Runtime Evidence

Let AI act. Manage the consequences.

Connect an intended rule to the action boundary, decide whether to allow, block, or escalate, and produce an OVERT-compatible record for covered events. The record is tamper-evident and independently verifiable; its stated scope and exclusions still matter.

Sample runtime receipt sealed
receipt: {
  receipt_version: "2.0",
  overt_version: "1.1.0",
  policy: "policy.fsi.credit_match",
  model: "llama-4-maverick@2026-04-01",
  decision: "allowed",
  at: "2026-04-25T10:51:57Z",
  prev: glc_887ab46a7f,
  sig: ed25519:9c3a…d04e
}
OVERT-format · tamper-evident · independently verifiable

Keep protected payloads within the configured boundary

In sidecar mode, control evaluation and record generation can run inside your environment. The portable OVERT-format record can contain bounded decision metadata, hashes, and signatures rather than protected prompts or responses. The exact data path is deployment-specific and documented in the applicable configuration.

A data-minimizing record can support verification without carrying the protected payload

OVERT

Open standard at overt.is

Bounded Data

Metadata, hashes, and signatures follow the configured path.

Any Verifier

Independent verification. No vendor lock-in.

Covered control decisions. Independently verifiable.

A configured Glacis coverage path can produce signed operational records in an OVERT-compatible format. Each record identifies the named control, its reported decision, time, and coverage context without routinely exposing the governed payload.

OVERT-Format Receipts

Open standard for AI attestation. Machine-readable, human-auditable, interoperable across tools. overt.is

Tamper-Evident

Cryptographic commitments make covered-field modification detectable: changing the record invalidates signature verification.

Independent Verification

A conformant verifier with the record and applicable public-key material can check supported format, signature, and integrity properties without asking GLACIS to declare a pass. The disclosed format and procedure can reduce dependence on a Glacis-hosted dashboard.

Scoped Review Assembly

For a specific engagement, selected records can be assembled manually with workflow context, informational mappings, findings, remediation status, and verification metadata. This is not an automated product export.

Protected-Payload Boundary

In customer-hosted sidecar mode, protected payloads can stay inside your environment while bounded verification metadata, signatures, and cryptographic hashes follow the configured data path.

Scoped Review Packet

Signed records can be assembled with explanatory material and informational mapping references for a specific review. A proof-bundle export route is not currently offered; confirm the artifacts, fields, coverage, and reviewer acceptance for each engagement.

When “trust us” isn’t enough

AI vendors in security review. Give the customer signed records of what configured controls reported for covered events. Reviewers can verify the record integrity and signing path while assessing control effectiveness and coverage separately.

Regulated organizations deploying AI. Applicable duties differ by system, role, and jurisdiction. Operational records can support review of a control’s execution; they do not determine compliance.

Agent developers embedding supervision. Give customers a verifiable trail of covered control decisions without building the receipt format and verification tooling yourself.

Anyone whose AI decisions have consequences. If an AI output affects a person, a patient, or a financial outcome, signed records can make covered control decisions checkable. Whether the right controls ran effectively and consistently requires testing and coverage evidence too.

A review packet assembled from signed records

For one scoped workflow, selected signed records can be assembled manually with the context and informational mappings agreed for a particular review. Glacis does not currently offer an automated proof-bundle export route.

Built In

Define the action, rule, coverage boundary, and evidence a reviewer needs. Talk to us →

OVERT

Open standard. Verify receipts without vendor lock-in. overt.is →

Common questions about runtime evidence

What is an OVERT receipt?

An OVERT receipt is a structured attestation record in the open OVERT standard. It contains cryptographic commitments to named fields and a reported control decision. Verification establishes record integrity under the stated key and format; it does not establish completeness, control effectiveness, safety, or compliance.

How does the deployment handle protected data?

In customer-hosted sidecar mode, runtime controls and record generation can run locally. A portable record can use bounded metadata, hashes, and signatures instead of protected prompts or responses. The Order Form, DPA, and deployment configuration define the actual data path and any authorized processing.

Can a third party verify a record without GLACIS?

A conformant independent verifier with the record and applicable public-key material can check its format, covered signatures, and supported integrity properties without asking GLACIS to make the decision. That check does not establish completeness, control effectiveness, safety, or compliance.

What is an evidence pack?

For a scoped engagement, a review packet is a manually assembled bundle of selected signed records, workflow context, informational control mappings, findings, and remediation status. The contents and reviewer acceptance are engagement-specific; Glacis does not currently offer an automated proof-bundle export route.

Do receipts require GLACIS runtime controls?

Receipts are most useful when they are attached to real runtime controls. The Sprint starts in the action path you nominate, so the evidence has an actual control surface, data boundary, and reviewer context.

Evidence is one part of the accountability loop.

Diagnostic

Map the workflow surface

Identify consequential actions, intended rules, data boundaries, control gaps, and the evidence reviewers will need.

Assess a workflow

Controls

Runtime controls in the action path

Policy controls and allow, block, or escalate decisions for the requests inside the agreed coverage boundary—each producing the configured operational evidence.

Learn about controls