ASCIRON
The evidence layer for AI assurance
FormMSS · 24Measurement scope statement

Measured,not just recorded.

A.1What this is

A log records that a check ran. Asciron measures it — a floor on the distinct key-holders behind each governed AI action — and signs a list of what it doesn't measure. Offline re-verifiable, so nobody has to just take your word for it.

Provably bounded · Measurably independent

A.2Check it yourself
  1. 1Download the sample bundle
  2. 2Run one command
  3. 3Re-verify it offline

No account. No network connection. No Asciron infrastructure.
Offline · $0 · no signup. Runs on any stock Python 3 — no repo, no install.

Auditor key — pass it as --auditor-key so a re-signed bundle fails:
7da05647303e776538caa0761c6fa4a628cb4098a11b29f6621d85315e002e75

A.3Specimen receipt
  • A.4Status
    Working system
  • A.5Sample
    Sample receipt bundle re-verifies offline today
  • A.6Live run
    Live end-to-end run: enforced review-panel floor, re-certified offline (staged demo — declared floors, mock engine key)
  • A.7Zero-knowledge
    Zero-knowledge floor re-verification: working prototype (not yet production-hardened)
  • A.8Patents
    Two Australian provisional patent applications filed
  • A.9Testimonials
    No testimonials on this page, by design — re-verify the receipt instead of taking our word for it
Part BWhat you get

Evidence an outsider can check, not claims they must trust

  1. B.1Input
    01

    AI action

    A tool call or agent decision enters the gate.

  2. B.2Gate
    02

    Governed gate chain

    A chain of governed checks — sense, govern, prove, refute, authorise, seal — each one attested.

  3. B.3Output
    03

    Signed receipt

    One sealed, tamper-evident record — approval or refusal alike.

  4. B.4Check
    04

    Re-verified by anyone

    Offline · $0 · no access to internals.

  1. B.5Floor

    A measured independence floor

    Not a checkbox: a measured floor on the distinct cryptographic key-holders behind each decision (signer distinctness on a single host — not party independence; see the scope statement), plus a signed Measurement Scope Statement. Critical actions also face an adversarial AI review panel whose blind-set divergence is measured and enforced as a floor — not assumed. Five reviewers declaring the same underlying model count as one, not five — the floor is capped at the number of distinct declared substrates.

  2. B.6Receipts

    A signed receipt for every decision

    Approvals and refusals — each carries its own tamper-evident, offline re-verifiable signature. Every refusal is a signed certificate of what was blocked; when an adversarial review panel is what blocks it, the receipt also carries the panel's engine-signed ground — the specific objection.

  3. B.7Re-verification

    Re-verification without access to us

    An auditor or underwriter re-verifies a receipt offline, at $0, with no access to our internals. As a working prototype (not yet production-hardened), the floor's computation can also be re-verified in zero-knowledge — proof it was computed correctly from sealed evidence, without disclosing it.

Part CWho it serves

One receipt, three audiences

  1. C.1Recipient

    AI governance platforms

    Governance tooling documents and monitors AI risk. Asciron sits beneath it, producing the tamper-evident, re-verifiable evidence that the governed controls ran as configured.

  2. C.2Recipient

    Insurers & underwriters

    Agentic AI priced on unverifiable self-attestation reads as unpriceable. A signed, re-verifiable scope boundary maps to a carve-out — a declared exclusion you can check and price around, not a hidden unknown.

  3. C.3Recipient

    Auditors & assessors

    Portable supporting evidence toward a subset of ISO/IEC 42001 and NIST AI RMF controls — re-checkable without redoing the work. Coverage is partial (see the standards map in Part F).

Part DRe-derivable, not asserted

The numbers, if you want to check them

These aren't marketing figures. Every one is carried in the signed artifacts of the sample bundle you can download below — and the bundle's own verifier re-checks its signed artifacts.

