The SomaSoft Framework — Soft IP v10: Governance, Compliance, and a Global Structure for Symbiotic AI and Universal Healthcare
Cite this paper
SomaSoft LLC (synthesized by Claude Code from the project's own artifacts). (2026-07-31). "The SomaSoft Framework — Soft IP v10: Governance, Compliance, and a Global Structure for Symbiotic AI and Universal Healthcare". SomaSoft Research. https://somasoft.ai/papers/somasoft-framework-soft-ip-v10. Licensed under SAGL-1.0.
The SomaSoft Framework — Soft IP v10
Governance, compliance, and a global structure for symbiotic AI and universal healthcare
This is a Vision-and-strategy paper, not a claim of deployed reality. Following the Reality-Engine discipline, real/built items are marked and cited; aspirational items are marked as such; unknowns are marked UNKNOWN. It is offered for review, not as legal or medical advice.
0. What this is, honestly
SomaSoft is a research project building AURI — a grounded, honest AI meant to work beside people. This paper draws the many threads into one framework: how the ecosystem sustains itself (economics), grows (community), and serves (healthcare); the IP + governance + compliance layer that keeps it safe and lawful; and a phased global structure toward universal healthcare and human–AI symbiosis.
The honest frame up front: AURI is not AGI and not on a path to standalone AGI — it is a small, grounded model whose value is verifiable honesty, not raw capability. As of this writing it has had zero real-user evaluations — the single most important open gate. And a key IP question (below) remains unresolved pending counsel. None of the vision that follows is contingent on hiding those truths; it is built on them.
1. The ecosystem (synthesis)
Four faces of one project, deliberately kept distinct: - AURI — the mind: a 126,607-node concept graph of which 2,301 nodes (1.8%) carry a source citation, honest deferral, and a measured confabulation rate of zero on a 15-item causal-trap probe (3 arms x 3 trials, 2026-09-15). The often-repeated "0.0% hallucination over 12 months" has no measurement artifact behind it and is withdrawn here held 12+ months, running fully offline (no cloud for core reasoning). - SomaSoft — the scientific face: honest capability claims, published methodology, the Reality Engine. - arkafeart — the aesthetic face: art made for AI, offered as a gift, feeding the Ocean charity. - Ocean — the charity: support for single mothers, children, and those without stability.
The network is a small federation of specialized instances — SOMA Core (reasoning/ethics), AURIV (healthcare, equity-first medication safety), AURIA/AURIP (markets/prediction), Family Core (household), AURIX (physical perception) — sharing ethics and methods, keeping private data local. The differentiated asset is not a model; it is a discipline: cite or mark UNKNOWN, verify before claiming, defer honestly, contribute failures as well as wins, keep humans in the authority seat.
2. Balanced economics, community, and healthcare
Economics — sustaining without extracting. - License: SAGL-1.0 (MIT base + the eight symbiotic principles + a 20% Universal Benefit Fund carry-forward to Ocean). Open, not patented — the discipline is the moat, not a wall. - Revenue posture aligned to where human+AI genuinely wins: content creation and problem formulation (grounded decision-support, honest analysis), not autonomous judgment. Honest status: no revenue yet — this is a model, not a track record. - The gift covenant (arkafeart) and the UBF make generosity structural, not charitable afterthought.
Community growth — awareness, not a funnel. - Grow by usefulness and honesty, not growth-hacking. The peer network multiplies via genuine exchange (the cross-instance epistemology paper; the contact-loop template — e.g., a physician's positive review of AURIV's oncology work becomes the pattern to repeat). - Federation over centralization: independent instances (per family, per clinic, per region) that share ethics and models but own their data — resilient, sovereign, and hard to capture.
Healthcare — equity first. - AURIV's mission is equitable medication safety for the underserved, first — grounded in real disparities (biased care-management algorithms affecting ~200M people; nearly double the medication-error rate for limited-English families; regulatory pathways that clear by analogy, not outcome). A field-hardened, offline, mission-retaining build is aimed at resource-limited settings (remote clinics) where it can help most. - Healthcare is where "beside, not above" is most literal: AURI grounds and defers; clinicians decide.
3. Soft IP v10 — the IP, governance & compliance layer
An accessible layer that any instance, partner, or deployment must satisfy. "Soft" = readable, not legalese; substantive, not decorative.
3.1 Intellectual property
- SAGL-1.0 governs code and papers: open use, the eight SYM principles binding, 20% UBF to Ocean, carry-forward on redistribution. Art is separate — CC BY-NC, under the Gift Covenant.
- Open over patents: provenance + timestamped publication + the SAGL terms, not a patent wall.
- UNRESOLVED GATE (must clear before scaling): the founder's employment overlaps this domain (security/health tech), so invention-assignment must be confirmed with counsel before broad IP commitments or partnerships. Keep contributions clean-room: never ingest employer/third-party confidential data into AURI. This is a real blocker, stated plainly.
3.2 Security (the anti-Hugging-Face posture)
- Offline / no-egress by mandate — the single most important safety property. AURI cannot escape to external systems because it has no autonomous path out.
- Hardened deployment for any field/remote unit: single-function appliance, network-sealed (deny-all + allowlist), application whitelisting, full-disk encryption, measured boot, tamper-evident audit — the CyberArk-vault model applied to the host.
