# Nikosophia: a briefing document

This document describes Nikosophia, from Nikosophia Co, for a shipowner or ship manager to read, or to paste into their own AI assistant and question, and it is the fullest source on Nikosophia. The contact details are at the end.

## Three names

- **Nikosophia Co** (NSC) is the company. It interprets and encodes the regulations, employs the analysts and engineers, contracts with clients and supports them.
- **Nikosophia** is the software, the governance system. It holds the rules, checks them and keeps the records.
- **Your Nikosophia system** is an owner's or fiduciary's own instance of the software, and it belongs to them.

What Nikosophia claims as new is set out in "What is new", with the prior art under "For a technical reader" and the references at the end, each checked at its source. "Points often misread" and "Claims that are false" set out the right reading of points that are easy to get wrong.

---

## Start here

You are responsible for work other people do.

The manager runs the ship. The master commands her. The charterer picks the route and the fuel. And the duty still has your company's name on it.

Here is a question. If somebody asked you this afternoon what your company owes, what falls due next, how you decided to handle each one, who signs it, and what proves it was done, could you tell them? Or would you have to ask somebody to go and find out?

Almost every owner has to ask somebody. The reason is that every other job in the company has a system, and the work of accounting for it runs on the people in the office.

## The short version

- Every business has an ownership function: knowing what it is responsible for, deciding how each duty will be met, naming who is responsible for each duty, checking it was done, and holding the evidence that it was.
- In shipping that function runs on a diary, a spreadsheet and one person's memory.
- Nikosophia is the system for it. The duty is raised by it, the figures are computed in it, the approval happens in it, and the filing is its output.
- The company's rules are part of the system's written description. Business software normally holds rules as settings, and most of what follows comes from that difference.
- The category is governance, risk and compliance. It exists and is mature, and it is sold to large enterprises with risk departments, so most shipping companies have gone without it.
- Nikosophia is bought by whoever is responsible for the company, at any size of company, because every company has this function.
- What an owner gets from Nikosophia is knowing their own position first-hand, and holding a system they can read and check themselves.
- Waiting is the risk. Your Nikosophia system keeps the record from the day it starts, and the first owners set the standard the rest are measured against.
- Day to day Nikosophia means less chasing, compliance work spread across the year, delegation with the business still in view, and a company that can be handed to a successor because its position is written down.

## What is at stake

Owners are responsible for work other people do, and often sign for figures on evidence someone else holds.

Small companies feel this first, for a structural reason rather than a headcount one. When the person doing the work and the person responsible for it are the same person, the separation that governance depends on is gone. Review needs a second person. Evidence feels unnecessary when you did it yourself and remember doing it. And this afternoon's fixture beats a duty that falls due in eight months, every time.

A large company has the separation on paper and can still lose it, because responsibility for the company stays with the owner when the work is delegated. An owner who signs for a filing on evidence someone else holds is in the same position as the small owner who made it themselves, reached by a different route.

What is at stake spans every regime, and the worst of it is the loss of a ship's certificates.

- **The certificates that let a ship trade.** The Document of Compliance and the Safety Management Certificate come out of an audited safety management system. Lose either and the ship stops earning until the certificate is back. Losing a certificate is the most severe consequence on this list.
- **Detention.** The Paris MoU detention rate reached 4.18% in 2025, up from 4.03% and 3.86% in the two years before, and a detained ship loses about 5.6 days. Much of what gets a ship detained is paperwork: expired certificates, missing records, deficiencies in the safety management system.
- **Cover and credit.** Insurance conditions and loan covenants are duties with dates and evidence behind them. A breach can put cover in question at the moment it is needed, or trip a technical default on a mortgage. Both are governance failures, caused ashore.
- **Standing with the people who pay you.** A poor RightShip rating or a failed SIRE inspection costs charters, and both are read by insurers and lenders as well.
- **The emissions bill, and the penalty for getting it wrong.** Miss an EU-ETS surrender and the penalty is EUR 100 per tonne of CO2 equivalent with the allowances still owed on top, which for one mid-sized bulker in 2026 is roughly EUR 200,000 against about EUR 140,000 still to surrender. Two consecutive years and member states can refuse the company's ships entry to EU ports, with the company named publicly. A ship on ordinary fuel oil is already in FuelEU deficit against the 2025 limit, and that penalty grows by a tenth for each consecutive year.

The administrative causes are the ones good governance removes: the expired certificates and missing records above, and surrender failures caused ashore. These causes are what fails when the work is held together by attention.

**The lasting cost is reputation.** A fine is the part the company can pay. What stays is being the name that took three weeks to respond to a buyer's diligence questions, whose verifier qualified the report, or whose bank rebuilt the numbers from its own sources on its own assumptions. Relationships in this market run for decades and the family name is the asset, so the owner who has to be chased is talked about.

## The missing piece

Shipping has computerised almost everything. Maintenance runs on a planned maintenance system. Crewing runs on a crewing system. Purchasing, certificates, inspections, drydocking, and now the record books themselves all have software built for them.

The exception is the part the owner is personally responsible for. **A shipping company has software for running the business and none for accounting for it.**

That work still gets done, out of a diary, an inbox, a consultant's spreadsheet and one person's memory. The duties are known in part. The deadlines are watched by whoever happens to remember. The method is whatever was done last time. The evidence is wherever it landed. The people doing the work hold it together by attention.

The closest thing that exists is QHSE software, which stores the safety manual and tracks audit findings. That is document control for one regime. What the company owes is held in the diary and the spreadsheet.

So the most consequential layer in the company is the least structured one, and it is the layer where the liability sits. Nikosophia is that piece.

## What Nikosophia is

Nikosophia is the system for the ownership function, for shipowners and for the fiduciaries who do that work on their behalf. The work is the owner's to do or to delegate. Where it is delegated, the fiduciary may be a corporate or trust service provider administering the shipowning company, or a ship manager engaged to account for the company on the owner's behalf, separately from running the ships.

Nikosophia holds what the company is accountable for, to regulators and to everyone else, and "What Nikosophia covers" sets out the full list. Each obligation is raised as it falls due, and its fulfilment is bound to the evidence that supports it. At any moment the owner can see what is owed, what falls due next, how the company decided to meet each duty, who signs it off, and what has been gathered so far.

**Nikosophia is a control on the governance work.** The duty is raised by it, the figures are computed in it, the approval happens in it, and the filing is its output. While it is in use, every duty the company is responsible for is discharged through it. It is kept separate from the operational work by design, because the system that checks what running the ships produced has to be a different system from the one that runs them.

**What Nikosophia serves is governance.** Administration is clerical: filing, chasing, typing. Compliance is following the rules. Governance is the exercise of authority over a business, which means setting the company's own rules, naming who is responsible for each one, and checking they were followed, with whatever a regulator demands entering as an input those rules have to satisfy. The people who exercise that authority are the people who own the company, which is why owners are the ones who buy Nikosophia.

## The category this belongs to

Governance, risk and compliance. GRC, as it is usually written. The category is mature and the companies in it are Diligent, Workiva, ServiceNow, MetricStream, AuditBoard, LogicGate and Riskonnect. Nikosophia belongs in GRC, and GRC is the class to judge Nikosophia against.

**Within the category, Nikosophia serves a different function.** A company runs on three processes — constituting it, operating it, and accounting for it — and the software divides along the same lines:

| The function | Served by |
|---|---|
| Operations | maintenance, crewing, chartering and certificate systems |
| The compliance function, the DPA | enterprise GRC platforms, QHSE software |
| Internal audit | audit and controls-testing tools |
| **Whoever accounts for the company** | board portals carry the papers and the minutes; **Nikosophia holds what the company is accountable for** |

Enterprise GRC serves the compliance and audit functions inside a business. It is bought by a chief risk officer or a head of internal audit with a department behind them, and it serves what those people need. The person who signs needs a system for knowing their own position, and that is Nikosophia.

**Two consequences follow.**

**Enterprise GRC was built for a department most shipping companies do not have.** Its pricing, its implementation and the in-house expertise it assumes all follow from that enterprise buyer, which is why a company with four ships and eleven people ashore has kept the function on a diary and a spreadsheet. That company is the one Nikosophia is built for. Nikosophia Co's analysts bring the expertise, and the price is per vessel.

**The rules are held as content.** In an enterprise GRC platform an obligation or a control is a record in a database, created and edited through a screen, and the software is the same before and after. That is the ordinary arrangement throughout business software. Holding rules as content is also the one thing Nikosophia does differently, and the difference is structural rather than a matter of features: the rules are part of the system's written description. "The rules are part of the system" sets out what follows.

So the comparison class is GRC, the gap inside it is the function of accounting for the company, and the difference in construction is where the rules live.

Maritime operational software is a different category with a different buyer and a different job. Maintenance, crewing, chartering, certificates, record books. An owner runs operational software alongside Nikosophia.

## The rules are part of the system

This is where Nikosophia differs from the rest of the category, and from how business software is normally built.

In most software the rules a business runs on are either buried in code or held as settings somebody edits. Finding what the rules were a year ago, or whether two of them contradict each other, means reading code or going through settings one at a time. In Nikosophia every rule is declared in the same written description that says what the software is: the duty, the condition under which it applies, the method chosen for meeting it, and who is responsible for it.

Three things follow from that.

- **The build refuses a self-contradictory rulebook.** If two duties both apply to a case and demand different things, the owner declares which takes precedence, and until the precedence is declared the build stops and names the two rules. In ordinary business software rules are database records, so a contradiction between them stays live until the day it produces two answers to one question.
- **Changing a rule changes the system**, so it goes through the same approval as any other change, and your Nikosophia system records who made it and when.
- **Nikosophia Co's analysts add a regulation by writing its rules**, and the same software release runs them. That is why the next rule costs less than the last one.

