Why
We started this because an entire industry has learned to sell reassurance instead of proof, and nobody was stopping it.
Marketers publish claims they never checked against the rules that actually govern them, and find out the hard way, in a public ruling, months later. Companies bolt AI onto their business and hand it real decisions, and when someone finally asks who approved that, and on what authority, and whether that authority was still good by the time it mattered, there is no answer. There is a policy document. There is a slide. There is a person saying trust me. There is almost never a record that survives being questioned.
That gap is not a technical oversight. It is a choice, made across an entire market, to sell the appearance of oversight because the real thing is harder and less flattering to admit you do not have.
We refuse that choice. Everything we have built exists to replace trust me with check for yourself, in compliance and in governance both, because a business, a regulator, an insurer, or a customer should never have to take anyone's word for something that can be shown.
Where we are
We started narrow and honest about it: a tool that checks marketing copy against the actual rules regulators enforce, across eleven jurisdictions and thirty risk categories, in under a minute, before a complaint ever gets filed. That product is live, it works, and it stays exactly what it is.
Building it taught us the harder problem sitting underneath. Checking what a business said is only half the job. Nobody was proving what a business did, or who was accountable for letting an AI system do it, or whether that accountability had quietly expired by the time something went wrong.
So we named the actual gap. Every real authorisation has three parts: who granted it, when they granted it, and whether their authority still held at the moment it mattered. Almost every governance product on the market answers the first two and skips the third entirely, because the third one is the only one that can catch you out later.
We built the third one. Every authorisation record in our product now carries an expiry and the specific, named condition that would void it, written down at the moment someone signs, not added afterwards as an afterthought. An authority with no expiry is not a strong grant. It is one nobody was ever forced to think about ending.
We chained every high value record cryptographically, sealed the ones that matter most with an independent, third party timestamp, and made the result checkable by any stranger, publicly, without asking our permission. This document is checked exactly that way. And when we found a genuine flaw in our own tamper evidence system this week, we said so, fixed it, and proved the fix in production before calling it done.
We did all of this as one person, building fast, being argued with in public by people who know this space, and treating every good argument as a feature request rather than a threat.
The governance lifecycle
Most governance programs stop at stage one, a document describing intent. The record only becomes real evidence once it survives stages two through eight.
Discover
Find where AI already makes or shapes decisions, including tools nobody formally approved. The free governance assessment scores six dimensions; the shadow AI audit surfaces the unauthorised tools already touching real decisions.
Free governance assessment + Shadow AI auditAuthorize
Every system gets a boundary authorization record: who approved it, what role they held, what options were weighed, what risk was knowingly accepted, and the exact date and named condition that voids the grant. A decision, not a policy.
Boundary authorization record — who / when / whetherCompliance
Marketing copy, claims and disclosures checked against the actual rules regulators enforce, across eleven jurisdictions and thirty risk categories, before a complaint does the checking for you.
Compliance check — 11 jurisdictions, 30 categoriesOne of two pillars. Compliance checks what's said, run before the copy goes out, not after a complaint does it for you.
Governance
Every governance decision is checked and sealed the moment it happens, chained cryptographically with SHA-256, so editing, deleting or backdating a past entry breaks the chain and is provable, not just unlikely. Compliance checks what's said; governance seals what's decided.
Governance decision, cryptographically sealed liveThe other pillar. Governance seals what's decided, a distinct check from compliance and just as load-bearing.
Review
A named person's honest first read is sealed before the AI's own reasoning is shown, so a sign-off can never be a rubber stamp on what the AI already said. Pushback rate and average time to sign-off are tracked, not just the final answer.
Commit-before-reveal + reviewer signalRemediate
Disposing of a flag isn't the same as fixing it. Whether something was actually remediated, and when, is a separate, later confirmation, sealed on its own so a judgment call and a genuine fix can never be collapsed into one event.
Remediation record, sealed separately from dispositionDecay
Authorization isn't permanent by default. Every grant carries a named condition or date that voids it, and unreviewed, unbounded or overdue grants are surfaced as the live risk they are, not left to quietly expire unnoticed.
Falsifier conditions + authorization decay trackingProve
High value records carry an independent RFC 3161 trusted timestamp from a third party authority, and are cross sealed inside the Witness Network, so separate companies vouch for each other's evidence. Anyone can verify a record publicly, no account, without trusting our word for it.
RFC 3161 timestamp + Witness NetworkRead the reasoning behind each stage in the whitepaper, or see every free tool.
This is the accountability layer: proof of who decided, when, and whether it holds up. It isn't a substitute for a formal conformity assessment, live model monitoring, or a regulatory filing. The linked tools above prepare real documents; none of them submit or certify anything on your behalf.
Everything we offer today
None of this is a pitch deck concept. It is a platform, built in the open, with each part answering the same question from a different angle: not trust me, check.
Compliance checking. Paste marketing copy in and it is checked against the actual rules regulators enforce, across eleven jurisdictions and thirty risk categories, in under a minute. The same rules behind real, published rulings, so a business finds the problem before a complainant does, not after.
Governance scoring. A real, numbered score across six dimensions for how well a business oversees its use of AI, mapped to the EU AI Act, GDPR, NIST, and ISO 42001, not a vague maturity label dressed up as insight.
Authorisation records. The who, when, whether framework itself, built into the product. Every AI system a business approves gets a record naming who signed off, when, and the expiry and conditions that would void their authority. This is the evidence a regulator, an insurer, or a court actually asks for when something goes wrong, not a policy document asserting good intentions. See the full record structure, field by field.
Public verification. Every high value record is sealed and, for the ones that matter most, timestamped by an independent authority. Anyone, with no account and no need to trust us, can check that a record has not been edited, deleted, or backdated since it was made. This document is proof of that, checkable at the link above.
A suite of free tools. Because proof should be something anyone can try before they pay for anything. A fine calculator that shows real regulatory exposure. A contract red flags checker. An accessibility checker. A shadow AI audit. A tool that checks whether a website exposes AI generated content without disclosure. And The Witness Test, five short questions that reveal whether a company's own AI evidence is independently witnessed or simply trusts itself. Every one of them free, no card required, built to demonstrate the standard rather than gate it behind a sales call.
Honest pricing. Everything the law actually requires should not cost what this industry charges for it, and we price accordingly. Small businesses and solo operators should be able to afford the same standard of proof as anyone else.