Edit source upstream, not here. - Preserve evidence tiers. Do not promote claims up the [C] < [D] < [S] < [B] < [E] ladder when reproducing them here; [I]/[A] qualifiers never substitute for [B]/[E].
- Regenerate from source. If the upstream source changes, regenerate this page rather than editing it independently.
- Canonical Path:
SKYZAI_ORG/07_PWAs/skyzai_org/wiki/B4-helios-hardware.md
Output: This is content. Route edits to upstream source. Regenerate when source changes.
K3 public-DAV authority history — 2026-07-12
K3 historical reference — not active authority
Current public-DAV boundary — 2026-07-10. Pre-launch target design; nothing here is live. The active DAV is public and targets PRISM, with no K2 runtime, launch, genesis/bootstrap, or fallback dependency. Consequential authority requires at least two natural-person councilors; AI/caste seats stage unsigned proposals only. Before quorum, behavior fails closed to read-only/proposal, simulation, or deterministic sandbox, and a live decision receipt remains gated pending quorum.
If the wearable is lost or compromised, no keys are exposed. For a private act, the Natural Person's phone signs; for public-DAV consequence, the validator consumes a decision receipt from at least two natural-person PRISM councilors. Three substrates remain distinct: L1 hardware sensor + unsigned AI processing + the applicable typed authority receipt.