Arboria Principles
Most statements of principle are written to be agreed with. This one is written to be checked. Every commitment below is one we can be held to against the published record, and more than one of them has already cost us a result we would rather have kept.
Scope the claim to the evidence
Our results come from a simplified three-dimensional kinematic simulator. That makes them claims about coordination algorithms — how a decentralized rule behaves when information arrives late, or partially, or not at all — and it does not make them validation of physical hardware. The distinction is easy to blur, and we take care not to blur it. A real orbital ephemeris anchors orbits; it does not launder a claim about anything else, and we will not let the credibility of one layer be quietly borrowed by another.
The practical form of this commitment is that we say what a number is every time we report one. Where a figure is a projection rather than a measurement, its caption says so. Where a comparison rests on a thin sample, we report the interval and not merely the point estimate — because a point estimate without an interval is an assertion wearing the clothes of a result.
Publish the refutations, in the paper that made the claim
Several of the hypotheses this lab built papers around have since been refuted by our own instrumentation. Those refutations are published in the papers that originally advanced them, in the sections that made the claims, and none is buried in a footnote.
We introduced a queueing model to argue that buffering decouples production rates across scales — then instrumented it, and found the queues run saturated in every regime we measured, where no such decoupling is possible. The model earned its place in the paper precisely by destroying the hypothesis it was built to support. Separately, a headline improvement of 29% failed to survive re-measurement at a higher seed count, and turned out to be an outright loss in a regime we had described as a harmless tie. We rewrote the paper around what the data showed rather than around what we had hoped for.
We record this as calibration, not penance. A lab that publishes only its wins is not measuring anything; it is advertising. The correction is part of the product.
Make failure loud
The dangerous defect in scientific software is not the crash. It is the plausible default — the empty series that averages to zero, the missing metric that reads as a perfect score, the benchmark that quietly ran a different algorithm than the one on its label. None of these fail a test, because a plausible number is not an exception, and nearly every serious defect we have found in our own stack has been of exactly this kind.
So our instrumentation is built to raise rather than to substitute. A metric that cannot be computed is an error, not a zero. A comparator that cannot be dispatched aborts the run rather than falling back to the very method it was meant to be tested against. The coordination layer is pinned by cryptographic fingerprints that fail the build the moment a refactor perturbs a published number — a safeguard we can vouch for, because it has already caught one.
Reproducibility, to the limit of what we can honestly offer
Every published figure names the immutable experiment batch behind it, and every batch records the software versions, the configuration, and the hardware that produced it. Figures are generated by committed scripts that declare their own provenance, so a figure cannot drift away from its data without the drift becoming visible.
Our engines are proprietary, and we will not pretend that external reproduction means the same thing under that constraint as it would with open source. We say so plainly rather than promising more than we can deliver — and we publish the batch identifiers, the configurations, and the reduction scripts, so that what can be checked, can be.
Dual-use caution
Swarm methods are not neutral. The same coordination that lets a fleet allocate work efficiently lets it search, track, and deny; and decentralization — which is our subject — is precisely the property that makes such systems hard to interdict. We do not contribute directly to lethal autonomous weapons, and we gate the publication of work that would materially accelerate them. That is a constraint on what we release, not a disclaimer appended to it.
Orbital and planetary responsibility
Large deployments in orbit create collision-cascade risk, and deployments beyond Earth create contamination risk. Both are irreversible on human timescales, which puts them in a different category from the trade-offs engineering usually adjudicates. Our simulations and our recommendations treat debris, deorbit, and forward contamination as first-order design constraints rather than externalities to be handled later, by someone else.
Open collaboration
We publish, we build tooling meant to be used outside this lab, and we would rather be corrected early than cited uncritically. If you find an error in our work, we want to hear about it — that is what the contact page is for. A correction is worth more to us than a citation.
Last updated: 13 July 2026.