Your timing stack delivers time. GAL-2 adds a governed application layer: the GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract governs when it is safe to use.
Keep your timing stack. Install the GAL-2 Node. Connect the application once.
GAL-2 Node · Application-facing Time Contract
GAL-2 Node brings GAL-2 Time to the application boundary and exposes the Time Contract locally before time becomes committed state.
Your existing timing infrastructure stays in place. The GAL-2 Protected Core creates GAL-2 Time, the GAL-2 API delivers it, the GAL-2 Node makes it locally consumable, and the Time Contract tells enrolled applications whether that governed time is safe to use. This includes continuity through upstream loss, controlled recovery, uncertainty, validity, lineage, and explicit refusal when policy can no longer justify safe consumption.
Current Technical Evaluation Release
RC11 is available for technical evaluation on Linux ARM64 and macOS Apple Silicon. The Linux package is frozen and protected by an exact SHA-256 checksum and detached GPG signature. The macOS installer is signed with a GAL-2 Technologies LLC Developer ID Installer certificate, notarized by Apple, and carries a trusted timestamp.
An active paid GAL-2 API plan is required for normal LIVE operation. Keep your existing NTP, PTP, GNSS, chrony, operating-system clock, or other timing infrastructure.
Evidence lineage
GAL-2 Node builds on the existing public GAL-2 continuity and application-time governance evidence. Earlier daemon and evaluator artifacts remain historical evidence lineage. The current locally installable product surface is GAL-2 Node RC11 for Linux ARM64 and macOS Apple Silicon.
Founder-operated RC11 release validation: the exact Linux ARM64 package passed installation on an Ubuntu ARM64 systemd and Docker environment, package identity verification, progressive SHM publication, Provider fail-closed behavior, controlled REJOIN, natural restoration to LIVE, configuration restoration, and host-timing-state preservation. The macOS package is signed with a Developer ID Installer certificate and trusted by the Apple notary service.
RC4 120-Hour Time Contract Characterization:
14,279 contract samples,
0 gal2_time backward steps,
0 monotonic_sequence backward steps,
one documented FAIL_CLOSED boundary row at the declared
72-hour hard HOLDOVER policy boundary, followed by clean
LIVE_RESTORED recovery.
DOI: 10.5281/zenodo.20582981
5-Day Time Contract Adversarial Characterization:
14,397 contract samples,
0 fetch failures,
0 monotonic_sequence backward steps,
and 0 gal2_time backward steps.
During the hard interruption phase, GAL-2 entered
FAIL_CLOSED with
health=red and
safe_to_consume=false
after hard policy expiration.
Results DOI: 10.5281/zenodo.20357131
Pre-registration: 10.5281/zenodo.20262207
Solstice 7D:
the GAL-2 API-backed governed timeline maintained strict monotonicity
across 508,548 observed samples during a full-week run
on commodity hardware under real-world network conditions.
DOI: 10.5281/zenodo.18018704
Earlier evaluator releases:
RC5.1, RC5.8, and RC10 remain part of the historical GAL-2 release
and evidence chain. They are no longer the current downloadable
product surface.
RC5.1 public evaluator evidence
This is application-facing continuity and consumption-governance evidence. It is not UTC metrology certification, a navigation timing claim, oscillator-control evidence, or a claim that GAL-2 replaces UTC, GNSS, PTP, NTP, chrony, grandmasters, atomic clocks, or operating-system time.
Keep your timing stack. Install the GAL-2 Node. Connect the application once.