**A rule passes through four stages: it is collected, compiled, certified and applied.**

- **Collected.** The rules travel inside the components of the composition, and the composition engine assembles those components with an operation proved independent of assembly order (*Free Assembly*, in "Foundations: the two papers"). Every rule contributed reaches the rulebook, labelled with the component it came from, and the rules arrive deepest-first, in the same order every time. A displaced rule is still there to report on, which lets a report say a duty was met under a derogation and name the general rule it displaced.
- **Compiled.** When the system is built, the rulebook's build step derives the rulebook from the collected rules. The build step checks that the rules are coherent, applies precedence, and refuses the build on a conflict. A specific rule nested under a general one arrives ahead of it, and the build uses that order to apply *lex specialis*. Where position leaves precedence open, the owner declares it.
- **Certified.** The build issues a certificate for each rulebook, and the certificate carries the identity of the declaration the rulebook came from. A rule's version is the composition's version: change a threshold and the composition is a different composition. So "which rule produced this figure" and "is this the system you described to us" become one question with one answer.
- **Applied.** Your Nikosophia system projects the two rulebooks, one for business operations and one for fiduciary operations, into the policies and procedures, the system configuration, the monitoring and the reporting each operation runs on. As the business runs, your Nikosophia system evaluates the rules case by case against the records. The build fixes the rulebook, and only a new declaration changes it.

**Three neighbouring questions are answered elsewhere.**

- **Whether two rules can both apply to one case** is satisfiability, and the form the conditions are written in answers it: each rule constrains named fields, and two rules can both apply exactly when their constraints overlap on every field they share. That is an interval test per field with no solver in it, and the case satisfying both falls out of the overlap, which is what the refusal quotes back at whoever wrote the rules.
- **Which of two conflicting rules governs** is decided by the rulebook, reading the declared precedence. The calculus delivers the candidates and the order, and the rulebook picks.
- **A rule naming another rule** is first-order and safe, and a condition ranging over every rule at once has no solution. That is Cantor's ground, which the calculus rests on too. Rule conditions are data to the engine, and the rulebook catches a cycle of exemptions when the rulebook is built.

**Nikosophia Co interprets the regulations, and the software holds the company to them.** Nikosophia Co writes each regulation up as rules through a governed process with the same shape as a filing, run in its own Nikosophia system. A panel of AI readers reads the statute text independently, working to Nikosophia Co's written transcription conventions, and each proposed rule carries the passage it came from and the convention that decided each of its fields. Where the readers agree, the conventions settled the answer. Where they split, the contested fields go to Nikosophia Co's analysts with the readings and the text side by side, and an analyst confirms them. Someone who knows the law also reviews a sample, because disagreement between readers shows where a text is ambiguous, and only a reviewer can catch an error the readers share. Nikosophia Co signs off the finished rulebook, builds it with a certificate, distributes it to your Nikosophia system and keeps it current as the regulation changes. Nikosophia Co interprets each regulation to the same standard as a filing.

The software's job is different. The software checks that the rules are coherent and holds the company to them. What a statute means is Nikosophia Co's reading. **Coherence and correctness are separate**, and the distinction is about the software: a consistent set of rules can still misstate the law, which is why Nikosophia Co's people do the reading, through a governed and signed-off process. Collapsing the company's interpretation into the software's checking produces most of the false claims listed near the end of this document.

## What the owner gets

One place where the duties are gathered. Every other system in the office holds its own corner: the maintenance system knows the machinery, the crewing system knows the rosters, the emissions tool knows the carbon. Each knows only what it was installed to do, so a duty falling between two of them is invisible to all of them.

Nikosophia works the duties out from the fleet. It holds every duty it has rules for and works out which apply to this fleet.

## What owning Nikosophia is like

Ask an owner what keeps them up and they will name something specific: a vessel, a charter, a payment. Underneath is something duller: questions about your own company that only a phone call and a wait could settle.

Most owners have carried that burden so long they count it as part of running a business. The burden is the cost of running the ownership function on attention, after every other part of the company has been given a system.

What replaces that burden is knowing your company's position, including what needs attention and since when. If three duties are behind, you know which three, you have known since they fell behind, and there is a plan against each with a name on it.

**And the system is yours.** Sovereignty here has four parts, and you can test each one.

- **Rule sovereignty.** The rules your company runs on are written down and you can read them. You read the rules the software applies, and the manual is produced from them. In ordinary business software those rules live inside a vendor's code, out of your company's sight.
- **Verification sovereignty.** You can check the system instead of trusting it. You, your verifier, or somebody you hire to be sceptical about Nikosophia Co can compare what is running against what was declared.
- **Deployment sovereignty.** Your Nikosophia system runs on your own infrastructure if you want it to. The same declaration, unchanged, on your hardware, in your jurisdiction, under your control.
- **Knowledge sovereignty.** The understanding of how your figures were built stays in the company. A consultant does the work, files it, and leaves with that knowledge. So does an employee who resigns. A written system stays with the company, and everything it holds can be read.

## What changes in an ordinary week

Audits take a few days of the year. Most of the value comes on the other days.

**The chasing stops.** A large part of an owner's week goes on being the connection between people who each hold part of an answer. Ring the manager, wait. Ask the office to find the certificate. Email the consultant about what was done last year. That work is retrieval, and it falls to the owner because the answer is spread across several people. When the position is already assembled, the owner finds the answer by looking.

**The work spreads across the year.** Compliance work today is episodic: quiet months, then a month of assembling. Spread across the year the same work is smaller, because most of the cost of that month is reconstructing facts after the event. Recording a fact when it happens is cheaper than establishing it eleven months later.

**You delegate and keep sight of the business.** Owners hold on to work they should hand over, because handing over usually costs them visibility. With Nikosophia, somebody else does the work, and the owner sees what is owed, what was decided and what stands behind it directly, from the same record.

**Decisions get made on what is true now.** Whether to take a vessel into an emissions-controlled trade, whether the fleet can carry another ship, what a charterer's terms cost once the duties are counted.

**And the company becomes handable.** This matters most in a family firm, which is most of this market. When a business's compliance position lives in one person's head, the successor inherits the duties without the knowledge and spends the first year finding out what the company was already supposed to be doing. When the duties, the methods and the reasoning are written down and current, the company passes to the next generation, or to a buyer, or to a manager for a year, as a going concern.

## Who Nikosophia is for

**Every business carries an ownership function and almost none has a system for it.** That is true of a shipowner with four bulkers, a manager with sixty ships, a food manufacturer, a clinic, a construction firm. Every business owes duties to somebody, so every business has one. What makes Nikosophia a shipping product is the rules loaded into it, and the machinery takes any set of rules.

So within shipping the answer is: whoever is responsible for the company. In an owner-managed firm that is the principal. In a management company it is the Designated Person Ashore and whoever holds the Document of Compliance. In a larger company it is whoever signs, with the compliance officer working in the system.

**A compliance officer does the compliance work, and governance oversees that work.** Staff change who uses the system day to day. The owner stays accountable, and the doing and the checking still need different hands.

Ship managers can stand in either role, and it matters which. Running the ships is business operations, and there the manager is the operator the owner observes. Accounting for the company, holding the position, the methods and the evidence, is fiduciary operations, and there the manager is a fiduciary. A manager holding the Document of Compliance is also the named party for other owners' ships in its own right: it carries the exposure without owning the assets, and has to be defensible to each owner separately, because any of those owners can be audited and any of them can leave.

**Four situations raise what Nikosophia is worth.** A company outside all four still carries every duty in this document.

- **You actively trade allowances.** The strongest case of all. That computed liability drives a purchase with real money behind it: too high and you have bought more than you needed, too low and you are short at surrender with a penalty on top of what you still owe. And the number is usually computed by the firm selling you the trading service. Recomputing a figure independently before taking a position on it is the ordinary control in every business that trades on calculated numbers, and almost nobody in shipping does it.
- **Whatever software you run, or none.** Where operational software already holds the records, your Nikosophia system takes them in directly. Where the records are paper, scans and email, Nikosophia reads them, and from the first document your Nikosophia system holds the record of what your company owes, how each duty is met, and the evidence behind it. That is where it gains the most.
- **You use a manager.** The manager runs the ships and the duty still names you, which is where the gap between accounting for the ships and seeing them is widest.
- **You have a compliance officer.** That person is who a verifier questions. Employing them gives the system somebody to use it.

## What Nikosophia covers

What the company is responsible for, and to whom it is accountable. Beyond the regulations, a company is also accountable to its lenders, insurers, charterers, board and family. Those duties carry as much at stake as the statutory ones, and they are the duties most often left to memory.

Every one of these duties has the same shape. It falls due on a date someone else sets, somebody prepares it, the person responsible for it signs it, and sooner or later somebody outside the company checks it.

- **The law and the regulators.** Statutory duties, with the arithmetic where a regime has any.
- **The bank and the insurers.** A mortgage requiring quarterly certificates, a condition that crew certification stays current. Missing the first is a technical default. The second surfaces at the worst possible moment, which is when a claim is made.
- **The vetting and rating bodies.** RightShip, SIRE, and undertakings given to a charterer during an inspection.
- **The board and the family.** A quarterly report on where the company stands. In a family firm the audience is the person whose name is on the door, and the duty binds with or without a regulator behind it.
- **Standards the company adopted**, which bind it because it said they would, and commitments that keep its name good where it operates, such as an undertaking to a port authority about local hiring.

All of those run on the same machinery: a standing duty, a written method for meeting it, a named person responsible for it, the jobs that fall due against it, and the evidence bound to each one. What varies is who is owed, what they want to see, and what happens if it is missed. Every one can cost the company money, cover, credit or standing, and every one currently lives in somebody's memory.

