Skip to content
VerifAIer
Product Dossier

The whole product, stated at its limits.

Every capability below is measured, and every one of them travels with the boundary of the claim. Parts I to XII describe what exists in the current build. Part XIII is the road ahead, and nothing in it is available today.

How to read thisWhat am I looking at?

Two vocabularies, and one rule about tense.

Every capability in this document carries two labels and one sentence. The labels answer different questions and neither is carried by colour.

Does it exist
Available today: AVAILABLE
The capability exists in the current build and can be used today.
Planned, and not built yet: PLANNED
It does not exist yet and is intended. Part XIII says under what conditions.
Not declared yet: PENDING
Partly present, or present with a boundary wide enough that availability would be the wrong word. The bound beside it says which.
How you get it
Available Now
Implemented, tested, ships in the current build.
Pilot
Works, and requires an unpacked install, direct access or a pilot arrangement.
Coming Soon
Designed and scoped, and not yet reachable.
Roadmap
Designed and not implemented.
The two rules this document is bound by

The bound. Every capability below is followed by the boundary of its claim. That sentence is not a disclaimer bolted on afterwards; it is part of the claim, it comes from the same measurement, and a capability recorded without one cannot be published at all.

The tense rule. Parts I to XII are written in the present tense and describe the current build. Part XIII is written about the future and nothing in it is available today. The two are separate parts rather than separately styled paragraphs, so no reader has to infer which they are in.

Part IWhy does this exist?

Executive overview

The problem, the category, and what VerifAIer is.

AI systems are moving from answering questions to taking actions. The question stops being whether the answer was good and becomes whether the action was allowed, and whether anyone can show that afterwards.

The premise

Access is not authority.

A model with an API key can call it. That is capability. Whether it was permitted to call it, for this principal, under this policy, at this moment, is a different question, and most AI estates have no component that answers it. Handing an agent a credential is not the same as granting it authority, and the gap between the two is where consequential mistakes live.

The requirement

Governance has to work in three tenses.

Before an action, something has to decide whether it may proceed. During it, a person may have to be asked, and the answer has to bind to that exact action rather than to the category it belongs to. After it, the decision has to be recoverable by someone who was not there. A product that only does the third one is a log.

The shape of the problem

The estate is heterogeneous, and it will stay that way.

Organisations do not run one model from one vendor through one framework. They run several, they change them, and the assistants individuals use are not the ones their employer chose. A governance layer that belongs to one vendor governs one vendor, which is why this one is built as an independent layer with a vendor-neutral contract at its boundary.

The thesis

One infrastructure, four audiences.

VerifAIer Me, Developers and AI Builders, Enterprise, and Government and Sovereign are personas and products over ONE platform: one authority model, one evidence model, one governance capability set. They have distinct front doors. They do not have distinct product truth, and no surface may claim a capability because its audience would value it.

The differentiation is the chain, not any single link
A tool that does one slice: Records what a model said
What is attempted here: Decides whether an action may run, then records the decision and the outcome
A tool that does one slice: Logs, in the application's own format
What is attempted here: Sealed, tenant-scoped, append-only evidence that joins on canonical identities
A tool that does one slice: Shows a dashboard derived from the log
What is attempted here: Re-derives the governance decision from its own recorded derivation
A tool that does one slice: Is specific to one vendor or one framework
What is attempted here: Sits behind a vendor-neutral adapter contract, with coverage stated adapter by adapter

Most products implement a slice of identity, authority, policy, preventive control, approval, runtime, evidence, receipts, re-derivation, reconstruction, memory governance and trust. The claim here is the attempt at COHERENCE across all of them over a heterogeneous estate, and it is a claim only to the extent the parts below measure it. No comparative superiority is asserted against any named product.

Part IIWhat is actually built?

VerifAIer today

The current product state, capability by capability.

The current build, in the numbers it publishesevery figure is measured, none is a target
10governed action paths
0unintercepted paths
8canonical action kinds
8 of 12action families preventable
8 of 8of those, posture-selectable
32receipt kinds
12durable evidence stores
11of them append-only
14reconstruction subjects
6 of 8supported families reconstruct fully
2governance adapters
7 of 8highest measured coverage level
10named environments at level 0
14MCP tools, 5 of which act
52command-line commands
608HTTP API routes
Note

A number goes stale loudly and an adjective does not, which is why this document counts. Ten governed paths is a coverage statement and not a modest way of saying comprehensive: the boundary is in Part V, and the complete list of every material capability with its own status is in Part XII.

Governed, before the fact
Ten action paths are evaluated before execution and none is unintercepted. A refusal means the action did not run.
Recorded, whatever the outcome
Refusals are recorded as fully as successes. A governed operation that was denied leaves the same class of evidence as one that proceeded.
Re-derivable, not merely stored
The governance decision re-derives from its own recorded derivation. What does not replay, and is never claimed to, is the model's generation.
Local before it is hosted
The command line governs with no account, no organization and no server, and still produces a receipt. Everything else is built on that path.
Part IIIWhich of these is me?

