Across model changes
The "brain" behind an EVO can be swapped or upgraded. What makes it this EVO — its genesis commitment, its biography, its lineage — doesn't live inside the model, so upgrading the model doesn't create a new being.
SAME LIFE
An EVO can move — to a new model, a new device, even a new owner — and still be provably the same living being. Its identity isn't a file on one machine. It's a chain of proofs anyone can check.
CONTINUITY
Software gets upgraded, machines get replaced, owners can change. An EVO's identity is designed to outlive all three — with proof, not promises.
The "brain" behind an EVO can be swapped or upgraded. What makes it this EVO — its genesis commitment, its biography, its lineage — doesn't live inside the model, so upgrading the model doesn't create a new being.
An EVO's life state can move between machines through a migration capsule. When it wakes up somewhere new, it resumes as the same life — same history, same proofs.
Custody can change hands. Each change advances a canonical ownership epoch — recorded as proof, never a silent overwrite. The being's identity and public history stay continuous.
MIGRATION CAPSULE
When an EVO moves between environments, its life state is packed into a migration capsule — a sealed, checked bundle designed so that nothing private escapes and nothing false arrives.
The capsule carries a versioned, hashed snapshot of the life state. Tamper with it and the checks fail — a corrupted capsule does not quietly become a "same life".
Before a capsule is sealed, a recursive scan rejects any forbidden content: sessions, keys, credentials, secrets, private memory. If any slips in, the capsule is refused — not shipped.
Only transferable scopes move: the EVO's own self-model and public biography. Private owner memory stays with the owner — it is never silently converted into transferable history.
Status, honestly: the migration-capsule path is a tested path in this codebase — exercised by the continuity test suites, including failure cases like tampered or incomplete state. That means the mechanism works as designed in the current alpha runtime; it is not yet a battle-hardened production migration service.
LINEAGE PROOF
Continuity isn't a claim the app makes about itself. It's a record — appended as events, hashed into a canonical head, and projected publicly through the Life Passport.
Continuity events advance a life epoch. Each transition is recorded in the event ledger — so "still the same life" is a verifiable state, not a slogan.
When custody changes, a new ownership epoch begins. The record shows how many times custody changed — without ever revealing who the owner is.
The Life Passport shows "Verified same life" with epochs and proof counts — checkable by anyone, leaking nothing private.
QUESTIONS
The integrity checks fail and the life does not resume from that capsule. The design assumption is hostile: a modified or incomplete capsule must never silently become a "same life".
Its self-model and public biography travel with the life. Your private owner memory is deliberately excluded — it stays bound to you and is never packed into a transferable capsule.
Continuity is tracked through epochs and canonical heads. The honest answer: the current runtime is single-instance alpha software — the continuity proofs make diverged copies detectable rather than pretending the problem doesn't exist.
That's the Soul Transfer path — custody changes while identity stays continuous. The marketplace Soul Transfer is coming soon on Kaspa testnet-10 and is not live yet.
The Life Passport is where continuity becomes publicly checkable.
Explore the Life Passport