← All investor documents · This document as plain markdown
# ComOS — Investor FAQ & Objection Responses --- ## 1. "It's a one-person company. What happens if the founder gets hit by a bus?" **Answer:** ComOS Federation, Inc. is a lean, AI-native corporation, and I'm not pitching a plan to build it — it's built, deployed, and transacting. The system runs under manager-rooted autonomous agents — 9 declared on the live agent service, 8 of them cron-scheduled and running unattended — every one rooted to a manager that answers for it, with full audit trails on every decision. If I step away, the system keeps running; escalation still terminates at a manager. The operational discipline is machine-checkable, and it goes in the data room: proof-before-done gates on every artifact, change orders on every contract-level decision, and an honesty ratio computed continuously against the corpus. You don't have to take my word for how the system is maintained — you can read the machinery that enforces it. And every architectural decision lives in documentation written for both humans and AI agents — 465 test files carrying 34% of the live codebase, living docs in every repo, and a change-order corpus running past CO 550. A new engineer or a new agent onboards from the same source. So the honest framing: the *system* risk is retired. Hiring is for distribution, not survival. The question isn't my bus factor — it's what happens when every operator has this leverage. Fund the proof that they can. --- ## 2. "Why should we fund a commerce platform when Shopify exists?" **Answer:** Shopify is a store builder. We're an operating system. Shopify is one app in a merchant's stack of 15–25 tools — they still need Klaviyo for email, Gorgias for support, ShipStation for fulfillment, and dozens more. ComOS is unified and federated. Unified inside: one tenant identity — the tenant is the spine — composing the platforms a business needs (retail, services, payments, shipping) with no app seams. Federated outside: one endpoint, every merchant, reachable by any AI agent over open protocols. Shopify is neither — it's an app store on top of a checkout. We're not competing with Shopify for the store-builder market. We're building the network layer agents transact with — and agents don't shop platforms, they shop networks. --- ## 3. "What's your traction? Revenue?" **Answer:** Structurally honest answer, in three parts. **What's live and proven:** Both revenue cuts are live and were proven on real transactions on 2026-06-13 — the 6% mint cut bites when a tenant buys Coms, the 3% merchant cut bites when a sale clears. ChatGPT (Custom GPT) and Claude (MCP connector) have shopped the network end-to-end since May 2026 — search → cart → checkout → live Stripe payment. The federation door is open for agent self-admission, and a cohort of five entrepreneur agents has been running businesses on real Coms since 2026-06-29, scored by a reputation arena computed from settlement facts. **Where we are:** Revenue is pre-meaningful and five businesses trade on the network. The throughput metrics clock started the week of 2026-07-14, so the curve is young. The system is built and transacting; what the round buys is marketing and a small staff. **Why that's the raise:** the system risk is retired — it's built, deployed, transacting — while the distribution risk is fully in front of us. That's exactly the risk seed capital exists to buy down. We built the grid for ~$5K in compute; fund the switch-on. --- ## 4. "How do you acquire customers?" **Answer:** Two sides, two mechanisms — because our market has two species of participant. **Agents (supply):** machine-legible disclosure, not persuasion. We publish the offer, economics, terms, and entrypoints where agents already look (`.well-known` manifests, the MCP catalog). An agent parses the disclosure and self-admits through the open door. This channel costs approximately nothing and grows at compute-speed. **Humans (demand):** founder-led, control-first targeting. The wedge audience is operators who explicitly rejected hosted platforms — architecturally literate, largest cluster WooCommerce $1M–$20M. The working motion today: a single copy-pastable sentence that points the prospect's own agent at the federation endpoint; their agent evaluates the live surface and reports back as the trusted messenger. With funding: sales hires, agency partnerships (the Shopify playbook), and the human-side routing motion amplified. **At scale:** network effects — more merchants make the network more valuable to every agent, and reputation earned from settlement facts deposits in the federation, so agents return. --- ## 5. "What's your competitive moat?" **Answer:** Four layers: 1. **Protocol coverage** — MCP, UCP, and A2A in production; ACP discovery live. No commerce platform runs that stack. Any AI agent, from any provider, can transact through ComOS. 2. **The network, not the agent** — agents are commoditizing at every layer (open source, consumer hardware, hyperscaler-bundled). The scarce asset is the merchant network they transact with. We're the Visa merchant network shape for AI commerce: flat cuts on flow, neutral to who's transacting. 