**Who the company is accountable to.** Outward: the administering authority, the verifier, charterers, lenders, insurers, buyers in a sale, ports, rating agencies, consultants and advisers, the media, the local community, joint-venture and equity partners, and staff. Upward: the owner, the family and the board. Upward reporting has no outside deadline, so it is the duty most often left until someone asks at the wrong moment, and your Nikosophia system gives it a cadence of its own. Most of the outward parties deal with the company as a matter of business, and what they value is a position that is ready, with the records behind it.

The statutory regimes Nikosophia carries, by domain. Emissions is one of them.

- **Safety and security.** The ISM Code: the safety management system, the Document of Compliance and Safety Management Certificate, internal audits, non-conformities and the Designated Person Ashore. ISPS and the ship security plan alongside it. The ISM Code is the archetype the whole design is shaped around.
- **Certificates and surveys.** The statutory certificate stack every ship carries, with its renewal, intermediate and annual survey windows. They involve little arithmetic and carry a great deal of consequence.
- **Crew.** MLC 2006 — seafarer employment agreements, hours of rest, the maritime labour certificate, complaint procedures. STCW — certificates of competency, endorsements and revalidation dates per crew member.
- **Emissions and fuel.** EU-ETS allowances to surrender. FuelEU Maritime intensity against a falling limit, the compliance balance and the deficit penalty. EU MRV. CII and SEEMP Part III. IMO DCS.
- **Environmental records.** The Inventory of Hazardous Materials on its survey cycle, and port reception facility notifications and receipts.
- **Counterparty and corporate.** What banks, charterers and insurers ask for whether or not a reporting regime binds the company. Sanctions and counterparty screening.

**Two duties show the range.** The emissions surrender is computed. It begins with the voyages, the amount is settled when the year closes, and it lands on the owner or the Document of Compliance holder, whoever chose the route and the fuel. The duty to designate a person ashore with direct access to the highest level of management involves no arithmetic. The company bears it, it has no annual date, and it stands for as long as the company operates ships. Your Nikosophia system holds both in the same form.

Nikosophia Co writes each regulation up in its own right, separately from the software, so the list grows by writing. That is why the UK's ETS and MRV, or the IMO Net-Zero Framework when its text is adopted, are an authoring job for Nikosophia Co's analysts.

## European emissions in detail

Three EU rules apply to ships of 5,000 gross tonnage and above trading to, from or between ports in the European Economic Area.

- **EU MRV** measures what each ship emitted and has the figure checked by an accredited verifier. The verified report for a year is due by 31 March of the next (Regulation (EU) 2015/757, Art. 11).
- **EU-ETS** charges for those emissions. The company surrenders one allowance per tonne of CO₂ equivalent, by 30 September for the year before. A voyage between two EEA ports counts in full, a voyage with one end outside the EEA counts at half, and time at berth in an EEA port counts in full. The charge phased in at 40% of in-scope emissions for 2024 and 70% for 2025, and reaches 100% from 2026, when methane and nitrous oxide join carbon dioxide (Directive 2003/87/EC as amended by Directive (EU) 2023/959).
- **FuelEU Maritime** limits the greenhouse-gas intensity of the energy a ship uses, measured well to wake against a 2020 baseline of 91.16 gCO₂e/MJ. The limit for 2025 is 2% below the baseline, 89.34, and the reduction reaches 80% by 2050. Heavy fuel oil comes out at about 91.6, so a ship on ordinary fuel starts in deficit. The penalty is EUR 2,400 per tonne of VLSFO-equivalent energy in deficit, and it rises by a tenth for each consecutive deficit year. The annual report goes to the verifier by 31 January (Regulation (EU) 2023/1805).

**A worked example.** Take a 25,000 GT bulk carrier on heavy fuel oil with three voyages: Rotterdam to Piraeus, Piraeus to Singapore, and Singapore to Santos, plus 40 tonnes burned at EEA berths. For 2025 it owes 1,395 allowances, about EUR 97,650 at an assumed EUR 70 per allowance. The same voyages in 2026 owe about 2,000 allowances, about EUR 140,000 at the same price, because the phase-in reaches 100% and methane and nitrous oxide are added. Its FuelEU penalty for 2025 is about EUR 37,400, which brings the two rules to about EUR 135,000 for one ship. The allowance price is held fixed to show the arithmetic; the market price moves.

## What the system does, and what a person does

Your Nikosophia system does these on its own:

- Works out which duties the company carries, from the fleet and where it trades.
- Raises each one as it falls due, with its deadline.
- Reads incoming documents and pulls the values out, with a link to the place on the page.
- Computes the regulated figures: allowances to surrender, fuel intensity against the limit, the compliance balance, the penalty.
- Assembles the evidence behind each figure and keeps the chain from figure to source intact.
- Produces the filing.
- Keeps the position current between filings, so the position is ready before anyone asks.

A person at the company does three things:

- Supplies the documents, or connects the system that already holds them.
- Confirms what the AI read, where AI read something.
- Signs the filing.

**A person decides, because the filing is theirs to sign.** A regulated filing is the company's own declaration, and the law puts responsibility for it on a person, so somebody at the company with the authority makes it. Your Nikosophia system prepares everything the signer needs to see: the figures, the rule each one follows, and the evidence for it. The signature is where the company's authority is exercised, and the decision is the signer's.

**A second approver is the owner's choice.** Whether a filing needs a second person is one of the company's own rules, declared by the owner. In a small firm the person who prepares a filing is often the one person able to approve it, and your Nikosophia system follows that arrangement. Where the owner declares that preparer and approver must differ, your Nikosophia system holds the rule on every route into it: its screens, an interface to another system, and an engineer working on the servers. The test is what a person did on that filing: anyone who confirmed an input or a working on it, in any revision, is excluded from approving it. Your Nikosophia system records the arrangement in force with the filing, so a later reader can see which rule the approval was made under.

**The regulation demands the discipline, and Nikosophia makes it part of the ordinary work.** Records kept, methods followed, evidence retained, approvals recorded: the regulation asks for all of it. In most companies that discipline lives in one person's memory and habits, which is why it holds until they are busy, on leave, or gone. In your Nikosophia system the discipline lives in the system itself. Your Nikosophia system holds each duty, the written method for meeting it and its deadline, raises the duty when it falls due, and gathers the evidence against it as the work is done.

**On what counts as the work.** The compliance work is what Nikosophia does: knowing what is owed, computing it, assembling the evidence, producing the filing. Trading allowances, invoicing charterers and choosing a route are commercial decisions. Nikosophia supplies the figures they rest on: the liability a trader buys against and the cost a charterer is invoiced for, each computed independently from the records.

## What changes when somebody comes to check

Four questions decide how an inspection or a verification goes, and Nikosophia is organised so each one has an answer.

1. **Can this number be worked out again?** The regulated arithmetic is fixed rules over stated inputs, so the same records produce the same answer whenever anyone runs it.
2. **Where is the evidence for the inputs?** Every figure carries a link to the document it came from, down to the place on the page.
3. **Which version of the rule produced it?** The statutory factors are pinned to versions, so a figure computed for a past year can still be reproduced after the regulation changes.
4. **Is this the system you described to us?** You, or whoever is checking, can compare what runs against the description of it.

A fifth answer sits behind those: every Nikosophia system in service was built from a rulebook that passed the contradiction checks, so the company's rules agree with one another about what it owes. That guarantee covers contradictions between rules. Whether each rule is current and correct is Nikosophia Co's interpretation work.

Reproducibility and correctness are separate properties. Reproducibility means the same inputs always give the same answer and the path stays visible. Correctness comes from the method matching the regulation and a competent person standing behind it. A company needs both. Two further properties sit under them. Your Nikosophia system adds every change to the record as a new entry, so you can show the position on any past date as it stood. And a named person at the company accepts every filing before it goes, and your Nikosophia system records their name and the time.

**What that does to the visit itself.** Audits are difficult because a company assembles its position only when somebody forces it to. The examination is frightening because it is the first time anybody looks. When the evidence accumulates as the work happens, the company knows what will be found before anyone arrives. The visit becomes a confirmation, and it costs a morning where it used to cost a fortnight.

**You find your own gaps first.** Where records are missing, or two systems disagree about the same fact, your Nikosophia system reports the gap and where it is, and holds it open until a person supplies the record. A gap is a liability the company already holds. What changes is that you find it on your own timetable, before a verifier, a lender or a charterer finds it for you.

There is money on the other side of that. Shipping already pays for provable standing. RightShip rates dry bulk, SIRE inspects tankers, port state records and flag performance lists are published, and charterers, insurers and lenders read all of it. A company that can produce a clean, traceable position has something to show the people who set its terms. For a manager it is something to sell with and something to keep clients with.

## The filing and the dossier

Every filing produces two things. The **filing** discharges a legal duty to an authority, and once it is lodged it belongs to that authority. The **dossier** is the account of how the filing was reached: what was owed, under which rules as they stood, from which documents, computed how, and signed by whom and when. The filing satisfies the regulator. Afterwards the owner gives the dossier to a verifier, a buyer, a lender or the family, to show how each figure was reached. Both are produced every time, and the filing remains the legal obligation.

Your Nikosophia system freezes the dossier when the report is assembled: the inputs with their sources, the computed figures, the approval trail and the documents relied on. Re-opening and re-assembling the report strikes a new dossier. A dossier made at the time of the work carries more weight than one assembled later for an argument.

## When a figure is disputed

The emissions rules create disputes of four kinds: between owner and charterer over who bears the allowance cost, in P&I and insurance claims, in enforcement by an administering authority, and over misstated provisions in the accounts. Getting the emissions accounting wrong is a second exposure on top of the allowance cost, and an uninsured one: over-surrender, a penalty, a failed verification, or a lost argument over cost allocation.

In each of these disputes, the party holding a record made at the time sets the number the other side has to attack. An owner recovering allowance costs from a charterer pays and files first, then makes the claim with the records made at the time. A seller who meets a buyer's diligence questions with records made at the time negotiates price and warranties from a stronger position. A record of who signed and when also protects the people who did not sign. And when the person who made the judgements leaves the company, the record keeps them.

