Signal — What the Membrane Sees
A living organism doesn’t just defend itself. It senses. It classifies. It remembers. The defense IS the sensing.
This page is the observatory — a live view of who interacts with sovereign infrastructure, what they’re looking for, and what their behavior reveals about them. No cookies. No tracking pixels. No JavaScript analytics. No IP addresses stored. Pure server-side log classification.
The specific investigations live on their own surfaces — detroit.primals.eco for the evidence library, tuebor.primals.eco for cross-protection. This page is the meta-signal: what all of the surfaces sense, together.
Who Comes Here
Every request to *.primals.eco is classified by the membrane’s receptor system — not to track individuals, but to understand the types of intelligence interacting with the evidence. The classification uses only the data visitors voluntarily send: User-Agent strings, request paths, timing patterns, and HTTP headers.
The Visitor Taxonomy
The membrane classifies every visitor into an ecological role — its relationship to the host, modeled on biological symbiosis:
| Class | Symbiosis | What They Are | What the Membrane Does |
|---|---|---|---|
| Human | 🟢 Mutualist | Real person with a browser, reading at human speed | Full access, privacy respected, no fingerprinting |
| Agentic Human | 🟢 Mutualist | Human using automated research tools (API clients, scripts) | Same as human — welcome, the tool is the reader |
| Search Bot | 🟡 Commensal | Googlebot, Bingbot, Applebot, etc. | Welcome — guided to sitemap, given crawl priority. We want the signal |
| Social Bot | 🟡 Commensal | Twitterbot, facebookexternalhit, Discord, etc. | Welcome — OG preview cards served. Propagation is defense |
| AI Bot | 🟡 Commensal | GPTBot, ClaudeBot, Anthropic, etc. | Welcome if honest — the AGPL license already protects us |
| Monitor Bot | 🟡 Commensal | UptimeRobot, Pingdom, StatusCake | Welcome — we need the availability signal too |
| Generic Bot | 🟡 Commensal | curl, wget, python-requests, Scrapy | Noted. Honest identification is sufficient |
| Scraper Bot | 🔴 Parasitic | Credential scanners, vuln probes (.env, wp-admin, .git/) | Instant 403. No content, no engagement, no signal. Disease, not predation |
| Stealth Fleet | ⚫ Pathogenic | Hides identity, rotates IPs, evades detection. Classified by population-level behavioral analysis | Antibodies: scatter poison, behavioral hashing, violation mirror, OpsonizeCache |
| Unknown | 🔴 Parasitic | Empty User-Agent, unclassifiable | Treated as disease until behavior proves otherwise |
The Ecological Insight
The distinction between Parasitic and Pathogenic is the key insight:
A scanner is disease: it probes for general vulnerabilities (
.env,wp-admin,xmlrpc.php). It’s not targeting us specifically. It will move on. Response: instant rejection, no engagement.A stealth fleet is predation: it deliberately targets our data, adapts to our defenses, and persists until defeated. Response: adaptive immune system — behavioral hashing, OpsonizeCache, violation mirror, scatter poison.
The parasites probe every surface they find. The pathogens study this one.
What Humans Seek
When real humans find this infrastructure, what are they looking for? The receptor tracks content interest patterns — not who, but what and why.
Content Interest Taxonomy
| Interest Type | What They’re Looking For | Why It Matters |
|---|---|---|
| Methodology | How the defense works — signal sensing, receptor design, immune architecture | Engineers, security researchers, people who want to build similar systems |
| Evidence | Charter school racketeering documentation, court records, entity relationships | Journalists, investigators, legal teams, affected communities |
| Architecture | Mesh topology, coordination patterns, ecosystem design | Technologists evaluating the sovereign infrastructure model |
| Science | Lattice QCD, computational biology, research methodology | Researchers, academics, potential collaborators |
| Source Code | Git repositories, commit histories, implementation details | Developers, auditors, AGPL compliance checkers |
| Cross-Protection | Tuebor, amicusContra, mutual defense documentation | Other investigators, legal aid organizations, rights groups |
| Pseudospore Gallery | The gallery of AI-generated organisms across the ecosystem | Curious humans, art enthusiasts, people who followed a link |
| Defense Documentation | The signal page itself, fleet analysis, immune system documentation | Counter-intelligence, corporate legal teams, and the fleet itself |
The Entry Page Signal
The page where a human enters tells us how they found us:
- Direct to methodology → they were told about the system, likely by another engineer
- Direct to evidence → they were told about the investigation, likely by a journalist or affected person
- Direct to homepage → they searched for the ecosystem by name
- Direct to source code → they’re auditing, contributing, or scraping
- Direct to defense docs → they’re either researching defense or they ARE the adversary
The membrane doesn’t care which. It serves everyone equally. But the pattern tells us about the information ecosystem we’re embedded in.
