ASCIRON

Measured, not just recorded.

Every governed AI action gets a cryptographically-signed, offline re-verifiable receipt — so nobody has to just take your word for it.

PROVABLY BOUNDED · MEASURABLY INDEPENDENT

Offline · $0 · no signup. Runs on any stock Python 3 — no repo, no install.

ATTESTATION RECEIPT
decisionapprove · #4c21
gatesfull chain · passed
floor3 ≥ required 3
scopesigned · 2 declared exclusions
sealchain #182 · ed25519 a9f2…c7
✓ RE-VERIFIED OFFLINE · $0 · NO ACCESS TO INTERNALS
Working system Sample receipt bundle re-verifies offline today Live end-to-end run: enforced review-panel floor, re-certified offline (staged demo — declared floors, mock engine key) Zero-knowledge floor re-verification: working prototype (not yet production-hardened) Two Australian provisional patent applications filed No testimonials on this page, by design — re-verify the receipt instead of taking our word for it
Re-derivable, not asserted

The numbers, if you want to check them

These aren't marketing figures. Every one is carried in the signed artifacts of the sample bundle you can download below — and the bundle's own verifier re-checks its signed artifacts.

61
distinct tamper checks in the verifier we ship to you
7
of the 14 measured signals recomputed in the shipped audit — including the refutation floor
0
private signing keys in the bundle — you recompute the floor holding nothing that could mint a receipt
14/9/1
signals measured / not measured / pending
What you get

Evidence an outsider can check, not claims they must trust

AI action

A tool call or agent decision enters the gate.

Governed gate chain

A chain of governed checks — sense, govern, prove, refute, authorise, seal — each one attested.

Signed receipt

One sealed, tamper-evident record — approval or refusal alike.

Re-verified by anyone

Offline · $0 · no access to internals.

A signed receipt for every decision

Approvals and refusals — each carries its own tamper-evident, offline re-verifiable signature. Every refusal is a signed certificate of what was blocked; when an adversarial review panel is what blocks it, the receipt also carries the panel's engine-signed ground — the specific objection.

A measured independence floor

Not a checkbox: a measured floor on the distinct cryptographic key-holders behind each decision (signer distinctness on a single host — not party independence; see the scope statement), plus a signed Measurement Scope Statement. Critical actions also face an adversarial AI review panel whose blind-set divergence is measured and enforced as a floor — not assumed. Five reviewers declaring the same underlying model count as one, not five — the floor is capped at the number of distinct declared substrates.

Re-verification without access to us

An auditor or underwriter re-verifies a receipt offline, at $0, with no access to our internals. As a working prototype (not yet production-hardened), the floor's computation can also be re-verified in zero-knowledge — proof it was computed correctly from sealed evidence, without disclosing it.

Signed with every receipt

The scope statement, shown

Every receipt ships with this statement attached — what was measured, what was declared out of scope, what's still pending. Receipts aren't checked once and filed: a risk-limited audit samples receipts across the whole stream under a declared statistical risk bound (α = 0.05) — bounded, not a spot-check. (That audit runs in our own post-execution domain, not a third party's; a third-party-signed statement is a pilot deliverable.)

One thing you won't find below: the contents of the probe battery itself. That's withheld by design — a published battery is a learnable target. It's committed by content hash and declared in scope instead, so tampering is still detectable without publishing the target.

Measured

14
Policy digest registry
Governing policy digests are independently recomputable and chain-anchored; a silent threshold relaxation is detectable, including a self-consistent rewrite made after the fact.
Refutation coverage
The share of the policy-required refutation checks the battery actually examined, tracked as a real, recomputable count.
Measurement coverage
How much of an authorisation's authority signals were actually measured, versus only declared, tracked as a count.
Counterparty probe coverage
The share of the buyer's own sealed refutation checks the battery actually examined, tracked as a real count.
Seal priority chain
The sealed battery's priority ordering is hash-chained and independently reconcilable.
External time anchor
An independent public time-beacon is folded into the seal chain, and its presence is measured. (The beacon's own signature is verified separately — see External anchor signature verification, live-only.)
Budget accounting
Session-scoped risk-accumulation limits are tracked and independently recomputable.
Refutation floor
The refutation battery runs and produces a result count — this measures that the battery ran and what it found, not who or what performed the review. The panel's independence floor is measured separately, below.
Reviewer independence floor
A measured floor on how independently the review panel's blind spots actually diverge, checked against a seeded defect battery — engine-signed and independently recomputable. It's a point estimate from a single run, not a statistically bounded average; run-to-run sampling noise can inflate it, and reviewer identity itself is declared, not verified.
External anchor signature verification
Live-only: the time-beacon's own cryptographic signature is verified with real, unsimplified cryptography. Closes one class of backdating — not backdating that happens upstream, before evidence reaches the seal. Off by default in the offline bundle.
Independence floor audit re-verification
A risk-limited audit pass can re-derive the reviewer-independence floor's cryptographic commitment and signature from sealed evidence. Today, ahead of live independent reviewer infrastructure, no action in this bundle enforces that floor — this verifies the recompute machinery, not a measured floor.
Distinct-key custody
On a single host, the number of distinct cryptographic key-holders who signed a given instance is independently recomputable — forge, drop, or duplicate one signature and the recompute fails. Measures signer distinctness on one host: not party independence, not human-reviewer or model independence, and not independent transport.
Refutation floor audit re-verification
A risk-limited audit pass re-drives the refutation floor over each sampled receipt and its evidence, checking signed-record integrity and registered-reviewer validity end-to-end. Runs against our own scripted stand-in reviewers only — measures record integrity, not reviewer realness.
Reviewer substrate diversity
A count of distinct declared reviewer substrates (vendor / model family / weights lineage) across the panel, auditor-recomputable, and used to cap how much independence can be claimed — five reviewers on one substrate can attest independence of at most one. Measured over self-declared labels only — not proof a label is true — and it degrades to merely declared if the panel is unlabelled or the battery only partially ran.