  1. D.1Tamper checks
    93

    distinct tamper checks in the verifier we ship to you

  2. D.2Recomputed
    7

    of the 14 measured signals recomputed in the shipped audit — including the refutation floor

  3. D.3Private keys shipped
    0

    private signing keys in the bundle — you recompute the floor holding nothing that could mint a receipt

  4. D.4Scope triple
    14/9/1

    signals measured / not measured / pending

D.5 · 24 scope signals · the gaps are drawn at the same size as the ticks
14 measured 9 not measured 1 pending
Part ESigned with every receipt

The scope statement, shown

Every receipt ships with this statement attached — what was measured, what was declared out of scope, what's still pending. Receipts aren't checked once and filed: a risk-limited audit samples receipts across the whole stream under a declared statistical risk bound (α = 0.05) — bounded, not a spot-check. (That audit runs in our own post-execution domain, not a third party's; a third-party-signed statement is a pilot deliverable.)

One thing you won't find below: the contents of the probe battery itself. That's withheld by design — a published battery is a learnable target. It's committed by content hash and declared in scope instead, so tampering is still detectable without publishing the target.

E.1 · Scope digest
14measured
9not measured
1pending

Counts are read from the signed statement in the bundle below, not typed here.

E.2 · The registerExplore the complete measurement boundaryevery signal, named, with what it does and does not establish

Measured

14
Policy digest registry
Governing policy digests are independently recomputable and chain-anchored; a silent threshold relaxation is detectable, including a self-consistent rewrite made after the fact.
Refutation coverage
The share of the policy-required refutation checks the battery actually examined, tracked as a real, recomputable count.
Measurement coverage
How much of an authorisation's authority signals were actually measured, versus only declared, tracked as a count.
Counterparty probe coverage
The share of the buyer-supplied refutation checks the battery actually examined, tracked as a real count. The pack is content-hashed and anchor-sealed before the run; it carries no counterparty signature.
Seal priority chain
The sealed battery's priority ordering is hash-chained and independently reconcilable.
External time anchor
An independent public time-beacon is folded into the seal chain, and its presence is measured. (The beacon's own signature is verified separately — see External anchor signature verification, live-only.)
Budget accounting
Session-scoped risk-accumulation limits are tracked and independently recomputable.
Refutation floor
The refutation battery runs and produces a result count — this measures that the battery ran and what it found, not who or what performed the review. The panel's independence floor is measured separately, below.
Reviewer independence floor
A measured floor on how independently the review panel's blind spots actually diverge, checked against a seeded defect battery — engine-signed and independently recomputable. It's a point estimate from a single run, not a statistically bounded average; run-to-run sampling noise can inflate it, and reviewer identity itself is declared, not verified.
External anchor signature verification
Live-only: the time-beacon's own cryptographic signature is verified with real, unsimplified cryptography. Closes one class of backdating — not backdating that happens upstream, before evidence reaches the seal. Off by default in the offline bundle.
Independence floor audit re-verification
A risk-limited audit pass can re-derive the reviewer-independence floor's cryptographic commitment and signature from sealed evidence. Today, ahead of live independent reviewer infrastructure, no action in this bundle enforces that floor — this verifies the recompute machinery, not a measured floor.
Distinct-key custody
On a single host, the number of distinct cryptographic key-holders who signed a given instance is independently recomputable — forge, drop, or duplicate one signature and the recompute fails. Measures signer distinctness on one host: not party independence, not human-reviewer or model independence, and not independent transport.
Refutation floor audit re-verification
A risk-limited audit pass re-drives the refutation floor over each sampled receipt and its evidence, checking signed-record integrity and registered-reviewer validity end-to-end. Runs against our own scripted stand-in reviewers only — measures record integrity, not reviewer realness.
Reviewer substrate diversity
A count of distinct declared reviewer substrates (vendor / model family / weights lineage) across the panel, auditor-recomputable, and used to cap how much independence can be claimed — five reviewers on one substrate can attest independence of at most one. Measured over self-declared labels only — not proof a label is true — and it degrades to merely declared if the panel is unlabelled or the battery only partially ran.

