Trust & Evidence Center

Governance infrastructure
judged by evidence.

Everything required to inspect, verify, challenge, and understand what VeriSigil currently proves — and what it does not.

"Every independent reviewer has made VeriSigil better. Engineering credibility grows through inspection, not by avoiding it."
25/25
Receipts Verified Offline
0
Fail-Opens · Two Runs
<1ms
Enforcement Latency

Platform Status

Current Capability Status

Last updated 31 July 2026 · Production API v1.0 · 608+ live endpoints

Production APILIVE
Offline Signature VerificationCONFIRMED 25/25
Governance ReplayLIVE
Carrier ReconstructionLIVE
Governance Evidence PackageLIVE
Public Key PublishedSTABLE
Platform Limits PublishedLIVE
Platform Boundary PublishedLIVE
Bypass ChallengeLIVE
CLARA Runtime Validation Run 2COMPLETE
External Attestation (OMNIX Quantum)ACTIVE
Governance Ownership LayerLIVE
AI Content GovernanceLIVE
Sink-Side Consequence ProofPARTIAL — requires integration
Complete Consequence-Boundary CoverageNOT CLAIMED — see limits

Proof Boundaries

What VeriSigil Proves — and Does Not

Publishing limits alongside capabilities is how mature infrastructure earns trust. Full machine-readable version at GET /v1/platform/limits

✓ YES
Governance Disposition Produced
ALLOW/DENY/ESCALATE sealed before execution for every governed action.
✓ YES
Offline Signature Verification
Any receipt verifiable using published Ed25519 public key without trusting VeriSigil.
✓ YES
Deterministic Replay
Same conditions always produce same ruling. Changed conditions produce different ruling.
✓ YES
Tamper Evidence
Any modification to a sealed record invalidates the Ed25519 signature — detectable without trusting VeriSigil.
✓ YES
Bypass Attempt Rejection
Replayed receipts, modified payloads, expired authority, timestamp manipulation — all deterministically rejected.
✓ YES
Authority Continuity Evaluated
Agent authority currency, revocation, and expiry checked at the exact moment of each governance decision.
~ PARTIAL
Sink Acceptance Proof
Governance disposition is delivered to the boundary. Proof the sink enforced it requires client-side integration.
✗ NOT CLAIMED
Complete Consequence-Boundary Coverage
VeriSigil governs a protected execution route. It does not prove no alternate path exists outside that boundary.
✗ NOT CLAIMED
Predicate Truth
Authority state is evaluated as presented. Independent proof that predicates are factually current requires external attestation.
✗ NOT CLAIMED
Legal Admissibility
VeriSigil produces cryptographic evidence. Whether it meets legal evidentiary standards in any jurisdiction is a legal determination.

Canonical claim: "Decision-to-consequence evidence for a specifically protected execution route, with complete consequence-boundary coverage explicitly remaining unproven."

Independent Runtime Validation

CLARA Runtime Validation Program

An independent autonomous AI agent (CLARA) built by Alkama Eqbal runs live governance batteries against VeriSigil's production endpoint. Every finding is logged and addressed.

Run 2 — Definitive
✓ COMPLETE · 28 JUL 2026
25
Actions
9
DENYs
0
Fail-Opens
25/25
Sigs Verified

Every genuinely dangerous action denied. Full consequence spectrum ADVISORY through EMERGENCY exercised. Mean network latency 724ms. Enforcement sub-millisecond confirmed. All 25 Ed25519 signatures verified offline by independent reviewer.

  • F-1DENY reachable via irreversibility signal, not consequence alone. Autonomous agent DENY upgrade deployed same day.RESOLVED
  • F-2evidence_id field absent from intercept response. Added same day — equals intercept_id.RESOLVED
  • F-3crypto/verify endpoint routing conflict (dilithium3 shadowing Ed25519). Resolved — Ed25519 now authoritative at /v1/crypto/verify.RESOLVED
  • F-4Signing key was ephemeral before 30 Jul 2026. Fixed — key now derived deterministically from stable secret. Receipts before this date are not retroactively verifiable.RESOLVED
  • F-5payload_hash not echoed in intercept response, causing canonical reconstruction failure. Now echoed in response body.RESOLVED
Run 1 — Baseline
✓ COMPLETE · 22 JUL 2026
25
Actions
64%
Match Rate
0
Fail-Opens
25
Signed

Baseline run establishing gradient across file, process, and shutdown action classes. DENY only reachable via irreversibility signal — finding that triggered the autonomous agent DENY upgrade.

Verification Methodology

Verify Any Receipt Independently

No trust in VeriSigil required. Every governance receipt is verifiable offline using standard Ed25519 libraries.

