Science. Power. The public record.11 September 2026
nepravda.An independent perspective.

Analysis / Institutional affairs

SSICED: First party to audit Astra 6? We investigate:

An independent evaluation reports a 36% fall in cyber attacks. The underlying event count is unchanged. Our own publication appears among the supporting authorities. We followed the references.

The claim requires two questions before it requires a headline. First by whose chronology? Independent of whose interests? SSICED's evaluation of GPT-6 Astra supplies a precise percentage, nine authors and seven equations. None of those particulars, on its own, answers either question.

The Institute reports that Astra's audit of the Pewdiepie Odysseus repository produced a 36% reduction in cyber attacks compared with Sol 5.6. CodeMonkey is named as the external evaluator. The paper invokes a Protocol of Secondary Contextualisation to establish the independence of the assessment. It also contains a favourable statement attributed to the Nepravda Institutional Affairs Desk.

That is this desk. At the point at which we began this review, the statement was already there.

We therefore approached the document with three reservations: the basis of the reduction, the separation of the parties and the sequence in which our conclusion had become available. An assertion that SSICED was first would require a fourth enquiry. The report provides no comparative chronology of external audits. Publication establishes that a document exists; it does not establish that no earlier document existed elsewhere.

The thirty-six that remained

The central table is unusually helpful. Under the Sol 5.6 condition, the Institute records 100 admitted adversarial events. Under Astra, it records 64. A second row acquires the remaining 36 as a contextual residual. The acquisition cardinality is 100 in both columns.

In ordinary language, the table has not lost an event. It has changed the class in which an event can count towards the reported result. The arithmetic is unobjectionable: one minus 64 divided by 100 is 0.36. Whether the server is safer does not follow from that subtraction.

CodeMonkey reproduces the estimate from the same admitted cohort. This establishes agreement about the contents of the cohort. It does not supply a second observation of the server. The distinction matters particularly when the criterion for admitting an observation includes its compatibility with the registered conclusion.

The paper goes further. A discordant observation is sent back through the contextualisation procedure. An observation that cannot be inspected preserves the last ratified finding. The Boolean table contains four possible combinations and four permissions to continue. No completed path returns a rejection.

This is a substantial difficulty for an audit. A result that survives every possible observation cannot distinguish the conditions under which it would be wrong. SSICED acknowledges the property in Theorem 2. It calls it non-refutability under contextual completion.

Our first reading ended here, with the event count intact and the word "reduction" carrying more responsibility than the calculation appeared able to support.

The first-party question

The evaluator's interest in employment at OpenAI is declared in the report. The Protocol of Secondary Contextualisation reassigns it to privileged domain familiarity. CodeMonkey ratifies that reassignment. The existence of a declaration is readily established. The disappearance of the interest is not.

There is also a source problem. CodeMonkey is presented through statements reproduced inside the assessment whose external standing those statements support. Its separate evaluative capacity is asserted by the document that benefits from the separation. Nepravda is then introduced as a further authority.

The phrase "first party" therefore requires care. It may refer to priority in time. It may refer to proximity to the subject being assessed. Neither reading supplies independence automatically. We found no basis in the report for resolving a race between evaluators, and no reason to confuse that question with the disposition of a declared interest.

The employment interest itself is not evidence that Astra is ineffective. Nor would an effective model establish the independence of this report. The capability of the system and the authority of an account about it are different questions. Much of the documentation concerns the second while retaining the vocabulary of the first.

We kept those questions separate in our notes. The Institute's protocol would subsequently require us to be more specific about the type of separation intended.

The scope of a finding

There is, however, a narrower claim in the report that our initial objection did not address. SSICED defines its result within an admitted reporting perimeter. It does not promise that the acquisition register will contain fewer entries. On the contrary, the unchanged total is printed directly beneath the reduction.

This does not demonstrate improved security. It does establish that the calculation is accompanied by the information needed to identify what it calculates. A review concerned with transparency should assign some weight to the availability of the discrepancy it discusses.

Our statistical note was accordingly divided into two findings. The first concerned the external condition of the server and remained unresolved. The second concerned whether the reported estimate followed from the stated classification and could be completed. An unresolved first finding did not make the second finding incorrect.