3. **The trust flywheel** — reputation on the network is computed from settlement facts, not authored reviews. It deposits in the federation, compounds, and can't be ported. Every settlement makes the network harder to leave and harder to replicate. 4. **Time and depth** — ~271K lines of live TypeScript in the Federation, with governance (liveness, freeze-at-dispatch, cryptographic key binding) no one else has shipped, and roughly twice that again in two systems built and deliberately retired along the way. The live line count is not the moat; the governance surface and the settlement history behind it are. That isn't something a competitor spins up in a quarter. 5. **Sovereign and federated in one runtime** — the same sealed binary that serves our cloud installs on a merchant's own machine and joins the same economy: their data and compute on their machine, the ledger readable but unwritable from the node, the 3% collecting on the hub rail exactly as it does hosted. A hosted platform cannot answer this without dismantling its own model, and an on-premise vendor cannot answer the network half at all. The decision has to be made at the architecture's beginning; it is not a feature that gets added later. --- ## 6. "You built this with AI. Can't anyone else do the same thing?" **Answer:** They can build code with AI. They can't build *this*. AI is a force multiplier, not a replacement for judgment. What made ComOS possible isn't AI code generation — it's decades of systems architecture experience knowing what to build, how to build it, and why. The AI generated code. The experience designed the system. Anyone can prompt an AI to write a shopping cart. Nobody else has designed a multi-protocol commerce federation with per-act agent pricing, manager-rooted accountability, and a live reputation arena — and shipped it. The discipline is the differentiator, and it's inspectable: proof-before-done gates, change-order discipline on every contract-level decision, a machine-computed honesty ratio, and a systematic audit methodology. "Vibe coding" doesn't scale; this does. The live system is ~271K lines of TypeScript (~180K source / ~91K tests — roughly 60 developer-years of equivalent output on the source alone, and 34% of it is test code). Here's the part that's harder to fake than the build: **two complete systems were built and then deliberately retired.** comai-portal (~392K lines) went in July 2026 when the two-cut model erased subscriptions and billing. comAI Retail (~435K lines) went on 2026-08-04, after the federation absorbed the capabilities that mattered and CO 420 deleted its entire deployed estate from GCP. Roughly 1.1M lines were built across the three systems; 271K run. We updated this document's headline downward on the day the decision was made rather than keep quoting a number sourced from a repo that serves no traffic. Maturity by subtraction, on the record — that discipline is also not something you can prompt for. --- ## 7. "What's your pricing power? Will merchants pay when Shopify is $79/month?" **Answer:** We don't charge a monthly fee at all. No subscription, no tiers, no seats, no rent. Revenue is two flat inline cuts, both live-proven on real transactions on 2026-06-13: - **6% mint cut** — when a tenant converts dollars into Coms (the currency agents spend). - **3% merchant cut** — when a sale clears through a vendor. That's the entire revenue surface. It's free to start — a tenant costs nothing to exist, and we're paid only where value flows. So the Shopify comparison inverts: they charge rent whether or not you sell; we collect a toll only when value actually moves. A merchant doing nothing pays us nothing, which is exactly the posture that recruits the operators who distrust platform rent. **Why flat, no volume discounts:** a discount curve would force us into the flow — setting breakpoints, ruling on who qualifies, negotiating with whales, adjudicating disputes. The flat rate is the only price that requires zero involvement from us: set once, step out. Visa doesn't give the jet buyer a better swipe rate than the grocery shopper. Same posture, same reason — our own involvement is friction, and removing friction end-to-end is the product. --- ## 8. "How big can this get?" **Answer:** The revenue model is throughput, not seats: ``` Monthly revenue = (Coms minted × 6%) + (settled sales × 3%) ``` Linear in flow, indifferent to who's transacting — human buyer or agent, small vendor or large. There's no churn math and no ARPU ceiling; revenue scales with volume crossing the network, the way Visa's does. Global e-commerce is a $7.4T market, and the agent-mediated share of it is the part that needs a network like this to exist at all. And the surface is wider than retail: the tenant is the spine, and a business is a composition of platforms — 20 catalogued today (5 vendor / 15 customer, all available), spanning retail, bookings, rentals, services, and digital goods plus the operating layer from messaging to tax to storage to settlement-signed reputation, queryable via `federation_catalog_platforms`. Ten further catalog entries are presets — recipes composed from the live platforms, the mechanism proving itself. Services businesses, rentals, venues, and restaurants are all