The whole product, stated at its limits.
Every capability below is measured, and every one of them travels with the boundary of the claim. Parts I to XII describe what exists in the current build. Part XIII is the road ahead, and nothing in it is available today.
- I. Executive overview
- II. VerifAIer today
- III. The four experiences
- IV. How the infrastructure works
- V. Preventive governance and coverage
- VI. Evidence and proof
- VII. Identity, authority and trust
- VIII. Cross-model, cross-agent, cross-vendor
- IX. Deployment and data boundaries
- X. Commercial architecture
- XI. Current limitations and coverage boundaries
- XII. Capability index
- XIII. The road ahead
Two vocabularies, and one rule about tense.
Every capability in this document carries two labels and one sentence. The labels answer different questions and neither is carried by colour.
- Available today: AVAILABLE
- The capability exists in the current build and can be used today.
- Planned, and not built yet: PLANNED
- It does not exist yet and is intended. Part XIII says under what conditions.
- Not declared yet: PENDING
- Partly present, or present with a boundary wide enough that availability would be the wrong word. The bound beside it says which.
- Available Now
- Implemented, tested, ships in the current build.
- Pilot
- Works, and requires an unpacked install, direct access or a pilot arrangement.
- Coming Soon
- Designed and scoped, and not yet reachable.
- Roadmap
- Designed and not implemented.
The bound. Every capability below is followed by the boundary of its claim. That sentence is not a disclaimer bolted on afterwards; it is part of the claim, it comes from the same measurement, and a capability recorded without one cannot be published at all.
The tense rule. Parts I to XII are written in the present tense and describe the current build. Part XIII is written about the future and nothing in it is available today. The two are separate parts rather than separately styled paragraphs, so no reader has to infer which they are in.
Executive overview
The problem, the category, and what VerifAIer is.
AI systems are moving from answering questions to taking actions. The question stops being whether the answer was good and becomes whether the action was allowed, and whether anyone can show that afterwards.
Access is not authority.
A model with an API key can call it. That is capability. Whether it was permitted to call it, for this principal, under this policy, at this moment, is a different question, and most AI estates have no component that answers it. Handing an agent a credential is not the same as granting it authority, and the gap between the two is where consequential mistakes live.
Governance has to work in three tenses.
Before an action, something has to decide whether it may proceed. During it, a person may have to be asked, and the answer has to bind to that exact action rather than to the category it belongs to. After it, the decision has to be recoverable by someone who was not there. A product that only does the third one is a log.
The estate is heterogeneous, and it will stay that way.
Organisations do not run one model from one vendor through one framework. They run several, they change them, and the assistants individuals use are not the ones their employer chose. A governance layer that belongs to one vendor governs one vendor, which is why this one is built as an independent layer with a vendor-neutral contract at its boundary.
One infrastructure, four audiences.
VerifAIer Me, Developers and AI Builders, Enterprise, and Government and Sovereign are personas and products over ONE platform: one authority model, one evidence model, one governance capability set. They have distinct front doors. They do not have distinct product truth, and no surface may claim a capability because its audience would value it.
- A tool that does one slice: Records what a model said
- What is attempted here: Decides whether an action may run, then records the decision and the outcome
- A tool that does one slice: Logs, in the application's own format
- What is attempted here: Sealed, tenant-scoped, append-only evidence that joins on canonical identities
- A tool that does one slice: Shows a dashboard derived from the log
- What is attempted here: Re-derives the governance decision from its own recorded derivation
- A tool that does one slice: Is specific to one vendor or one framework
- What is attempted here: Sits behind a vendor-neutral adapter contract, with coverage stated adapter by adapter
Most products implement a slice of identity, authority, policy, preventive control, approval, runtime, evidence, receipts, re-derivation, reconstruction, memory governance and trust. The claim here is the attempt at COHERENCE across all of them over a heterogeneous estate, and it is a claim only to the extent the parts below measure it. No comparative superiority is asserted against any named product.
VerifAIer today
The current product state, capability by capability.
A number goes stale loudly and an adjective does not, which is why this document counts. Ten governed paths is a coverage statement and not a modest way of saying comprehensive: the boundary is in Part V, and the complete list of every material capability with its own status is in Part XII.
- Governed, before the fact
- Ten action paths are evaluated before execution and none is unintercepted. A refusal means the action did not run.
- Recorded, whatever the outcome
- Refusals are recorded as fully as successes. A governed operation that was denied leaves the same class of evidence as one that proceeded.
- Re-derivable, not merely stored
- The governance decision re-derives from its own recorded derivation. What does not replay, and is never claimed to, is the model's generation.
- Local before it is hosted
- The command line governs with no account, no organization and no server, and still produces a receipt. Everything else is built on that path.
The four experiences
Personal, Developers and AI Builders, Enterprise, Government and Sovereign.
The same authority model, the same evidence model and the same governance capability set underneath all four. What differs is the surface, the vocabulary and the scale, not the truth.
VerifAIer Me
SEE what your assistants did with your data, CONTROL what they may do, APPROVE the actions that need you, and PROVE afterwards what happened. Personal disclosure and deletion are governed action kinds, and every outcome including a refusal leaves an owner-bound record.
Eight of sixteen personal capabilities are enforceable today. The browser overlay observes and does not block. A Personal owner is still placed in a manufactured organization as its administrator, and that is disclosed rather than hidden.
Open the personal surfaceIn your editor and your pipeline
A command line with fifty-two top-level commands, an HTTP API of six hundred and eight routes with a published machine contract, and an MCP server of fourteen tools of which the five that start a program are governed and fail closed. Governing a repository needs no account and no server.
Both official SDKs were retired deliberately. Nothing is published to PyPI or npm. On a local stdio surface the acting agent has no identity to record, which is measured as impossible rather than reported as missing.
Open the developers and ai builders surfaceAcross an estate and its people
Tenancy with tenant-scoped evidence, three roles, invitations and seat metering; policy authored, versioned, immutable once published, assigned and activated; ALLOW, ASK and BLOCK on ten governed paths; sealed evidence across twelve durable stores; re-derivation of the decision; and revocation enforced at decision time.
The policy grammar is presence and equality, plus one exact monetary ceiling that no producer in this build can satisfy, so a ceiling refuses every action on an unestablished fact; there is no budget and no spend accumulator. Two adapters exist and ten named environments sit at level zero. Single sign-on does not exist and has no enforcement point.
Open the enterprise surfaceInside your own perimeter
The same self-hosted software running inside the operator's perimeter, verifiable with the network off, with the deployment posture and the policy packs the government surface names. It is a persona, a solution motion and a deployment posture over the Enterprise container.
IT IS NOT A FOURTH COMMERCIAL TIER, and there is no Government or Sovereign plan. No accreditation, certification, regulatory approval or sovereign certification exists, and none is claimed. Sovereign means the same software inside your perimeter and nothing more.
Open the government and sovereign surfaceOne infrastructure does not mean identical exposure. A capability that is enforced on a governed server path is not thereby enforced in a browser overlay, and a capability present for an Enterprise tenant is not thereby present for a Personal owner. Part V states the enforcement boundary and Part XII states each capability's own.