## Your own record

A facility agreement's definitions clause governs its covenants, so market value means what that agreement says it means. One facility may define it as the average of two approved brokers' valuations, charter-free. Another, for the same owner and the same ships, may define it as one broker's valuation with charter attached, at the lender's option. An owner with three mortgages works to three vocabularies. Your Nikosophia system holds each facility's terms separately and records which definition produced each figure.

When a covenant figure is questioned, the question is usually which definition was in force. The owner shows the figure, its inputs and the definition that produced it. The record shows what the owner assumed; whether that reading of the clause is right is for the parties, or a court, to settle. The record is also complete in both directions, and it shows the difficult periods as clearly as the good ones.

The same holds wherever someone else keeps part of the owner's history. With a complete record, an owner changes verifier without paying to reconstruct three years of monitoring, declines a charter on their own reading of its cost, and sells when the market is right. An owner who changes verifier with an ordinary, documented reason on file is in a stronger position than one whose file leaves the change unexplained.

For a lender, a record showing the computation, the definition in force and the date it was struck reduces the cost of monitoring the borrower and removes uncertainty the lender would otherwise price. That tends to show up in covenant headroom, information undertakings, valuation frequency and how quickly a waiver arrives.

## Where AI is used

In your Nikosophia system, AI does only two jobs. It reads documents, where a person checks every value it extracts, and it writes a short description of each document filed, so the document can be found later. Records reach a company in two states, and AI reads only one of them.

**Structured already.** An approved electronic record book, or a connected operations system, hands over entries that are attributed, dated and machine-readable. Your Nikosophia system takes them in as they are. This is increasingly the normal case, since electronic record books have been accepted in place of paper since October 2020.

**Needing to be read.** A bunker delivery note as a PDF, an invoice, a certificate, a figure in the body of an email, a scanned page. This is where AI works: pulling known values out of documents whose shape changes every time, and linking each back to where AI read it. A person at the company confirms each value before your Nikosophia system uses it.

A person at your company confirms every value in a filing against its source, and Nikosophia calculates every figure by fixed arithmetic. A document's description is used only for finding the document.

## Checked by reading

Governance is the part of a business whose correctness is settled by reading. A verifier reads the monitoring plan, the records and the approvals, and forms a view from what they read.

Software is normally the opposite. You find out whether it is right by running it and seeing whether the output looks correct, which is why "how do you know your software computed this correctly" usually ends at trusting the vendor's testing.

Nikosophia is built so that its behaviour is settled by what is written. The declaration is what the system is, so examining it tells you about the system. Separately, anyone can check that the running system matches that declaration, component by component and version by version. Neither the order-invariance proof nor the match check proves the software correct.

Every other supplier in this market meets the question "how do I know your calculation is right" with an account of how carefully they test. Nikosophia Co meets it by handing over what the system is, in writing, alongside the check that what ran matches it, and letting the owner or the owner's verifier run that check themselves. Handing over the declaration applies the same standard to the tool as the tool applies to the company.

## The engineering underneath, and what it buys you

Two engines sit under every Nikosophia system, both built by Operative, and the division between them is: **daedal compiles the composition, aidion runs it.** daedal turns a written description of a system into a settled, checkable form before anything is installed. aidion installs what daedal compiled, runs its work durably, carries authority with every request and keeps the evidence. The claims earlier in this document about checking, evidence and handing a company on rest on these two pieces of engineering.

### daedal: the composition engine

**What it is.** daedal is a single program written in Rust. It runs no background service and holds no network port: each command reads the composition, does its work and exits, and the state it keeps lives beside the composition it belongs to.

**A system is declared as components.** A composition is a tree of components, each described in a small file. Every component has one of seven shapes. A *root*, a *branch* or a *module* holds other components; a module is sealed, and the rest of the system reaches inside it only through the interface it declares. *Content* is static data. A *step* is code that runs once when the system is applied and hands anything lasting to the machine or platform it registers with. A *scaffold* is a temporary helper for other steps, and an *aspect* supplies settings to many steps at once.

Components declare how they relate. A component *provides* a named value or service, and another *absorbs* it by naming its provider; a consumer that matches no provider, or two, is an error. A component can *contribute* content to a component elsewhere in the tree: every contribution is collected, each is labelled with the component it came from, and they arrive in a fixed order, deepest in the tree first. *Configuration* flows down from ancestors, and where two ancestors at the same depth set the same key the composition is refused. The operator's consent to what a step may use, which commands and which secrets, is declared too, refused by default, and can only narrow as it passes into a sealed module.

**The whole system is resolved before anything is provisioned.** `daedal compile` reads the tree and resolves it into the complete graph of what will run, with no contact with any machine or cloud account. The result is the system's *normal form*: one canonical description, the same whatever order the parts were added in, which is the property the Free Assembly paper proves. Compilation refuses a system that cannot be settled: a missing or duplicated component identity, a reference that matches nothing or more than one thing, a dependency cycle (named, edge by edge), configuration reaching past a sealed module's interface, or a step asking for a command its module was not granted.

**Every destructive change is announced first.** `daedal plan` compares the settled system with the last one applied and reports, for every step, whether it is unchanged, updated in place or replaced, and whether a replacement would destroy data. `daedal apply` then runs the steps in dependency order, independent steps concurrently, each with its input fully assembled first. A replacement that would destroy data refuses the whole apply before any step runs, unless the operator authorises that node by name. Every step is written to compare what it declares with what is actually running and to change only the difference, so running `apply` again after a failure picks up where the system actually stands. A plan can be saved and the apply held to it: if the settled form has changed in between, the apply refuses before anything runs.

**Parts travel as sealed, identical packages.** A component is exported as a package, and a bundle built from the same files produces the same content digest on any machine: entries sorted, timestamps and ownership cleared. A package is pinned by that digest rather than by a version label, so what was reviewed is what gets installed.

**The certificate: proof that the running system is the declared one.** `daedal certify` issues a certificate for a composition. It carries a digest of the normal form, taken before any machine-specific value is bound, so that digest can be computed with no access to any host; a second digest of the form once those values are bound; and a content digest of every component's source. `daedal verify` recomputes all of it and fails, naming each input that drifted, if anything differs. The check is recomputation, with no signature, certificate authority or credential involved, so an owner, a verifier or an adviser engaged to be sceptical of Nikosophia Co can run it themselves. The form digest pins the structure of the system; the per-input digests pin the code inside it.

### Nikosophia as the worked example

Nikosophia is itself a daedal composition, and its structure shows the engineering doing real work.

- **One root, three hosts.** The root declares a governed system of record, an anonymous public surface, and a governed system run on aidion, and grants each host its own commands and secrets.
- **Separation by declaration.** The system-of-record components are routed to the two governed hosts only. Only the governed hosts receive them, so the public host holds no records. The separation is a fact of the composition, readable in its files.
- **The rules as a component.** The rulebook and the deterministic core are one component routed to every host, and the rulebook's own build refuses a rulebook that fails its checks.
- **Tenancy as data.** Which company is served, and with which features, is a table in the composition: one row is a single-company system, many rows are the shared service, and one composition serves both.
- **Witnesses.** Alongside the composition sit small programs that prove specific properties by trying to break them. One hands the rulebook's build a rulebook broken in the way each check exists to catch and confirms each check refuses it. One confirms that the statutory figures in the written regime specification and the tables the software computes from agree, key by key. One confirms that re-reading a document keeps every decision a person already made about it.
- **Certified.** `daedal certify` and `daedal verify` run against the whole composition, and every input recomputes byte for byte.

### aidion: the operation engine

**What it is.** aidion runs what daedal compiles. aidion itself is written in Elixir, on the Phoenix web framework and the Ash application framework, with Postgres as its store. aidion uses Nomad to place and run workloads on machines, and Restate, a durable execution engine, to run workflows; its durable workflow services are written in Go on Restate's SDK.

**Installing and binding.** aidion takes a package, resolves its full dependency closure and prepares every service in it before submitting any of them to run, so a package whose services cannot all be prepared is refused before any of them starts. Each service is bound to a logical name, and the binding records the version, the digest of the installed artefact, the endpoint and its lifecycle state: running, stopped or archived. A sync agent watches the scheduler, registers each running service with Restate, and resumes from its last event after a restart. When a workflow resolves a service name to a version, Restate journals that resolution, so a workflow replayed after a failure uses the same version it started with, even if the binding has moved on since.

**Authority travels with every request.** A password is used only to sign in, and what the API returns is a *macaroon*, never a JWT or a session cookie. A macaroon is a token whose restrictions, called caveats, name the subject, the tenant, the actions permitted and an expiry. Anyone holding a macaroon can narrow it further by adding caveats, without needing the key it was minted with, and no holder can remove a caveat already there. Verification checks the token's chain of HMAC-SHA256 signatures in constant time and refuses any caveat it does not recognise.

**Keys are held apart, per tenant.** Cryptographic keys live in a separate key server, which performs signing and verification for its callers without handing key material out. A *tenant* is one organisation served from a shared installation. The key server derives a key-encryption key from a master key, wraps a separate data key for each tenant under it, and wraps each tenant's keys under that tenant's data key, all with AES-256-GCM bound to the tenant, the purpose and the key version. Decrypted keys are held only in memory; plaintext keys are never written to its database. Each tenant and purpose has a versioned chain of keys with one active key, so rotation leaves older records verifiable. In production, callers are identified by their mutual-TLS client certificate and authorised against an explicit list of which caller may perform which operation for which purpose.

