Origin • Cocoons • Chrysalis
Three-layer immutability — sub-ms local hashing → regional QBFT → 101-validator root chain.
Origin • Cocoons • Chrysalis is the three-layer immutability architecture that makes every record written into the Parinita ecosystem cryptographically provable from the moment of creation through to permanent sovereign anchoring. Every consequential action across the fabric — twin actions, inference receipts, governance decisions, CRM events, identity assertions — is born attested.
What it does
-
Layer 1 — Origin
Sub-millisecond append-only NVMe log at every POP with SHA-256 hashing and dual signatures (secp256k1 + post-quantum ML-DSA-65, HSM-backed). The local log is the birth certificate.
-
Layer 2 — Cocoons
Six regional QBFT shard rings (5–7 validators each) batch Origin hashes into Merkle trees and reach consensus on the Merkle root in under 200ms. Sovereign workloads get a priority lane under 100ms.
-
Layer 3 — Chrysalis
101-validator QBFT root chain on Hyperledger Besu, one validator per POP across 42 U.S. states, HSM-backed at FIPS 140-3 Level 3, 68-of-101 supermajority finality.
-
Verified Reasoning Chain
Solidity smart-contract construct that records every model invocation, routing decision, retrieval, and synthesis step that produced an AI output — cryptographic trace from prompt to answer, independently verifiable.
-
Post-quantum from day one
Dual-signature path on every block — classical secp256k1 for Ethereum compatibility plus ML-DSA-65 (CRYSTALS-Dilithium, FIPS 204). No migration when the ecosystem moves.
-
101-LLC legal stamp
One Delaware LLC per POP jurisdiction-stamps every receipt — every Chrysalis record is legally defensible at the originating POP.
How it works
When any record is written — a twin action, AI involvement record, inference receipt, CRM engagement, governance decision, identity assertion — Origin hashes it immediately on the originating POP’s Plane 5 NVMe append-only log, generates two HSM signatures (classical and post-quantum), and publishes the hash on the regional NATS JetStream subject. Sub-millisecond. The API response is not delayed; the local log is the proof of birth.
Cocoons batch records (every 25–50 records or every 20–30 seconds), construct a Merkle tree, and reach QBFT consensus on the Merkle root in under 200ms. Each Cocoon ring serves a geographic region. Tier 4 enterprise/sovereign workloads ride a priority lane under 100ms; Tier 1 standard volume rides a lower priority lane under 1 second. Governance decisions and identity assertions bypass Cocoons entirely and write directly to the Chrysalis root.
The Chrysalis root chain — 101 validators, one per POP — finalizes Cocoon checkpoints with 68-of-101 supermajority. Every block carries both a secp256k1 ECDSA and an ML-DSA-65 post-quantum signature, so the chain is verifiable today on any Ethereum-standard verifier and already proof-anchored for the post-quantum future.
Why three layers
To alter a record post-anchoring, an adversary would need to simultaneously alter the append-only NVMe log, compromise the regional Cocoon ring, AND compromise 68 of 101 geographically distributed HSM-protected Chrysalis validators — a combination that is not viable under any realistic threat model.
Parinita Sovereign (data-sovereignty governance) and Parinita Secure (XDR/SIEM evidence) consume Verified Reasoning Chain entries as their substrate, and every other Parinita product writes to it.
Related products
Part of the Parinita AI Edge
Bring Origin • Cocoons • Chrysalis into your stack.
Every Parinita product runs on the same 9-plane fabric across 101 edge POPs. Talk to us about a pilot, or see how the pieces fit together.