AXM · Foundry Exit · the whole hull

Replace the ship,
one plank at a time.

You don't leave Foundry in one move. You swap it plank by plank — the ontology, its data, the pipeline schemas, the dependency DAG — each for a sovereign, sealed, detached-verifiable equivalent. The vessel keeps sailing the whole time. This is the hull today: all nine planks sealed to a verifiable artifact — four carrying the full surface, the rest carrying exactly what can be carried, each labeled with which.

9 / 9 planks sealed · 4 full-surface, the rest carrying exactly what can be carried — never “9/9 sovereign”
✅ FULL — whole surface travels 🟩 CONTRACT — defs + source; not the engine 🔧 SOURCE — source verbatim; runtime rebuilt 📝 ATTESTED — exportable sealed; rest attested
All nine planks now seal to a verifiable artifact — but sealed is not sovereign. The four FULL planks hold the load: your meaning (ontology), data, and its shape and flow (schemas + DAG). CONTRACT planks carry definitions + source, not the engines. The SOURCE plank carries your transform code, not the runtime — no export of a runtime can exist. The ATTESTED planks seal what's exportable and honestly attest the rest; the permission plank is sealed as a deliberate non-port — porting a vendor's who-sees-what graph is porting the surveillance, not escaping it. Nothing here is run against a live tenant; the child shards are synthetic samples.
ship manifest: sh1_4c06f47e13ebe764fa5d7738c6e469a75f79575f12815ef4b806680cda9ef4b8 · verify PASS (detached, out-of-band key) · 9/9 planks sealed

The ship still floats before it's finished.

That's the point of rebuilding plank by plank instead of a big-bang migration: you don't need every plank swapped to have a valid, verifiable, sovereign vessel. The moment the ontology is sealed, you have a record that verifies with nothing but its own bytes. Seal the pipelines and it grows. axm-exit-ship ties them into one hull whose custody is a single genesis sh1_, which axm-verify accepts detached — Palantir removed, AXM removed.

Run it yourself: axm-exit-ship --out ./ship_out (demo), or point it at a directory with your own ontology/ and pipeline/ captures. Full breakdown of every plank — what travels, what you rebuild, and where there's simply no export — is in the workflow exit map, and the ship itself in SHIP_OF_THESEUS.md.