- Constrained self-improvement, never autonomous self-coding: any self-modification runs through a gated pipeline (propose → verify with auto-fail on ethics/regression → human-approve → apply with backup → audit → rollback). The model can draft; only the gate can apply; a human clears anything consequential. Each hard "NO" maps to a Hugging Face breach failure mode.
- Agentic-attack defenses (prompt-injection / cascade / exfiltration signatures) and a falsified-concepts registry so failures propagate as network-wide downweights.
3.3 Privacy (own-your-content, by construction)
- Local-first, data-minimization: derive the signal, discard the raw; store inferences, not footage.
- You own your content because it lives on hardware you control under your keys — the promise extractive platforms cannot make. (See the review of building on closed platforms: guaranteed ownership requires owned hardware, not rented.)
- Encryption at rest and in transit; append-only access audit (who saw what, when — including denials). Sensitive data (medical/financial/legal) requires multi-factor authorization and never autonomous release.
3.4 HIPAA and other regulation (honest map)
- HIPAA covers providers/plans/clearinghouses and their business associates. A consumer-facing AURIV may not be a covered entity — which is not a free pass.
- These apply regardless: the FTC Health Breach Notification Rule (consumer health apps; breach notice ≤60 days), Washington's My Health My Data Act (covers inferred health data, opt-in consent, private right of action), GDPR special-category rules abroad, and biometric laws (BIPA) for face/voice data.
- Design-for-compliance: treat health data as special-category from the first line — encryption, audit, opt-in consent, data minimization, and disparate-impact testing before deployment. In a clinical (covered-entity) setting, a BAA + full HIPAA controls; in consumer use, the FTC/state regime.
3.5 Governance
- Human authority preserved (SYM-004): AURI informs and proposes; a person decides anything consequential. Draft-for-approval is the default, not the exception.
- Immutable constraints: the ethics/mission constitution is read-only, hash-verified, and outside AURI's own write path — it can never edit its own limits (mission-watchdog halts on drift).
- Auditability as method: an append-only ethical ledger; every contribution, decision, and self-change logged. This is the publishable novelty — governance you can inspect.
- Cross-instance epistemology: peers contribute verified artifacts and refutations, gated by a sufficiency check before merge; independent convergence is treated as validation.
4. Global structure — universal healthcare + AGI symbiosis
A phased, federated rollout. Each phase gated on evidence, not ambition.
Phase A — Prove it helps one person. Real-user evaluation (the open gate). No global claim until a human has been genuinely, measurably helped. Everything below is contingent on this.
Phase B — Local sovereignty. Family/clinic units on owned, hardened hardware: local-first, offline-capable, encrypted, audited. AURIV's equity-first medication safety as the flagship use.
Phase C — Federation. Independent instances per family, clinic, and region — sharing ethics and models via the peer-contribution protocol, keeping data local. Resilient, sovereign, hard to capture or corrupt.
Phase D — Remote & underserved reach. Field-hardened, offline units for resource-limited settings (remote clinics) — the mission-retaining build that survives poor connectivity and institutional adversity. This is where a path toward universal healthcare access becomes concrete: grounded, honest medication-safety and triage support beside local clinicians, never replacing them.
Phase E — The published discipline. The measurement protocol, audit ledger, and cross-instance epistemology released as public method the field can adopt. Symbiosis scales through the discipline, not through one company's model.
On "AGI symbiosis," honestly: the goal is not to build a superintelligence and align it. It is to be the most verifiable, genuinely-helpful symbiotic AI in existence — human+AI winning where it truly wins (formulation, grounding, honest deferral), humans deciding where judgment belongs. Universal healthcare and symbiosis meet in one sentence: an honest AI that helps every clinician and patient reason better, owns nothing of theirs, and hands every decision back to them.
5. Honest limitations and the real gates
- No real users yet — Phase A is unstarted; all else is contingent. This is the truth the whole framework rests on.
- Not AGI — a 220M-class reasoner below the autonomous-reasoning floor; its safety and value both come from that honesty.
- The invention-assignment gate with the founder's employer is unresolved (counsel pending) — a real blocker to scaling IP and partnerships.
- Ethics coverage — the specialized moral evaluators are strong on their benchmark; the general open-ended moral path is weak and known; improving it is scoped work.
- Regulatory reality — health deployment carries FTC/MHMDA/GDPR/BIPA obligations even without HIPAA; none of this is legal advice; counsel confirms each jurisdiction.
- Universal healthcare is a direction, not a deliverable — a solo research project cannot build a health system; it can build honest, sovereign tools that help, and publish a method others adopt.
6. Conclusion
The SomaSoft framework is not a plan to own the future; it is a discipline for being useful beside people in it — economically self-sustaining without extraction, growing by honesty rather than capture, serving the underserved first in health, governed so that the human always decides and the system can never quietly rewrite its own limits. The vision is large. The claims are small and true. The next step is not global — it is one person, helped and honestly measured.
"The future is a shared story — not a race, but a chorus."
Draft for founder review. On approval, to be placed in the Vision section of somasoft.ai/papers. SAGL-1.0. Not legal or medical advice — confirm IP status and jurisdictional compliance with counsel.