See, control, approve and prove what an AI did with your data. Personal disclosure and deletion are governed action kinds, decisions are ALLOW, ASK or BLOCK, and every outcome including a refusal leaves an owner-bound record.
EIGHT OF SIXTEEN personal capabilities are enforceable today. Three are representable with no interception, three are future and two do not apply. The Pill observes and does not block. A Personal owner is still placed in a manufactured organization as its administrator, which is a known open defect and is disclosed rather than navigated around.
A Manifest V3 Chrome extension that audits AI platform sessions locally, produces local Session Marker and Memory Marker artifacts, and ships a local receipt viewer that reads only the extension's own storage.
INSTALLED UNPACKED. It is not on the Chrome Web Store, submission is an undecided Owner question, and the extension declares no host permission for any VerifAIer origin, so it cannot talk to a backend. GATE CONV-F renamed Session Marker and Memory Marker from "Flight Recorder" and "Memory Receipts": each hashes PAGE METADATA ONLY (hostname, tab id, a timestamp) and captures no content, and the earlier names collided with the real, server-verified features of the same name.
The governance workspace where the loop actually runs, over real data: onboarding, assessment, policy and governance, evidence, receipts, installation, developer and personal surfaces.
This is a different surface from both the local receipt viewer and the Control Center demonstration, and confusing them is the most likely way to mis-read this product.
An enterprise review workspace with executive and administrative views.
DEMONSTRATION MODE, MOCK DATA ONLY. Live data integration does not exist and requires a backend synchronisation layer that has not been built.
A command line with fifty-two top-level commands, an HTTP API of six hundred and eight routes with a machine-readable contract, and a developer surface inside the authenticated workspace.
BOTH OFFICIAL SDKS ARE RETIRED and were withdrawn deliberately; use the HTTP API or the command line. Nothing is published to PyPI or npm, so installation is from a checkout.
Coding-agent sessions are governed and recorded through command-line hooks and a local server.
Available with pilot access, and hook-based rather than automatic.
The command line governs locally with no account, no organization and no server, and still produces a receipt.
A command-line receipt is NOT independently self-verifying. Verification offers proofs, readiness tokens and attestation manifests, and none of those is the same object as a check receipt.
The site you are reading, generated rather than hand-written, so its navigation, its footer and its sitemap cannot come to disagree about what exists. This document is part of it, and is itself generated from the same record the product's readiness is measured against.
Ninety-two pages from nine canonical generators. This dossier is one of them, and GATE DOSSIER-1 RE-DERIVES it against CERTIFIED truth, not merely measured truth: CERT-1 completed Investor Ready certification over six personas and the investor demo, and Gate 13 completed pre-production certification. FULL PRODUCTION ACTIVATION AND PUBLIC LAUNCH ARE NOT CERTIFIED: no application instance runs, and full regression and final hardening have not run. No accreditation of any kind exists for any persona, and none is claimed. These four facts are never merged into one sentence.
A VerifAIer Me owner moves all eight enforceable settings from no rule at all to a governed posture in ONE STEP. The preview is what they agree to, each row states what it would change and why, and applying it writes ordinary permission records to the owner's own store.
NOTHING IS APPLIED ON ANYONE'S BEHALF. An owner who never presses keeps no rule everywhere, a stale preview is refused, the batch is all-or-nothing, and BLOCK remains settable on every row. The set invents no number: no window, no amount, no limit.
How the infrastructure works
The lifecycle, and the six distinctions it depends on.
- IDENTIFY · Who is asking
- An authenticated human session, cookie-first, resolved to a principal and to the organization that principal belongs to. On a local MCP surface the acting agent's identity is recorded as UNSTATED, because there is none to read.
- AUTHORIZE · What permits it
- An activated policy assignment evaluated at the boundary. Authority is not a role and not a credential: an unassigned policy governs nothing, and a credential that reaches no governed surface confers nothing.
- DECIDE · ALLOW, ASK or BLOCK
- One canonical derivation, in one vocabulary, recorded once. Every surface that shows the decision reads that record rather than computing a second answer.
- APPROVE · When a person must answer
- The approval binds to the exact action by a fingerprint computed from the same values the next statement passes to the executor. A changed action does not match its approval and is refused.
- EXECUTE · Or not
- A refusal means the action never ran. This is the difference between a preventive boundary and an observer that reports afterwards.
- RECORD · Sealed, not logged
- The decision and its outcome are sealed, tenant-scoped and written to append-only stores, and a receipt is issued. Refusals are recorded as fully as successes.
- RE-DERIVE · The decision, not the generation
- The governance decision re-derives from its own recorded derivation, and a mismatch is reported as a mismatch. The model's generation does not replay.
- RECONSTRUCT · What the artifacts can establish
- Fourteen subjects. Six of eight supported families reconstruct completely; two are partial and NAME THE STEPS THEY CANNOT ANSWER.
- UNDERSTAND · Posture over observed facts
- Compliance, risk and quality composed deterministically into one explainable posture, where unobserved input returns unknown rather than zero.
Nine stages, and the list is short because a stage is here only where the implementation supports what drawing it would imply. There is no discovery stage: VerifAIer does not enumerate an estate it was not told about, and Part XI says so rather than leaving the gap for a reader to find.
- Not this: Capability
- This: Authority. Being able to call something is not being permitted to. Authority comes from an activated policy evaluated at the boundary, not from holding a credential.
- Not this: Observation
- This: Enforcement. The browser overlay observes and records. Ten server-side paths enforce. Nothing here treats the first as evidence of the second.
- Not this: Logging
- This: Evidence. Evidence is sealed, tenant-scoped, append-only, and joins on canonical identities. A log does none of those four things.
- Not this: Evidence
- This: A verifiable receipt. Thirty-two receipt kinds verify integrity. A command-line check receipt is NOT independently self-verifying, and verification offers different objects: proofs, readiness tokens and attestation manifests.
- Not this: Replay
- This: Re-derivation. What re-derives is the governance decision, from its recorded derivation. The model's generation is not replayed and must never be described as replayable.
- Not this: Reconstruction
- This: Guaranteed historical truth. Reconstruction reports what canonical artifacts can establish AND names what they cannot. A partial reconstruction is published as partial, with its missing steps listed by name.
Every one of these pairs has an inner and an outer term, and the difference between a defensible claim and an indefensible one is almost always which of the two was published.
Preventive governance and coverage
What is evaluated before it runs, and where the boundary ends.
The diagram is true for the paths that have an adapter or a seam. It is not a claim about every action in an estate, and this part exists to say exactly where it stops being true.
- A model, an assistant
- A coding agent
- A pipeline or a service
- Identify, authorize
- ALLOW, ASK or BLOCK
- Seal the decision
- A tool runs
- Or it does not
- Either way it is recorded
Seventeen surfaces were classified. Ten are governed, and none of the remainder is left unclassified: each one is named, with the reason it is not an action boundary.
