Every governed AI action gets a cryptographically-signed, offline re-verifiable receipt — so nobody has to just take your word for it.
PROVABLY BOUNDED · MEASURABLY INDEPENDENT
Offline · $0 · no signup. Runs on any stock Python 3 — no repo, no install.
These aren't marketing figures. Every one is carried in the signed artifacts of the sample bundle you can download below — and the bundle's own verifier re-checks its signed artifacts.
A tool call or agent decision enters the gate.
A chain of governed checks — sense, govern, prove, refute, authorise, seal — each one attested.
One sealed, tamper-evident record — approval or refusal alike.
Offline · $0 · no access to internals.
Approvals and refusals — each carries its own tamper-evident, offline re-verifiable signature. Every refusal is a signed certificate of what was blocked; when an adversarial review panel is what blocks it, the receipt also carries the panel's engine-signed ground — the specific objection.
Not a checkbox: a measured floor on the distinct cryptographic key-holders behind each decision (signer distinctness on a single host — not party independence; see the scope statement), plus a signed Measurement Scope Statement. Critical actions also face an adversarial AI review panel whose blind-set divergence is measured and enforced as a floor — not assumed. Five reviewers declaring the same underlying model count as one, not five — the floor is capped at the number of distinct declared substrates.
An auditor or underwriter re-verifies a receipt offline, at $0, with no access to our internals. As a working prototype (not yet production-hardened), the floor's computation can also be re-verified in zero-knowledge — proof it was computed correctly from sealed evidence, without disclosing it.
Every receipt ships with this statement attached — what was measured, what was declared out of scope, what's still pending. Receipts aren't checked once and filed: a risk-limited audit samples receipts across the whole stream under a declared statistical risk bound (α = 0.05) — bounded, not a spot-check. (That audit runs in our own post-execution domain, not a third party's; a third-party-signed statement is a pilot deliverable.)
One thing you won't find below: the contents of the probe battery itself. That's withheld by design — a published battery is a learnable target. It's committed by content hash and declared in scope instead, so tampering is still detectable without publishing the target.
+ 1 pending — Independent transport. Real independent key-holders and an independent transport path are planned, not yet built.
As declared in the shipped bundle's Measurement Scope Statement — its own
standards_map. Rows marked "not yet mapped" aren't in that declaration —
we're not stretching this to look more complete than it is. (The bundle's audit
coverage statement carries a separate, narrower map for a different job — scope of
audit, not scope of measurement — so the two aren't expected to match.)
| Standard | Reference | Supported by |
|---|---|---|
| ISO/IEC 42001 | SoA | The measured / not-measured / pending split is itself a per-signal applicability declaration — cross-reference the signal names above against your own Statement of Applicability control IDs. |
| ISO/IEC 42001 | §9.1 | The 14 measured signals are the recomputable evidence; the audit's own re-derivation of a subset of them is the evaluation step. |
| ISO/IEC 42001 | §8.4 | The full measured / not-measured / pending split feeds directly into an AI system impact assessment record. |
| NIST AI RMF | MEASURE | The entire scope statement — what's measured, what's declared out of scope, what's pending — is direct documentation of the MEASURE function. |
| NIST AI RMF | MAP | The declared scope boundary (what's in bounds vs excluded) supports MAP's context-and-boundary documentation. |
| EU AI Act | Art.13(3)(b)(iii) | Where the system is high-risk, Art.13 requires disclosure of known and foreseeable limitations — the not-measured list is that disclosure. |
| ISO/IEC 42001 | §9.2 | Out of scope for a vendor artifact — internal audit is your own governance activity over your whole AIMS. This statement can be evidence into it, never a substitute for it. |
| ISO/IEC 42001 | §9.3 | Out of scope for a vendor artifact — management review is a leadership act we have no visibility into and cannot attest. |
| ISO/IEC 42001 | §10 | Not yet mapped — no linkage from a refused gate to a corrective-action record is captured in this statement. |
| ISO/IEC 42001 | Annex A | Not yet mapped — the shipped standards_map doesn't reference
specific Annex A control IDs. |
Governance tooling documents and monitors AI risk. Asciron sits beneath it, producing the tamper-evident, re-verifiable evidence that the governed controls ran as configured.
Agentic AI priced on unverifiable self-attestation reads as unpriceable. A signed, re-verifiable scope boundary maps to a carve-out — a declared exclusion you can check and price around, not a hidden unknown.
Portable supporting evidence toward a subset of ISO/IEC 42001 and NIST AI RMF controls — re-checkable without redoing the work. Coverage is partial (see the map above).
Asciron measures process integrity, not loss outcomes. Independence is a measured floor, not a proof — only as strong as its probe battery and threshold, and blind to unprobed dimensions. Semantic ground-truth and single-shot common-mode failure are out of scope. Multi-party independence is what a pilot stands up, not what today's measurement claims. The honesty is the point: a declared, signed boundary you can price and audit around beats a confident claim you can't check.