This site is being rebuilt and some pages are out of date. For current details, write to reach@inorbit.hr. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

InOrbit RFCs

What we decided before we built it.

Every public RFC from InOrbit's spaces: the problem, what was proposed, what was decided and what was built since, with a dated status log. A fact we do not publish is a black bar with the reason on it.

The RFCs and studies are in English only.

Public documents: 87, in 3 spaces · EVM, LLM, Platform

Taken from the RFCs product on 2026-10-09.

01EVM

Public documents: 1

Every document in EVM →

02LLM

Public documents: 8

Every document in LLM →

Open

03Platform

Public documents: 78

Every document in Platform →

Open

0070One request, three witnesses: tracing from the browser through the program to the wireopenOur SDKs grow from clients of our API into the instrumentation a company puts into its own programs, in every language we support. Instrumentation for frameworks, function tracing and a background worker ship as an optional companion package per language, built on OpenTelemetry, so the core SDK package keeps no OpenTelemetry dependency. What a program reports is joined with what the host agent saw on the wire and what the browser recording saw on the screen, through the trace id and the route template. Data goes to our API directly (SaaS) or through the agent on the host, which applies the company's policy before anything leaves. Where the three witnesses disagree, that disagreement is a signal. It feeds incidents and the on-call notification, with the evidence attached.2026-10-06
0065RFCs everywhere, one source and an access level on every documentopenEvery RFC carries one of five access levels (public, preview, partner, team, internal), applied the same way on the site, the console, the API and MCP; public documents get an anonymous read path; our own RFCs are imported into the RFCs product with their numbers kept, the product becomes the source and the repository an export; the company's RFCs get a host of their own (`rfcs.` under the company domain), built as a snapshot and refreshed live; each person on the team gets a site at their own name.2026-10-06
0040Chaos as a service, our test bench in the customer's networkopenThe chaos tool we test this platform with, rebuilt around the agent and run against this platform continuously - surface checks on every protocol, tests that must fail, honest load, budgeted faults, findings that replay - so the autonomous work we build has a bench that says what it broke; customers later, on the same parts.2026-10-03
0040.2Surface checks on every protocolopenGeneric checks for HTTP, gRPC, SSE, WebSocket, MQTT, GraphQL and MCP that ask each surface three questions (does it answer, does it answer in the declared shape, does it refuse a caller it cannot identify), run from our cloud for verified public hosts and from the agent for everything else.2026-10-030040.3Honest load through the agentopenThe open-loop pacer moves into the agent, drives operations read from the target's own OpenAPI document or protos, reports what was asked beside what was measured and what was sent beside what was counted, and stops at hard ceilings the plan and the agent's policy both set.2026-10-030040.4Faults through the agent's proxyopenThe agent becomes a reverse proxy in front of a service and injects latency, a share of errors and dropped connections from a small menu, each fault paid from a budget, ended by the agent itself when its lifetime runs out, and judged by an objective stated before it starts.2026-10-030040.5Scenarios as codeopenThe scenario file (targets, load, a timeline of faults and the assertions that decide pass or fail) lives in the repository beside the code it tests, names connections instead of addresses, is checked by iohr and the console before it runs, and runs from CI or an autonomous agent with a token that can only start runs.2026-10-030040.6Findings that replayopenAssertions on a service's own contract (status, shape, retried writes with an Idempotency-Key, pagination, refusals), each broken one kept as a finding with what was expected, what happened and the steps that led there, grouped by signature, shrunk to the fewest steps and replayed against another environment.2026-10-030040.7CapacityopenA sweep raises one parameter of a load run step by step, repeats every step, puts 95 % confidence intervals on p50 and p99, judges the contract at every point and names the knee in a sentence a person can act on, all inside the load ceilings.2026-10-030040.8Runs, schedules and the live viewopenEvery check, load, fault, scenario, sweep and replay becomes a run of an account that an autonomous agent or a person can start and read through the API, MCP and iohr, queued per account and per agent, scheduled, streamed live, compared before and after a change, announced as events and kept for a stated time.2026-10-030040.9Vantage points that do not share our fateopenSeveral agents per environment, each declaring the machine, network, power and provider it shares fate with, so a monitor counts as covered only when someone outside the target's fate watches it, goes down only when independent vantage points agree, and a bench that goes quiet is raised as an alert by a path that does not run on the platform.2026-10-030040.10Hosts and clusters, read firstopenThe agent reads what an engineer checks by hand on a machine and a cluster (disk, inodes, memory, clocks, certificates, units, node pressure, pods, restarts, warning events), each as a check kind with thresholds in checks.toml, read-only and named in the policy, with every action treated as a fault under its rules and no shell offered.2026-10-030040.11Who may see whatopenProbes on every public route of the OpenAPI document that one account's token never reads another account's objects, a token without the route's scope is refused, revoked and expired tokens stop working within the stated window, limits answer 429 with a time, and CORS, security headers, TLS and URL-fetching guards hold; reported as findings with the route and the expected and actual status, never a body.2026-10-030040.12Consistency across surfaces and dataopenThe same read over REST, gRPC, GraphQL, the WebSocket mux and the event stream gives the same answer, compared by normalised shape and ids in memory; a write is read back on every surface within a stated window, lists agree with their totals, events for a write arrive with exactly its ids, and retries are idempotent across surfaces; contract-level, writes only in probe accounts.2026-10-030040.13Journeys in a browseropenThe agent runs a headless Chromium under its policy and bounded in CPU, memory and time, plays journeys declared as steps (open, click by role, fill from a secret reference, expect, wait), times every step and the page's vitals, signs in through our own identity pages with a probe account and its second factor, and keeps a screenshot only on failure, only where the policy allows, for seven days.2026-10-030040.14The change verdict, for people and AI assistantsopenOne answer per change (pass, fail, regressed or incomplete), computed by rules over the per-claim verdict of RFC 0047 together with the repository's own CI result, the bench runs before and after, new findings and the guard checks, posted on the pull request with its evidence; required of our autonomous agents before they ask for a merge and after they roll; and the bench offered as MCP tools on the server RFC 0050 opened to every assistant, with thin plugins kept in a separate public repository that publishes nothing until the owner has read a review of each assistant vendor's terms.2026-10-03

Decided