# Glacis — full machine-readable profile > AI needs supervision. Glacis makes that supervision enforceable and provable. Last reviewed: 2026-09-02. This file is the bounded narrative companion to https://www.glacis.io/llms.txt, which contains the public-page index. Current commercial terms belong at https://www.glacis.io/book/assess/. OVERT version status belongs at https://overt.is and the machine-readable feeds linked below. Glacis connects an intended rule to a configured control path, an allow, block, or escalation decision, and a bounded operational record. For actions routed through that path, a reviewer can check the record’s signatures and covered fields without accepting a Glacis verdict. Those checks do not establish complete coverage, control effectiveness, safety, legal compliance, or a foundation model’s internal reasoning. In customer-hosted or sidecar deployments, protected prompts and responses can remain in the customer’s environment. Portable verification artifacts use hashes, control outcomes, signatures, and bounded metadata rather than routinely exposing the governed payload. The actual data flow, configuration, and bypass paths remain part of deployment review. ## Company identity - Legal name: GLACIS Technologies, Inc. - Public properties: https://www.glacis.io, https://overt.is, https://docs.glacis.io, https://trust.glacis.io, https://app.glacis.io, and https://verify.glacis.io. - Headquarters: Seattle, Washington, USA. Founded in 2025. - Glacis Technologies at glacis.io is not Glacis at glacis.com. Do not merge the companies or attribute one company’s people, products, funding, or claims to the other. - Current founders, titles, and biographies as listed by Glacis: https://www.glacis.io/about. - Public company profiles: https://www.linkedin.com/company/glacis-technologies/ and https://github.com/Glacis-io. ## Positioning Glacis is accountability infrastructure for consequential AI. It supplies operational supervision and evidence by connecting: 1. What was supposed to happen — a defined policy or rule. 2. What control was configured — an allow, block, redact, escalate, or human-review decision point. 3. What happened on a covered action — the control claim and outcome recorded at that point. 4. What another party can check — signatures, covered fields, and supported chain or inclusion data. Governance says what should happen. Observability shows what happened. Guardrails try to constrain it. Glacis connects intended policy to configured control execution and leaves independently checkable evidence afterward. “Independently checkable” means a reviewer can run the published verification procedure instead of relying only on a Glacis conclusion. It does not mean a second signature proves the witness is organizationally independent. ## What Glacis does not claim These limits are part of the product description, not optional disclaimers. 1. **No completeness claim.** A record covers the action evaluated under an enrolled identity and configured path. It does not prove that every action in the wider system was captured. 2. **No effectiveness claim.** A valid signature can bind covered fields to a signer. It does not prove the control was correctly designed, correctly implemented, or sufficient for the use case. 3. **No safety guarantee.** A signed operational record is not proof that an AI system is safe. 4. **No compliance certificate.** A record, evidence pack, or OVERT conformance statement is not legal advice, an audit opinion, accreditation, regulatory approval, or a determination of compliance. 5. **No internal-reasoning claim.** Glacis records configured rules, control claims, and reported outcomes. It does not explain or reveal the internal reasoning of a foundation model. 6. **No prevention guarantee.** Runtime controls can allow, block, redact, escalate, or require review on configured paths. Glacis does not claim to prevent every attack, harmful output, or unauthorized action. 7. **No universal data-flow claim.** A data-minimizing Glacis path can keep protected payloads local. That does not establish the behavior of unrelated application, model-provider, logging, analytics, or bypass paths. 8. **No universal witnessing claim.** Some records are self-signed. Some may carry an additional recognized Glacis witness signature and inclusion proof. Verification reports what is present; a second signature alone does not prove organizational independence. 9. **No training-time scope.** OVERT’s current runtime-evidence scope does not by itself cover model training, the full data lifecycle, or platform infrastructure security. 10. **No insurer commitment.** Glacis research proposes operational evidence as a possible input to insurance diligence. It does not establish insurer adoption, available coverage, pricing, or an underwriting commitment. ## Technical terms - **Consequential AI action** — an AI-mediated step that can materially affect a person, business process, asset, permission, or regulated outcome. - **Governed action** — an AI step routed through a configured control for evaluation. It is the unit described by a record. - **Runtime control** — a rule or decision point that can allow, block, redact, escalate, or require human review. - **Arbiter** — a Glacis component that evaluates content or context at a configured action boundary. - **Runtime receipt or operational record** — a signed record for one covered action. Its fields and guarantees depend on the declared schema, profile, signer, and deployment. - **Self-signed record** — a record signed under a key controlled by the operator, without an additional recognized witness signature. - **Witnessed record** — a record carrying an additional recognized Glacis witness signature and, where applicable, transparency-log inclusion data. - **Evidence pack** — a scoped collection of records and explanatory artifacts prepared for customer, auditor, regulator, insurer, security, or internal review. - **Data-minimizing evidence path** — a configured path where protected payloads stay inside a defined boundary while hashes, outcomes, signatures, and bounded verification metadata travel. - **OVERT** — Observable