Your timing stack delivers time. GAL-2 adds a governed application layer: the GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract governs when it is safe to use.
Keep your timing stack. Install the GAL-2 Node. Connect the application once.
GAL-2 Node · Application-facing Time Contract
GAL-2 Node brings GAL-2 Time to the application boundary and exposes the Time Contract locally before time becomes committed state.
Your existing timing infrastructure stays in place. The GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract tells enrolled applications whether that time is safe to use — including continuity through upstream loss, controlled recovery, uncertainty, validity, lineage, and explicit refusal when policy can no longer justify safe consumption.
Current Limited Release
The current release is distributed as a signed release handoff containing the frozen GAL-2 Node RC10 payload, release signature, signing public key, checksums, release identity, and operator documentation.
An active paid GAL-2 API plan is required for normal LIVE operation. Keep your existing NTP, PTP, GNSS, chrony, operating-system clock, or other timing infrastructure.
Evidence lineage
GAL-2 Node builds on the existing public GAL-2 continuity and application-time governance evidence. Earlier daemon and evaluator artifacts remain historical evidence lineage; the current locally installable product surface is GAL-2 Node.
RC4 120-Hour Time Contract Characterization:
14,279 contract samples,
0 gal2_time backward steps,
0 monotonic_sequence backward steps,
one documented FAIL_CLOSED boundary row at the declared
72-hour hard HOLDOVER policy boundary, followed by clean
LIVE_RESTORED recovery.
DOI: 10.5281/zenodo.20582981
5-Day Time Contract Adversarial Characterization:
14,397 contract samples,
0 fetch failures,
0 monotonic_sequence backward steps,
and 0 gal2_time backward steps.
During the hard interruption phase, GAL-2 entered
FAIL_CLOSED with
health=red and
safe_to_consume=false
after hard policy expiration.
Results DOI: 10.5281/zenodo.20357131
Pre-registration: 10.5281/zenodo.20262207
Solstice 7D:
the GAL-2 API-backed governed timeline maintained strict monotonicity across
508,548 observed samples during a full-week run on commodity
hardware under real-world network conditions.
DOI: 10.5281/zenodo.18018704
Earlier evaluator releases:
RC5.1 and RC5.8 remain part of the historical GAL-2 public evidence chain.
They are no longer the current downloadable product surface.
RC5.1 public evaluator evidence
This is application-facing continuity and consumption-governance evidence. It is not UTC metrology certification, a navigation timing claim, oscillator-control evidence, or a claim that GAL-2 replaces UTC, GNSS, PTP, NTP, chrony, grandmasters, atomic clocks, or operating-system time.
Keep your timing stack. Install the GAL-2 Node. Connect the application once.
Representative Local Time Contract
{
"schema": "gal2-daemon-time-contract-v1",
"version": "1.2.0-contract-rc.4",
"gal2_time": "2026-08-14T15:56:43.395737Z",
"safe_to_consume": true,
"mode": "LIVE",
"health": "green",
"reason": "fresh_api_sync",
"valid_until":
"2026-08-14T15:57:21.115406Z",
"monotonic_sequence": 1,
"uncertainty_ms": 574.518,
"uncertainty_ms_basis":
"conservative_model_v1_not_external_metrology_validated",
"holdover_age_sec": null,
"max_holdover_sec": 259200.0,
"source_lineage": [
"gal2_api",
"gal2_daemon_rc3_base",
"rc4_72h_holdover_policy",
"rc5_ixoye_witness_contract"
],
"witness_ref": {
"layer": "IXOYE",
"role": "out_of_band_attestation",
"policy": "advisory_only",
"effect_on_safe_to_consume": "none"
}
}
Runtime lineage note:
identifiers such as gal2-daemon-time-contract-v1 and the historical
entries in source_lineage preserve the contract/runtime lineage.
The current public product name is GAL-2 Node.
Creates GAL-2 Time.
Makes it locally consumable.
Governs its use.
safe_to_consume.
GAL-2 Node · Limited Release
Install GAL-2 Node alongside your existing timing infrastructure. An active paid GAL-2 API plan is required for the Node to enter LIVE operation and receive GAL-2 Time. The Node then makes GAL-2 Time locally consumable and exposes the Time Contract to your application.
Keep your timing stack. Install the GAL-2 Node. Connect the application once.
Designed for one continuously running GAL-2 Node at the standard 30-second API polling interval. At that cadence, one Node uses approximately 86,400 requests in a 30-day month or 89,280 requests in a 31-day month.