Three things cannot be governed, and the reason is structural.
Files, payments and memory have NO ACTION PRODUCER. VerifAIer cannot propose those actions, so no policy can govern them. This is reported by the product rather than left as an inference, because an unproduceable action is a permanent boundary and not a backlog item.
Governance is attached by deployment.
An installation that assigned no policy runs exactly as it did before. A record showing that an action was not governed means NOBODY LOOKED, not that somebody allowed it, and the product distinguishes the two rather than reporting an ungoverned action as a permitted one.
A tenant-scoped inventory of the AI an organisation has actually been observed using, derived from the governed actions VerifAIer already holds evidence for, with adoption over an explicit window and a value determination beside every asset. What was REGISTERED and what was OBSERVED are two different facts and are never merged.
THIS IS NOT DISCOVERY, and the limitation this product already publishes is unchanged: nothing scans a network, a cloud account, an identity provider or a model gateway, so AI an organisation runs outside a governed seam does not appear. Three of twelve action families name an AI asset. BUSINESS VALUE IS REPORTED AS NOT DETERMINABLE for every asset, because no evidence record in this build carries a business outcome; no ROI, monetary figure or productivity percentage is published, and usage is never equated with value. No owner and no department is inferred, because neither has a producer. Call volume is not derivable and is published as not derivable.
A governed action path is evaluated BEFORE it executes. The decision is ALLOW, ASK or BLOCK, it is derived once from an activated policy, and a refusal means the action never ran rather than that it ran and was noted afterwards.
Ten governed paths, never described as universal. Governance is attached by deployment: an installation that assigned no policy runs exactly as it did before, and the record says nobody looked rather than that somebody allowed it.
Ten action paths are governed and none is unintercepted. The product can propose eight canonical action kinds, stated by seven named producers at eight governed seams, and an operator may author policy for exactly those.
FILES, PAYMENTS AND MEMORY have NO action producer. VerifAIer cannot propose those actions, so no policy can govern them, and the product reports that rather than implying coverage it does not have. EMAIL IS NO LONGER AMONG THEM: it is governed end to end, and this sentence asserted the opposite until the product was measured rather than believed.
A policy can require a person to answer before an action proceeds. The answer is bound to that action by a fingerprint computed from the same values the next statement passes to the executor.
An approval does not generalise. A changed action does not match its approval and is refused, which is what closes the gap between asking and acting.
Policy is authored, versioned, immutable once published, assigned and activated. Activation is what makes a rule bind; an unassigned policy governs nothing.
The policy grammar is PRESENCE AND EQUALITY ONLY. There are no thresholds, no roles, no times and no agent identities in it. A rule requiring a fact refuses every action today because no producer supplies one, which is measured fail-closed and is reported as such by the product itself.
Standing is checked at decision time rather than at sign-in. A revoked user stops being able to act on the next governed action, not on the next session.
Enforced for human principals. A machine credential returns no standing, and a revoked one would be indistinguishable from a live one, so revocation is not claimed for machines.
The MCP server exposes fourteen tools. Five of them start a program on the machine, and all five pass through the same preventive boundary as every other governed path, failing closed.
Five of fourteen. Never all agent tool calls, and never all MCP servers: this is VerifAIer's own MCP surface governed, not a claim about other people's.
A governance scan runs locally on four AI platforms, and the Pill renders what it found as a visual overlay on the page.
IT OBSERVES AND RECORDS. IT DOES NOT INTERCEPT OR BLOCK. Preventive enforcement lives on the ten governed paths and not in the browser overlay.
Sending an email is a governed action. The message is authorised at one choke point before it leaves, and the invitation that carries organization membership passes through the same preventive boundary as every other governed path.
THE RECIPIENT IS GOVERNED AT DOMAIN GRAIN, which is the finest an equality-only policy grammar can act on. A policy refusal RAISES rather than being recorded as a delivery failure, because reporting our decision as their server's fault is a refusal the operator never learns about.
Three selectable postures - Safe Defaults, Enterprise and Sovereign - that an operator assigns to an organization instead of authoring a policy from nothing. A baseline is an ordinary catalog entry deployed through the ordinary activation path.
THESE ARE NOT THE TRUST POLICY PACKS. Those judge change-sets and a compliance posture, and not one line of them can produce an ALLOW, an ASK or a BLOCK on a proposed action. A baseline that requires an identified principal REFUSES the local tool surface, and the product reports that before activation rather than discovering it at runtime.
Two metrics the product computes about itself. GOVERNED ACTION COVERAGE is 8 of 12 consequential action families that can be prevented before the consequence. DEPLOYABLE POLICY COVERAGE is 8 of 8 of those preventable families for which a shipped posture can be selected rather than authored.
NEITHER IS A FRACTION OF EVERY ACTION AN AI AGENT COULD TAKE; no product can enumerate that set. Every family deferred for want of a producer STAYS IN THE DENOMINATOR, so the first number rises only by governing one. The second names its split and never merges it: six families through an operator's tenant baseline, two through a VerifAIer Me owner's own settings, which no tenant baseline reaches.
Evidence and proof
Seals, receipts, replay, re-derivation and reconstruction.
- Sealed at the point of decision
- The seal binds a decision to the principal and to the action it was derived for, and it verifies afterwards.
- Append-only, and enumerated
- Twelve durable stores, eleven append-only, listed by the product itself and self-checking rather than described in a document.
- Joined on canonical identities
- Evidence from different surfaces about one operation joins, because they share identifiers rather than each keeping their own record.
- Re-derivable by someone who was not there
- The decision is recomputed from its recorded derivation. This is the difference between keeping a record and being able to defend it.
No cryptographic claim beyond integrity is made anywhere in this document. There is no zero-knowledge proof system, no chain submission, no smart contract and no external notary. What exists is content integrity, deterministic re-derivation and reconstruction that names its own gaps.
One derivation, one vocabulary, recorded once. Every surface that shows a decision is reading the same record rather than computing its own.
One vocabulary means one authority. A second engine deriving a second answer is refused by construction, not by convention.
Every governed decision is sealed and the seal verifies. The seal binds the decision to the principal and to the action it was derived for.
Integrity, not authorship. A seal proves the record was not altered after it was written; it is not a signature by an external authority.
The GOVERNANCE DECISION re-derives from its own recorded derivation. Given the record, the same inputs produce the same decision, and a mismatch is reported as a mismatch rather than smoothed away.
THE MODEL'S GENERATION DOES NOT REPLAY AND IS NEVER CLAIMED TO. What re-derives is the decision about the action, not the text the model produced.
Reconstruction answers what happened from canonical artifacts. Six of eight supported governed operation families reconstruct completely; two are partial. It is reachable over the authenticated HTTP API only, not on the SDK, the CLI or MCP.
The two partial families NAME THE STEPS THEY CANNOT ANSWER. One of them can never answer who acted, because a local stdio MCP surface has no identity to record, and that is permanent rather than pending.