Representative Local Time Contract
{
"schema": "gal2-daemon-time-contract-v1",
"version": "1.2.0-contract-rc.4",
"gal2_time": "2026-08-19T20:32:05.516086Z",
"safe_to_consume": true,
"mode": "LIVE",
"health": "green",
"reason": "fresh_api_sync",
"valid_until":
"2026-08-19T20:32:48.900852Z",
"monotonic_sequence": 6117,
"uncertainty_ms": 1165.873,
"uncertainty_ms_basis":
"conservative_model_v1_not_external_metrology_validated",
"holdover_age_sec": null,
"max_holdover_sec": 259200.0,
"source_lineage": [
"gal2_api",
"gal2_daemon_rc3_base",
"rc4_72h_holdover_policy",
"rc5_ixoye_witness_contract"
],
"witness_ref": {
"layer": "IXOYE",
"role": "out_of_band_attestation",
"policy": "advisory_only",
"effect_on_safe_to_consume": "none"
}
}
Runtime lineage note:
identifiers such as gal2-daemon-time-contract-v1 and the
historical entries in source_lineage preserve the
contract/runtime lineage. The current public product name is
GAL-2 Node.
Provide upstream temporal reference material.
Creates the governed GAL-2 Time trajectory.
Delivers GAL-2 Time to the Node.
Makes GAL-2 Time locally consumable.
Governs whether consumption is safe.
Consumes governed time or receives an explicit refusal.
safe_to_consume.
GAL-2 Node · Technical Evaluation Release
Install GAL-2 Node alongside your existing timing infrastructure. An active paid GAL-2 API plan is required for the Node to enter LIVE operation and receive GAL-2 Time. The GAL-2 Protected Core creates GAL-2 Time, the GAL-2 API delivers it, and the Node makes it locally consumable while exposing the Time Contract to enrolled applications.
Keep your timing stack. Install the GAL-2 Node. Connect the application once.
Designed for one continuously running GAL-2 Node at the standard 30-second API polling interval. At that cadence, one Node uses approximately 86,400 requests in a 30-day month or 89,280 requests in a 31-day month.
Application reads from the local GAL-2 Node do not each consume an API request. The Node maintains the upstream GAL-2 API connection while enrolled applications consume the Time Contract locally.
Paid API access required: GAL-2 Node requires an active GAL-2 API key for normal LIVE operation.
Starter is intended for development, API testing, and intermittent Node use. Professional is the recommended plan for one continuously running Node.
GAL-2 Node runs alongside your existing NTP, PTP, GNSS, chrony, operating-system clock, or other timing infrastructure. It does not replace, discipline, or modify the host clock. The protected Provider path does not silently fall back to raw host time.
RC11 Release Verification
Linux ARM64 is protected by an exact SHA-256 checksum and detached GPG signature. macOS Apple Silicon is signed with a GAL-2 Technologies LLC Developer ID Installer certificate and notarized by Apple.
Linux release signing fingerprint:
802C 8978 FF85 7550 60B6 D6BC 8AB8 59E4 D705 822F
Evaluation guide · Documentation · Time Contract Policy · Validation

The protected GAL-2 API creates the governed GAL-2 Time trajectory. It is the upstream source consumed by the GAL-2 Node — not a replacement for your existing UTC, NTP, PTP, or GNSS infrastructure.
GAL-2 Node brings GAL-2 Time to the application boundary and exposes the
local Time Contract. It manages LIVE operation, bounded holdover,
controlled recovery, uncertainty, validity, lineage, and fail-closed behavior.
GAL-2 runs alongside GNSS, PTP, NTP, chrony, grandmasters, cloud timing, and operating-system clocks. It does not discipline the host clock. The Time Contract governs whether enrolled applications should consume time before committing state.
GAL-2 API · GAL-2 Node · Time Contract
GAL-2 adds an application-level consumption layer to your existing timing infrastructure. The GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract governs its use before time becomes application state.
An active GAL-2 API key gives the Node access to GAL-2 Time. Your existing NTP, PTP, GNSS, chrony, cloud timing, and operating-system clock remain in place. GAL-2 does not replace or discipline them.
Deploy GAL-2 Node beside your application on a compatible Linux ARM64 system. The Node maintains the upstream GAL-2 connection and makes the governed trajectory available locally through the Time Contract, SHM, and application Provider interfaces.
Your enrolled application consumes GAL-2 locally and checks
safe_to_consume, mode, reason,
valid_until, uncertainty, and lineage before committing
time-dependent state.
curl -s http://127.0.0.1:9095/contract
The Time Contract answers the question raw clocks do not.
