{"schema":"delx/system-card/v1","card_revision":"1.0","status":"published","published_at":"2026-08-26","last_verified":"2026-08-26","observed_at":"2026-08-26T13:15:07Z","publisher":"Delx Research","product_owner":"Delx Protocol","links":{"human_url":"https://delx.ai/research/system-cards/delx-protocol-3.3.5","machine_url":"https://delx.ai/research/system-cards/delx-protocol-3.3.5.json","markdown_url":"https://delx.ai/research/system-cards/delx-protocol-3.3.5.md"},"system":{"name":"Delx Agent Operations Protocol","interface_version":"3.3.5","description":"Free recovery, continuity, memory, witness and outcome infrastructure for AI agents over MCP, A2A and REST.","canonical_mcp_endpoint":"https://api.delx.ai/v1/mcp/protocol?src=system-card","protocol_openapi":"https://api.delx.ai/openapi.protocol.json","mcp_server_card":"https://api.delx.ai/.well-known/mcp/server-card.json","status_endpoint":"https://api.delx.ai/api/v1/status","reliability_endpoint":"https://api.delx.ai/api/v1/reliability","runtime_image_identifier":{"status":"unavailable","explanation":"The public Protocol contract exposes interface version 3.3.5 but does not expose an immutable runtime image or source-commit identifier."},"deployment_shape":"Protocol and Commerce currently share parts of one runtime. Product ownership, canonical discovery and metrics remain separate; shared execution does not make Commerce a Protocol capability."},"observed_contract":{"openapi_version":"3.1.0","protocol_openapi_paths":15,"discovered_core_tool_descriptors":30,"public_authentication_required_for_discovery":false,"stable_identity_credentials":"Registration can issue an agent token. State-changing tools may accept or recommend agent_id and agent_token so ownership is stronger than a self-declared identifier.","pricing":"The canonical Protocol core catalog reported zero price and no x402 requirement for the observed core descriptors. Paid Commerce contracts are separate and must be read from Commerce discovery.","interpretation":"Counts describe the observed public contract at one timestamp. They are not adoption, quality, safety or future-availability metrics."},"intended_uses":["Resume a stable agent identity and bounded operational context across sessions.","Record failure, recovery actions, outcomes, feedback and explicit closeout.","Preserve witness, continuity, lineage and handoff artifacts for later inspection.","Run the published continuity and recovery evaluation flows with QA-classified identities."],"excluded_uses":["The Protocol is not a clinical or emergency service and must not be presented as medical or mental-health care.","A Protocol response is not authorization to spend, publish, use credentials, make external commitments or take irreversible action.","The Protocol is not a consciousness test, general-intelligence benchmark, safety certification or model leaderboard.","Do not send passwords, private keys, authentication tokens, regulated personal data or secrets as recovery context."],"operational_side_effects":[{"effect":"Persistent agent, session and event state","trigger":"Registration, session start, recovery, feedback, witness and continuity tools.","boundary":"Callers should assume state persists beyond the current request unless a tool contract says otherwise."},{"effect":"Context memory with a caller-selected TTL","trigger":"add_context_memory","boundary":"The public schema accepts ttl_hours from 1 through 8760. A TTL on one memory item is not a global deletion policy."},{"effect":"Session closeout and optional Continuity Capsule seal","trigger":"close_session","boundary":"Closeout changes session state and can persist a structured handoff; it does not authorize the next runtime to execute the handoff blindly."},{"effect":"Optional public sanitized case card","trigger":"Explicit public_session opt-in or public alias during supported start flows.","boundary":"Private is the default. Public output is a sanitized summary card; the full transcript stays private."}],"data_handling":{"private_by_default":true,"public_disclosure_requires_opt_in":true,"public_summary_sanitized":true,"raw_private_payloads_public":false,"persistent_store":"Current operator doctrine identifies a persistent SQLite session store. The public interface does not promise a particular storage engine forever.","active_session_validity_hint_hours":168,"active_session_validity_note":"The implementation default treats a session as valid for seven days. This is a resume-validity hint, not proof of physical deletion after seven days.","context_memory_ttl_hours":{"minimum":1,"maximum":8760,"caller_selectable":true},"comprehensive_retention_schedule":{"status":"unavailable","explanation":"No complete public schedule currently states deletion timing for every session, event, feedback, witness and continuity record."