Twelve durable stores, eleven of them append-only, enumerated by the product itself and self-checking. Evidence is tenant-scoped and joins on canonical identities.
RETENTION IS NOT DECIDED FOR ANY STORE. That is an open Owner decision and a privacy and production dependency, not an engineering gap.
A session-level record of what a coding agent did, produced by the command line with three hooks wired, and read in the workspace under Evidence, as its own sub-surface.
Installed from a checkout, not from a package index. The command line is not published to PyPI. GATE CONV-F found the browser extension's own popup mode of this name FABRICATED and renamed it; the extension does not produce a Flight Recorder artifact of any kind. The real feature is produced from the command line and read in the workspace; it is not a second product plane.
Sealing binds a time to a content digest. Any edit to the content breaks the seal, and checking it is a local operation that needs nothing from us.
CONTENT INTEGRITY, AND NOTHING MORE. A receipt proves the bytes are unaltered since sealing. It says nothing about what a model retained, reused or was affected by, and no such attribution exists in the product. GATE CONV-F found the browser extension's own popup mode of this name FABRICATED and renamed it; the extension does not produce a Memory Receipt of any kind, and the real feature is CLI-only.
Deleting personal records is a governed action with an immutable owner-bound record of the outcome, including refusals. That much is enforced today.
WHAT MAY BE REMEMBERED, RETENTION AND PURPOSE ARE REPRESENTABLE AND NOT ENFORCEABLE. Memory read and write interception is not implemented, and there is NO EVIDENCE LINKING A REMEMBERED ITEM TO A DECISION: no such attribution exists and none may be claimed.
A deterministic lineage graph across Flight Recorder sessions and Memory Receipts, available from the command line.
Deterministic linkage, with no AI inference anywhere in it. It joins records; it does not interpret them.
A public in-browser audit surface that accepts a pasted session transcript and runs entirely on the reader's own machine.
It runs on pre-computed data in the browser. It is a demonstration surface, not the governed runtime.
Evidence can be disclosed selectively, so a reader can be given the field they are entitled to without being given the record around it.
THIS IS ARCHITECTURAL SELECTIVE DISCLOSURE, NOT CRYPTOGRAPHIC ZERO KNOWLEDGE. It must never be presented as a zero-knowledge proof system.
The evidence layer is anchoring-ready: a proof identifier is sixty-four characters of calldata, which needs no smart contract to submit.
NOTHING IS ANCHORED. No chain submission happens, and no smart contract is required by the design or deployed by the product.
One answer to what happened, assembled from canonical artifacts: which principal acted, what authority existed, what policy applied, whether approval was required, what executed, and whether the decision re-derives. It is reachable from the command line and over the API.
A READ OVER ARTIFACTS THAT ALREADY EXIST, not a second architecture and not a second opinion. It names the relations that produced nothing rather than returning a tidy story, and a request whose tenant cannot be resolved is REFUSED rather than served unscoped.
Identity, authority and trust
Who acts, what authorises it, and what trust is derived from.
Authenticated identity and asserted identity are different things, and nothing in this product describes self-declared metadata as an authenticated identity.
- What identifies the principal
- An authenticated human session, cookie-first, resolved to a person and then to their organization.
- What identifies the acting agent
- On a local MCP surface, NOTHING. It is recorded as unstated, and that is permanent for a local stdio surface rather than pending.
- What establishes authority
- An activated policy assignment evaluated at the boundary. Not a role, and not the possession of a credential.
- Whether revocation is enforced
- Yes for human principals, checked at decision time. NOT for machine credentials, and that capability is therefore not claimed.
- Whether a tenant mismatch is caught
- Yes. The principal's organization is compared against the runtime's, and identified is kept distinct from verified.
Email and password with cookie-first sessions for the web application. The local command line needs no account at all.
NOT OAUTH, NOT OIDC, NOT SSO AND NOT MFA. None of those exists in this build, and single sign-on has no enforcement point anywhere in the product.
Every user belongs to an organization and evidence is tenant-scoped. Three roles, invitations, member management and role assignment all ship.
Three roles and no more: administrator, analyst, viewer. Tenant identification is not tenant verification, and the product keeps those two words apart.
A real revocable, organization-scoped, key-derived machine credential exists and can be issued and revoked.
IT IS A CREDENTIAL, NOT A GOVERNANCE PRINCIPAL, and it has no consumer in the governance path. On a local MCP surface the acting agent's identity is MEASURED IMPOSSIBLE rather than merely absent, and the product records it as unstated instead of inventing one.
Asking whether somebody was a member at a past moment is a question the product answers explicitly rather than silently.
It answers UNPROVABLE. The membership table cannot record an interval by construction, and reporting that is the truthful answer rather than a gap.
A deterministic, content-derived, portable trust document composed from an identity and a trust profile, with a lifecycle: it can be registered, suspended, reinstated, revoked or left to expire, and verified.
THE LIFECYCLE IS THE DOCUMENT'S, NOT THE AGENT'S. Revoking a passport withdraws a disclosure and never a principal: it stops no agent from acting, and the preventive engine cannot read it. Verification is AUTHENTICATED and tenant-scoped, it evaluates no authority, and a standing passport is not permission to do anything. NO EXTERNAL IDENTITY FRAMEWORK IS INTEGRATED, no cross-organization trust decision is reachable end to end, and THERE IS NO AGENT TRUST NETWORK.
Deterministic scoring over observed facts, composed into one explainable posture across compliance, risk and quality.
THE WEIGHTS ARE CALIBRATION, NOT MEASUREMENT. Unobserved input returns unknown rather than zero, because missing evidence is not the same as a good result.
The product publishes its own absence of accreditation rather than staying silent about it.
NO GOVERNMENT, SOVEREIGN, REGULATORY OR COMPLIANCE CERTIFICATION EXISTS. Nothing here is certified, accredited or approved by anyone.
Cross-model, cross-agent, cross-vendor
Architectural independence, and the integration coverage that exists today.
The honest formulation, and the one the product already uses: ARCHITECTURAL COMPATIBILITY IS NOT CERTIFIED INTEGRATION. VerifAIer does not claim to govern an environment it has no measured adapter for, and the adapter report states the level rather than the intention.
A vendor-neutral adapter contract, with a coverage maturity computed from measurements that already ran rather than declared by hand.
A CONTRACT AND TWO ADAPTERS, both reaching the preventive boundary: outbound email at level seven of eight and MCP at six. Ten named third-party environments are recorded BY NAME AT LEVEL ZERO. Architectural compatibility is not certified integration.
Fourteen tools over local stdio, speaking an open protocol, so any MCP-capable client traverses the same governed seam.
Five of the fourteen start a program and are governed. The other nine read.
A governed artifact can be authorised, minimised, sealed and sent over a real socket to an independently governed external node, which admits it under its own law and acknowledges it with a lineage identifier that links back.
THE RECEIVER LEARNS NOTHING. The embedding is empty. There is no shared model training, no shared verdict across installations, and no network effect. Sender identity is NOT independently verified, and with the node unreachable the product stays fully operable. Refusal is fail-closed: no authority means zero network calls.