Not only “what time is it?” but whether GAL-2 Time is currently safe for an enrolled application to consume, why that decision was made, and how long that decision remains valid.
gal2_time
safe_to_consume
mode
reason
valid_until
uncertainty_ms
holdover_age_sec
monotonic_sequence
source_lineage
Fresh GAL-2 synchronization is available.
The Node continues from the last valid GAL-2 state under bounded policy.
Controlled reconciliation is used when recovery requires it.
If safe consumption can no longer be guaranteed, GAL-2 refuses rather than silently falling back to raw host time.
Keep your timing stack. Install the GAL-2 Node. Connect the application once.
Why it matters
Timing infrastructure tells systems what time it believes it is. GAL-2 adds a governed consumption boundary before time is trusted, written, ordered, logged, or committed by an enrolled application. The GAL-2 Node exposes that decision locally through the Time Contract, while the Protected Core that creates GAL-2 Time remains protected.
safe_to_consume
before committing time-dependent state.
The GAL-2 API delivers GAL-2 Time created by the Protected Core. The GAL-2 Node makes that trajectory locally consumable, while the Time Contract exposes the decision an enrolled application needs: whether time is safe to consume, why, for how long, and under what continuity state. The underlying GAL-2 governance model remains protected.

Time-boundary failures
GAL-2 Node is designed for enrolled application paths that should not blindly consume time during discontinuities, reference loss, stale state, recovery events, legacy timestamp boundaries, or other timing conditions that can affect ordering, transactions, logs, expirations, coordination, and committed state.
Leap-second-like events, clock steps, and other discontinuities can create
brittle application behavior when software assumes that every timestamp is
automatically safe to consume. GAL-2 Node gives enrolled applications a
governed path through gal2_time,
safe_to_consume, validity, uncertainty, mode, reason,
sequence, lineage, and fail-closed behavior.
GAL-2 does not patch legacy binaries, kernels, firmware, database engines,
schemas, operating systems, or 32-bit time_t implementations.
Those require platform-level remediation.
GAL-2 operates at a different boundary: where an enrolled application is deciding whether time should become committed state. When the underlying platform can execute the GAL-2 integration path, the Time Contract can expose an unsafe condition and allow the protected application path to refuse, degrade, hold over, or fail closed instead of silently committing time it should not consume.
When the GAL-2 API becomes temporarily unavailable, the Node can continue from the last valid GAL-2 state under bounded holdover policy while uncertainty grows explicitly. When upstream access returns, recovery may return directly to LIVE or use controlled REJOIN when reconciliation is required.
If the declared safety boundary is exhausted, the protected path transitions to FAIL_CLOSED rather than silently substituting raw host time.
Claim boundary GAL-2 does not replace platform-level Y2038 remediation, operating-system updates, firmware replacement, database schema migration, legacy binary remediation, UTC infrastructure, or clock synchronization systems.
It operates at the application-consumption boundary: GAL-2 API creates GAL-2 Time, GAL-2 Node makes it locally consumable, and the Time Contract governs whether an enrolled application should use it.
Platform remediation fixes platform limitations. GAL-2 governs whether time is safe to become application state.GAL-2 Node · Technical Evaluation Release
GAL-2 Node receives GAL-2 Time through the GAL-2 API, makes it locally
consumable, and exposes the application-facing Time Contract through
local interfaces including /contract, SHM, and the SDK Provider.
Available now for technical evaluation
Linux ARM64 + macOS Apple SiliconFrozen RC11 package with exact SHA-256 identity and detached GPG signature.
Native RC11 installer signed with Developer ID Installer and notarized by Apple.
GAL-2 Node requires an active paid GAL-2 API key for normal LIVE operation. Professional is the recommended plan for one continuously running Node at the standard 30-second polling interval.
At the standard cadence, one continuously running Node uses approximately 86,400 requests in a 30-day month or 89,280 requests in a 31-day month. Application reads from the local Node do not each consume an API request.
Protected Core: creates the governed GAL-2 Time trajectory from reference inputs. The Protected Core is the generation layer. It is distinct from the API and from the locally installed Node.