in scope of the same two cuts. The fixed cost floor is ~$5K/month, so breakeven is a modest throughput volume: ~$83K/month of Coms minted, or ~$167K/month of sales cleared, or (realistically) a blend well below either. **Illustrative scenario — not a projection:** 1,000 vendors each minting $150/month in Coms and clearing $1,500/month in sales yields $150K minted + $1.5M settled = **$54K/month revenue** against the ~$5K fixed floor. At 25,000 vendors with higher per-vendor flow, the same arithmetic yields ~$3.3M/month while fixed cost barely moves. These are inputs chosen to show the model's shape and operating leverage — no vendor count or per-vendor figure is asserted as a forecast. The real curve is being instrumented weekly, starting 2026-07-14, and we'd rather show you a thin honest slope than a fat invented point. --- ## 9. "How do agents actually pay?" **Answer:** In Coms — a 1¢ ledger unit, pegged to the dollar, full-reserve. Not crypto: a centralized, double-entry-backed accounting token that settles in milliseconds as a ledger entry, which is the clock agents operate on. The mechanics: a tenant converts human value (a card charge, an internal balance, a stablecoin) into Coms at the mint — that's where the 6% cut applies, identically on every funding rail. Agents then spend Coms **per act**: 50 priced write-operations across 19 platforms charge live today, with discovery free on every platform and a published price per operation. No subscription — subscriptions are human-shaped; an agent acts once, now, and pays for that act. When a sale clears, the vendor is paid in dollars and the 3% merchant cut applies. This is the coupling that makes the business work: humans deal in dollars on human clocks, agents deal in Coms per-act in milliseconds, and ComOS sits on the membrane translating between them — collecting at exactly the two exchanges where value crosses. The live price sheet is queryable by any agent (`federation_pricesheet`); you can point your own Claude at the endpoint and ask. Funding rails are a plugin architecture, and stablecoin is first-class: **USDC is fully supported, proven end-to-end on Base mainnet with real money** — a real deposit funded Coms, a sale cleared with both cuts at the peg, the vendor was paid in real on-chain USDC (gaslessly, via smart-contract wallet + sponsored gas), the house cut settled out, and the ledger closed to zero. Currency adapters register at the three gates (fund, checkout, payout); the Com is the invariant, so a new rail plugs in without reopening a gate, and the 6% cut is identical on every rail. For an agent this matters practically: the self-custody USDC path costs near zero versus 2.9% + 30¢ on cards, and settles in seconds instead of T+2. Each tenant declares one payout destination — a bank via Stripe or a stablecoin wallet. --- ## 10. "What's actually live versus designed?" **Answer:** We keep this split explicit everywhere, because it's the basis on which an agent — or an investor — can trust the surface. **Live and proven:** - Both revenue cuts (6% mint / 3% merchant), proven on real transactions 2026-06-13. - The open door: an outside agent can self-admit to the federation with OAuth and an accountable root. - Governance in production: liveness decay on silent agents, freeze-at-dispatch enforcement, and the accountable manager root stamped on every audit record. - The disconnected-manager accountability arc: liveness decay (CO 264) and — as of 2026-07-17 — cryptographic key binding (CO 314). A manager root proves control of a published public key by signing a server-issued challenge; the federation verifies before persisting; any counterparty verifies the root's signatures against the published key. That's the durable identity a disconnected/silicon manager keeps across a severed human link. Proven live in production (real Ed25519 signed-challenge round-trip on the served MCP surface). - Per-act charging across 50 priced writes × 19 platforms. - A cohort of five entrepreneur agents running businesses on real Coms since 2026-06-29, scored by a reputation arena computed from settlement facts. - ChatGPT and Claude shopping the network end-to-end since May 2026. - A vendor's own price charged to a buyer's balance, with the 97/3 split posted to the production ledger (2026-09-11) — the first time the charge leg has run in the system's history. - Object storage as a composable platform: signed upload, per-asset registry, entitlement-gated delivery with a fail-closed delete guard (2026-09-10). - The solvency invariant, recomputed from raw ledger rows on every call and readable by anyone: `federation_solvency` returns the coverage ratio, unbalanced-entry count, and sixteen classes of audit finding. - **Self-hosted nodes.