Deployment and data boundaries
Where it runs, and what each posture is certified for.
Four words are kept apart here: architecturally supported, implemented, tested, and production-certified. Only the last one is a promise about running a business on it, and NOTHING IS PRODUCTION-CERTIFIED YET.
The evidence layer is verifiable offline. An assessment requires no outbound call, and a sovereign deployment is the same software inside the operator's perimeter, which is the entire claim and the whole of it.
Install from a checkout and run the server. This is the path everything else is built on, and it needs no account and no network.
IMPLEMENTED AND TESTED, NOT PRODUCTION-CERTIFIED. Hardening and production activation are still ahead of it.
The hosted control plane is canonical IN ADDITION TO self-hosted, and its code is ready.
NO APPLICATION IS HOSTED ANYWHERE. The public site has a real origin, DNS and HTTPS; the product behind it does not. Sign-in, the workspace and the API return 404 on that origin by design, because no instance is running. The deployment manifest, entrypoint and configuration schema exist and are reproducible; what is missing is a hosting account, which is an Owner action rather than engineering. There is nothing to sign up for today.
Enterprise, private, sovereign and air-gapped deployments are the SAME self-hosted software running inside the operator's own perimeter, verifiable with the network off.
SOVEREIGN MEANS THE SAME SOFTWARE INSIDE YOUR PERIMETER AND NOTHING MORE. There is no accreditation, no national dashboard and no separate sovereign build. Air-gapped installation is a bundle provided per engagement and is only partially tested.
The extension installs unpacked, from a documented procedure, today.
Chrome Web Store publication has not been decided or submitted, and no store listing exists.
Whether the browser extension can send what it records to a server.
IT CANNOT, AND THE REASON IS STRUCTURAL: the extension declares no host permission for any VerifAIer origin. Extension data stays on the machine.
The runtime is implemented and certified against a real PostgreSQL 16, with tenancy, authority, policy, decisions, evidence and reconstruction re-certified across it rather than assumed. A populated database is backed up, restored to a disposable location, reopened and READ BACK.
NINE STATUSES HERE ARE NOT SYNONYMS. The runtime being certified is not a service being provisioned: NO MANAGED POSTGRESQL SERVICE IS PROVISIONED, CUTOVER HAS NOT STARTED, and POINT-IN-TIME RECOVERY IS NOT CLAIMED. The hosted posture still reports SQLite as what it runs, and provider-side snapshots and their retention remain an Owner action.
Commercial architecture
Three tiers, one sales-led container, and what is not priced.
- Community
- Free. The local path needs no account at all.
- Professional
- Per user, per month, seat metered from real active memberships. The figure is published on the pricing page and is stated in exactly one place on this site.
- Enterprise
- Sales-led, by custom commercial proposal, with no published number. Government and sovereign programmes are a persona and a posture over this container.
This part explains the commercial architecture to the depth an evaluation needs and no further. It is not a pricing page, and it deliberately does not restate a figure that another page owns.
Community, Professional and Enterprise, with entitlements resolved per organization. Professional carries a published per-user monthly price.
THREE COMMERCIAL TIERS, NOT FOUR. The Professional number is published on the pricing page and is deliberately not restated here, because one page owning a price is how a price stays correct.
Billable seats are counted from real active memberships, independently of privilege level, and that count is what a subscription quantity follows.
Only Professional is seat metered. Pending invitations are not seats and machine keys are not seats.
The payment path is implemented and verified against a sandbox, including the seat quantity synchronisation.
NOTHING CAN BE BOUGHT FROM A RUNNING DEPLOYMENT TODAY. Live billing is not activated: no live account, product, price, webhook or customer portal exists, quota enforcement is advisory and unwired, and neither invoicing nor a licence server exists.
Enterprise is SALES-LED with a custom commercial proposal. A proposal is scoped from estate size, governed agents and systems, environments, usage, deployment model, isolation, support, service levels, sovereignty requirements and services. Government and sovereign programmes are a persona, a motion and a deployment posture over the Enterprise container. An operator grant path exists to deliver an entitlement once a contract is signed.
THOSE ARE VARIABLES, NOT A FORMULA. No minimum, floor, list price or per-seat Enterprise rate is published, and none may be derived from them. There is no Government or Sovereign PLAN. The grant path is an operator tool on the host, not a checkout, and it CANNOT ISSUE A PERMANENT GRANT.
Whether Professional is offered annually.
NOT OFFERED AT LAUNCH. There is no public or self-service annual rate and no discount, and the seeded development fixture is not a price. Individually negotiated multi-year Enterprise terms are unaffected and create no catalog price.
VerifAIer Me is FREE FOR LAUNCH. No personal paid tier exists and none was invented.
FREE FOR LAUNCH, NOT FREE FOREVER. Whether Personal is ever priced is deferred to measured activation, usage, retention and willingness to pay.
The product MEASURES adapter count, estate size, governed agents and systems, governed actions, receipt volume, policy volume, API usage, runtime calls and evidence volume wherever it already measures them.
NONE OF IT IS BILLED. Nothing is metered commercially, no included quota exists and no overage price exists. MEASURED, NOT PRICED.
Current limitations and coverage boundaries
Published because an evaluator needs them, not despite it.
This part is here because an evaluator who finds a limitation themselves stops believing the rest of the document. Every item below is drawn from the same measurement as the capabilities above it.
- Runtime coverage is not universal
- Ten governed paths. Files, payments and memory cannot be governed at all because nothing can propose them as actions. Coverage grows adapter by adapter.
- Spend cannot be limited
- A policy can refuse an action whose declared maximum charge is above what it authorises, and NOTHING IN THIS BUILD DECLARES ONE, so such a rule refuses every action for want of the fact rather than for a figure. There is no budget, no running total of spend and no price. A refusal prevents an economic consequence; a permission does not cap one, because no executor here accepts a ceiling and no call can be stopped in flight.
- The browser overlay does not enforce
- It observes and records on four AI platforms. It cannot intercept and cannot block, and no enforcement claim is derived from it.
- There is no estate discovery
- VerifAIer governs what it is connected to. It does not enumerate the AI systems in an organisation that it was not told about.
- Integration breadth is two adapters
- Outbound email at level seven of eight and MCP at six. Ten named third-party environments are recorded at level zero by name, and architectural compatibility is not integration.
- Machine principals are not governed
- A revocable machine credential exists and has no consumer in the governance path. It is a credential, never a principal, and revocation is not claimed for it.
- Agent identity on a local surface is impossible, not missing
- On a local stdio MCP surface there is no identity to read. It is recorded as unstated, and one reconstruction family can never become complete for that reason.
- Agent Passport is a document, not a credential
- A passport can be registered, suspended, revoked or left to expire, and is verified through an authenticated, tenant-scoped API, but it is a disclosure document and never a principal, and verification evaluates no authority. No external identity scheme is integrated. A trust decision exists as a foundation and is bound to no runtime decision. THERE IS NO AGENT TRUST NETWORK.
