Signed agents, evidence passports, claim-control, audit trails and timestamp-ready proof packages for organizations operating with AI, disputed digital files and automated decisions.
We apply our own claim-control to ourselves: only the modules marked available ship today.
| Module | What it does | Status |
|---|---|---|
| Vestigium Evidence Passport | Disputed-file intake; hash manifest; technical evidence state; signed PDF/JSON dossier; verify & review. | available |
| CAAD claim-control | Anti-overclaim control — deterministically downgrades, blocks, or requires review when evidence does not support a stronger claim. Not an "AI reviewer". | available |
| Sigillum | Internal integrity & accountability seal — signs the Evidence Passport and the CAAD audit decision; supports the verify flow. | available |
| Risk Intelligence | AI & business risk exposure as a single, board-actionable number. See Risk Intelligence → | available |
| Regulatory Change Radar | Detects regulatory drift, maps it to your obligations, and seals each alert into a signed, tamper-evident chain anyone can verify over HTTP. See the Radar → · live verify. | available |
| Timestamp layer | Non-qualified RFC 3161 timestamp today. Qualified eIDAS timestamp (QTSP) is the next professional trust layer — not yet integrated. | partial |
| Agent Mandate Certificate | Who an AI agent is, what it may and may not do, and who is responsible. | roadmap |
| Agent Action Evidence Passport | What an agent did, under what mandate, with what evidence, and what a human approved. | roadmap |
| Living Certificate | Ongoing trust status — revocation, mandate validity, evidence updates. | roadmap |
| AI Act Evidence Pack | Article 4 literacy and Article 50 transparency evidence; internal AI-governance dossier. | roadmap |
| Primary | fraud & compliance, fintech, insurance, business risk, platform trust & safety, AI-agent companies, regulated SMEs using AI. |
| Secondary | litigation / IP / reputation lawyers, professional review, expert consultants. |
| SHA-256 | locks file / manifest identity |
| CAAD | prevents false success — downgrade / block / review |
| Sigillum | signs our decision (internal integrity seal) |
| QTSP timestamp | external qualified time (roadmap; freeTSA non-qualified now) |
Even a qualified timestamp proves only that a hash existed at a time — not that the content is authentic or that an event happened. That boundary is held by CAAD + signed limitations.