Cryptographic proof that your AI safety controls executed—
not just that they were configured.
✓ Controls are documented
✓ Policies are configured
✓ Changes are tracked
✓ Assessments completed
◆ PHI redaction ran on request_id:0x4a3
◆ Consent verified before recording
◆ Bias check completed on inference
◆ Guardrail executed at t=1702456789
The gap: Logs show you have a guardrail. They don't prove it ran on a specific inference. When an AI prescribes a treatment, you need cryptographic proof—not log assertions.
Each attestation signed with customer-held private key. Non-repudiable proof of execution.
Deterministic Pseudo-Random Function for auditable sampling. Prove decisions weren't manipulated.
Certificate Transparency-style append-only log. Tamper-evident with inclusion proofs.
Chain-of-custody guarantee: Every attestation is signed at creation, witnessed by independent network, anchored to append-only log. Mathematical proof of "what happened when"—analogous to NNSA material tracking.
Auditing 100% of AI inferences is impractical. But random sampling creates trust gaps: "How do we know you didn't cherry-pick?"
Key insight: Given the DPRF key, anyone can independently verify that sampling decisions were mathematically correct—without accessing underlying data.
Auditor can re-run DPRF on any request hash to confirm sampling decision was correct.
Organization cannot predict which requests will be sampled without the key.
Verification requires only request hashes—never the actual content.
Similar to Time Travel's chain-of-custody tracking, but applied at the individual inference level rather than configuration snapshots.
Native OSCAL format for direct import into RegScale, Xacta, or any CCM platform.
Real-time attestation feed for continuous controls monitoring integration.
AI-specific controls that don't exist in traditional frameworks:
What regulators and insurers will expect:
Standard of care precedes law. NIST AI RMF and ISO 42001 are becoming the de facto duty of care for AI systems—creating legal exposure even without formal regulation.
4 patent families filed November 2025
DPRF, Witness Protocol, Edge Attestation, Transparency Log
Novel combination of CT logs + AI compliance
Fenwick & West IP counsel. Provisional filings convert to full applications Q1 2026.
GRC platforms prove you have controls. GLACIS proves they ran.
Together: continuous, cryptographic compliance evidence.
Joe Braidwood • [email protected] • 415-215-3209