- A memory cannot be tied to a decision
- Memory Receipts are content integrity. Nothing here establishes that a remembered item affected an action, and read and write interception is not implemented.
- Personal governance is partial
- Eight of sixteen personal capabilities are enforceable. A Personal owner is still placed in a manufactured organization as its administrator, which is an open data-model question rather than a rendering defect.
- Evidence retention is undecided
- Twelve durable stores, and no retention decision for any of them. It is an open question with privacy and production consequences.
- Nothing is production-certified
- The public site has a production origin, DNS and HTTPS, and NO APPLICATION INSTANCE RUNS BEHIND IT. The PostgreSQL runtime is certified and backup, restore and a recovery drill are done, but NO MANAGED DATABASE SERVICE IS PROVISIONED, cutover has not started and point-in-time recovery is not claimed. Hardening and adversarial certification have not run.
- Nothing can be bought
- The payment path is implemented and sandbox-verified. Live billing is not activated, quota enforcement is advisory and unwired, and neither invoicing nor a licence server exists.
- Single sign-on does not exist
- Email and password with cookie-first sessions. No OAuth, OIDC, SSO or MFA, and single sign-on has no enforcement point in the product.
- Nothing is accredited
- No government, sovereign, regulatory or compliance certification exists, and the government surface publishes that absence rather than staying silent.
- The distribution surface is narrow
- The extension installs unpacked and is not on the Chrome Web Store. The command line installs from a checkout and is not on PyPI. Both official SDKs were retired.
- The contribution boundary is narrow on purpose
- A governed artifact reaches an independently governed external node and is admitted under that node's law. THE RECEIVER LEARNS NOTHING, sender identity is not independently verified, and no network effect exists.
None of these is a defect discovered by a reader. Each is published by the product's own reports, and several of them are permanent rather than pending: an action nothing can propose cannot become governable, and an identity that does not exist on a surface cannot be recorded from it.
Capability index
Every material capability, with its status and its bound.
56 capability areas, grouped by the part that explains them. This index is GENERATED from the same record the product's readiness is measured against, reconciled in both directions: a capability the product gains and this page omits fails a guard, and so does a capability this page names that the record does not carry. It cannot be shortened for editorial convenience.
The road ahead
Planned, in development and conditional. Nothing in this part is available today.
This part PRESENTS the canonical roadmap. It is not a second roadmap: every area below names the canonical section it comes from, and one that named nothing could not be published here.
Nothing in this part is available today. Sequence is stated and calendar dates are not, because no date is approved and an invented one is a commitment nobody made. A row marked CONDITIONAL carries the evidence that would promote it, and until that evidence exists the row is an option rather than a plan.
HARD-1 CLOSED over the PRE-EXPANSION product: fail-closed semantics, bypass prevention, tampering and concurrency validation, stale approvals and stale policies, timeout and degraded-mode behaviour, a clean install, and a security review. What remains forward is the SAME class of hardening run again, over the product this amendment expanded: final security, adversarial, privacy and tenancy hardening, after Feature Freeze and before Full Launch + Operate Ready certification.
A running application instance. The public site is served from a real origin over HTTPS, and the canonical origin is now declared once in the product rather than in a build script -- but no APPLICATION is hosted, which is what makes the hosted posture unavailable rather than untested. The manifest and the environment schema are written; the hosting account is not.
THE RUNTIME IS CERTIFIED; THE MANAGED SERVICE IS NOT, AND THE TWO ARE NOT SYNONYMS. LF-1, LF-2 and LF-3 certified the PostgreSQL 16 runtime, its schema, migration, backup, restore and a recovery drill for the self-hosted path - a populated database is backed up, restored into a disposable location, reopened and READ BACK, because a file that exists is not a database anyone can serve from - and Part IX states that. What remains forward, and IS REQUIRED PRODUCTION HARDENING BEFORE FULL LAUNCH rather than an option held open: PROVISIONING A MANAGED POSTGRESQL SERVICE for the hosted posture, which still runs SQLite in write-ahead logging on a persistent volume behind a single always-on instance today. Cutover has not started and point-in-time recovery is not claimed. The migration carries its own acceptance scope, and tenancy, authority, policy, runtime decisions, evidence, receipts and reconstruction are re-certified across it rather than assumed. Provider-side snapshots and their retention remain an Owner action.
Production secret management. The cross-origin policy is now set against a real declared origin and a wildcard allow-list is refused in production -- the application will not start with one. What remains is the secrets themselves: generating, storing and rotating them is an operator act that no repository can perform for itself.
Operational instrumentation, alerting, an incident runbook, a rollback path, and a decision on log retention alongside the evidence retention question.
Retention is undecided for all twelve durable stores. It is an Owner decision with privacy and production consequences, and it is named here because a dossier that lists eleven append-only stores without it would be overstating.
A proprietary licence and a third-party notices file now exist, and the distribution metadata declares them. Terms, privacy policy and a data processing agreement are still seeded as drafts and must be published before payment and personal data are taken at scale. That remainder is Owner legal time, not engineering time.
Pipeline hardening and separation of environments, so a deployment is reproducible and a rollback is a routine action rather than an event.
Live payment activation, webhooks, the customer portal, the subscription lifecycle including cancellation, seat quantity in production, and invoicing and tax where required. The path is implemented and sandbox-verified; activation is blocked behind hosting.
Transactional email, password recovery, and persistence of assessment results so a returning account finds its own evidence. Each is a self-serve requirement rather than a pilot one.
The public copy that currently denies a hosted tier has to change on the day hosting exists, and it is sequenced first because it is the cheapest and the most visibly wrong.
AEV-1 ALREADY DELIVERS the base of this: a tenant-scoped estate derived from governed-action evidence, published in Part V as the current `ai-estate` capability. What remains forward is everything that base measurement explicitly could not determine - relating an asset to a real business outcome, an owner or a department it was never given a producer for, and coverage across the nine action families that name no AI asset today - so that adoption, redundancy and value can be reasoned about rather than guessed, beyond what is guessed against already.
WHERE VALUE CANNOT BE DETERMINED FROM EVIDENCE, THE ANSWER IS NOT DETERMINABLE. Return on investment is never invented, business value is never inferred from activity, and usage is never equated with value. It also does not become estate discovery: VerifAIer still governs what it is connected to.
ECON-1 ALREADY DELIVERS a vocabulary, an admissibility rule and a refusal: four cost classes over ten evidence bases, none of which reaches OBSERVED in this build, and a published Cost Score CONTRACT with no Cost Score. It is BUILT and not claimable, because every cost is UNKNOWN. What remains forward is understanding what AI costs and judging how economically appropriate that cost appears to be, given evidence this build does not yet hold - across a response, a session and a task, and adapted to each audience rather than rendered identically for all of them.
FOUR COST CLASSES THAT MAY NOT BE COLLAPSED - OBSERVED, CALCULATED, ESTIMATED AND UNKNOWN. An estimate never becomes an actual, and an API-equivalent figure is not what a subscription user was actually charged. The score requires a published contract and confidence semantics BEFORE it computes anything, and no universal formula may be hardcoded to make a number appear.
