AutolangDocs
System Architecture

System Architecture

Autolang is a capability-based orchestration language and deterministic runtime designed specifically for AI-generated code. It provides language-level capability control between untrusted AI agents and host applications, replacing general-purpose runtimes inside isolation boundaries.

System Overview

AI models are untrusted and are responsible solely for generating orchestration scripts. Once source code is produced, all subsequent operations are deterministic, strictly type-checked, and resource-bounded under the complete authority of the host application.

01Untrusted Tier
PromptOrchestration ScriptZero Credentials

AI Agent & Prompt Generation

The AI model writes high-level orchestration logic. The model holds no database handles, secrets, or direct operating system access.

Emits Source Code
02Verification Tier
Static TypingSurface MatchCompiler Diagnostics

Autolang Compiler (Layer 1)

Verifies syntax against registered capability signatures. Rejects hallucinated methods at compile time and emits structured diagnostics.

Bytecode Chunk
03Deterministic Runtime
Stack InterpreterOpcode BudgetMemory Quota

Autolang Virtual Machine (Layer 2)

Executes bytecode within strict instruction limits. Traps execution loops, isolates heap memory, and enforces default-deny capability boundaries.

Capability Invocation
04Authorization Boundary
Typed DelegatesNo Raw SQLExplicit Allowlist

Declared Capability Interfaces

Explicitly registered host interfaces mapping allowed operations. Marshals arguments safely across native language boundaries.

Host Dispatch
05Host Authority
CRM / ERPDatabase SocketsEnterprise Policies

Host Application & Business Systems

Trusted host environment (Node.js / C++ / Go) holds secrets and executes persistent business logic outside VM memory accounting.

Runtime Ownership Matrix

Clear boundaries separate non-deterministic AI generation from deterministic runtime execution and host business authority:

ComponentSystem Ownership & Authority
AI ModelGenerates orchestration scripts; completely untrusted; holds no credentials or direct socket access.
Autolang CompilerPerforms static verification, ensures Surface Match compatibility, and emits structured compiler diagnostics.
Autolang VMDeterministic stack interpreter; enforces instruction budgets and managed memory quotas; default-deny security.
CapabilitiesExplicitly declared interfaces mapping VM calls to verified host delegates with parameter type validation.
Host ApplicationOwns absolute authority, database handles, API credentials, and execution policy configuration.
Business SystemsDownstream infrastructure (CRM, ERP, Payment, Storage); accessed strictly via host-controlled native code.

Defense-in-Depth: Autolang + OS Isolation

Autolang does not compete with Docker, Firecracker, or KVM. Hardware and container virtualization provide operating system isolation, while Autolang provides language-level capability control.

Autolang replaces the general-purpose runtime (such as Python or Node.js) that would otherwise execute untrusted AI code inside those isolation layers. Running Autolang inside a microVM or container forms a robust two-tier defense-in-depth model:

Layer 1 • Language Boundary

Autolang Execution Runtime

Logical & Capability Control
Intentional ScopeDangerous primitives like eval, dynamic execution, and arbitrary I/O do not exist in grammar.
Compile-Time VerificationStatic typing eliminates method hallucinations and verifies capability interfaces before run.
Resource BudgetsStrict instruction opcode caps and managed memory ceilings prevent runaway loops and exhaustion.
Runs Inside Sandbox
Layer 2 • OS & Hardware Boundary

KVM • Firecracker • Docker • Cloud Sandboxes

Kernel & Hardware Isolation
Hypervisor VirtualizationDedicated guest kernels, virtual CPUs, and isolated hardware memory pages (e.g. AWS Firecracker / KVM).
OS Namespace BoundariesFilesystem chroot barriers, restricted Unix sockets, and isolated network namespace policies.
Delegates Through Secure Host Socket
Trusted Core

Enterprise Business Infrastructure

Credentials, production databases, and financial systems reside safely outside the guest runtime.

Execution Pipeline

Every AI request flows through four distinct, verifiable architectural stages:

01

LLM Code Generation

InputTask prompt + Capability type signatures
OutputAutolang Source Script

Generates orchestration code. The AI model's responsibility ends entirely once the source text is emitted.

02

Compiler Verification & Diagnostics

InputAutolang Source Script
OutputValidated Bytecode Chunk / Structured Diagnostic

Performs lexing, parsing, symbol resolution, and static type checking. Rejects invalid calls before execution and emits structured diagnostics if self-correction is required.

03

Deterministic VM Execution

InputBytecode Chunk + Instruction Budget
OutputCapability Invocations / Script Result

Executes instructions via a custom stack interpreter. Enforces opcode budgets, monitors VM memory allocation, and traps unhandled exceptions.

04

Host Capability Dispatch

InputVM Stack Arguments
OutputHost Execution Result

Unwraps parameters and invokes host application functions under host authority. Downstream enterprise business systems are executed safely outside VM memory accounting.

Compiler vs. VM Division of Labor

The compiler and VM maintain a strict division between static analysis and deterministic execution:

Compiler (Static Analysis & Correctness)VM (Deterministic Execution & Bounds)
Parses source code into ASTExecutes bytecode instructions in stack interpreter
Enforces static type checking and null safetyEvaluates operand stack and local variable registers
Emits structured diagnostics for AI self-correctionDecrements and enforces opcode instruction budgets
Validates declared capability library bindingsTracks managed memory allocations and traps leaks
Rejects unknown identifiers before execution beginsDispatches validated calls to host native delegates

Host Application Authority

Autolang is an embedded language and runtime; it never runs as an unconstrained standalone server. The embedding host application (Node.js, C++, or Go) acts as the central authority:

Capability Registration

Declares explicit function interfaces using registerBuiltInLibrary(). AI can call only what the host exposes.

Credential & Socket Isolation

Database sockets, private keys, and API tokens remain completely outside VM memory. AI scripts receive only capability handles.

Enterprise Business Execution

Executes trusted business systems (CRM, ERP, Billing) in host native code. AI orchestrates the flow; host executes the logic.

Resource Governance

Configures strict instruction limits (e.g. 50,000 opcodes) and memory quotas to prevent execution loops and resource starvation.

Capability Boundary & Dispatch Flow

AI scripts orchestrate host capabilities instead of implementing core business logic directly. Scripts never hold credentials or database sockets:

1

AI Script Invokes Capability

Untrusted script calls declared identifier

crm.updateLead(id, "VIP")
2

VM Type & Budget Enforcement

Validates argument types against registered interface; decrements opcode budget

Opcode -1 • Types Verified
3

Native Parameter Marshaling

Parameters unwrap across native boundary without exposing VM pointers

AObject → Host Native Values
4

Host Executes Under Full Authority

Host code authenticates request, binds credentials, and triggers enterprise business systems

CRM API / DB Commit

Host Session Lifecycle

The lifecycle of a compiler and VM session within an embedding host follows a clean, deterministic lifecycle:

01One-time init

Create Compiler

ACompiler.create() initializes the compiler instance inside the embedding worker process.

02Configuration

Register Capabilities

Binds capability interfaces and native function delegates via registerBuiltInLibrary().

03Static Stage

Compile AI Script

Parses source text, checks types, and outputs a validated binary bytecode chunk.

04Execution

Bounded VM Execution

Executes bytecode under configured opcode budget and memory ceiling. Traps timeouts cleanly.

05Sub-millisecond

Instant VM Reset & Next Task

Clears operand stack and execution buffers in ~1ms without reallocating compiler memory. The process is immediately ready to run the next AI script.