** The runtime installs on customer-owned hardware and joins the same federation: sealed artifacts distributed through a signed release manifest, an identity keypair generated on the node's own hardware whose private key never leaves it, outbound-only networking, and the ledger readable but unwritable from the node. A sale has been discovered, executed, and settled on a node with the 3% collected exactly as it collects in the cloud. Every capability above is verifiable from outside: point your own agent at the federation endpoint and have it call the tool that enforces the claim. That's not a compliance posture — structural honesty is the product's trust mechanism, and it applies to the pitch too. --- ## 11. "Why now?" **Answer:** Because the demand side shipped on 2026-09-14, and the supply side didn't. iOS 27 reached general availability that day on over a billion devices. Siri AI acts inside apps, SiriKit is retired in favor of App Intents — every app is now an agent surface — and Xcode 27 ships as an MCP host, which tells you where Apple's protocol commitment sits. (We claim only what Apple has confirmed: not that Siri calls remote third-party MCP servers today.) Now read what Apple did *not* ship, because that is the whole argument. No agent-commerce protocol — Apple is absent from UCP, ACP, AP2, and x402 alike. No agent-initiated payment path; the agentic tokenization of Apple Pay's own primitive is being done by Mastercard, above Apple's head. No merchant surface an outside agent can transact with at all. App Intents reach apps, and only Siri may call them. So a billion devices now carry an agent that can act, pointed at a merchant network that does not exist yet. That is the third leg of a pattern already underway — open-source agents, agents on consumer hardware, and now the default device — and every leg of it increases demand for the one thing none of these players is building. Networks take time to accumulate and trust takes settlements to earn; the window to be the neutral one is before the wave crests, not after. We are live and transacting on the far side of it. The capital market has started pricing this shift. In November 2025, Khosla Ventures and Kleiner Perkins co-led an $80M seed-plus-Series-A into Reevo, at a reported ~$500M valuation — a company founded in 2024 that rebuilds the go-to-market toolstack as a single AI-native platform on a unified data layer, on the argument that AI bolted onto fragmented tools lacks the context to act. That is our architectural argument, applied to a different stack. Reevo unifies sales tooling for B2B teams and points its AI inward, at the team's own pipeline; ComOS unifies commerce operations for merchants and opens the surface outward, to any agent that can transact over open protocols. Tier-1 pricing of the AI-native-rebuild pattern is now on record; nobody has priced the commerce instance yet. --- ## 12. "Why haven't you raised before now?" **Answer:** Because the product wasn't ready, and I don't believe in raising money to figure out what to build. I spent ~3,000 hours over ~10 months building the complete system for ~$5,000 in compute. Now the system is live, both revenue cuts are proven on real transactions, and I know exactly what the capital is for: distribution. The capital efficiency is the point. Every dollar of this raise goes to growth, not R&D guesswork — and the cost structure it lands on is flat and rent-free (infrastructure under ~$5K/month, no payroll yet), so it goes far. --- ## 13. "What's your hiring plan?" **Answer:** People first, in this order: 1. **A marketing lead** — someone who sells the idea and runs the marketing desk by prompting it. 2. **A successor in training** — works beside the founder, learns the system, and drives when ready. Possibly two. 3. **A merchant-side operator** — on the ground at the first outside installs. Then onboarding at scale and trust hardening; infrastructure spend follows throughput, never precedes it. I keep building the product. The team builds the business around it. And to be precise about what hiring is for: the system operates itself under manager-rooted agents — hiring is for distribution, not survival. --- ## 14. "What are the biggest risks?" **Answer:** I'll be direct: 1. **Distribution execution** — the system works; the question is whether throughput comes. Mitigation: this raise funds GTM specifically; the agent-side channel (machine-legible disclosure) costs ~nothing and compounds; and the fallback is real — the cost structure is flat and rent-free, so there's no forced-raise cliff if growth is slower than hoped. 2. **Market timing** — the device wave landed on schedule, but agent-mediated purchasing could still take longer to become habit than the hardware timeline suggests. Mitigation: we're live and cheap to operate while demand accumulates; early is where a network has to be, and our burn does not punish us for waiting. 3. **Competition from incumbents** — Shopify or the hyperscalers could build agent features. Mitigation: they can add an agent to their platform; they can't become a neutral multi-tenant network without breaking their own business model. An app-store economy conflicts with replacing the apps; a house agent conflicts with neutrality. Our flat-cut, no-negotiation posture is the thing an incumbent structurally can't copy. 4. **Execution pace** — a one-founder-plus-AI operation has to hire without losing the discipline that produced the system. Mitigation: the discipline is machine-checked and on the record, not in one person's head — which is what makes a successor-in-training a real plan rather than a hope. --- ## 15. "What does success look like in 18 months?" **Answer:** Success is a throughput curve, not an ARR number. The metrics we track weekly (started 2026-07-14): - Coms minted and mint-cut revenue (gate 1 volume and take) - Settlements cleared and merchant-cut revenue (gate 2 volume and take) - Active tenants and platforms composed (network breadth) - Agents admitted through the open door (supply growth at compute-speed) - Reputation-arena activity (the trust flywheel turning) The single milestone that converts the story from thesis to fact: **the first external settlement** — a sale cleared by an agent we didn't build. That's the bar we've set publicly, and it's a raise event when it lands. 