Application reads from the local GAL-2 Node do not each consume an API request. The Node maintains the upstream GAL-2 API connection while enrolled applications consume the Time Contract locally.
Paid API access required: GAL-2 Node requires an active GAL-2 API key for LIVE operation.
Starter is intended for development, API testing, and intermittent Node use. Professional is the recommended plan for one continuously running Node.
GAL-2 Node runs alongside your existing NTP, PTP, GNSS, chrony, operating-system clock, or other timing infrastructure. It does not replace or discipline the host clock.

The protected GAL-2 API creates the governed GAL-2 Time trajectory. It is the upstream source consumed by the GAL-2 Node — not a replacement for your existing UTC, NTP, PTP, or GNSS infrastructure.
GAL-2 Node brings GAL-2 Time to the application boundary and exposes the
local Time Contract. It manages LIVE operation, bounded holdover,
controlled recovery, uncertainty, validity, lineage, and fail-closed behavior.
GAL-2 runs alongside GNSS, PTP, NTP, chrony, grandmasters, cloud timing, and operating-system clocks. It does not discipline the host clock. The Time Contract governs whether enrolled applications should consume time before committing state.
GAL-2 API · GAL-2 Node · Time Contract
GAL-2 adds an application-level consumption layer to your existing timing infrastructure. The GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract governs its use before time becomes application state.
An active GAL-2 API key gives the Node access to GAL-2 Time. Your existing NTP, PTP, GNSS, chrony, cloud timing, and operating-system clock remain in place. GAL-2 does not replace or discipline them.
Deploy GAL-2 Node beside your application on a compatible Linux ARM64 system. The Node maintains the upstream GAL-2 connection and makes the governed trajectory available locally through the Time Contract, SHM, and application Provider interfaces.
Your enrolled application consumes GAL-2 locally and checks
safe_to_consume, mode, reason,
valid_until, uncertainty, and lineage before committing
time-dependent state.
curl -s http://127.0.0.1:9095/contract
The Time Contract answers the question raw clocks do not.
Not only “what time is it?” but whether GAL-2 Time is currently safe for an enrolled application to consume, why that decision was made, and how long that decision remains valid.
gal2_time
safe_to_consume
mode
reason
valid_until
uncertainty_ms
holdover_age_sec
monotonic_sequence
source_lineage
Fresh GAL-2 synchronization is available.
The Node continues from the last valid GAL-2 state under bounded policy.
Controlled reconciliation is used when recovery requires it.
If safe consumption can no longer be guaranteed, GAL-2 refuses rather than silently falling back to raw host time.
Keep your timing stack. Install the GAL-2 Node. Connect the application once.
Why it matters
Timing infrastructure tells systems what time it believes it is. GAL-2 adds a governed consumption boundary before time is trusted, written, ordered, logged, or committed by an enrolled application. The GAL-2 Node exposes that decision locally through the Time Contract, while the Protected Core that creates GAL-2 Time remains protected.
safe_to_consume
before committing time-dependent state.
The GAL-2 API delivers GAL-2 Time created by the Protected Core. The GAL-2 Node makes that trajectory locally consumable, while the Time Contract exposes the decision an enrolled application needs: whether time is safe to consume, why, for how long, and under what continuity state. The underlying GAL-2 governance model remains protected.

Time-boundary failures
GAL-2 Node is designed for enrolled application paths that should not blindly consume time during discontinuities, reference loss, stale state, recovery events, legacy timestamp boundaries, or other timing conditions that can affect ordering, transactions, logs, expirations, coordination, and committed state.
Leap-second-like events, clock steps, and other discontinuities can create
brittle application behavior when software assumes that every timestamp is
automatically safe to consume. GAL-2 Node gives enrolled applications a
governed path through gal2_time,
safe_to_consume, validity, uncertainty, mode, reason,
sequence, lineage, and fail-closed behavior.
GAL-2 does not patch legacy binaries, kernels, firmware, database engines,
schemas, operating systems, or 32-bit time_t implementations.
Those require platform-level remediation.
GAL-2 operates at a different boundary: where an enrolled application is deciding whether time should become committed state. When the underlying platform can execute the GAL-2 integration path, the Time Contract can expose an unsafe condition and allow the protected application path to refuse, degrade, hold over, or fail closed instead of silently committing time it should not consume.
When the GAL-2 API becomes temporarily unavailable, the Node can continue from the last valid GAL-2 state under bounded holdover policy while uncertainty grows explicitly. When upstream access returns, recovery may return directly to LIVE or use controlled REJOIN when reconciliation is required.