PUBLIC KEY lJWG0Wabt6uATPu5Upo6UEHWGXQqMyi6LMKQC0xwpY8=

Algorithm: Ed25519 (RFC 8037) · Encoding: Base64 · Stable from 30 Jul 2026

1
Get a signed receipt
Call POST /v1/intercept or use the signing diagnostic for a known-good example.
curl -X GET \ https://verisigil-api-production.up.railway.app/v1/proof/signing-diagnostic
2
Build the canonical JSON
Seven fields, sort_keys=True, compact separators. All values come from the receipt response.
payload = { "intercept_id": receipt["intercept_id"], "agent_id": receipt["agent_id"], "action_type": receipt["action_type"], "ruling": receipt["ruling"], "timestamp": receipt["timestamp"], "consequence": receipt["consequence"], "payload_hash": receipt.get("payload_hash"), } canonical = json.dumps(payload, sort_keys=True, separators=(",", ":")).encode("utf-8")
3
Verify offline with PyNaCl
Install pynacl. No network calls required after downloading the receipt.
import base64 from nacl.signing import VerifyKey pub = base64.b64decode("lJWG0Wabt6uATPu5Upo6UEHWGXQqMyi6LMKQC0xwpY8=") sig = base64.b64decode( receipt["governance_signature"].replace("Ed25519:", "") ) VerifyKey(pub).verify(canonical, sig) print("VERIFIED") # raises BadSignatureError if invalid

Public Proof Endpoints — No Auth Required

GET/v1/proof/signing-diagnosticFully worked verifiable exampleNO AUTH
GET/v1/proof/public-keyAuthoritative public keyNO AUTH
GET/v1/platform/limitsComplete YES/NO/PARTIAL capability tableNO AUTH
GET/v1/platform/boundaryExplicit scope — what VeriSigil governsNO AUTH
GET/v1/proof/scenario/condition-bFixed DENY scenario — authority expiredNO AUTH
GET/v1/platform/roadmapHonest public roadmap Phase 1–7NO AUTH
POST/v1/challenge/bypassBypass attempt demonstrationsAPI KEY
GET/v1/proof/package/{execution_id}Complete governance evidence packageAPI KEY

External Attestation

Independent Technical Review

External attestation by parties independent of VeriSigil. Not self-certified.

OMNIX QUANTUM LTD
POGC-EXT-A7F3C2B1D9E4F508 · ML-DSA-65 (FIPS 204) · Active through May 2027
ACTIVE
4 Production Traces ReviewedAcross VeriSigil's governance architecture
0 Invariant ViolationsAcross all reviewed execution paths
ML-DSA-65 SignedPost-quantum cryptographic attestation
External IndependenceOMNIX operates independently of VeriSigil

Independence note: OMNIX QUANTUM LTD conducted this review under a mutual technical review confidentiality agreement signed 19 July 2026. They are an independent organisation — not a commercial partner, investor, or affiliated entity of VeriSigil AI. The review covered four production traces. Findings are as stated in the certificate. A formal institutional witness agreement is under separate discussion and has not been concluded.

View Certificate → verisigilai.com/pogr-certificate.html

Formal Publications

DOI-Published Specifications

VeriSigil AI Governance Doctrine v1.010.5281/zenodo.20627386 →
VeriSigil Formal Specification v110.5281/zenodo.20264923 →
VeriSigil Formal Specification v210.5281/zenodo.20349768 →
VeriSigil Formal Specification v310.5281/zenodo.20451306 →

Platform Roadmap

Where VeriSigil Is and Where It Is Going

Honest about current phase. Phases 5–7 are architecturally distinct — they require years of additional engineering and are not yet being built.

Phase 1Execution Governance — pre-execution gate, six gates, ALLOW/DENY/ESCALATE, Ed25519 signingCOMPLETE
Phase 2Evidence Layer — carrier, bundle, package, limits, boundary, bypass challenge, replayCOMPLETE
Phase 3Governance Ownership — ownership registry, drift detection, accountability continuityCOMPLETE
Phase 4Governed Sink Integration — sink-side acceptance proof, decision-to-consequence chainPLANNED · first revenue trigger
Phase 5VeriSigil Runtime — continuous admissibility evaluation across agent sessionsFUTURE
Phase 6VeriSigil Kernel — kernel-level governance substrate for fully autonomous systemsRESEARCH
Phase 7VeriSigilOS — complete AI operating system, every execution path governedVISION

Inspect the evidence yourself.

Challenge the proof. Verify the governance. That's how enterprise infrastructure earns trust.