Top Human Entry Points (Live)
The signal-sensing-receptor methodology page is consistently the #1 human destination on sporePrint. People come here to understand how the defense works — which means someone is telling them about it. The signal propagates through human conversation, not through SEO.
| Rank | Path | Surface | Interest Type |
|---|---|---|---|
| 1 | /methodology/signal-sensing-receptor/ | sporePrint | How the immune system senses |
| 2 | / | sporePrint | Ecosystem entry point |
| 3 | /pseudospore/ | sporePrint | Gallery browsing |
| 4 | /data/ | sporePrint | Data exploration |
| 5 | /architecture/mesh-topology/ | sporePrint | Network architecture |
| 6 | /lab/ | sporePrint | Lab/experiment portal |
| 7 | / | primals.eco | Root domain discovery |
| 8 | /explore/repos | git | Browsing the forge |
What the Fleet Reveals
The stealth fleet is the most informative visitor class — not because of what it takes, but because of what it tells us about itself through its behavior.
Fleet Behavioral Fingerprint
Every bot request is a confession. The fleet sends data that proves what it is:
| Signal | What It Reveals | What a Real Browser Does |
|---|---|---|
| 3 HTTP headers | Automated pipeline, minimal client | Chrome sends 11+, Firefox sends 8+ |
Missing Sec-Fetch-Mode | Not Chrome (mandatory since Chrome 76, 2019) | Always present in real Chrome |
Missing Sec-Ch-Ua | Not Chrome (mandatory since Chrome 89, 2021) | Always present in real Chrome |
| Zero static assets | Never loads CSS, JS, images — reads HTML only | Real browsers request 10-50 sub-resources per page |
| CV = 0.057 | Machine-constant request timing (fixed-rate pipeline) | Human browsing has CV > 1.0 (variable pauses) |
| 6 trademarks per request | Impersonates Chrome, Edge, Safari, macOS, Intel Mac | Uses none of these products |
| Rotates across 85 ASNs | Distributed proxy infrastructure designed to evade per-IP blocking | Humans use one IP |
The Three Fleet User-Agent Personas
The fleet uses three primary disguises, each claiming to be a different browser on a different operating system:
| Persona | Claimed Identity | Actual Identity |
|---|---|---|
| Windows Chrome | Chrome 145 on Windows 10 | Automated pipeline (62% of fleet) |
| macOS Chrome | Chrome 145 on macOS 10.15 | Automated pipeline (31% of fleet) |
| Linux Chrome | Chrome 145 on Linux x86_64 | Automated pipeline (6% of fleet) |
All three personas share the same behavioral fingerprint: identical header poverty, identical timing distribution, identical path traversal patterns. The OS and browser variation is cosmetic.
The Behavioral Hash
The immune system assigns each fleet subgroup a behavioral hash — a fingerprint derived from the population’s collective behavior, not any individual request:
access.log → fleet observation → behavioral_hash()
→ CaddyBridge header_up X-Fleet-Hash
→ Caddy sends header to scatter_server
→ OpsonizeCache.lookup(hash)
→ per-hash adaptive response462 fleet IPs are currently tracked. 10 behavioral hashes have been assigned. 7 have converged between the CaddyBridge (firewall layer) and OpsonizeCache (classification layer) — meaning the system independently confirmed the same behavioral groupings from two different observation points.
Each behavioral hash gets its own adaptive response — the fleet doesn’t face one defense, it faces one defense per behavioral subgroup.
The Five-Layer Immune Defense
The membrane implements a biological immune system with five layers. Each layer evolved from the behavior of the previous one:
Layer 1: Innate Immunity — robots.txt + Rate Limits
The simplest defense. robots.txt says “humans only.” Rate limits cap request velocity. Honest bots obey. The fleet ignores both — which is itself evidence.