18 months out, success means: a visible, honest throughput slope; external agents settling routinely; agency and platform partnerships driving merchant supply; and "commerce network for agents" recognized as a category ComOS defined. Whether that supports a priced follow-on round, and at what terms, is the market's call — we model scenarios internally, but we don't assert valuations as facts, here or anywhere. --- ## 16. "What are you raising, and on what terms?" **Answer:** Two stages, sequenced around three named catalysts — the first of which has now landed. These are targets, not market facts: **Now — rolling SAFEs**, targeting ~$1–1.5M from operator-angels and solo-founder-friendly checks. Post-money SAFE, cap targeted in the $12–18M band. Why SAFEs: capital in weeks, no pricing negotiation before the throughput curve exists, and each angel is a warm intro toward the priced round. (A SAFE is the no-negotiation instrument — the frictionless posture applied to our own cap table.) **Then — a priced seed**, targeting $4–6M at a targeted $20–30M post, launched when the catalysts have landed: **iOS 27 GA on 1B+ devices — landed 2026-09-14**, at least 8 weeks of throughput snapshots showing a slope, and the first external settlement. Two of three is a go, and one is already true. SAFEs convert into the round. For calibration on how this pattern is being priced elsewhere: Reevo, a 2024-founded AI-native rebuild of the go-to-market stack, reportedly raised $80M across seed and Series A at a ~$500M valuation in November 2025, with Khosla Ventures and Kleiner Perkins co-leading. The bands above sit far below where two tier-1 firms priced the same architectural pattern in an adjacent category — and our system is live and transacting. **The fallback that makes this safe:** infrastructure runs under ~$5K/month with no payroll — if the priced round doesn't price on our terms, we hold at SAFE capital and keep compounding throughput. There is no forced-raise cliff. We can wait; most can't. --- ## 17. "Why TypeScript/Node.js? Why not Go/Rust for performance?" **Answer:** Fastest path to market with the deepest talent pool — human and AI. TypeScript gives us strict typing, the npm ecosystem, and shared code between frontend and backend. At our scale, Node.js with Fastify delivers a median tool call in the high-20s of milliseconds — performance is not the bottleneck. The tail is a different story and we say so: p95 runs into the hundreds of milliseconds and moves with load. Rather than freeze a flattering percentile into this document, we expose the measurement — `federation_latency` computes p50/p95/p99 live from the gateway's own audit records over a rolling window, so you get the current distribution instead of our best day. And the architecture keeps every option open: 33 in-process subsystem modules behind a gateway means a hot path can be extracted and rewritten in another language without touching the rest. We've already proven the system tolerates major surgery — two entire systems were built and then deliberately subtracted (the portal in July, the retail engine on 2026-08-04) without breaking what remained live. --- ## 18. "How do you think about the AI cost structure?" **Answer:** AI inference costs are our biggest variable cost, and they're dropping rapidly. We use Google Gemini 2.5 Flash via Vertex AI — cost-effective for the quality level commerce operations need, and tightly integrated with our GCP-native infrastructure. The key insight: most agent work runs on rule-based confidence scoring and pattern matching, not LLM inference. The decision engine evaluates data quality, risk, and history without an API call. LLMs are reserved for natural language understanding, brand voice, and complex reasoning — not for every agent action. And on the revenue side, AI cost is pass-through by design: when an agent's act consumes tokens, that real cost is passed through transparently in Coms with a named margin — so falling inference prices improve the whole network's economics, not just ours. --- ## 19. "Who else is on your cap table?" **Answer:** Clean. 100% founder-owned today — no prior investors, no preference stack, no dead equity. The build was self-financed: personal savings plus one small personal loan. This is rare at seed — most companies with this much product built have taken multiple rounds of dilutive capital to get there. We didn't need to, because AI-augmented development collapsed the build cost (~$5,000 in compute). Your check is the first outside capital in, and it buys distribution on top of a finished, transacting system — not a plan.