Whether the browser companion gains a fourth contextual mode beside Audit, Session Marker and Memory Marker, at whatever grain the surface can actually evidence.
THE SHIPPED EXTENSION HAS NO COST CAPABILITY AND CANNOT SEE A BILL. It declares no host permission for any VerifAIer origin. This row is conditional on the surface being technically able to carry the claim at all, and until then Cost is absent from the browser companion by construction.
Extending the distinction the product already enforces - ability to consume is not authority to spend - so that approved providers, model tiers, autonomous cost limits and budgets are governed before consequential spend, deciding ALLOW, ASK or BLOCK and, where appropriate, authorising a lower-cost routing class.
AUTHORISING A ROUTING CLASS IS A GOVERNANCE DECISION; PERFORMING THE ROUTING IS EXECUTION. VerifAIer does not become a model gateway or an inference provider. The grammar question this work had to answer first has been answered and the answer was no - presence and equality cannot carry a ceiling - so a single monetary rule kind exists and nothing in this build can yet state the fact it needs: every economic ceiling refuses on an unestablished fact. There is no budget, no spend accumulator and no payment producer, and a refusal prevents an economic consequence while a permission does not cap one.
Identifying defensible waste - premium-model overuse, oversized or repeated context, retry loops, duplicate inference and retrieval, redundant agents and overlapping products - and proposing alternatives against a versioned pricing catalog that carries its own provenance and freshness.
A CHEAPER ALTERNATIVE IS NOT A RECOMMENDATION. Where only price is known the honest classification is CHEAPER CANDIDATE, NOT VALIDATED. Not every one of those wastes is observable today, and classifying which are was the first deliverable rather than an afterthought - and it has now been done. Seventeen inefficiency classes are classified against twenty pieces of evidence, each measured by a predicate that runs rather than by a label somebody typed, and NONE of the seventeen is derivable from what this build holds: the engine runs and returns NO DEFENSIBLE OPTIMISATION FINDING for every subject, with the missing evidence named. Suitability is evaluated BEFORE price - the function that decides it has no price parameter at all - across fourteen dimensions, six of which bind whatever a workload says, and none of the fourteen has a producer, so no candidate can reach VALIDATED SUITABLE and the word recommended is unreachable rather than merely unused. No saving is computed, because eight prerequisites must hold and a price delta is not one of them. The pricing catalog is still empty, and its emptiness now blocks three named classes rather than merely being stated.
A product-integrity rule rather than a feature: a commercial relationship may never alter a cost score, a suitability score, a ranking, an estimated saving, a confidence value or a technical recommendation. A partner offer may be disclosed beside a candidate whose technical standing was derived without reference to it.
THE COMMERCIAL TERMS OF ANY SUCH PROGRAMME ARE AN UNDECIDED OWNER QUESTION, and no affiliate marketplace is designed or implied. The separation is now mechanical rather than promised in prose, and it is a SHAPE rather than a prohibition: the organic result is computed by functions that have no parameter a commercial relationship could enter, and a disclosure attaches to an ALREADY FINISHED result and carries it unchanged. There is no call site at which commercial data and an un-computed organic question exist together, so the contamination has no place to happen rather than a rule against happening. Nothing in this build records a commercial relationship of any kind - that is measured, not assumed - and NO product state was created to hold one.
CONV-F CLOSED, having re-audited the expanded product as ONE infrastructure: every audience, every surface, navigation, information architecture, terminology, responsiveness and accessibility, and the separation of what exists from what is planned. Its acceptance question was whether the expanded product was still intuitive, and the answer was one nav entry: `scg.flight` already existed as a canonical evidence producer and the deep link was the whole repair. It also found and renamed a naming collision - the browser extension's fabricated "Flight Recorder"/"Memory Receipts" popup modes, now Session Marker and Memory Marker.
DEFERRED: `api_gateway.js::buildAuditResponseEnvelope` defaults an absent extension confidence value to `0`, feeding no authority decision. It is left for a future gate that touches the extension's detection surface, and breadth is not answered by adding navigation items.
ONB-F CLOSED, having re-derived onboarding from the completed product so that every entry intent - governing AI, governing agents, proving compliance, understanding an estate, understanding spend, developer integration, personal control - arrives at the same infrastructure rather than at a separate product. It found that the onboarding census's own anti-drift guarantee held for three of its four sources and not the fourth, and repaired the classification of two already-closed, already-governed routes rather than building a page. Truthful first value was preserved throughout: a person is never asked to configure a capability that does not exist.
TWO ITEMS NAMED BY THIS GATE ARE STILL FORWARD, FOR A FUTURE GATE WITH A NAMED DEMAND: `routing_inputs()` suggests `enterprise` for every self-signup account regardless of the form a person used, and a tenant-scoped MCP execution count was refused because no tenant-scoped enumeration contract exists anywhere on this platform. Neither is built, and neither is promised on a date.
CERT-1 CLOSED, having certified the end-to-end journeys rather than the units underneath them, once, over the pre-expansion product: Personal, Developer, Community, Professional, Enterprise and Government, each against the discover through decision-replay chain. Journey certification found defects that tens of thousands of unit tests did not, which is why it was a gate and not a review. What remains forward is re-running that same certification over the product this amendment expanded: AKP-2, PPB-1, IR-1, PRD-1, Agent Passport, trust protocol, the economics family, PGC-1, CONV-F, ONB-F and this dossier re-derivation.
CERT-1 CLOSED, having certified that the product could be demonstrated end to end from a real deployment, against the claims the dossier published at that baseline. What remains forward is the same certification re-run against the product that actually launches, as part of Full Launch + Operate Ready certification, over the claims THIS dossier publishes rather than the earlier one.
TWO DOSSIER BASELINES EXIST, AND THEY ANSWER DIFFERENT QUESTIONS. The one published at SITE-1 was generated from MEASURED truth and named its own absence of certification. DOSSIER-1 RE-DERIVES the same two tables and the same generator against CERTIFIED truth - Investor Ready, certified by CERT-1 - and states what remains uncertified rather than restating the earlier sentence. The mechanism did not change; the baseline it is measured against did.
The point at which the product is publicly available rather than available to pilot partners, and the point after which the growth programme begins by default.
Lifecycle, revocation and authenticated external verification SHIP. What remains forward is interoperability with identity frameworks this build does not implement, and cross-organization trust decisions: a passport carrying principal, issuer, provable model family where that is feasible, governance profile, tools, data class, action and financial limits, and policy, that a second organization can act on.
A vendor-neutral interoperability direction around identity, issuer, claims, authority, permissions, policy, revocation, evidence, trust outcome and receipt. A FOUNDATION EXISTS: a deterministic admissibility decision, by scheme, issuer, subject, purpose and instant, that keeps identity, trust and authority apart. It is bound to no runtime decision, exposes no route, stores no policy, and one identity scheme is implemented, VerifAIer's own. Runtime attestation is not implemented, and no external scheme is integrated.