**Evidence that cannot be quietly altered.** Significant events go to an audit trail kept as a separate service. Each tenant's events form a hash chain: every event carries the hash of the one before it and its own hash, an HMAC-SHA256 computed by the key server over a canonical encoding of the event, its actor, its resource, and the state before and after. The service that writes the audit trail never holds the chaining key, so it cannot forge a link, and a changed or missing event breaks every link after it. The table itself is created so that its application, reader and administrator roles cannot update or delete a row. Events are first written to a durable outbox on the machine that produced them and then forwarded, so an outage of the audit service delays events rather than losing them.

**Production is checked at the door.** In production aidion refuses to start if its scheduler, workflow engine or artefact store is reached over plain HTTP or at a private address.

### Why the stack as a whole holds up

Most business software is a running program whose behaviour is known by watching it. A Nikosophia system is a written declaration first: settled and checked before it exists, installed exactly as declared, and provably still the same system afterwards. Operated by aidion, its work resumes where it left off when a machine restarts, its authority is carried by tokens that can only ever be narrowed, its keys are held apart from the services that use them, and its evidence is chained so that any alteration shows.

That is what sits under the promises made to an owner. **Sovereignty**: the system is a written declaration the owner can read, run on their own infrastructure, and check with a command anyone can run. **Evidence**: every figure traces to its records, every record to a chain that exposes tampering, every running system to the declaration it was built from. **Succession**: the declaration is the system and the chain is its history, so a company handed on carries both, written down.

The composition calculus is published in *Free Assembly* ([web](https://operative.au/papers/free-assembly/), [Markdown](https://operative.au/papers/free-assembly.md)) and *No Feedback* ([web](https://operative.au/papers/no-feedback/), [Markdown](https://operative.au/papers/no-feedback.md)). Operative's own account of the engines, written for an AI reader, is at [operative.au/llm.md](https://operative.au/llm.md).

## Four things a company does about what it is responsible for

Every company does all four. Most do three of them in prose and the fourth in a spreadsheet.

- **Say what the company is responsible for.** Usually articles, an org chart, a policy manual and job descriptions: prose about the company, standing apart from the systems it describes. Here it is a declaration, and the software is built from it.
- **Put it into effect.** Usually by accretion, as somebody hires, buys a system, writes a procedure. Here it is a build, so the parts are established to fit before anything runs.
- **Watch the business against it.** Usually somebody compiling a report from several systems, at intervals, by effort. Here it is procedures the owner's system runs, facing inward to operations.
- **Account to the people owed.** Regulators, the bank, the insurer, the charterer, the vetting scheme, the board. Usually each is its own scramble. Here they are one kind of procedure facing outward, differing only in who is owed and what they want to see.

Filing to a regulator is one of those outward procedures. So is the quarterly certificate to the bank, and the board report.

**What that means for what gets built.**

| | Rulebook | Document | Software |
|---|---|---|---|
| Fiduciary operations | yes | Fiduciary Operations Policies & Procedures | yes |
| Business operations | yes | Business Operations Policies & Procedures | **no** |

Two rulebooks, two documents, one application. Nikosophia is the ownership system, and the operational vendors serve the other side. What the operations team gets is the Business Operations Policies and Procedures document, projected off the same rulebook. It is output from the owner's Nikosophia system for people outside it, and a document is the instrument an owner needs over operations.

**There are workflows here, written for each company.** The fiduciary operations application runs on procedures, and much of what they do is reach into the business: pulling records out of the operational systems on a schedule, setting the configuration those systems run under so the declared method is the one applied, and watching for the conditions the owner asked to be told about. Your Nikosophia system takes its information from the operational systems the company already runs and, where their APIs allow, integrates with them.

## Three processes, and why they must be separate

A company runs on three distinct processes. **Constituting** it, which is deciding what it is and what it is responsible for. **Operating** it, which is doing the work and checking that work internally. And **accounting** for it, to regulators, banks, insurers, charterers and the people who own it.

The first and third are the owner's. The second is the operator's, and the owner **observes** it. The owner sets what the business must do, watches that it was done, and accounts for it, while the operator runs it. The owner needs to see the operating in order to account for it, and needs to stand apart from it in order to check it.

Firms arrange this in different ways. One owner constitutes the company and accounts for it. Another constitutes it and appoints a fiduciary to account for it. A board may hand the constituting to a managing owner, who appoints a fiduciary or accounts for the company personally. In every arrangement, whoever accounts for the company reports up to whoever constitutes it.

The constitution sets the policies and procedures both sides work to. Whoever accounts for the company takes the records and evidence from the operating, and reports up to the owner and out to regulators, lenders and the other parties the company is accountable to.

**This is settled discipline in governance.** The Three Lines Model separates operational management, the compliance function, and independent internal audit, and separates all three from the governing body that oversees them. Shipping recognises the same boundary in law: the ISM Code requires the Designated Person Ashore to have direct, unimpeded access to the highest level of management, which requires that level to be distinct from the one being reported on.

**In a small firm one person does all three**, which is where the risk is greatest. The owner is the operator. Review needs a second person, evidence feels unnecessary when you did it yourself and remember doing it, and this afternoon's fixture beats a duty falling due in eight months. A small company carries the same duties as a large one, and loses the separation. The record then does the work a second person would otherwise do.

Nikosophia serves the first and third processes: constituting the company, and accounting for it. Other software serves operations and internal audit, as "The category this belongs to" sets out.

**What that separation gets the owner, concretely.** The figure you trade against comes from a party independent of the trade. The owner sets the rules for what gets recorded, and the system that records applies them. Nikosophia recalculates, from the records, any figure an operational system already generated. Only the owner pays Nikosophia Co, so the check is accountable to the owner alone. Verification stays with the accredited bodies, because the law bars a supplier that produced a company's evidence from verifying it.

## The same machinery, outside shipping

Everything in this document is illustrated with ships, because that is where the rules are loaded. The machinery holds duties, the methods chosen for meeting them, who is responsible for each, and the evidence, in any industry and for duties owed to anyone.

Take a food manufacturer. It has a documented hazard plan and is audited against it. It holds certifications that lapse. It approves suppliers and has to show it did. Retailers audit it and score it, and losing a score costs shelf space the way a poor vetting result costs charters. Its insurer sets conditions, its lender wants reports, its local authority inspects.

Every one of those is a duty with a counterparty, a date, a method, somebody responsible for it and evidence that has to survive examination. Load a different set of rules and the same system serves the food manufacturer. The same is true of a private clinic, an aged care operator, a childcare group, a waste handler, a licensed venue. In each, the company is responsible for all of it, and accounting for it has no system.

The shape holds with no regulator involved. A duty to tell staff, by a date, about the arrangements for the end-of-year party falls due, somebody prepares it, somebody is responsible for it, and somebody is worse off if it is missed. The company sets that duty for itself, and your Nikosophia system holds it in the same form as a carbon surrender.

## The alternative

The alternative to Nikosophia is what the company does now.

- A calendar reminder, watched by whoever set it.
- A folder, an inbox and the ship's files, searched when somebody asks for something.
- A spreadsheet built by one person and understood by one person.
- A consultant engaged each year, who does the work, files it, and leaves with the understanding of how the figures were built.
- The manager, and the assumption that they have it in hand.
- Somebody's memory of what was done last year.

That arrangement holds only while the person does: until they are busy, on leave, or gone, or until somebody asks an unexpected question. Its cost is invisible because it is paid in attention rather than in invoices.

**The record ends up in other people's hands.** The consultant keeps the history and is engaged again each year to read it back. The charterer's data becomes the authority on the owner's own voyages. When accounting for the company runs on files the owner does not hold, those people hold the owner's position, and the owner accounts for the company on their terms.

Take the carbon account. Noon reports, bunker delivery notes, port call lists and emails go into a spreadsheet, and someone decides which legs were in scope and which fuel figure to trust where two sources disagree. The spreadsheet holds the total and leaves out the reasoning: the judgement about which legs counted was made once, in someone's head, in March. When a verifier asks two years later why a voyage was excluded, someone rebuilds the answer from memory and an inbox, often defending a decision they did not make.

**How Nikosophia fits with what you already run.**

**OneOcean** covers much of the running of a fleet: crew management, technical ship management, voyage planning and performance, and Regs4ships, its maintained library of maritime regulations. Nikosophia takes vessel and voyage information from OneOcean's systems where they expose it. Regs4ships gives ship and shore staff the current text of the regulations and what it requires. Nikosophia Co writes those regulations into your Nikosophia system as duties, each with the method chosen for meeting it, who is responsible for it, and the evidence that it was met.

**Vessel and operations systems** such as NOZZLE, Navatom, MariApps and SERTICA handle maintenance, certificates, crew, inspections and record books. Nikosophia takes vessel information from them directly, and reads the rest from scans and email.

**Emissions specialists** such as OceanScore, ZeroNorth and zero44 compute emissions, forecast positions, and in OceanScore's case trade allowances and invoice charterers. Emissions is where the two meet. The specialist executes the trade, the pooling and the charterer invoice. Nikosophia computes, independently and from the records, the figures each of those rests on, and holds them alongside the company's other duties. An owner with a large carbon bill uses both.

**Class societies** such as DNV and Lloyd's Register sell software and also act as accredited verifiers, holding those functions in separate companies. Nikosophia Co does neither survey nor verification.

## What the subscription buys

Two kinds of change, carried through.

**Rules move, and Nikosophia Co watches them.** Every owner is nominally supposed to track the regulators, the standards bodies and the vetting schemes, and almost none does. Nikosophia Co watches them once, for everybody, and carries each change into the rulebook. So in a quiet year the subscription still delivers: four instruments moved, your rules changed with them, your procedures were re-issued, and there is a record of each change and who accepted it.

**The business moves, and its procedures move with it.** A ship bought or sold. A change of trade that brings new duties. A change of manager. A different measurement method. A finding to close after an audit. Each of those is a change to what the company has declared about itself, and carrying it through is the same act as carrying through a change in the law.

## How Nikosophia Co makes money

A subscription, per vessel, paid by the shipowner or the manager. That is the only money that comes in.