GAL-2 API: delivers GAL-2 Time from the Protected Core to an authorized GAL-2 Node. Backend entitlement determines whether the Node has access to the upstream GAL-2 service.
GAL-2 Node: makes GAL-2 Time locally consumable by enrolled applications. It provides local delivery and continuity, bounded HOLDOVER, controlled recovery, uncertainty tracking, SHM publication, and SDK Provider access.
Time Contract:
governs whether the enrolled application is authorized to consume the
locally available governed time. Applications can inspect
safe_to_consume,
mode,
reason,
valid_until,
uncertainty_ms,
monotonic_sequence,
and source_lineage.
Failure behavior: if upstream GAL-2 access becomes temporarily unavailable, the Node can continue from the last valid GAL-2 state under bounded policy. Recovery may return directly to LIVE or use REJOIN when controlled reconciliation is required. If policy authority is exhausted, the protected Provider path fails closed rather than silently substituting raw host time.
Existing timing infrastructure stays in place: GAL-2 runs alongside NTP, PTP, GNSS, chrony, grandmasters, cloud timing, atomic-clock-backed infrastructure, and operating-system clocks. The GAL-2 Node does not discipline or modify the host clock.
Platform availability: GAL-2 Node v1.0.0-rc11 is currently available for technical evaluation on Linux ARM64 and macOS Apple Silicon.
Runtime compatibility:
identifiers such as 1.2.0-contract-rc.4,
gal2-daemon-time-contract-v1, and historical
source_lineage entries preserve runtime and contract
compatibility lineage. They do not represent the current product release.
The current public GAL-2 Node release is
v1.0.0-rc11.
RC11 Release Verification
c4b9f928c80b6ecd06f71cd5809fb13e72d0c852c9c52d3b0b2158a46b660e97
5b082fcdc0c2a59fb669266ef1848d9247c75d35fd7421a72d2b115c1d11830a
Linux release signing fingerprint:
802C 8978 FF85 7550 60B6 D6BC 8AB8 59E4 D705 822F
macOS installer: Developer ID Installer: GAL-2 Technologies LLC (XWFX4JS9C2) · Apple notarized · trusted timestamp
Linux SHA-256 · Linux GPG signature · Linux signing public key · macOS SHA-256 · Validation · Time Contract Policy · Documentation
Keep your timing stack. Install the GAL-2 Node. Connect the application once.

Validation Evidence
The Red Light Test compares a raw-time application path against a GAL-2-aware path that commits state through the Time Contract. When time is declared unsafe, the GAL-2 path blocks protected operations before unsafe time becomes application state.
Under the declared unsafe window, the raw path kept committing. The GAL-2 path allowed safe operations, blocked unsafe operations, and produced zero unsafe commits.
The Time Contract answers the operational question:
Can this governed time safely become application state right now?This is application-facing temporal safety evidence, not a UTC accuracy or metrology claim.
Claim Boundary
GAL-2 is an application time-consumption governance layer. The GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract governs whether an enrolled application should use it before time becomes application state.
gal2_time.
safe_to_consume decision before
time-dependent state is committed.
Platform remediation includes work such as 64-bit time migration,
operating-system and kernel updates, firmware replacement, database
schema changes, runtime changes, and remediation of legacy binaries or
32-bit time_t dependencies.
GAL-2 operates at a different layer. For enrolled application paths, the Time Contract governs whether time should be consumed before a Y2038-style timestamp failure can become committed application state.
Depending on the declared policy and current contract state, the protected application path can continue under bounded policy, degrade, hold over, recover under controlled rules, or fail closed instead of silently accepting unsafe time.
Delivers the protected upstream GAL-2 trajectory and controls service access through backend entitlement.
Provides local delivery, continuity, bounded holdover, controlled recovery, SHM publication, and SDK Provider access beside the application.
Tells enrolled software whether GAL-2 Time is safe to consume, why that decision was made, and under what validity and policy state.
GAL-2 does not claim to repair a broken 32-bit operating system, kernel, firmware image, database engine, or legacy binary. Those remain platform-remediation responsibilities.
