Connect an intended rule to the action boundary, decide whether to allow, block, or escalate, and produce an OVERT-compatible record for covered events. The record is tamper-evident and independently verifiable; its stated scope and exclusions still matter.
receipt: { receipt_version: "2.0", overt_version: "1.1.0", policy: "policy.fsi.credit_match", model: "llama-4-maverick@2026-04-01", decision: "allowed", at: "2026-04-25T10:51:57Z", prev: glc_887ab46a7f, sig: ed25519:9c3a…d04e }
Data-minimizing sidecar architecture
In sidecar mode, control evaluation and record generation can run inside your environment. The portable OVERT-format record can contain bounded decision metadata, hashes, and signatures rather than protected prompts or responses. The exact data path is deployment-specific and documented in the applicable configuration.
A data-minimizing record can support verification without carrying the protected payload
Open standard at overt.is
Metadata, hashes, and signatures follow the configured path.
Independent verification. No vendor lock-in.
What runtime evidence provides
A configured Glacis coverage path can produce signed operational records in an OVERT-compatible format. Each record identifies the named control, its reported decision, time, and coverage context without routinely exposing the governed payload.
Open standard for AI attestation. Machine-readable, human-auditable, interoperable across tools. overt.is
Cryptographic commitments make covered-field modification detectable: changing the record invalidates signature verification.
A conformant verifier with the record and applicable public-key material can check supported format, signature, and integrity properties without asking GLACIS to declare a pass. The disclosed format and procedure can reduce dependence on a Glacis-hosted dashboard.
For a specific engagement, selected records can be assembled manually with workflow context, informational mappings, findings, remediation status, and verification metadata. This is not an automated product export.
In customer-hosted sidecar mode, protected payloads can stay inside your environment while bounded verification metadata, signatures, and cryptographic hashes follow the configured data path.
Signed records can be assembled with explanatory material and informational mapping references for a specific review. A proof-bundle export route is not currently offered; confirm the artifacts, fields, coverage, and reviewer acceptance for each engagement.
Who this is for
AI vendors in security review. Give the customer signed records of what configured controls reported for covered events. Reviewers can verify the record integrity and signing path while assessing control effectiveness and coverage separately.
Regulated organizations deploying AI. Applicable duties differ by system, role, and jurisdiction. Operational records can support review of a control’s execution; they do not determine compliance.
Agent developers embedding supervision. Give customers a verifiable trail of covered control decisions without building the receipt format and verification tooling yourself.
Anyone whose AI decisions have consequences. If an AI output affects a person, a patient, or a financial outcome, signed records can make covered control decisions checkable. Whether the right controls ran effectively and consistently requires testing and coverage evidence too.
How you get it
For one scoped workflow, selected signed records can be assembled manually with the context and informational mappings agreed for a particular review. Glacis does not currently offer an automated proof-bundle export route.
Define the action, rule, coverage boundary, and evidence a reviewer needs. Talk to us →
Open standard. Verify receipts without vendor lock-in. overt.is →
Frequently asked questions
An OVERT receipt is a structured attestation record in the open OVERT standard. It contains cryptographic commitments to named fields and a reported control decision. Verification establishes record integrity under the stated key and format; it does not establish completeness, control effectiveness, safety, or compliance.
In customer-hosted sidecar mode, runtime controls and record generation can run locally. A portable record can use bounded metadata, hashes, and signatures instead of protected prompts or responses. The Order Form, DPA, and deployment configuration define the actual data path and any authorized processing.
A conformant independent verifier with the record and applicable public-key material can check its format, covered signatures, and supported integrity properties without asking GLACIS to make the decision. That check does not establish completeness, control effectiveness, safety, or compliance.
For a scoped engagement, a review packet is a manually assembled bundle of selected signed records, workflow context, informational control mappings, findings, and remediation status. The contents and reviewer acceptance are engagement-specific; Glacis does not currently offer an automated proof-bundle export route.
Receipts are most useful when they are attached to real runtime controls. The Sprint starts in the action path you nominate, so the evidence has an actual control surface, data boundary, and reviewer context.
Supervision in practice
Diagnostic
Identify consequential actions, intended rules, data boundaries, control gaps, and the evidence reviewers will need.
Assess a workflowControls
Policy controls and allow, block, or escalate decisions for the requests inside the agreed coverage boundary—each producing the configured operational evidence.
Learn about controls