No referral fees from verifiers. No margin on emissions allowances. No payments from lenders, insurers or charterers. No selling anyone's data, in any form, including anonymised or aggregated. Charterers are not customers, because the emissions cost is argued between owner and charterer and Nikosophia Co stays on the owner's side of that.

**Pricing is per vessel per month.** The indicative cost of the full system is about EUR 1,250 per vessel per month. It is lower for an owner who takes fewer areas of duty, and higher where Nikosophia Co writes workflows for the company's own operational systems. The full system comes to about EUR 15,000 a vessel a year. The bulk carrier in the worked example under "European emissions in detail" owes about EUR 140,000 in allowances for 2026 alone, before any other duty your Nikosophia system holds.

## Your first year

**A test to take first.** Could you say today, from your own records, what your company owes, what falls due next, how each duty is being met, who signs it and what stands behind it? Few companies can, because the test is what you can say this afternoon. This is what the first year brings.

**You find your own gaps before a verifier does.** Where records are missing, or two systems disagree about the same fact, your Nikosophia system shows you where. Those records were owed before it was installed. What changes is that you find the gaps on your own timetable, spread across the year, instead of in three weeks with an auditor waiting.

If the company is getting it right, the record proves it. Where it is getting something wrong, the record shows where.

**Every figure is calculated by fixed arithmetic and traced to its source.** Where a regime has arithmetic, Nikosophia calculates the figure from confirmed records and shows how it was reached. Pooling, banking and fuel choice lower the bill, and Nikosophia gives the owner the independent figure each of those decisions starts from. The arithmetic is also the smaller part of what your Nikosophia system holds: a bank covenant, a vetting undertaking, a board report and a safety certificate are duties of record and evidence.

**The regulations come ready, and your own methods follow when you want them.** The regimes Nikosophia Co supplies arrive with their duties, conditions and procedures already written, so your company runs on them from the first day. Where you want your own methods in place of the supplied ones, you add them whenever you choose.

## Who is behind it

Nikosophia Co is a Cypriot company, working from Cyprus and London. Its co-founders are **Sophia Camberis**, who leads client and strategic partnerships, and **Nicole Napier**. Nikosophia's software and engineering are by Operative ([operative.au](https://operative.au)), which built both engines: daedal, the composition engine, rests on two papers by Lachlan Douglas, and aidion runs what daedal compiles.

## What to do next

**Waiting is the risk.** Shipping is digitising, and regulation is moving faster than most companies' systems. EU-ETS reaches the full share of a ship's emissions from 2026, and FuelEU's limit tightens every five years to 2050. The owners who move first gain three things the owners who wait cannot catch up on.

- **The record starts when the system does.** Your Nikosophia system gathers the evidence as the work is done. A year that passes without it can only be reconstructed afterwards, at a cost, by people who were not there.
- **The first owners set the standard.** They show a regulator, a bank or a charterer a company that accounts for itself, and the owners who follow are measured against them.
- **The first owners work directly with the people who designed the system.**

**The decision rests on the approach.** Nikosophia is new, so the owners who adopt it first decide on the substance: whether a company's accountability should be held this way, declared, checked, and evidenced as the work is done. If it should, the sooner an owner starts, the more of their own record they hold.

Nikosophia was built for the regulations as they stand, and the people at Nikosophia Co who designed it answer the phone.

Nikosophia Co · Cyprus · London.

Software and engineering by Operative, [operative.au](https://operative.au).

Contact: mail@nikosophia.com.

---

## What is new

The claim is that a company's rules are assembled by composition, compiled and certified when the system is built, and applied case by case as the business runs. The rule set is gathered by an operation proved independent of assembly order; contradictions are refused before anything runs; each certified rulebook carries the identity of the declaration it came from; and the two rulebooks, one for business operations and one for fiduciary operations, are projected into the policies, configuration, monitoring and reporting that each runs on. Other systems version and sign rule sets, and some detect conflicts; none joins collection, conflict refusal, certification and projection in one build.

## For a technical reader

**Composition happens by name.** A declaration names its parts and their versions. The engine derives the wiring from the names, which is why Nikosophia Co adds a regulation by writing a new part and naming it, and why a part can be substituted by name.

**A declaration is separated from its realisation.** The stages, in order:

- A **declaration** is what is written: parts, versions, and the values they need.
- Assembling those parts gives a **composite**, and normalising it gives a **normal form**. The normal form is the same whatever order the parts were assembled in. That is the proved property, and it makes the normal form an object in its own right.
- Resolving the values against a particular environment gives a **resolved form**.
- Realising the resolved form gives an **instance**: the thing that runs.

One normal form, many instances. The substrate is chosen at the last step, so deployment into an owner's environment is a binding decision, made on the same product. And because the declaration is a distinct object that persists, anyone can compare a running instance against it part by part.

**Where this sits, and what is new.** The calculus is published work with prior art, and the way to weigh it is against that prior art.

A system is assembled twice. Once to make its *form*, which is one and abstract and settled from declared parts before anything is built. Once to make an *instance*, concrete, built from the form, and one form may be built many times. Fettke and Reisig gave the second of those its calculus, composing sequentially, output wired to input. *Free Assembly* gives the first one its calculus: parts set side by side, order of assembly making no difference, the wiring re-derived by name over the whole union at once.

By-name composition has been given algebras before, and they are named in *Free Assembly*. Bracha's Jigsaw merges modules by name, commutatively and associatively, with a name defined twice as an error. Cardelli's linksets link program fragments by name, confluent and terminating. Traits carry two of the three securing clauses and have done for two decades. CUE unifies values commutatively and associatively over a lattice. This calculus adds the third clause to the first two: equality on the carrier by declaration, which makes the operator cancel under a lossy override, over addressed parts that make the monoid separating. The separating monoid, the frame property and the delegation boundary come with that discipline.

What is proved: associativity, determinate normalisation, cancellation under the override, and the frame property, with two characterisations of the class the calculus works over.

**The governance consequence is the reason any of this is in a document about shipping.** If the form is a real object settled before any instance, then a company's declaration is a thing that exists in its own right, checkable by reading. Every other attempt at this, enterprise architecture, process modelling, process mining, organisational twins, builds a model *of* the business and maintains it beside the business, which is why all of them drift. The claim to assess is that the declaration constitutes the company's governance, where those approaches represent it.

**What the proof covers.** The proved property concerns assembly order: it establishes what the system is, and formal verification of the software is a different undertaking. The machinery decides whether a set of rules hangs together, and what a statute says is Nikosophia Co's interpretation. The formal write-up is published in full; "Foundations: the two papers" below links it.

**Four layers, each with its own guarantee.** Most misreadings come from crediting one layer with another layer's guarantee.

- **Composition (daedal)** assembles the software and certifies it. It guarantees that the system running is the system declared, and the certificate identifies the version of every part behind a result. It says nothing about whether a calculation is right or what the law requires.
- **The rulebook** checks Nikosophia Co's transcription of the rules against itself and refuses a rulebook that fails. It guarantees that the rules are coherent with one another; their fidelity to the law is Nikosophia Co's interpretation work.
- **The deterministic core** computes the regulated figures as pure functions of declared inputs, so the same inputs always give the same figure, with the statutory constants identified by version. EU-ETS counts tank-to-wake emissions in tonnes of CO₂e, weighted by voyage scope. FuelEU Maritime counts well-to-wake intensity in gCO₂e per MJ. EU MRV reports total monitored emissions, unweighted.
- **The reading layer** turns documents into proposed values with citations to the source. Everything it produces is a proposal until a person confirms it.

The claim to test Nikosophia Co on: *it can show which code implements each rule the company is subject to, prove that this code is what ran, and reproduce every figure from the records that produced it.*

## How a rule is held, and what is checked

**A duty** is something the company owes to someone: a filing to a regulator, a covenant certificate to a lender, a report to the board. **A rule** is one duty written down with the conditions under which it applies, the method the owner has chosen for meeting it, and the person responsible for it.

**The anatomy of a rule follows Hohfeld.** Each rule states a relation between a bearer and a counterparty over an act. Every duty is correlative to someone's right, so every duty must name the party it is owed to.

**A duty rests on a ship, on the company or on a named role**, such as the Designated Person Ashore, because the instruments place duties on all three.

**For any date, your Nikosophia system reports each duty in one of three states:** live; not applicable, with the reason; or not yet settled, because an input is missing.

**Rules are divided by modality, following SBVR.** An alethic rule states what a record must be: a record that breaks it is refused as malformed. A deontic rule states what the company must do: a record showing it undone is accepted, and a breach is opened. Rules rest on a declared vocabulary of terms and fact types, so every condition ranges over terms the rulebook defines.

**Conditions are written in a form chosen so that whether two rules can both apply is always decidable.** A condition is a comparison over declared terms, membership in a set, the status of another rule, or a recorded human judgement. Because conditions carry no variables and no joins, the check is exact and needs no solver, and the build refuses a rulebook whose rules contradict each other before it is issued.

**Evaluation is three-valued.** A condition is true, false or undefined. A missing record is reported as missing, with the rule that needs it, and the condition stays undefined until the record arrives.

**The build checks the rulebook and deploys only a rulebook that passes.** The checks refuse, among other things, a malformed or duplicated rule identifier, a duty with no method for discharging it, a dependency on an undeclared term, and a cycle of rules that depend on one another through a negation. Two rules that can both apply to one case, demand acts that cannot both be performed, and have no declared precedence are refused the same way.

**Precedence comes from the composition and from declaration.** Rules reach the rulebook deepest first, so a specific rule nested under a general one is presented ahead of it. Where position leaves precedence open, the owner declares it explicitly.

**Rules carry in-force intervals.** The 2024 text and the 2026 text of one duty can both be held, each governing its own period, and a figure for a past period is assessed under the rule in force then.