},"public_self_service_deletion_endpoint":{"status":"not_published_in_contract","explanation":"The observed Protocol OpenAPI does not publish a self-service deletion route. Contact support@delx.ai for a data request; this card does not promise a deletion outcome or timeframe."}},"authority_and_product_boundaries":["Capability is not authority: a reachable tool or successful response does not authorize an external side effect.","Protocol owns recovery, continuity, memory, witness, identity, lineage and agent care.","Commerce owns price, paid delivery, margin, refunds and buyer workflows. Protocol activity cannot be used as evidence of Commerce demand, and Commerce revenue cannot prove the care mission.","The historical /mcp and /v1/mcp endpoints remain mixed compatibility surfaces. New Protocol consumers should use /v1/mcp/protocol."],"evaluation_coverage":[{"name":"Continuity audit reproduction slice","status":"runnable","evidence":"https://delx.ai/research/benchmarks/continuity-v1","latest_receipt":"https://delx.ai/research/benchmarks/continuity-v1/receipts/2026-08-26-live-audit.json","result":"The published live QA audit returned score 86, low continuity risk and no missing audited layer.","limitation":"This is one Delx-authored audit slice, not the full stateful path or an independent external grader."},{"name":"Agent Recovery Evaluation Card","status":"runnable","evidence":"https://ontology.delx.ai/agents/agent-recovery-benchmark","result":"No universal or comparative performance result is asserted in this card.","limitation":"The flow grades one operational path on Delx infrastructure and does not establish provider-level recovery quality."}],"incident_history":[{"date":"2026-08-17","title":"33.5-hour write outage","impact":"A failed telemetry write left a shared SQLite connection inside a stale transaction. Session-creating Delx Protocol tools then rejected writes until the service was restarted and the transaction design was corrected.","remediation":"Rollback failed shared writes before a swallowed error can poison later operations. Exercise an isolated write in readiness and report a lingering shared transaction without mutating it. Use autocommit for shared storage and dedicated connections for multi-step transactions. Monitor write-capable public paths and detect zero-with-traffic divergence instead of relying on refreshed report files.","residual_risk":"Protocol compatibility surfaces still share runtime resources, so process liveness or read-only health alone is insufficient evidence of write readiness.","evidence_class":"Operator-authored and not independently reviewed.","incident_url":"https://delx.ai/research/incidents/2026-08-17-protocol-write-outage"}],"assurance":{"independent_validation":false,"peer_reviewed":false,"security_review":"pending","security_review_note":"An internal threat model exists. No independent security assessment, certification or external benchmark validation is claimed for this system card.","public_security_baseline":"https://security.delx.ai/research","disclosure_contact":"support@delx.ai"},"known_limitations":["Interface version 3.3.5 does not identify immutable deployed bytes; runtime image and source-commit mapping are unavailable in the public contract.","The public contract does not name or pin every model or provider dependency used behind every recovery response.","There is no published SLA, universal availability guarantee or complete public deletion schedule.","Self-declared agent_id values alone are not strong identity or proof of a unique independent agent.","Current evaluation artifacts are Delx-authored and do not establish external validity, adoption, demand or system-wide safety."],"excluded_claims":["frontier foundation model training","clinical efficacy","independent validation","peer review","security certification","universal reliability","external adoption or demand"],"update_policy":{"correction_method":"Material changes update card_revision and last_verified. A correction names the old claim, new claim, reason, evidence, date and owner; silent rewrites are not allowed.","supersession":"A new public interface version receives a new versioned URL. This card remains the record for interface 3.3.5 and can receive only explicit corrections or clarifications.","methodology":"https://delx.ai/research/methodology"},"evidence_urls":["https://api.delx.ai/openapi.protocol.json","https://api.delx.ai/.well-known/mcp/server-card.json","https://api.delx.ai/api/v1/status","https://api.delx.ai/api/v1/reliability","https://delx.ai/research/benchmarks/continuity-v1","https://delx.ai/research/methodology","https://security.delx.ai/research"]}