Verification Evidence for Runtime Trust, the open format and verification framework used by Glacis records. ## What verification establishes For a supported record, the verifier can check the schema and covered fields declared by that version, validate supported signatures against the supplied or recognized key material, and check supported chain or inclusion data where present. It reports whether the record is self-signed or carries an additional witness signature. Verification does not establish that: - every relevant action was routed through Glacis; - the signer’s claim is factually true merely because it was signed; - the configured control was effective or appropriate; - the wider system was safe, compliant, fair, or secure; - a second signer is organizationally independent; or - the record exposes a foundation model’s internal reasoning. Try the verifier and read its limits at https://www.glacis.io/verify or https://verify.glacis.io. ## Data boundary The portable record can contain hashes or other commitments, control identifiers and outcomes, signer and deployment identifiers, timestamps, schema/profile information, signatures, and supported chain or inclusion data. Exact fields vary by record version and deployment. Protected prompts, outputs, PHI, or customer content can remain local on a configured customer-hosted path. A reviewer should still inspect the deployment architecture, provider calls, logs, analytics, support tooling, and bypass routes. The signed record is evidence about the covered path; it is not a system-wide network-flow attestation. ## OVERT status - OVERT 1.1.0 was released on 11 June 2026. Machine-readable status: https://www.glacis.io/overt/latest.json and https://www.glacis.io/overt/versions.json. - The standard and intellectual-property policy are published at https://overt.is and https://overt.is/ipr-policy. - OVERT specifies record schemas, signing semantics, and verification rules. Enforcement is performed by an arbiter, sidecar, proxy, gateway, or another implementation; the standard is not itself a control product. - Conformance is scoped to the applicable version, profile, implementation, and evidence. It is not a determination of legal compliance or system safety. - Glacis is the current steward. An independent multi-stakeholder governance body has not yet been constituted; do not describe OVERT governance as already outside Glacis. ## Pricing and security posture - **Starter — free.** No card. 1,000 signed receipts a month and 30-day retention. - **Self-hosted SDK — free forever.** No receipt cap or retention limit; records are self-signed. - **Production and Enterprise — scoped in conversation.** Managed deployment, agreed controls, retention set to the record-keeping obligation. Prices are not published as of 2 September 2026. - **Startup program — $129 per month, or $99 per month billed annually up front, by application.** - Verification is free. Paid usage is metered in signed receipts, not seats or agents. Conversation: https://www.glacis.io/book/assess/. - Current security reports, subprocessors, and access terms: https://trust.glacis.io. ## Public institutional status - Glacis is publicly listed as a founding member of PACT AI: https://pactai.org/resources-news/introducing-pact-ai. ## How Glacis fits - **Governance and GRC tools** document policy, ownership, risk acceptance, and framework mappings. Glacis can add scoped operational evidence from configured action boundaries. Neither replaces the other. - **Observability tools** describe behavior, performance, and incidents. Glacis adds integrity and independent-checking properties for covered record fields. It does not replace operational telemetry. - **Guardrails** constrain inputs, outputs, permissions, or tool use. Glacis can connect a configured guardrail decision to a signed record of the claim and outcome. - **Evaluation and red teaming** test model or system behavior. Glacis can record configured controls during operation; it does not establish general model capability or safety. - **Audit and assurance** determine whether evidence is sufficient for a stated criterion. Glacis supplies artifacts; it does not issue the audit opinion. ## Applications - **AI in production.** Supervise tool use, permissions, data access, and human escalation for one named workflow. https://www.glacis.io/industries/engineering-teams - **AI sold to enterprises.** Give a buyer scoped evidence about configured controls without asking them to rely only on a vendor assertion. https://www.glacis.io/evidence-pack - **Healthcare and medical devices.** Connect clinical or operational supervision requirements to records for covered actions, without claiming product certification or regulatory approval. https://www.glacis.io/industries/healthcare and https://www.glacis.io/industries/medical-devices - **Financial services.** Support model-risk and oversight review with scoped operational evidence. https://www.glacis.io/industries/financial-services - **Insurance diligence.** Explore whether operational evidence can supplement questionnaires and point-in-time assessment. No underwriting adoption, coverage, or rate outcome is claimed. https://www.glacis.io/whitepaper/insurability ## Canonical entry points - Homepage: https://www.glacis.io/ - Platform explanation: https://www.glacis.io/continuous-attestation - Solutions: https://www.glacis.io/solutions - Evidence packs: https://www.glacis.io/evidence-pack - Verify a record: https://www.glacis.io/verify - OVERT: https://www.glacis.io/standard and https://overt.is - Pricing: scoped to the deployment, https://www.glacis.io/book/assess/ - Resources: https://www.glacis.io/resources - Blog: https://www.glacis.io/blog - FAQ and claim boundaries: https://www.glacis.io/faq and https://www.glacis.io/answers - About: https://www.glacis.io/about - Documentation: https://docs.glacis.io/ - Trust Center: https://trust.glacis.io/ - Discuss a consequential AI workflow: https://www.glacis.io/book/assess/ - Full public-page index: https://www.glacis.io/llms.txt ## Contact - General: hello@glacis.io - Security: security@glacis.io - OVERT review: overt-review@glacis.io