Not measured

9
Operational independence
Single-host cryptographic key distinctness is measured (see Distinct-key custody); genuine party, human, or model independence, and independent transport, are not.
Role enforcement
Which authoriser roles actually signed is enforced internally, not independently measured; single-host key distinctness is measured, but role-to-party independence is not.
Training-data correlation
Shared provenance or correlation across model training data is not measured.
Reviewer model identity
Which model or vendor is truly behind a review seat is not measured; substrate labels are self-declared, and label truthfulness is not verified.
Reviewer seat reality
Whether review seats are live models with genuine blind spots, versus scripted stand-ins, is not measured on the default offline path.
Sensor input integrity
The authenticity of the upstream input signal that triggers governance is not measured.
Planner correctness
Whether the AI's proposed plan is correct or a hallucination is not measured; only that it's bound to a fixed, unchangeable claim.
Outcome correctness
Process integrity is measured; whether the authorised action was actually the right call is not. Process integrity isn't loss.
Reviewer resistance to adversarial input
Whether the review panel can be steered by the content it is reviewing is not measured. Reviewers see the action and its justification as text and report their own verdicts; the seeded-defect battery that measures blind-spot divergence runs over fixed stored probes, never over the live request — so a crafted input that sways several reviewers the same way is a correlated failure the measured floor cannot see.

+ 1 pending — Independent transport. Real independent key-holders and an independent transport path are planned, not yet built.

Part FFor your evidence matrix

Where this statement maps — and where it doesn't yet

As declared in the shipped bundle's Measurement Scope Statement — its own standards_map. Rows marked "not yet mapped" aren't in that declaration — we're not stretching this to look more complete than it is. (The bundle's audit coverage statement carries a separate, narrower map for a different job — scope of audit, not scope of measurement — so the two aren't expected to match.)

F.1 · Standards mapOpen the full standards mapISO/IEC 42001 · NIST AI RMF · EU AI Act — including the rows we do not map
StandardReferenceSupported by
ISO/IEC 42001SoA The measured / not-measured / pending split is itself a per-signal applicability declaration — cross-reference the signal names above against your own Statement of Applicability control IDs.
ISO/IEC 42001§9.1 The 14 measured signals are the recomputable evidence; the audit's own re-derivation of a subset of them is the evaluation step.
ISO/IEC 42001§8.4 The full measured / not-measured / pending split feeds directly into an AI system impact assessment record.
NIST AI RMFMEASURE The entire scope statement — what's measured, what's declared out of scope, what's pending — is direct documentation of the MEASURE function.
NIST AI RMFMAP The declared scope boundary (what's in bounds vs excluded) supports MAP's context-and-boundary documentation.
EU AI ActArt.13(3)(b)(iii) Where the system is high-risk, Art.13 requires disclosure of known and foreseeable limitations — the not-measured list is that disclosure.
ISO/IEC 42001§9.2 Out of scope for a vendor artifact — internal audit is your own governance activity over your whole AIMS. This statement can be evidence into it, never a substitute for it.
ISO/IEC 42001§9.3 Out of scope for a vendor artifact — management review is a leadership act we have no visibility into and cannot attest.
ISO/IEC 42001§10 Not yet mapped — no linkage from a refused gate to a corrective-action record is captured in this statement.
ISO/IEC 42001Annex A Not yet mapped — the shipped standards_map doesn't reference specific Annex A control IDs.
Part GStraight about scope

What we don't claim

Asciron measures process integrity, not loss outcomes. Independence is a measured floor, not a proof — only as strong as its probe battery and threshold, and blind to unprobed dimensions. Semantic ground-truth and single-shot common-mode failure are out of scope. Multi-party independence is what a pilot stands up, not what today's measurement claims. The honesty is the point: a declared, signed boundary you can price and audit around beats a confident claim you can't check.

Part HWhat happens next

The bundle is the demo. A pilot is the test.

Downloading answers one question: can this be re-checked by someone with no reason to trust us? It can — that is why it ships at $0 with no signup. What a sample bundle cannot tell you is whether the boundary holds on your actions, under your policy, with your auditor helping draw the scope statement.

That is a pilot, and pilots here are paid — a scoped engagement with a price attached is the only honest test of whether this is worth building on. Real reviewer seats, multi-party independence and a third-party-signed statement are pilot deliverables, not things today's measurement claims.

H.1Pilot fee
AU$22,000

Australia

USD 15,000

Outside Australia

H.2What the fee buys

A fixed fee for a fixed eight-week engagement on one governed use-case — not a retainer, not a subscription, not billed by the hour. Half on signature, half on delivery.

You keep the signed evidence bundle for your actions, a mapping report your assessor can read against your named obligation, the stdlib-only re-verifier, and the readout — including what the pilot did not show.

H.3Reply channel

Sydney-based · replies come from me, not a sales team.