Not measured

9
Operational independence
Single-host cryptographic key distinctness is measured (see Distinct-key custody); genuine party, human, or model independence, and independent transport, are not.
Role enforcement
Which authoriser roles actually signed is enforced internally, not independently measured; single-host key distinctness is measured, but role-to-party independence is not.
Training-data correlation
Shared provenance or correlation across model training data is not measured.
Reviewer model identity
Which model or vendor is truly behind a review seat is not measured; substrate labels are self-declared, and label truthfulness is not verified.
Reviewer seat reality
Whether review seats are live models with genuine blind spots, versus scripted stand-ins, is not measured on the default offline path.
Sensor input integrity
The authenticity of the upstream input signal that triggers governance is not measured.
Planner correctness
Whether the AI's proposed plan is correct or a hallucination is not measured; only that it's bound to a fixed, unchangeable claim.
Outcome correctness
Process integrity is measured; whether the authorised action was actually the right call is not. Process integrity isn't loss.
Reviewer resistance to adversarial input
Whether the review panel can be steered by the content it is reviewing is not measured. Reviewers see the action and its justification as text and report their own verdicts; the seeded-defect battery that measures blind-spot divergence runs over fixed stored probes, never over the live request — so a crafted input that sways several reviewers the same way is a correlated failure the measured floor cannot see.

+ 1 pendingIndependent transport. Real independent key-holders and an independent transport path are planned, not yet built.

For your evidence matrix

Where this statement maps — and where it doesn't yet

As declared in the shipped bundle's Measurement Scope Statement — its own standards_map. Rows marked "not yet mapped" aren't in that declaration — we're not stretching this to look more complete than it is. (The bundle's audit coverage statement carries a separate, narrower map for a different job — scope of audit, not scope of measurement — so the two aren't expected to match.)

StandardReferenceSupported by
ISO/IEC 42001SoA The measured / not-measured / pending split is itself a per-signal applicability declaration — cross-reference the signal names above against your own Statement of Applicability control IDs.
ISO/IEC 42001§9.1 The 14 measured signals are the recomputable evidence; the audit's own re-derivation of a subset of them is the evaluation step.
ISO/IEC 42001§8.4 The full measured / not-measured / pending split feeds directly into an AI system impact assessment record.
NIST AI RMFMEASURE The entire scope statement — what's measured, what's declared out of scope, what's pending — is direct documentation of the MEASURE function.
NIST AI RMFMAP The declared scope boundary (what's in bounds vs excluded) supports MAP's context-and-boundary documentation.
EU AI ActArt.13(3)(b)(iii) Where the system is high-risk, Art.13 requires disclosure of known and foreseeable limitations — the not-measured list is that disclosure.
ISO/IEC 42001§9.2 Out of scope for a vendor artifact — internal audit is your own governance activity over your whole AIMS. This statement can be evidence into it, never a substitute for it.
ISO/IEC 42001§9.3 Out of scope for a vendor artifact — management review is a leadership act we have no visibility into and cannot attest.
ISO/IEC 42001§10 Not yet mapped — no linkage from a refused gate to a corrective-action record is captured in this statement.
ISO/IEC 42001Annex A Not yet mapped — the shipped standards_map doesn't reference specific Annex A control IDs.
Who it serves

One receipt, three audiences

AI governance platforms

Governance tooling documents and monitors AI risk. Asciron sits beneath it, producing the tamper-evident, re-verifiable evidence that the governed controls ran as configured.

Insurers & underwriters

Agentic AI priced on unverifiable self-attestation reads as unpriceable. A signed, re-verifiable scope boundary maps to a carve-out — a declared exclusion you can check and price around, not a hidden unknown.

Auditors & assessors

Portable supporting evidence toward a subset of ISO/IEC 42001 and NIST AI RMF controls — re-checkable without redoing the work. Coverage is partial (see the map above).

Straight about scope

What we don't claim

Asciron measures process integrity, not loss outcomes. Independence is a measured floor, not a proof — only as strong as its probe battery and threshold, and blind to unprobed dimensions. Semantic ground-truth and single-shot common-mode failure are out of scope. Multi-party independence is what a pilot stands up, not what today's measurement claims. The honesty is the point: a declared, signed boundary you can price and audit around beats a confident claim you can't check.