If the declared safety boundary is exhausted, the protected path transitions to FAIL_CLOSED rather than silently substituting raw host time.
Claim boundary GAL-2 does not replace platform-level Y2038 remediation, operating-system updates, firmware replacement, database schema migration, legacy binary remediation, UTC infrastructure, or clock synchronization systems.
It operates at the application-consumption boundary: GAL-2 API creates GAL-2 Time, GAL-2 Node makes it locally consumable, and the Time Contract governs whether an enrolled application should use it.
Platform remediation fixes platform limitations. GAL-2 governs whether time is safe to become application state.GAL-2 Node · Limited Release
GAL-2 Node connects to the GAL-2 API, makes GAL-2 Time locally consumable,
and exposes the application-facing Time Contract through local interfaces
including /contract, SHM, and the SDK Provider.
Available now: Linux ARM64
Next platform: macOS Apple SiliconCurrent GAL-2 Node v1.0.0-rc10 release.
Native GAL-2 Node platform release in development.
GAL-2 Node requires an active paid GAL-2 API key for LIVE operation. Professional is the recommended plan for one continuously running Node at the standard 30-second polling interval.
At the standard cadence, one continuously running Node uses approximately 86,400 requests in a 30-day month or 89,280 requests in a 31-day month. Application reads from the local Node do not each consume an API request.
GAL-2 API: creates and delivers GAL-2 Time from the protected GAL-2 governance core. Backend entitlement determines whether the Node has access to the upstream GAL-2 service.
GAL-2 Node: makes GAL-2 Time locally consumable by enrolled applications. It provides local continuity, bounded holdover, controlled recovery, uncertainty tracking, SHM publication, and SDK Provider access.
Time Contract:
governs whether the enrolled application should consume GAL-2 Time.
Applications can inspect safe_to_consume,
mode, reason, valid_until,
uncertainty_ms, monotonic_sequence,
and source_lineage.
Failure behavior: if upstream GAL-2 access becomes unavailable, the Node can continue from the last valid GAL-2 state under bounded policy. Recovery may return directly to LIVE or use REJOIN when reconciliation is required. If the declared safety boundary is exhausted, the protected path fails closed rather than silently substituting raw host time.
Existing timing infrastructure stays in place: GAL-2 runs alongside NTP, PTP, GNSS, chrony, grandmasters, cloud timing, and operating-system clocks. The GAL-2 Node does not discipline the host clock.
Platform availability: GAL-2 Node v1.0.0-rc10 is currently available for Linux ARM64. A native macOS Apple Silicon GAL-2 Node is the next planned platform release and is not included in RC10.
Release verification
080a17dc6f477a6a707e78efe14412d3a0f15d38cc2829cda0ddd9bf8024ac6b
Signing fingerprint:
802C 8978 FF85 7550 60B6 D6BC 8AB8 59E4 D705 822F
Release identity · GPG public key · Validation · Time Contract Policy · Documentation
Keep your timing stack. Install the GAL-2 Node. Connect the application once.

Validation Evidence
The Red Light Test compares a raw-time application path against a GAL-2-aware path that commits state through the Time Contract. When time is declared unsafe, the GAL-2 path blocks protected operations before unsafe time becomes application state.
Under the declared unsafe window, the raw path kept committing. The GAL-2 path allowed safe operations, blocked unsafe operations, and produced zero unsafe commits.
The Time Contract answers the operational question:
Can this governed time safely become application state right now?This is application-facing temporal safety evidence, not a UTC accuracy or metrology claim.
Claim Boundary
GAL-2 is an application time-consumption governance layer. The GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract governs whether an enrolled application should use it before time becomes application state.
gal2_time.
safe_to_consume decision before
time-dependent state is committed.
Platform remediation includes work such as 64-bit time migration,
operating-system and kernel updates, firmware replacement, database
schema changes, runtime changes, and remediation of legacy binaries or
32-bit time_t dependencies.
GAL-2 operates at a different layer. For enrolled application paths, the Time Contract governs whether time should be consumed before a Y2038-style timestamp failure can become committed application state.
Depending on the declared policy and current contract state, the protected application path can continue under bounded policy, degrade, hold over, recover under controlled rules, or fail closed instead of silently accepting unsafe time.
Delivers the protected upstream GAL-2 trajectory and controls service access through backend entitlement.