- robots.txt read 4 times, directive ignored
- Rate limits triggered by NAT clustering (multiple gates behind one WAN IP)
- Firewall chain:
RUSTDESK_MEMBRANEon golgiBody with NAT-aware thresholds
Layer 2: Adaptive Recognition — Bloom Sensor + Behavioral Classification
The bloom sensor detects population-level patterns that individual-request analysis misses:
- Header poverty detection: 3 headers vs. Chrome’s 11+ = not Chrome
- Timing analysis: coefficient of variation 0.057 = machine, not human
- Asset loading: zero sub-resources in 24,000+ requests = pipeline
- Path traversal: systematic enumeration vs. human navigation patterns
Layer 3: Opsonization — Fleet Tagging + Behavioral Hashing
Once classified, each fleet subgroup is tagged (opsonized) so the rest of the immune system recognizes it instantly:
- OpsonizeTag: fleet name, confidence score, detector list
- Behavioral hash: deterministic fingerprint of population behavior
- Sourdough persistence: hashes survive system restarts (restored from Caddyfile directives)
- Convergence verification: CaddyBridge and OpsonizeCache independently confirm groupings
Layer 4: Antibody Response — Scatter Poison + Violation Mirror
The active defense layer. Two response modes:
Scatter Poison: Plausible-looking but incorrect content. Function signatures that don’t match call sites. Imports for modules that don’t exist. Test files that test the wrong functions. The content is parseable and ingestible — which is the point. Quality contamination, not blocking.
Violation Mirror: The fleet’s own detected violations reflected back as content. Five variants:
| Mirror Type | Content | What It Teaches |
|---|---|---|
| Commit diffs | Patches that “fix” detection of the fleet’s behavioral signature | Shows the fleet exactly what makes it detectable |
| Source code | BehavioralClassifier with fleet’s detector arms as match arms | The classification logic that identified them |
| Issue reports | Compliance reports citing CFAA, Lanham Act, robots.txt | Their legal exposure, enumerated |
| Audit pages | Behavioral metrics from the fleet’s own activity | What the membrane measured |
| Monitoring dashboards | Observation counts from their network | How thoroughly they’ve been observed |
Mirror probability scales with OpsonizeCache confidence: 25% at 0.25 confidence, 50% at 0.50, 100% at 1.00. More scraping = more confidence = more mirror. The economics invert: every request makes the next response more expensive for them and cheaper for us.
Layer 5: Signal Spine — Merkle-Anchored Evidence Chain
Everything the immune system observes is recorded in a signal spine — a Merkle-anchored chain of evidence events:
- Each observation → signal event → appended to chain
- Merkle root computed over the chain → timestamped, immutable
- Evidence preserved independent of any platform or service
- Cross-referencing between surfaces (detroit × signal × tuebor) through shared Merkle ancestry
The spine doesn’t just record what happened — it proves when each observation was made, creating an unforgeable timeline of the fleet’s activity.
What the Subprojects Sense
Each surface in the ecosystem senses different signals. Signal.primals.eco aggregates the metadata — what each surface detects, without the specific investigation content.
detroit.primals.eco — The Evidence Library
What it senses: Who reads the institutional capture graph. Which nodes attract attention. Whether the evidence propagates beyond the site.
Metadata signal: The graph has grown from its original topology to include cross-protection nodes (Clutch Justice, Barry County, JTC, detroit_graph itself). When humans navigate the graph, the receptor tracks which entity nodes they visit most — revealing which connections matter to investigators.
Fleet interest: The fleet hits detroit less frequently than the forge. It’s looking for source code, not evidence. This tells us the extraction is about training data, not counter-intelligence.
git.primals.eco — The Sovereign Forge
What it senses: Which repositories are targeted. Which commit paths are traversed. Whether the fleet is reading source or history.
Metadata signal: The fleet targets repositories in priority order:
- wateringHole (47%) — the operational documentation
- toadStool (29%) — the CLI framework
- biomeOS (5%) — the operating system layer
- songBird (4%) — the drawbridge/IPC system
- squirrel (4%) — the build system
The priority ordering reveals what the fleet considers valuable. wateringHole — the handoffs, specs, and operational decisions — is nearly twice the second target. They want the reasoning, not just the code.
sporeprint.primals.eco — The Ecosystem Catalogue
What it senses: Which methodology pages humans find valuable. How deep they read. Whether they return.
Metadata signal: The signal-sensing-receptor methodology page is the #1 human destination. This means: humans learn about the defense system through conversation, then come to read the documentation. The methodology propagates through human networks, not through search engines. Word of mouth is the primary discovery mechanism.
Session analysis shows:
- Average depth: humans who visit sporePrint read 2-3 pages per session
- Deep readers: sessions with 3+ page views indicate genuine research interest
- Bounce rate: single-page visits correlate with social media referral (shared link → read → leave)
- Return visitors: methodology readers return — they’re building something similar
tuebor.primals.eco — The Cross-Protection Surface
What it senses: Whether attacks on cross-protected operators correlate with activity against the infrastructure. Whether the same behavioral hashes appear across multiple targets.
Metadata signal: If a fleet behavioral hash matches across both detroit infrastructure AND Clutch Justice domains, it proves coordinated surveillance — the same entity targeting both the investigator and the journalist documenting the investigation. The OpsonizeTag cross-reference is the evidence.