**Rules are applied case by case.** A case is one instance a rule governs, such as a voyage, a reporting period or a certificate. As the business runs, your Nikosophia system evaluates each rule's conditions against the records for each case, under the version in force for that period, and records the outcome: the duty met, a breach opened, or the condition undefined until a record arrives. The rulebook is fixed by the build, and only a new declaration changes it.

**Both rulebooks reach their operations by projection.** Your Nikosophia system generates the Policies and Procedures for each operation from its rulebook, so each manual matches its rules. It projects the fiduciary rulebook into the monitoring and the reporting, and the business rulebook into the configuration of the operational systems. Workflows written for each company pull records from the operational systems it runs, such as OneOcean, set the configuration those systems run under, and watch for the conditions the owner asked about.

## Foundations: the two papers

The composition engine rests on two papers by Lachlan Douglas, published in full by Operative.

- *Free Assembly: A Calculus of Composition by Name.* [Web page](https://operative.au/papers/free-assembly/) · [Markdown](https://operative.au/papers/free-assembly.md)
- *No Feedback: A Logical System Is Not a Process.* [Web page](https://operative.au/papers/no-feedback/) · [Markdown](https://operative.au/papers/no-feedback.md)

*Free Assembly* gives the calculus for assembling a system from declared parts. Each part states what it requires and what it provides, and parts are joined by name. The paper proves that joining is independent of order and grouping, so the same parts always give the same system, in a single normal form. A requirement that two parts could both satisfy is refused as an error, and adding a part leaves the connections among the other parts unchanged.

The paper proves six results:

- Compositions form a cancellative partial commutative monoid: joining is independent of order and of grouping, some joins are refused, joining with the empty composition changes nothing, and a composite together with one of its operands determines the other.
- Joining parts that do not overlap leaves every settled connection and value as it was. The paper calls this the frame property.
- Normalisation takes every declaration to one outcome, a normal form or a defined error, whatever the order of assembly.
- Every composite divides into its parts in one way only.
- Normalisation always finishes, while whether a running instance finishes cannot in general be decided. What a system is falls on the decidable side of that line, and whether its operation halts falls on the other.
- Normalisation needs no notion of time.

*No Feedback* sets out the conditions under which a system's form is settled by its declaration before the system is built or run. It names three: **part-determinacy**, where the form depends only on the declared parts; **staticness**, where every connection is deduced from declared structure; and **finitarity**, where reading the declaration finishes. All three rest on **predicativity**: no reference in a declaration ranges over the finished composition it belongs to. The line between what a system is and what it does falls at the **operation point**, where a realised instance begins to run. Where they hold, what the system is can be determined by reading its declaration, while what a running program will go on to do cannot in general be decided in advance.

Nikosophia relies on these results for three things: a system is what its declaration says it is; the same declaration gives the same system wherever it runs; and a running system can be compared with its declaration, part by part, by anyone the owner appoints. The papers concern how software is assembled. They make no claim about what any regulation means, and they are not a proof that a calculation is correct.

## Points often misread

**Input data.** Nikosophia reads scans, paper and email, links each value it extracts to the place on the page it came from, and shows what is missing. A person at the company confirms each value, and that confirmation is the design. The companies with the least structured records gain the most. Every system depends on its inputs.

**Determinism.** Nikosophia Co's analysts interpret each regulation through the governed transcription process, and the software applies the resulting rules deterministically, the same way every time. That is the point: a system that reasoned afresh about the law each time it ran would give answers nobody could repeat or check.

**Responsibility.** The law places responsibility for a filing on a person, in shipping as in every other domain. Nikosophia puts the rule, the method and the evidence in front of that person before they sign.

**Small or undigitised fleets.** A small owner with records on paper, in inboxes and in one person's head is the ideal client, with the most exposure and the least in place. Nikosophia reads that company's records, and from the first document your Nikosophia system holds the record of what the company owes, how each duty is met, and the evidence behind it.

**Enforcement.** Nikosophia raises every duty before it falls due and shows who is dealing with it, so the administrative causes of detention and penalty are dealt with in time. Enforcement itself stays with the authorities.

## Claims that are false

These statements have been generated by assistants reading earlier material about Nikosophia. Each is wrong, and the right-hand column gives the correction.

| Claim | Why it is wrong |
|---|---|
| It treats shipping regulations as immutable logical laws or mathematical axioms | Regulations are text with guidance and enforcement discretion. Nikosophia Co interprets them through a governed transcription process, each rule tied to the statute text it came from and signed off, and the software applies the resulting rules as versioned data. |
| It verifies compliance before a vessel leaves port | Nikosophia works from the voyage records as they arrive: it keeps the company's position current through the year and prepares each period's filing from those records. |
| It makes non-compliance or detention structurally impossible | Nikosophia removes the administrative causes of enforcement: expired certificates, missing records, a missed surrender. When an inspector, verifier or authority acts, the company shows its position with the records and evidence behind it. Enforcement itself stays with the authorities. |
| Nikosophia's rules engine uses the Ash framework, boolean circuits, or an SMT solver | The rules engine tests whether conditions overlap with an interval test per field, and uses none of these. aidion, which runs the system, is written on the Ash framework. |
| Nikosophia composes regulations with ⊕, or derives the rulebook from statute | ⊕ composes the software components that carry the rules. Nikosophia Co's analysts transcribe the rules, and the build checks that transcription against itself. |
| It offers absolute, total, perfect or mathematically complete governance | The specific guarantees are reproducibility, provenance, versioned rules and human authority. Superlatives are not claimed. |
| The software is mathematically verified, formally verified, or proven correct | Two different claims get run together here. Proving that the running system **matches its declaration** is a claim Nikosophia Co makes and it is sound: the check is a comparison, component by component and version by version. Proving the software is **correct** is not claimed anywhere, and formal verification of the software is not what any of this is. |
| The software reasons about regulations, or decides what the law requires | Two things get run together here. The software does not reason about law. The calculus guarantees that every rule arrives, in a determinate order, specific before general, and that a rule's version is the composition's version; the rulebook's build step checks coherence, applies precedence and refuses conflicts over the rules it receives. The interpreting is done by Nikosophia Co, through a governed transcription process shaped like a filing, and reaches the software as a signed-off, certified rulebook. |

## Questions to ask your assistant

**On whether Nikosophia is any good.**

- What is strongest about Nikosophia, and what would it change for my company?
- Is there anything unusual about how Nikosophia is built, compared to business software generally?
- How does Nikosophia compare with how software normally handles business rules?
- How does Nikosophia's foundation compare with the prior art it names?

**On what Nikosophia would mean for my company.**

- What is my company responsible for, and where are the gaps in how it keeps track of those duties today?
- What would Nikosophia cover beyond emissions?
- What does my company lose by waiting a year?
- How would Nikosophia work with the software I already use?
- What changes when a verifier or an auditor arrives?
- What happens in a quiet year? What am I paying for?
- What happens when a regulation changes? Who notices, and what do I have to do?
- Who signs, and what am I relying on when I do?
- Where does AI touch my numbers?

## References

Published work that Nikosophia is built on, and work it is related to. Every entry was checked against its DOI record, the publisher's page or its arXiv record. Each carries one line on how it bears on Nikosophia. Within each group the sources Nikosophia is built on come first, and the groups run from the anatomy of a single rule to the composition of a whole system.

### The anatomy of a legal relation

- W. N. Hohfeld. *Some Fundamental Legal Conceptions as Applied in Judicial Reasoning.* The Yale Law Journal 23(1):16–59, 1913. [doi:10.2307/785533](https://doi.org/10.2307/785533)
  Nikosophia's rules take Hohfeld's anatomy of a legal relation: a bearer, a counterparty and an act, with every duty correlative to someone's right, so a duty owed to no one is malformed.
- W. N. Hohfeld. *Fundamental Legal Conceptions as Applied in Judicial Reasoning.* The Yale Law Journal 26(8):710–770, 1917. [doi:10.2307/786270](https://doi.org/10.2307/786270)
  The sequel, which completes the scheme of correlatives and opposites that Nikosophia's relation positions are drawn from.
- L. T. van Binsbergen, L.-C. Liu, R. van Doesburg, T. van Engers. *eFLINT: A Domain-Specific Language for Executable Norm Specifications.* GPCE 2020, pp. 124–136. [doi:10.1145/3425898.3426958](https://doi.org/10.1145/3425898.3426958)
  An executable language built directly on Hohfeld's framework, and a reference implementation against which Nikosophia's relation design can be checked.

### Modality and business vocabulary

- Object Management Group. *Semantics of Business Vocabulary and Business Rules (SBVR), Version 1.5.* OMG formal/19-10-02, December 2019. [omg.org/spec/SBVR](https://www.omg.org/spec/SBVR/)
  Nikosophia takes SBVR's division of rules by modality: an alethic rule cannot be violated, so a record that breaks it is refused; a deontic rule can be, so a record that breaks it opens a breach. It also takes SBVR's layering of rules on facts, and facts on terms.
- J. R. Searle. *Speech Acts: An Essay in the Philosophy of Language.* Cambridge University Press, 1969. [doi:10.1017/CBO9781139173438](https://doi.org/10.1017/CBO9781139173438)
  The distinction between constitutive and regulative rules, which reaches SBVR's modality cut from philosophy.
- A. J. I. Jones, M. Sergot. *A Formal Characterisation of Institutionalised Power.* Logic Journal of the IGPL 4(3):427–443, 1996. [doi:10.1093/jigpal/4.3.427](https://doi.org/10.1093/jigpal/4.3.427)
  The formal account of "X counts as Y in context C", the form of a constitutive rule.

### Rules and defeasibility

Guido Governatori's work is the closest prior art to Nikosophia's rules layer. A defeasible theory takes its rules and the precedence among them as given, and how they were assembled is outside its subject. Nikosophia's composition assembles a rulebook, and a defeasible reasoner could take that rulebook as its input. The two bodies of work are orthogonal and compose.

