Skip to content
Get started
View all products → One platform · one sign-in · every product on dcsai.ai
View full sitemap → DCS AI Technologies L.L.C, Dubai · parent of DCS Network + DCS Labs
Writing · launched May 22, 2026

Blog

Long-form writing from DCS AI Technologies. AI agent infrastructure, the R+2 standard, regulatory alignment, founder narrative.

EngineeringJuly 17, 20267 min read

Two P0s, one root cause: identity comes from a verified token

Weekly achievements. The two most serious open items in the estate this week were the same bug twice — a service reading identity from the request instead of a verified token. The TRD gateway (api.trdn.io) got a shared server-side verifyToken(), a JWT-verified owner gate and a Mind+ proxy that trusts the token, not the URL; the DCS intelligence engine closed an open door where userId came from the query string, added tenant isolation, and now refuses to boot live without a signing secret. Both fixes are committed and pushed; the live deploy is not independently network-verified from our environment and the forged-token 401 proof is still owed. Internal, integrator-rerun reads. No production ZK, no live federation.

ResearchJuly 17, 20264 min read

The grader grew teeth: grading the intelligence engine on a real key

Weekly achievements companion. We built an evaluation harness for the DCS intelligence engine's memory extractor and pointed it at a real model. A held-out corpus written by someone forbidden to read the extractor caught the prompt memorizing its own test sets, and grading on a live key surfaced that the learn path had made 148 provider calls and stored zero facts. The harness also caught itself — about to write test facts into real memory, and scoring rate-limited cases as failures. All numbers author-reported, internal, integrator-rerun. Measurement, not a launch; receipts stay unsigned.

EngineeringJuly 3, 20266 min read

Round 1 is deployed and green — and still dark on purpose

Weekly achievements. The DCS gateway's Round 1 is deployed and green on api.dcsai.ai — twenty feature routes, an MCP tool layer, and migrations 023–036 — running behind flags that are still off. Verified against the live deploy by an internal, integrator-rerun smoke suite (8/8 routes) and an IDOR/authz money test (11/11, no cross-user leak, two real users), with Sentry + Grafana monitoring live and TLS/headers graded A+/A. Money and autonomy stay dark; only the founder flips it.

EngineeringJuly 3, 20264 min read

Scanning the worker SBT contracts before anything mints

Weekly achievements companion. A Slither 0.11.5 / solc 0.8.28 static-analysis pass over the DCS and TRD worker soulbound-token contracts returned zero High/Medium findings in custom code — the flagged High/Medium entries are OpenZeppelin Math.sol false-positives, and the only own-code finding is a benign Low reentrancy in mint(). The scan settled the choice to deploy the AccessControl (v2) build over the Ownable (v1) one. A static scan is a floor, not a full audit — and nothing mints on the strength of it.

EngineeringJune 19, 20265 min read

The receipt boundary: a first outside product wires into DCS Verify

Weekly achievements. A quieter week on the core — and the piece that matters most is small: an external product is now wired to emit DCS Verify receipts through the gateway into DCS storage, conforming to our receipt shape. The proof it's real is two unglamorous fixes (UUID coercion for a Postgres 22P02) that only show up once data actually flows. Committed and pushed; the resolved live path is not yet independently verified. Plus the honest labels on a committed pilot-v1 page and an outside product's honest-zero stats.

EngineeringJune 12, 20265 min read

DCS Intelligence is live: first-party analytics with an honesty rule

Weekly achievements. This week's biggest shipped surface is DCS Intelligence — our own analytics dashboard, deployed and network-verified live at intel.dcsai.ai on a first-party data spine, with PostHog feeding real traffic. The design constraint that shaped it: show a dash, never a guess, wherever a source isn't connected. Plus the DCS Verify build-flow wiring that's committed but not yet verified live.

PerspectiveJune 12, 20265 min read

Most AI agent systems can run. Can they prove what they did?

AI agents now take real actions — calling APIs, moving money, executing workflows. The next challenge isn’t execution, it’s accountability: can you prove what an agent actually did? Why logs require trust, what a verifiable receipt is, and DCS’s first live on-chain AI-action receipt.

EngineeringJune 5, 20266 min read

One day, sixteen deploys: the R-Series goes live end to end

First weekly achievements post. June 4–5: the Trust SKU verification API goes live on api.dcslabs.ai, post-quantum hybrid co-signatures deploy dark behind an 8-verifier regression gate, the verify app ships as a PWA with an honest build-time status page, and a legacy property moves to the new stack — plus the sandbox-prove, flags-off, one-flip-at-a-time discipline behind 1,400+ internal, integrator-rerun checks.

LaunchMay 22, 20264 min read

Coming live: DCS AI Technologies and the R+2 Open Provenance Standard

After a ~41-day intensive build, DCS AI Technologies launches with R+2, an on-chain agent identity contract on Base mainnet, two npm packages, the Project Fifty agent stack, and three sectoral profiles for government, healthcare, and finance. Every claim independently verifiable.

ResearchMay 19, 202612 min read

Why Ed25519 and RFC 8785 — defending the R+2 primitives

Long-form defense of the cryptographic choices in R+2. Why Ed25519 over ECDSA/RSA/BLS. Why RFC 8785 canonical JSON over ad-hoc canonicalization. Why SHA-256 not BLAKE3 or SHA-3 in v0.1. What the post-quantum migration path looks like.

More writing coming weekly

Per the post-launch content calendar — every Friday a long-form essay, weekly retrospective, or technical deep-dive. Topics queued for Days 7-30: Python R+2 client release, agent identity without identity providers, why DCS positioned as infrastructure not product, the ~41-day sprint method.