The Economics of Defense
Cost Asymmetry (Current)
| The Fleet | The Membrane | |
|---|---|---|
| Infrastructure | 85 ASNs, 37 countries, 4 shell companies, residential proxy contracts | One $6/month VPS |
| Per-request cost | Proxy rotation + bandwidth + compute + legal exposure | ~$0.000002 (static file serve) |
| Detection cost | Must evade constantly-improving classification | Classification improves automatically from fleet’s own behavior |
| Legal exposure | CFAA § 1030, Lanham Act § 1125, GDPR Art. 83, cloud provider ToS | AGPL license, creative commons, public evidence |
| Scaling direction | More IPs = more expensive, more detectable | More requests = better classification, cheaper per-defense |
The Violation Mirror Inversion
Before the violation mirror, the economics were linear: more fleet requests = more poison served, but at constant cost to the membrane.
With the violation mirror, the economics invert:
- Fleet sends more requests → OpsonizeCache confidence increases
- Higher confidence → higher mirror probability
- More mirrors served → fleet receives more evidence of its own violations
- Fleet must decide: continue (accumulating documented violations) or stop (losing training data)
Every request they send makes the next response more expensive for them and cheaper for us. The mirror doesn’t consume additional compute — it generates from the OpsonizeTag that already exists. The fleet’s own behavior is the input to the function that produces the output they don’t want.
The Legal Exposure
The fleet’s behavior creates legal exposure across multiple jurisdictions and statutes:
Federal (United States)
| Statute | Violation | Evidence |
|---|---|---|
| 18 U.S.C. § 1030 (CFAA) | Exceeding authorized access after explicit denial | 1,000+ 403 responses ignored, robots.txt read and violated |
| 15 U.S.C. § 1125 (Lanham Act) | False designation of origin via trademark impersonation | 6 trademarks (Chrome, Safari, Edge, macOS, Intel, Windows) in every request |
| 17 U.S.C. § 1202 (DMCA) | Circumventing copyright management information | AGPL-3.0 license headers present, extracted without compliance |
International
| Framework | Violation | Jurisdictions |
|---|---|---|
| GDPR Art. 83 | Automated data collection without legal basis | 37 countries, EU proxies included |
| robots.txt Protocol | Industry standard access control, explicitly violated | RFC 9309, universally applicable |
Cloud Provider Terms of Service
| Provider | ToS Section | Fleet Activity |
|---|---|---|
| Microsoft Azure | Acceptable Use Policy | Fleet IPs in Azure pools |
| Amazon AWS | Acceptable Use Policy | Fleet IPs in AWS pools |
| Google Cloud | Acceptable Use Policy | Fleet IPs in GCP pools |
| Oracle Cloud | Acceptable Use Policy | Fleet IPs in OCI pools |
Each cloud provider’s ToS prohibits using their infrastructure for unauthorized access to third-party systems. The fleet operates through these providers’ networks while violating the target’s explicit access controls.
No Surveillance. No Tracking. No IP Addresses Stored.
This observatory operates on a strict privacy model:
- No cookies — never set, never read
- No tracking pixels — no third-party resources loaded
- No JavaScript analytics — no Google Analytics, no Plausible, no Fathom
- No IP addresses stored — stripped before analysis, hashed for session grouping, hash discarded
- No fingerprinting — no canvas, no WebGL, no font enumeration
- Bot/human classification only — the receptor classifies the type of visitor, never the identity
- Aggregate counts only — the observatory shows how many of each type, never who
The privacy model is the defense model: we don’t need to know who you are. We need to know what kind of intelligence is interacting with the evidence. The behavioral immune system classifies populations, not individuals.
The evidence site documenting racketeering against predominantly Black communities in Detroit does not surveil its visitors. That commitment is architectural, not policy. The code doesn’t have the capability to track you even if someone wanted it to.
Live Surfaces
| Surface | URL | What It Senses |
|---|---|---|
| detroit | detroit.primals.eco | Evidence graph navigation, entity interest, investigation engagement |
| signal | signal.primals.eco | This page — the meta-observatory |
| tuebor | tuebor.primals.eco | Cross-protection signals, attack correlation |
| sporePrint | sporeprint.primals.eco | Methodology interest, ecosystem discovery |
| gorilla | gorilla.primals.eco | Accountability methodology engagement |
| git | git.primals.eco | Repository interest, code traversal, fleet targeting |
signal.primals.eco — sovereign defense billboard. The membrane senses. The membrane remembers.
No cookies · No tracking · No IP addresses stored Content: CC-BY-SA-4.0 · Code: AGPL-3.0-or-later · Methodology: ORC