GAL-2 provides a separate layer of application-state remediation at the commit boundary: it gives an enrolled application an explicit governed decision before time becomes trusted, written, ordered, logged, expired, transacted, or otherwise committed as application state.
Keep your timing stack. Install the GAL-2 Node. Connect the application once.
Evidence integrity
GAL-2 public validation packages are prepared with SHA-256 manifests, secret scans, public-safe artifacts, and reproducible evidence trails for technical review.
Scanned
Sealed
Published


Application-facing time governance
GAL-2 Node helps enrolled applications preserve ordering, continuity, and state safety across LIVE operation, bounded HOLDOVER, controlled REJOIN, degraded timing conditions, FAIL_CLOSED behavior, and restart continuity.
Your timing stack delivers time. GAL-2 governs whether software should consume it before time becomes state.
GAL-2 gives enrolled applications an explicit Time Contract before time-dependent state is committed. Instead of assuming that every available timestamp is automatically safe to consume, software can make a governed decision before time becomes durable application state.
The Protected Core creates the governed GAL-2 Time trajectory and the
GAL-2 API delivers it upstream. GAL-2 Node makes GAL-2 Time locally consumable,
while the Time Contract exposes fields including
gal2_time,
safe_to_consume,
mode, reason, validity, uncertainty, monotonic sequence, and source lineage
before an enrolled application acts.
GAL-2 Node can continue from the last valid GAL-2 state under bounded HOLDOVER policy while uncertainty grows explicitly. When upstream access returns, the Node may return directly to LIVE when reconciliation is not required, or use controlled REJOIN when it is.
If the declared safe-consumption boundary is exhausted, GAL-2 transitions the protected path to FAIL_CLOSED rather than silently substituting raw host time.
Restart continuity is treated as a governed decision, not an automatic assumption. GAL-2 evaluates continuity state before the Provider accepts a new publication path, including generation identity, GAL-2 progression, sequence state, freshness, validity, uncertainty, monotonic context, implementation compatibility, and source lineage.
A Provider does not silently accept an unexpected generation change as if nothing happened.
No. GAL-2 runs alongside GNSS, PTP, NTP, chrony, grandmasters, cloud timing, operating-system clocks, atomic references, and existing timing infrastructure. Those systems continue performing their own timing and synchronization functions. GAL-2 adds governance at the application-consumption boundary and does not discipline the host clock.
Teams operating distributed or stateful applications where ordering, transactions, ledgers, logs, caches, authorization, expirations, workflows, audit trails, recovery behavior, or Y2038 application-state boundaries depend on safe time consumption.
Yes. Install GAL-2 Node beside the application, provide active GAL-2 API access, and connect the protected application path to the local Node through the Time Contract, SHM, or SDK Provider. GAL-2 is designed to protect specific application workflows without requiring replacement of the existing timing stack.
Yes. An active paid GAL-2 API key is required for the Node to receive GAL-2 Time and operate in LIVE mode. The Professional plan is recommended for one continuously running Node at the standard 30-second polling interval.
Application reads from the local Node do not each consume an API request. The Node maintains the upstream GAL-2 API connection while enrolled applications consume GAL-2 locally.
GAL-2 Node v1.0.0-rc10 is currently available for Linux ARM64. A native macOS Apple Silicon GAL-2 Node is the next planned platform release.

Vision / IXOYE™ Time
GAL-2 is the practical application layer for governed time consumption. The GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract governs its use. IXOYE is the broader solar-witness vision: a path toward temporal continuity that can be public, observable, resilient, and independently witnessed against the natural cycle of the sun.
Today, GAL-2 governs how enrolled applications consume time before it becomes application state. The deeper vision is a future in which temporal continuity does not depend blindly on a single clock authority, but can also be witnessed beyond the systems it protects.
IXOYE is advisory-only. It is not the GAL-2 Time source, not a fallback
time source, and does not determine safe_to_consume.
The GAL-2 API creates GAL-2 Time through the protected upstream architecture,
and the Time Contract remains authoritative for application-side safe consumption.