05/14/2026
Most timing systems are built to answer one question:
“What time is it?”
But production software often needs a different question answered first:
“Can this time safely become application state?”
That is the boundary GAL-2™ Time Contract is built for.
A timing incident does not only live inside a clock.
It can become a bad commit, a broken ledger, a corrupted log, a failed authorization decision, a stale cache, or an ordering failure across distributed systems.
Leap-second-like discontinuities.
Y2038-style legacy boundaries.
GNSS degradation.
Stale references.
Backward steps.
Recovery out of phase.
These are not just timing problems.
They are application-state problems.
GAL-2 does not replace UTC, GNSS, PTP, NTP, chrony, atomic clocks, or grandmasters.
Keep your timing stack.
GAL-2 sits closer to the application and serves governed gal2_time through a Time Contract with:
safe_to_consume
valid_until
mode
reason
monotonic_sequence
source_lineage
When timing conditions are healthy, applications consume governed time normally.
When timing conditions degrade, GAL-2 can preserve bounded monotonic continuity where policy allows, perform controlled rejoin when the reference returns, or fail closed before unsafe time becomes committed state.
Precision protects the reference.
GAL-2 protects the consumer.
GAL-2™ Time Contract is currently available for technical pilots, architecture review, and design-partner evaluation.
Resilience Infrastructure GNSS PTP NTP Y2038