A log records that a check ran. Asciron measures it — a floor on the distinct key-holders behind each governed AI action — and signs a list of what it doesn't measure. Offline re-verifiable, so nobody has to just take your word for it.
Provably bounded · Measurably independent
No account. No network connection. No Asciron infrastructure.
Offline · $0 · no signup. Runs on any stock Python 3 — no repo, no install.
Auditor key — pass it as --auditor-key so a re-signed bundle fails:7da05647303e776538caa0761c6fa4a628cb4098a11b29f6621d85315e002e75
A tool call or agent decision enters the gate.
A chain of governed checks — sense, govern, prove, refute, authorise, seal — each one attested.
One sealed, tamper-evident record — approval or refusal alike.
Offline · $0 · no access to internals.
Not a checkbox: a measured floor on the distinct cryptographic key-holders behind each decision (signer distinctness on a single host — not party independence; see the scope statement), plus a signed Measurement Scope Statement. Critical actions also face an adversarial AI review panel whose blind-set divergence is measured and enforced as a floor — not assumed. Five reviewers declaring the same underlying model count as one, not five — the floor is capped at the number of distinct declared substrates.
Approvals and refusals — each carries its own tamper-evident, offline re-verifiable signature. Every refusal is a signed certificate of what was blocked; when an adversarial review panel is what blocks it, the receipt also carries the panel's engine-signed ground — the specific objection.
An auditor or underwriter re-verifies a receipt offline, at $0, with no access to our internals. As a working prototype (not yet production-hardened), the floor's computation can also be re-verified in zero-knowledge — proof it was computed correctly from sealed evidence, without disclosing it.
Governance tooling documents and monitors AI risk. Asciron sits beneath it, producing the tamper-evident, re-verifiable evidence that the governed controls ran as configured.
Agentic AI priced on unverifiable self-attestation reads as unpriceable. A signed, re-verifiable scope boundary maps to a carve-out — a declared exclusion you can check and price around, not a hidden unknown.
Portable supporting evidence toward a subset of ISO/IEC 42001 and NIST AI RMF controls — re-checkable without redoing the work. Coverage is partial (see the standards map in Part F).
These aren't marketing figures. Every one is carried in the signed artifacts of the sample bundle you can download below — and the bundle's own verifier re-checks its signed artifacts.
distinct tamper checks in the verifier we ship to you
of the 14 measured signals recomputed in the shipped audit — including the refutation floor
private signing keys in the bundle — you recompute the floor holding nothing that could mint a receipt
signals measured / not measured / pending
Every receipt ships with this statement attached — what was measured, what was declared out of scope, what's still pending. Receipts aren't checked once and filed: a risk-limited audit samples receipts across the whole stream under a declared statistical risk bound (α = 0.05) — bounded, not a spot-check. (That audit runs in our own post-execution domain, not a third party's; a third-party-signed statement is a pilot deliverable.)
One thing you won't find below: the contents of the probe battery itself. That's withheld by design — a published battery is a learnable target. It's committed by content hash and declared in scope instead, so tampering is still detectable without publishing the target.
Counts are read from the signed statement in the bundle below, not typed here.
+ 1 pending — Independent transport. Real independent key-holders and an independent transport path are planned, not yet built.
As declared in the shipped bundle's Measurement Scope Statement — its own
standards_map. Rows marked "not yet mapped" aren't in that declaration —
we're not stretching this to look more complete than it is. (The bundle's audit
coverage statement carries a separate, narrower map for a different job — scope of
audit, not scope of measurement — so the two aren't expected to match.)
| Standard | Reference | Supported by |
|---|---|---|
| ISO/IEC 42001 | SoA | The measured / not-measured / pending split is itself a per-signal applicability declaration — cross-reference the signal names above against your own Statement of Applicability control IDs. |
| ISO/IEC 42001 | §9.1 | The 14 measured signals are the recomputable evidence; the audit's own re-derivation of a subset of them is the evaluation step. |
| ISO/IEC 42001 | §8.4 | The full measured / not-measured / pending split feeds directly into an AI system impact assessment record. |
| NIST AI RMF | MEASURE | The entire scope statement — what's measured, what's declared out of scope, what's pending — is direct documentation of the MEASURE function. |
| NIST AI RMF | MAP | The declared scope boundary (what's in bounds vs excluded) supports MAP's context-and-boundary documentation. |
| EU AI Act | Art.13(3)(b)(iii) | Where the system is high-risk, Art.13 requires disclosure of known and foreseeable limitations — the not-measured list is that disclosure. |
| ISO/IEC 42001 | §9.2 | Out of scope for a vendor artifact — internal audit is your own governance activity over your whole AIMS. This statement can be evidence into it, never a substitute for it. |
| ISO/IEC 42001 | §9.3 | Out of scope for a vendor artifact — management review is a leadership act we have no visibility into and cannot attest. |
| ISO/IEC 42001 | §10 | Not yet mapped — no linkage from a refused gate to a corrective-action record is captured in this statement. |
| ISO/IEC 42001 | Annex A | Not yet mapped — the shipped standards_map doesn't reference
specific Annex A control IDs. |
Asciron measures process integrity, not loss outcomes. Independence is a measured floor, not a proof — only as strong as its probe battery and threshold, and blind to unprobed dimensions. Semantic ground-truth and single-shot common-mode failure are out of scope. Multi-party independence is what a pilot stands up, not what today's measurement claims. The honesty is the point: a declared, signed boundary you can price and audit around beats a confident claim you can't check.
Downloading answers one question: can this be re-checked by someone with no reason to trust us? It can — that is why it ships at $0 with no signup. What a sample bundle cannot tell you is whether the boundary holds on your actions, under your policy, with your auditor helping draw the scope statement.
That is a pilot, and pilots here are paid — a scoped engagement with a price attached is the only honest test of whether this is worth building on. Real reviewer seats, multi-party independence and a third-party-signed statement are pilot deliverables, not things today's measurement claims.
Australia
Outside Australia
A fixed fee for a fixed eight-week engagement on one governed use-case — not a retainer, not a subscription, not billed by the hour. Half on signature, half on delivery.
You keep the signed evidence bundle for your actions, a mapping report your assessor can read against your named obligation, the stdlib-only re-verifier, and the readout — including what the pilot did not show.
Sydney-based · replies come from me, not a sales team.