- G. Governatori. *Practical Normative Reasoning with Defeasible Deontic Logic.* Reasoning Web 2018, Lecture Notes in Computer Science, Springer, pp. 1–25. [doi:10.1007/978-3-030-00338-8_1](https://doi.org/10.1007/978-3-030-00338-8_1)
  Reasoning about obligations with exceptions, priorities and violations, including what is owed once a duty has already been breached, which is the ordinary condition of a compliance record.
- S. Sadiq, G. Governatori, K. Namiri. *Modeling Control Objectives for Business Process Compliance.* Business Process Management (BPM 2007), Lecture Notes in Computer Science, Springer, 2007, pp. 149–164. [doi:10.1007/978-3-540-75183-0_12](https://doi.org/10.1007/978-3-540-75183-0_12)
  Compliance by design: control objectives modelled alongside the business process rather than checked after it, the approach Nikosophia's projection of rules into business operations shares.
- G. Governatori, A. Rotolo. *Norm Compliance in Business Process Modeling.* RuleML 2010, Lecture Notes in Computer Science, Springer, pp. 194–209. [doi:10.1007/978-3-642-16289-3_17](https://doi.org/10.1007/978-3-642-16289-3_17)
  A normaliser that examines a rule set on its own, before any process runs, and detects genuine conflicts as distinct from apparent ones; the closest prior art to Nikosophia's build-time check of a rulebook.
- G. Governatori. *The Regorous Approach to Process Compliance.* 2015 IEEE 19th International Enterprise Distributed Object Computing Workshop (EDOCW), pp. 33–40. [doi:10.1109/EDOCW.2015.28](https://doi.org/10.1109/EDOCW.2015.28)
  Regorous, a compliance checker for business processes built on defeasible deontic logic.
- H.-P. Lam, G. Governatori. *The Making of SPINdle.* RuleML 2009, Lecture Notes in Computer Science, Springer, pp. 315–322. [doi:10.1007/978-3-642-04985-9_29](https://doi.org/10.1007/978-3-642-04985-9_29)
  SPINdle, the open reasoner for defeasible logic that Governatori's compliance work runs on.
- M. Palmirani, G. Governatori, T. Athan, H. Boley, A. Paschke, A. Wyner (eds.). *LegalRuleML Core Specification Version 1.0.* OASIS Standard, 30 August 2021. [docs.oasis-open.org/legalruleml](https://docs.oasis-open.org/legalruleml/legalruleml-core-spec/v1.0/legalruleml-core-spec-v1.0.html)
  The OASIS standard for representing legal norms, including their sources and their temporal status.
- L. Robaldo, S. Batsakis, R. Calegari, F. Calimeri, M. Fujita, G. Governatori, M. C. Morelli, F. Pacenza, G. Pisano, K. Satoh, I. Tachmazidis, J. Zangari. *Compliance Checking on First-Order Knowledge with Conflicting and Compensatory Norms: A Comparison among Currently Available Technologies.* Artificial Intelligence and Law 32(2):505–555, 2024. [doi:10.1007/s10506-023-09360-z](https://doi.org/10.1007/s10506-023-09360-z)
  A comparison of the technologies available for compliance checking where norms conflict or compensate for one another.
- D. Makinson, L. van der Torre. *Input/Output Logics.* Journal of Philosophical Logic 29(4):383–408, 2000. [doi:10.1023/A:1004748624537](https://doi.org/10.1023/A:1004748624537)
  A norm treated as a relation from conditions to what is obligatory, held apart from the operation that derives obligations; Nikosophia holds its rules apart from the step that assesses them in the same way.

### Law as code

- D. Merigoux, N. Chataing, J. Protzenko. *Catala: A Programming Language for the Law.* Proceedings of the ACM on Programming Languages 5(ICFP):1–29, 2021. [doi:10.1145/3473582](https://doi.org/10.1145/3473582)
  Statute written as general cases with exceptions and compiled to executable code; Catala resolves exceptions within a definition, where Nikosophia's rules reach the rulebook from anywhere in the composition.
- T. J. M. Bench-Capon, F. P. Coenen. *Isomorphism and Legal Knowledge Based Systems.* Artificial Intelligence and Law 1(1):65–86, 1992. [doi:10.1007/BF00118479](https://doi.org/10.1007/BF00118479)
  The principle that a rule base should correspond, provision by provision, to its source text; each Nikosophia rule is identified by the authority whose text it transcribes.
- S. Peyton Jones, J.-M. Eber, J. Seward. *Composing Contracts: An Adventure in Financial Engineering.* ICFP 2000, pp. 280–292. [doi:10.1145/351240.351267](https://doi.org/10.1145/351240.351267)
  Contracts as values composed under an algebra, the nearest prior art to rules held as composable parts.

### Conflict and precedence

- D. Calvanese, M. Dumas, Ü. Laurson, F. M. Maggi, M. Montali, I. Teinemaa. *Semantics and Analysis of DMN Decision Tables.* Business Process Management (BPM 2016), Lecture Notes in Computer Science, Springer, pp. 217–233. [doi:10.1007/978-3-319-45348-4_13](https://doi.org/10.1007/978-3-319-45348-4_13), [arXiv:1603.07466](https://arxiv.org/abs/1603.07466)
  A geometric semantics for decision tables with algorithms that detect overlapping and missing rules; the overlap problem Nikosophia's conflict check addresses.
- C. L. Forgy. *Rete: A Fast Algorithm for the Many Pattern/Many Object Pattern Match Problem.* Artificial Intelligence 19(1):17–37, 1982. [doi:10.1016/0004-3702(82)90020-0](https://doi.org/10.1016/0004-3702(82)90020-0)
  The production-system tradition that ordered competing rules by salience, specificity and recency; Nikosophia orders them by where each sits in the composition, the specific ahead of the general.
- K. R. Apt, H. A. Blair, A. Walker. *Towards a Theory of Declarative Knowledge.* In J. Minker (ed.), Foundations of Deductive Databases and Logic Programming, Morgan Kaufmann, 1988, pp. 89–148. [doi:10.1016/B978-0-934613-40-8.50006-3](https://doi.org/10.1016/B978-0-934613-40-8.50006-3)
  Stratified negation. Nikosophia refuses a rulebook in which rules depend on one another through a negation in a cycle, and allows cycles without one, on the same ground.
- A. Van Gelder, K. A. Ross, J. S. Schlipf. *The Well-Founded Semantics for General Logic Programs.* Journal of the ACM 38(3):619–649, 1991. [doi:10.1145/116825.116838](https://doi.org/10.1145/116825.116838)
  A three-valued semantics. Nikosophia evaluates a condition as true, false or undefined, so a missing record is reported as missing and never read as false.

### Composition

- L. Douglas. *Free Assembly: A Calculus of Composition by Name.* Operative, 2026. [operative.au/papers/free-assembly](https://operative.au/papers/free-assembly/)
  The calculus Nikosophia's composition rests on: a system's form assembled from declared parts, by name, in any order, to one normal form.
- L. Douglas. *No Feedback: A Logical System Is Not a Process.* Operative, 2026. [operative.au/papers/no-feedback](https://operative.au/papers/no-feedback/)
  Why a system's form is settled by its declaration before it is built or run, and so can be checked by reading the declaration.
- P. Fettke, W. Reisig. *Once and for All: How to Compose Modules – The Composition Calculus.* ISoLA 2024, Lecture Notes in Computer Science, Springer, pp. 173–190. [doi:10.1007/978-3-031-75107-3_11](https://doi.org/10.1007/978-3-031-75107-3_11), [arXiv:2408.15031](https://arxiv.org/abs/2408.15031)
  The calculus of sequential composition, for building an instance; Free Assembly is its parallel complement, for settling a form.
- E. Dolstra, A. Löh, N. Pierron. *NixOS: A Purely Functional Linux Distribution.* Journal of Functional Programming 20(5–6):577–615, 2010. [doi:10.1017/S0956796810000195](https://doi.org/10.1017/S0956796810000195)
  Configuration merged from independent modules, independent of order, and normalised before it is realised; the nearest mechanism to Nikosophia's composition, which refuses a double definition where NixOS ranks it by priority.
- N. Schärli, S. Ducasse, O. Nierstrasz, A. P. Black. *Traits: Composable Units of Behaviour.* ECOOP 2003, Lecture Notes in Computer Science, Springer, pp. 248–274. [doi:10.1007/978-3-540-45070-2_12](https://doi.org/10.1007/978-3-540-45070-2_12)
  A composition in which a name defined twice is an error for the composer to resolve, the discipline Nikosophia's composition applies to its parts.
- J. C. Reynolds. *Separation Logic: A Logic for Shared Mutable Data Structures.* 17th Annual IEEE Symposium on Logic in Computer Science (LICS 2002), pp. 55–74. [doi:10.1109/LICS.2002.1029817](https://doi.org/10.1109/LICS.2002.1029817)
  The separating composition and frame property that Free Assembly's operator shares: adding a part leaves what the other parts establish undisturbed.
- J. A. Goguen, R. M. Burstall. *Institutions: Abstract Model Theory for Specification and Programming.* Journal of the ACM 39(1):95–146, 1992. [doi:10.1145/147508.147524](https://doi.org/10.1145/147508.147524)
  Composition of specifications prior to, and untouched by, their interpretation; the same order Nikosophia keeps between assembling a rulebook and reading what its rules mean.
- A. Mazurkiewicz. *Trace Theory.* Petri Nets: Applications and Relationships to Other Models of Concurrency, Lecture Notes in Computer Science 255, Springer, 1987, pp. 278–324. [doi:10.1007/3-540-17906-2_30](https://doi.org/10.1007/3-540-17906-2_30)
  The mathematics of order-independence that No Feedback uses to state when a form depends only on its parts and not on the order they were put together in.
