Verification infrastructure for the agent era

Your AI makes claims.
Isonomai proves them.

A federation of six verification instruments that turns what an AI system says into executed, sealed evidence — so the claim that reaches your customer, your regulator, or your board is one a machine already tried to break.

Anchored claims verify with zero model calls. Unverifiable never becomes true.

Fail-closed. UNVERIFIABLE is a verdict, not an excuse.
Zero model calls for anchored claims.
sha256-sealed dossiers. Tamper shows.
The model plans and judges. It never executes.
Formats, not imports. Adopt one layer or all six.
The framework

Six layers. One rule: evidence or it didn't happen.

01 · Intent

wherefore

The decision ledger. Every non-obvious guard, magic number, or special case gets its reason recorded as a git-native trailer and note — quoted from history, or the lookup reports "not recorded." It never invents a plausible-sounding why.

Why: trailer + refs/notes/whyGlobal CLI, in daily use across the fleet.
02 · Rules

Pandect Live

Legal and compliance rules as cited, versioned, dated data — never model memory. Every rule carries its source, its effective date, and its verification trail behind it. The model is never the source of a rule.

rule@version + citation
03 · Decisions

RuleCore Dry-run

A deterministic compliance engine: same inputs, same rule version, same decision — reproducible to the hash. AI output is typed a Suggestion until a named human converts it, and real-world effects stay dry-run until a logged token authorizes them.

Reviewed<T> + LiveToken
04 · Claims

touchstone

The pipeline is CLAIM → PLAN → EXECUTE → JUDGE → GATE → DOSSIER. Five check kinds — exec, read, grep, fetch, json — cover code, text, and now structured data; json is the newest, anchored deep-equality against executed output. Verbatim anchors run at least eight characters; a pure, non-LLM gate renders the verdict.

dossier.json sha256Zero model calls to verify an anchored claim.
05 · Proof exchange

agent-exchange · proof-layer In validation

Sealed dossiers travel between machines as portable, signed artifacts. A counterparty re-checks the seal, not the story — verification that doesn't require trusting the sender.

receipt
06 · Outcomes

aletheia

The outcome ledger. Append-only and hash-chained, it records what a system claimed against what actually happened, so calibration is measured, not asserted.

outcome recordHash-chain verifier runs in public, checkable offline.
New — the claims gate

The claim is cheap.
The dossier isn't.

1
Claim

The assertion is stated in the open claim-batch format: what's claimed, and what would prove it.

2
Plan

The model proposes a check — exec, read, grep, fetch, or json — and nothing else. It plans; it does not run anything.

3
Execute

The check runs for real, in your environment, under your keys. The model never executes.

4
Judge

Output is compared against the claim: verbatim anchors must match character-for-character; json checks run anchored deep-equality.

5
Gate

A pure, deterministic, non-LLM function renders the verdict: SUPPORTED, REFUTED, or UNVERIFIABLE. No temperature, no prompt, no drift.

6
Dossier

The verdict, the evidence, and the run are sealed with a sha256 hash. Change one byte and the seal shows it.

json semantics: anchored deep-equality against executed output. A mismatch fails closed to UNVERIFIABLE — the gate never guesses. REFUTED is reserved for executed evidence that contradicts the claim.

claim-batch@0 is a format, not a platform. Anything that writes JSON can emit it; anything that reads JSON can consume it. Specification available on request →

One question survives every regime. Show me it operated.

Regulators stopped asking whether you have a policy. They ask for evidence it ran.

  • Texas TRAIGA — in force Jan 2026. NIST AI RMF operation-evidence stands as an affirmative defense.
  • FTC accuracy-substantiation enforcement — Operation AI Comply. Claims about what an AI system does must be substantiated before they're made.
  • EU AI Act, Article 50 — transparency obligations from Aug 2026. High-risk obligations land later: Dec 2027 and Aug 2028.
Security apparatus

Designed so you don't have to trust us.

separation

The model plans and judges. It never executes. Execution happens in your environment, under your keys.

byo-key

Bring your own key. Your credentials never transit our infrastructure; a viral day costs you nothing and leaks nothing.

gate

The verdict gate is pure, deterministic, non-LLM code. No temperature, no prompt, no drift.

fail-closed

Anything unproven is UNVERIFIABLE. The system has no way to say "probably."

seal

Dossiers are sha256-sealed. Change one byte and the seal shows it.

no-imports

Instruments are vendored, never imported across trust boundaries — no transitive supply-chain surface between layers.

words

We say verification and evidence — never audit, attestation, or opinion. Those are reserved professional terms (AICPA AT-C 205), and using them casually would be its own false claim.

Diligence, applied to ourselves

We ran the bear case first.

A six-stage market diligence with an adversarial QA gate — findings published to the ledger, kill criteria included.

55+vendors mapped — none sell evidence a control operated
6layers, adoptable one at a time
0model calls to verify an anchored claim
2layers with no commercial equivalent — intent ledger, proof registry

Read the diligence ledger →

For engineers

Built to be examined.

Every instrument is inspectable — deterministic gates, published verifiers, dossiers you can re-check offline.

Verify it yourself

Verified beats asserted.

The dossier covers every property: what's live, what's dry-run, what's still in validation — with the receipts to check us.

sealed · sha256 · fail-closed · model:null