MITHRIL · ENTERPRISE KOTOBA
The boundary Kotoba draws, at enterprise scale.
The enterprise edition of Kotoba — the language where AI writes freely and the compiler draws the boundary. Same language, same checked KIR, same content-addressed artifacts; with the policy, evidence and support a fleet requires.
Rendered live in your browser by kami-engine
Security as a property of the whole computation
Existing software adds security around the program. Kotoba makes it a property of the computation — and Mithril carries that property into an organisation.
No ambient authority
Filesystem, network, process, clock, model and secrets are grants, never defaults. A generated program cannot reach for what it was not given.
Authority survives compilation
Types, effects, resources and target support are admitted in checked KIR before anything is emitted. What the compiler admitted is what the host enforces.
PQ is the admission floor
Hybrid X25519 + ML-KEM-768 for new encrypted objects and ML-DSA-65 for publication authority — the coverage kotoba-lang.org publishes as machine-readable data, not a compatibility mode.
What Mithril adds
One language, one compiler, one specification. Mithril is the distribution of it that an enterprise can adopt, audit and keep.
| Capability | Kotoba (open) | Mithril (enterprise) |
|---|---|---|
| Language, compiler, checked KIR | The same | The same — pinned toolchain releases with an upgrade path |
| Toolchain distribution | Public releases | Private, signed, installable on an air-gapped site |
| Policy | Capability kits | Organisation policy packs: allow-lists as data, reviewed like code |
| Evidence | Public benchmarks and coverage | Per-artifact compliance exports: SBOM, admission receipts, release attestations |
| Library registry | kotoba-lang.org/libraries | A private registry on the same exact-CID dependency graph |
| Deployment | Kotoba Cloud | Kotoba Cloud, dedicated, or sovereign deployment |
| Support | Community | Named engineers, response targets, security advisories |
One boundary, end to end
The boundary is not a wrapper. It is carried from the source through the compiler into the artifact and onto the host — every step admits, none of them trusts the previous one.
-
Source
Inspectable programs in a Lisp-shaped language written for humans and agents alike.
-
Checked KIR
Elaboration into a typed intermediate representation. What cannot be typed is refused, not guessed.
-
Admission
Capabilities, effects and resource budgets are admitted as data — the grant is explicit and inspectable.
-
Artifact
Content-addressed output with a signed provenance. The CID is the identity; nothing is looked up by name.
-
Host
Only the admitted grant is bound. Enterprise hosts add the organisation's policy pack on top.
Proof, not promises
Mithril inherits every public claim Kotoba makes and adds no unpublished ones. Read the evidence where it is published.
Reproducible benchmarks
Cold build, runtime and build-scaling measurements with their samples.
Cryptographic boundaries
The machine-readable post-quantum coverage authority, as deployed.
Library provenance
Exact CID dependency graphs and compatibility evidence for published libraries.
Source
The language authority and the implementation, in the open.
Runs where you run
The operational surfaces are separate authorities, not one product: adopt the ones your boundary needs.
Questions
Is Mithril a fork of Kotoba?
No. There is one language, one compiler and one specification, published at kotoba-lang.org. Mithril is the enterprise distribution of exactly that.
Does Mithril change what a program is allowed to do?
It never widens it. Admission is the language's. A policy pack lets an organisation narrow what its hosts grant — and that narrowing is data, reviewed like code.
Can it run on an air-gapped site?
The toolchain runs without a JVM and artifacts are content-addressed, so a pinned toolchain and a private registry are all an offline site needs. Nothing phones home.
What is mithril.fund?
The home of the enterprise edition. Commercial terms and design partnerships are handled here; the language stays public at kotoba-lang.org.
Talk to us
Design partnerships are open to a small number of teams that run generated code in production. Tell us what your boundary has to hold.
Write to usOr email support@kotoba-lang.org with the subject “Mithril”.