The questions people actually ask before they trust this with a compliance obligation.
That a named person authorized your AI to act, within a scope declared before it acted, at a recorded moment in time — and that the record has not been altered since. Any change to a single character breaks the signature.
That the decision was correct, fair, lawful or unbiased. We certify the authorization and the integrity of the record. We do not audit your model, your training data, or your judgment. A certificate is evidence you can hand to a regulator; it is not a regulatory approval and not legal advice.
A log file can be edited, and it asks the reader to trust you. A certificate is signed with a key you do not hold, references a published standard, and can be checked by anyone without contacting us. The difference is between saying it happened and proving it.
Authorization happens up front: a person authorizes the AI to act within a declared scope. Individual routine decisions inside that scope are then certified automatically, with no manual step. What the certificate records is who granted that authority, how far it extended, and when it expired.
They keep verifying. Verification is offline, against the published Authority Confidence Rating standard, using a verifier you already have a copy of. Nothing calls our servers. This is the single most important design decision in the product, and it is deliberate.
No. Verification needs no account, no API key and no network connection. Anyone you hand a certificate to can check it with the free offline verifier.
Every certificate is signed with Ed25519 and with ML-DSA-87. Ed25519 is what verifies everywhere today. ML-DSA-87 is post-quantum, so a certificate signed now still stands if a quantum computer later breaks the classical signature. Compliance records outlive the cryptography that protected them, which is why both are present from the start.
Every published binary has a SHA-256 checksum in SHA256SUMS. Check the file before you run it. The Linux build is byte-reproducible, so you can rebuild it and get the same hash.
Linux x86-64, macOS Apple Silicon and macOS Intel. A Windows build is in progress. The verifier handles schema v1.2, v1.3 and v1.4.
One API call. You send the decision your AI made with your API key, and a signed certificate comes back in the response. There is nothing to install and no SDK you are required to use.
Yes. There is a Model Context Protocol server with three tools — issue, verify and fetch schema. The setup guide takes about five minutes and covers Claude on desktop, web, iOS and Android, Claude Code, Cursor, and any other MCP client.
Pick the one matching the kind of AI making the decision — reasoning, vision, predictive, tracking, industrial, mobility, financial, defense, or smart cities. All nine are available on every tier, including free. If you are unsure, start with Answer and Reasoning.
Requests above your allowance are declined until the month resets or you move to a higher tier. Nothing is billed by surprise, and certificates you already hold are unaffected. See pricing.
Your email address, the certificates issued to you including the decision content you submitted, and a small amount of abuse-prevention data at signup. The full detail is in the privacy policy.
No. Your submissions are used to issue and store your certificates. They are not used to train anything and are not sold or shared for marketing.
Yes, on Enterprise. On-premises deployment exists for organizations that cannot send decision content to an outside service at all. Ask us about it.
Yes. Ask and we will delete your account and your certificates. Once deleted we cannot reconstruct them — we do not keep a shadow copy.