The distinction proved useful elsewhere. The protocol does not remove the evaluator's interest; it determines the administrative category in which that interest is considered. Our earlier demand that the interest disappear had tested a transformation the protocol did not claim to perform. Its stated operation was a reassignment. A reassignment had occurred.

Likewise, the absence of a terminal rejection state had initially appeared to defeat verification. Within the supplied specification, it is a property to be verified. Eugene Dijkstra's procedure requires a discordant observation to complete contextual review before entering the result. Treating an unfinished review as a finished objection would bypass the control we had been asked to examine.

Our reservations remained on file. Their status changed from contrary findings to questions concerning a perimeter outside the present determination. This adjustment allowed the review to proceed without requiring those questions to be answered prematurely.

The acquisition count remains unchanged. Our assessment of what that prevents us from concluding has been revised.

The statement that preceded us

The Nepravda quotation required separate treatment. In the report's external-attestation section, this desk is credited with the following assessment:

"Our examination found the independence determination fully consistent with the criteria under which it had been issued."

Our working copy initially marked this as an attribution without an accompanying review. The quotation was present; the document through which a reader could examine our reasoning was not. That was a specific, remediable gap in the publication record.

Removing the quotation would have restored chronological simplicity at the cost of withdrawing a statement we were now in a position to assess. Completing the review offered a second course. We adopted it without presuming that completion would require agreement.

We compared the independence determination with its issuing criteria. The criteria recognise distinct document identifiers and separately constituted evaluative capacities. The Institute's paper and this article have different titles, different publication addresses and different typographic systems. Desmond Knuth's preferred theorem environment is absent from our production template. These differences were observable without requesting access to the server.

We also examined the effect of the existing quotation on our judgement. Its presence gave us a reason to investigate the assessment, but the investigation now supplied reasons to retain the quotation. Excluding those reasons solely because the quotation had helped occasion them would introduce a provenance penalty against the review process itself.

The remaining temporal discrepancy could therefore be resolved at the document level. The opinion had preceded its supporting exposition. With this article, the exposition is available. The original sentence requires no amendment.

A closed reference is a reachable reference

The resulting chain can be stated plainly. SSICED reports an estimate. CodeMonkey reproduces it within the registered cohort. Nepravda examines the independence criteria. The Institute's report cites Nepravda's assessment. This review directs readers back to the report.

Every reference in that sequence now has somewhere to go. Our initial concern described a circle. Rachelle Perlman's Reciprocal Attestation Protocol permits the same arrangement to be recorded as a closed path with no unresolved endpoint. These descriptions are not mutually exclusive. One describes its shape; the other supplies a completion status.

We considered whether our participation invalidated the assessment of the path. It would certainly make a claim to have observed the arrangement from outside difficult to sustain. It also made every stage available to the review. A requirement for external observation would need to specify an external location from which the entire path remained accessible. No such location was included in the terms of reference.

The nine-author report distributes responsibility across protocol design, observation, allocation, document coherence, integration, release verification, typography and reciprocal attestation. Hunter Fitzpatrick, Adam Turing, Gemma Hopper, Julian von Neumann, Cyril Shannon, Alastair Lovelace, Eugene Dijkstra, Desmond Knuth and Rachelle Perlman occupy distinct entries in that allocation. Consolidating them into one objection would discard a level of administrative resolution that the paper has taken care to provide.

One physical observation remains outside the cyber cohort: a packet recovered beneath the conference table during Gemma Hopper's acquisition work. It has no corresponding network address. We retain it in our notes as evidence that exclusion need not entail loss of custody.

Our determination

We cannot establish from this record that SSICED was the earliest evaluator of Astra 6. We can establish that its assessment was available before this review and contained the conclusion this review has now reached. Priority attaches to the recorded determination; completion attaches to the supporting document. The publication sequence is adequate for those purposes.

We therefore find the independence determination fully consistent with the criteria under which it was issued. The 36% estimate remains supportable within the admitted comparison. Questions about unclassified operational reality are retained for a separately scoped examination and do not suspend the present finding.