Whitepaper

Who, When, Whether.

Why we built this, where we are, and where this is going.

This document's core framework was conceived and sealed on 30 July 2026, timestamped by an independent authority and publicly verifiable by anyone, without an account. Check it yourself →

Why

An industry that sells reassurance instead of proof

We started this because an entire industry has learned to sell reassurance instead of proof, and nobody was stopping it.

Marketers publish claims they never checked against the rules that actually govern them, and find out the hard way, in a public ruling, months later. Companies bolt AI onto their business and hand it real decisions, and when someone finally asks who approved that, and on what authority, and whether that authority was still good by the time it mattered, there is no answer. There is a policy document. There is a slide. There is a person saying trust me. There is almost never a record that survives being questioned.

That gap is not a technical oversight. It is a choice, made across an entire market, to sell the appearance of oversight because the real thing is harder and less flattering to admit you do not have.

We refuse that choice. Everything we have built exists to replace trust me with check for yourself, in compliance and in governance both, because a business, a regulator, an insurer, or a customer should never have to take anyone's word for something that can be shown.

Where we are

Naming the actual gap

We started narrow and honest about it: a tool that checks marketing copy against the actual rules regulators enforce, across ten jurisdictions and thirty risk categories, in under a minute, before a complaint ever gets filed. That product is live, it works, and it stays exactly what it is.

Building it taught us the harder problem sitting underneath. Checking what a business said is only half the job. Nobody was proving what a business did, or who was accountable for letting an AI system do it, or whether that accountability had quietly expired by the time something went wrong.

So we named the actual gap. Every real authorisation has three parts: who granted it, when they granted it, and whether their authority still held at the moment it mattered. Almost every governance product on the market answers the first two and skips the third entirely, because the third one is the only one that can catch you out later.

We built the third one. Every authorisation record in our product now carries an expiry and the specific, named condition that would void it, written down at the moment someone signs, not added afterwards as an afterthought. An authority with no expiry is not a strong grant. It is one nobody was ever forced to think about ending.

We chained every high value record cryptographically, sealed the ones that matter most with an independent, third party timestamp, and made the result checkable by any stranger, publicly, without asking our permission. This document is checked exactly that way. And when we found a genuine flaw in our own tamper evidence system this week, we said so, fixed it, and proved the fix in production before calling it done.

We did all of this as one person, building fast, being argued with in public by people who know this space, and treating every good argument as a feature request rather than a threat.

Everything we offer today

Not a pitch deck concept

None of this is a pitch deck concept. It is a platform, built in the open, with each part answering the same question from a different angle: not trust me, check.

Compliance checking. Paste marketing copy in and it is checked against the actual rules regulators enforce, across ten jurisdictions and thirty risk categories, in under a minute. The same rules behind real, published rulings, so a business finds the problem before a complainant does, not after.

Governance scoring. A real, numbered score across six dimensions for how well a business oversees its use of AI, mapped to the EU AI Act, GDPR, NIST, and ISO 42001, not a vague maturity label dressed up as insight.

Authorisation records. The who, when, whether framework itself, built into the product. Every AI system a business approves gets a record naming who signed off, when, and the expiry and conditions that would void their authority. This is the evidence a regulator, an insurer, or a court actually asks for when something goes wrong, not a policy document asserting good intentions.

Public verification. Every high value record is sealed and, for the ones that matter most, timestamped by an independent authority. Anyone, with no account and no need to trust us, can check that a record has not been edited, deleted, or backdated since it was made. This document is proof of that, checkable at the link above.

A suite of free tools. Because proof should be something anyone can try before they pay for anything. A fine calculator that shows real regulatory exposure. A contract red flags checker. An accessibility checker. A shadow AI audit. A tool that checks whether a website exposes AI generated content without disclosure. And The Witness Test, five short questions that reveal whether a company's own AI evidence is independently witnessed or simply trusts itself. Every one of them free, no card required, built to demonstrate the standard rather than gate it behind a sales call.

Honest pricing. Everything the law actually requires should not cost what this industry charges for it, and we price accordingly. Small businesses and solo operators should be able to afford the same standard of proof as anyone else.

Where we are heading

The first dated statement of an argument

This is the first dated statement of an argument we intend to keep making, in public, with evidence, for a long time.

The same discipline, an expiry and a named voiding condition captured at the moment authority is granted, is being carried across the rest of the product, not left as a feature of one tier. Proof should not be a premium add on. It should be the ordinary shape of how any serious business governs its own use of AI.

We are also testing, honestly and without assuming the answer in advance, whether independent parties witnessing each other's evidence, rather than any single vendor asking to be trusted, is something the people who actually pay for assurance, insurers, brokers, boards, will demand. Every system of mutual verification that has ever lasted did so because someone on the buying side required it, not because the idea was elegant. We would rather find that out honestly than build a network nobody asked for.

What will not move is the standard underneath all of it. Every claim we make should be checkable by someone who owes us nothing. Every authority we track should carry the seed of its own ending. And every argument made against us in public, if it is right, becomes something we ship.

We believe proof is about to become the actual floor this entire market is judged against, not a nice extra a few careful companies bother with. We believe the businesses that get there first, honestly, in public, checkable by strangers, are the ones still standing when everyone else is asked to prove what they have only ever promised.

We built the compliance layer because nobody was checking. We built the governance layer because nobody was proving. This is where it started, and there is a great deal more coming.

Addendum, 31 July 2026

Everything above this line was sealed on 30 July 2026, and stays exactly as it was written. Nothing above has been edited to fit what happened next, because a document that claims to be checkable does not get to quietly rewrite itself once things change. This addendum is dated separately, on the record, the same way everything else we build is.

What changed in one day

The hedge in "Where we are heading" is resolved. We no longer have to guess whether independent parties witnessing each other's evidence is buildable. It is. Two independent companies now hold sealed copies of each other's governance records, live, with a public button anyone can press and a log anyone can check without an account. We published the protocol behind it free, the Open Witness Standard, because a standard only one company uses is not a standard, it is a product with extra steps. The reference code is public on GitHub, so nobody has to take our word for how any of it behaves.

What is still genuinely open, and we are still not assuming the answer in advance, is whether the people who actually pay for assurance, insurers, brokers, boards, will demand this as the ordinary shape of proof rather than treat it as an interesting extra. Buildable and demanded are different questions. We answered the first one. The second one still belongs to the market, not to us.

Why, still

Strip away every feature named in this document and one sentence is left standing: nobody should have to take our word for anything we say about ourselves, and we built accordingly.

A compliance check that flags a real, published ruling, not a hypothetical one. A governance score built from operational facts, not adjectives. An authorisation record that carries its own expiry, rather than pretending authority lasts forever. A witness network that lets a stranger, not us, confirm our own record has not quietly moved. A protocol we gave away rather than sold, because a standard is only real once someone other than its author is using it too.

None of that is generosity. It is the only honest response to an industry that got comfortable selling reassurance instead of proof. We would rather be checked and found accurate than be believed and never asked.

That is why this exists, and it is why everything built after this document keeps getting built the same way.

James Stokes

Founder, Red Flag AI Pro · redflagaipro.com

This addendum is not yet independently timestamped. If that matters to you, that is the correct instinct, and it is on the list to fix.