Provides local delivery, continuity, bounded holdover, controlled recovery, SHM publication, and SDK Provider access beside the application.
Tells enrolled software whether GAL-2 Time is safe to consume, why that decision was made, and under what validity and policy state.
GAL-2 does not claim to repair a broken 32-bit operating system, kernel, firmware image, database engine, or legacy binary. Those remain platform-remediation responsibilities.
GAL-2 provides a separate layer of application-state remediation at the commit boundary: it gives an enrolled application an explicit governed decision before time becomes trusted, written, ordered, logged, expired, transacted, or otherwise committed as application state.
Keep your timing stack. Install the GAL-2 Node. Connect the application once.
Evidence integrity
GAL-2 public validation packages are prepared with SHA-256 manifests, secret scans, public-safe artifacts, and reproducible evidence trails for technical review.
Scanned
Sealed
Published


Application-facing time governance
GAL-2 Node helps enrolled applications preserve ordering, continuity, and state safety across LIVE operation, bounded HOLDOVER, controlled REJOIN, degraded timing conditions, FAIL_CLOSED behavior, and restart continuity.
Your timing stack delivers time. GAL-2 governs whether software should consume it before time becomes state.
GAL-2 gives enrolled applications an explicit Time Contract before time-dependent state is committed. Instead of assuming that every available timestamp is automatically safe to consume, software can make a governed decision before time becomes durable application state.
The Protected Core creates the governed GAL-2 Time trajectory and the
GAL-2 API delivers it upstream. GAL-2 Node makes GAL-2 Time locally consumable,
while the Time Contract exposes fields including
gal2_time,
safe_to_consume,
mode, reason, validity, uncertainty, monotonic sequence, and source lineage
before an enrolled application acts.
GAL-2 Node can continue from the last valid GAL-2 state under bounded HOLDOVER policy while uncertainty grows explicitly. When upstream access returns, the Node may return directly to LIVE when reconciliation is not required, or use controlled REJOIN when it is.
If the declared safe-consumption boundary is exhausted, GAL-2 transitions the protected path to FAIL_CLOSED rather than silently substituting raw host time.
Restart continuity is treated as a governed decision, not an automatic assumption. GAL-2 evaluates continuity state before the Provider accepts a new publication path, including generation identity, GAL-2 progression, sequence state, freshness, validity, uncertainty, monotonic context, implementation compatibility, and source lineage.
A Provider does not silently accept an unexpected generation change as if nothing happened.
No. GAL-2 runs alongside GNSS, PTP, NTP, chrony, grandmasters, cloud timing, operating-system clocks, atomic references, and existing timing infrastructure. Those systems continue performing their own timing and synchronization functions. GAL-2 adds governance at the application-consumption boundary and does not discipline the host clock.
Teams operating distributed or stateful applications where ordering, transactions, ledgers, logs, caches, authorization, expirations, workflows, audit trails, recovery behavior, or Y2038 application-state boundaries depend on safe time consumption.
Yes. Install GAL-2 Node beside the application, provide active GAL-2 API access, and connect the protected application path to the local Node through the Time Contract, SHM, or SDK Provider. GAL-2 is designed to protect specific application workflows without requiring replacement of the existing timing stack.
Yes. An active paid GAL-2 API key is required for the Node to receive GAL-2 Time and operate in LIVE mode. The Professional plan is recommended for one continuously running Node at the standard 30-second polling interval.
Application reads from the local Node do not each consume an API request. The Node maintains the upstream GAL-2 API connection while enrolled applications consume GAL-2 locally.
GAL-2 Node v1.0.0-rc10 is currently available for Linux ARM64. A native macOS Apple Silicon GAL-2 Node is the next planned platform release.

Vision / IXOYE™ Time
GAL-2 is the practical application layer for governed time consumption. The GAL-2 API creates GAL-2 Time, the GAL-2 Node makes it locally consumable, and the Time Contract governs its use. IXOYE is the broader solar-witness vision: a path toward temporal continuity that can be public, observable, resilient, and independently witnessed against the natural cycle of the sun.
Today, GAL-2 governs how enrolled applications consume time before it becomes application state. The deeper vision is a future in which temporal continuity does not depend blindly on a single clock authority, but can also be witnessed beyond the systems it protects.
IXOYE is advisory-only. It is not the GAL-2 Time source, not a fallback
time source, and does not determine safe_to_consume.
The GAL-2 API creates GAL-2 Time through the protected upstream architecture,
and the Time Contract remains authoritative for application-side safe consumption.