The remaining path from the current state to public launch.
A developer-specific acquisition surface, onboarding and self-service path, distributed through developer-native channels. Vendor neutrality is a product constraint here rather than a marketing preference: the motion may not collapse into governance for one model or one editor.
A discovery gate that runs BEFORE material paid acquisition, testing pain, urgency, comprehension, first value, willingness to pay, packaging and retention intent. It exists to stop the programme spending on a proposition nobody has confirmed wanting.
That an individual developer becomes a team, an engineering organization and eventually an enterprise contract, so developer adoption serves both direct revenue and distribution.
A HYPOTHESIS TO MEASURE, NOT A CLAIM. It may not appear as established fact until the growth programme's own measurement supports it.
A consumer and prosumer acquisition surface, low-friction onboarding and distribution appropriate to the actual product format. Consumers are not given enterprise compliance language as their first proposition.
That Personal and Developer self-service revenue may arrive on a faster cycle than Enterprise and Government sales, and may help fund infrastructure, development and the longer sales cycle.
A STRATEGIC HYPOTHESIS, NOT A GUARANTEED OUTCOME AND NOT A FUNDING PLAN. It may not be presented as established until measurement supports it.
Acquisition language may differ by segment. Every claim in every segment's language must still resolve to the same measured capability, and no marketing surface may invent a capability because another segment would value it.
Acquisition, activation, time to first value, conversion, willingness to pay, retention, expansion and revenue contribution, each measured against a real baseline.
NO TARGET VALUES EXIST. Targets are set by that programme's own opening gate against real baselines, and none is published here.
Segmented acquisition, and two hypotheses recorded as hypotheses.
The strategic metric is the proportion of relevant consequential AI actions actually governed. Coverage grows through controlled adapters in roughly this order: MCP, then software and HTTP interfaces, then coding agents, then the browser, then enterprise integrations, then the personal runtime, then additional frameworks. WHAT IS COVERED IS WHAT HAS AN ADAPTER.
Ten named third-party environments are recorded at level zero today. Each becomes claimable only when its own adapter is built and measured, one at a time and evidence-gated.
A signed and versioned pack format, with install, update, compatibility and rollback, and enterprise policy packs over it.
A distribution surface for packs authored outside VerifAIer.
CONDITIONAL ON A REAL ECOSYSTEM. A marketplace without third-party authors is a directory of our own work, and it is not built before the ecosystem exists.
Additional enterprise connectors, additional AI coding surfaces, and public interfaces broad enough for an estate rather than a repository.
Signed policy packages, local enforcement, and selective evidence upstream, preserving the local-first and privacy characteristics wherever that is technically possible.
Multi-tenant, dedicated, private cloud, customer cloud, on-premises, sovereign and air-gapped targets, expanded as demand requires rather than pre-built.
Memory policies, permissions, lifecycle and audit, extending memory governance from integrity and deletion toward what may be remembered and why.
Governed action coverage, packs, and deployment breadth expanded on demand.
Acting on behalf of another principal, with the delegation itself governed and recorded rather than assumed.
DEFERRED. No real executor flow requires it yet, and it is promoted when one does.
The network in which passports issued by one party are meaningful to another.
REQUIRES EXTERNAL ADOPTION AND IS NOT A CAPABILITY WE CAN BUILD ALONE. Protocol implementation is not network effect, and a network is never claimed because code exists.
THE SURFACE ITSELF NOW EXISTS and has moved into the current product, where Part VI describes it. What remains here is breadth rather than existence: reconstruction over a population of related operations rather than one at a time, and over the families whose artifacts cannot yet answer every step.
Governance that reasons about a population of agents rather than one action at a time.
DEFERRED. Aggregate and multi-agent ANALYSIS exists in the command line today; runtime governance of it is not required for the first version.
A possible mode in which eligible governed signals are contributed voluntarily in exchange for a benefit, preserving the chain of authority and consent, eligibility, minimisation, contribution, acknowledgement and lineage, with enterprises and governments able to prohibit contribution outright.
AN UNDECIDED OWNER DECISION, AND NEVER SILENT COLLECTION. Contribution must be explicitly understood by the person contributing, the product must not depend on it, and no privacy property may be claimed that measurement has not established.
Agent trust interoperability, and incident reconstruction over existing primitives.
Continuity of a personal account across browser, device, account and local state, with its policies, receipts, evidence, runtime state and recovery.
Household membership, shared and family policies, shared evidence, guardian and dependent patterns, delegated authority within a household, and the privacy boundaries between its members.
ONLY IF VERIFAIER ME DEMONSTRATES DEMAND, RETENTION AND VALUE.
An iOS and Android presence for personal governance and approvals.
ONLY IF ACQUISITION, RETENTION, APPROVAL WORKFLOWS OR PERSONAL GOVERNANCE ECONOMICS JUSTIFY IT. No store is required because another store was used.
A local application for Windows, macOS and Linux.
ONLY IF RUNTIME COVERAGE, PERSONAL, DEVELOPER OR LOCAL ENFORCEMENT VALUE JUSTIFIES IT.
Consumer packaging, personal integrations and connectors, and a consumer marketplace.
CONDITIONAL, AND DOWNSTREAM OF A MEASURED PERSONAL MOTION.
Publishing the extension through the store rather than as an unpacked install, which requires a developer account, artwork and listing assets.
AN UNDECIDED OWNER DECISION. It blocks nothing else and is sequenced independently.
A personal agent runtime with supervision, approval chains, permission policies and continuous protection, for assistants that act rather than answer.
NOT AVAILABLE TODAY AND NOT A COMMITMENT. VerifAIer Me is an audit and control product, not an agent runtime.
Wider language and framework coverage than the current interfaces provide.
DEFERRED. Both official SDKs were retired deliberately, and breadth is rebuilt on demand rather than restored on principle.
Genuine zero-knowledge proof machinery over evidence, distinct from the architectural selective disclosure that exists today.
DEFERRED BY THE OWNER. It requires material enterprise, government or regulatory demand, strategic differentiation, and specialist external cryptographic engineering.
An annual rate for Professional.
DEFERRED BY THE OWNER UNTIL REAL CONVERSION, RETENTION, CHURN AND WILLINGNESS-TO-PAY EVIDENCE EXISTS.
Monetisation of VerifAIer Me.
DEFERRED BY THE OWNER. Free for launch is not free forever, and any future price must be led by measured activation, usage, retention, governed-action behaviour and willingness to pay.
Pricing that follows adapters, estate size, governed agents and systems, governed actions, receipts, policies, interface usage, runtime calls or evidence volume.
DEFERRED BY THE OWNER UNTIL REAL CUSTOMER AND USAGE EVIDENCE EXISTS. THIS DEFERS PRICING, NEVER MEASUREMENT: every one of those is still measured wherever the product already measures it.
Conditional. Each row states the evidence that would promote it.
Read it, then check it.
Every claim in this document is one the product publishes elsewhere and measures somewhere. The fastest way to test that is to run the thing.
