Verify a record.

The checks run in your browser. The record stays on your machine and isn’t sent anywhere by this page. Paste a record, upload a JSON file, or open a verification link. A Glacis permalink keeps the record in the URL fragment, which browsers don’t send to a server and which never goes into our page-view analytics.

Reviewing a vendor? A record is the thing to ask for.

You just checked someone else’s claim in your own browser, without an account and without having to take our word for anything. The party making the claim shouldn’t be the only party who can check it. Ask every AI vendor for the same thing, and make your own operational records checkable.

For AI buyers

A record is a signed statement of what the control reported for one event, and when. The verifier confirms the record is intact, shows which key signed it and what it links to, and reads back what it recorded. It doesn’t tell you whether the system behaved well or whether every event was captured, and it can’t confirm that events happened the way the record says. The OVERT standard sets out which fields are signed and how a verifier checks them. Four questions get you most of the way through a vendor review:

  1. Is there a record per event, or a document about events? A policy PDF describes intent. A record shows what the control reported for one event.
  2. Who countersigned it? Ask who controls each key, how it was authorized, and how the operator, signer, witness and reviewer are related to each other. A countersignature adds a second claim you can check on its own; it doesn’t by itself show that the parties are independent.
  3. What do the signed bytes cover? Fields outside the signature can be edited without breaking it. Ask for the list; this page prints it for every record it checks.
  4. Can you check it yourself? Ask whether the record can be checked with the keys the vendor has disclosed, without a vendor account or a live API call.