The four experiences

Personal, Developers and AI Builders, Enterprise, Government and Sovereign.

The same authority model, the same evidence model and the same governance capability set underneath all four. What differs is the surface, the vocabulary and the scale, not the truth.

Personal

VerifAIer Me

SEE what your assistants did with your data, CONTROL what they may do, APPROVE the actions that need you, and PROVE afterwards what happened. Personal disclosure and deletion are governed action kinds, and every outcome including a refusal leaves an owner-bound record.

The bound

Eight of sixteen personal capabilities are enforceable today. The browser overlay observes and does not block. A Personal owner is still placed in a manufactured organization as its administrator, and that is disclosed rather than hidden.

Open the personal surface
Developers and AI Builders

In your editor and your pipeline

A command line with fifty-two top-level commands, an HTTP API of six hundred and eight routes with a published machine contract, and an MCP server of fourteen tools of which the five that start a program are governed and fail closed. Governing a repository needs no account and no server.

The bound

Both official SDKs were retired deliberately. Nothing is published to PyPI or npm. On a local stdio surface the acting agent has no identity to record, which is measured as impossible rather than reported as missing.

Open the developers and ai builders surface
Enterprise

Across an estate and its people

Tenancy with tenant-scoped evidence, three roles, invitations and seat metering; policy authored, versioned, immutable once published, assigned and activated; ALLOW, ASK and BLOCK on ten governed paths; sealed evidence across twelve durable stores; re-derivation of the decision; and revocation enforced at decision time.

The bound

The policy grammar is presence and equality, plus one exact monetary ceiling that no producer in this build can satisfy, so a ceiling refuses every action on an unestablished fact; there is no budget and no spend accumulator. Two adapters exist and ten named environments sit at level zero. Single sign-on does not exist and has no enforcement point.

Open the enterprise surface
Government and Sovereign

Inside your own perimeter

The same self-hosted software running inside the operator's perimeter, verifiable with the network off, with the deployment posture and the policy packs the government surface names. It is a persona, a solution motion and a deployment posture over the Enterprise container.

The bound

IT IS NOT A FOURTH COMMERCIAL TIER, and there is no Government or Sovereign plan. No accreditation, certification, regulatory approval or sovereign certification exists, and none is claimed. Sovereign means the same software inside your perimeter and nothing more.

Open the government and sovereign surface
Note

One infrastructure does not mean identical exposure. A capability that is enforced on a governed server path is not thereby enforced in a browser overlay, and a capability present for an Enterprise tenant is not thereby present for a Personal owner. Part V states the enforcement boundary and Part XII states each capability's own.

VerifAIer MeAvailable today: AVAILABLE Available Now

See, control, approve and prove what an AI did with your data. Personal disclosure and deletion are governed action kinds, decisions are ALLOW, ASK or BLOCK, and every outcome including a refusal leaves an owner-bound record.

The bound

EIGHT OF SIXTEEN personal capabilities are enforceable today. Three are representable with no interception, three are future and two do not apply. The Pill observes and does not block. A Personal owner is still placed in a manufactured organization as its administrator, which is a known open defect and is disclosed rather than navigated around.

The Sentinel browser extensionAvailable today: AVAILABLE Available Now

A Manifest V3 Chrome extension that audits AI platform sessions locally, produces local Session Marker and Memory Marker artifacts, and ships a local receipt viewer that reads only the extension's own storage.

The bound

INSTALLED UNPACKED. It is not on the Chrome Web Store, submission is an undecided Owner question, and the extension declares no host permission for any VerifAIer origin, so it cannot talk to a backend. GATE CONV-F renamed Session Marker and Memory Marker from "Flight Recorder" and "Memory Receipts": each hashes PAGE METADATA ONLY (hostname, tab id, a timestamp) and captures no content, and the earlier names collided with the real, server-verified features of the same name.

The authenticated web applicationAvailable today: AVAILABLE Available Now

The governance workspace where the loop actually runs, over real data: onboarding, assessment, policy and governance, evidence, receipts, installation, developer and personal surfaces.

The bound

This is a different surface from both the local receipt viewer and the Control Center demonstration, and confusing them is the most likely way to mis-read this product.

The Control CenterNot declared yet: PENDING Pilot

An enterprise review workspace with executive and administrative views.

The bound

DEMONSTRATION MODE, MOCK DATA ONLY. Live data integration does not exist and requires a backend synchronisation layer that has not been built.

Developer surfacesAvailable today: AVAILABLE Available Now

A command line with fifty-two top-level commands, an HTTP API of six hundred and eight routes with a machine-readable contract, and a developer surface inside the authenticated workspace.

The bound

BOTH OFFICIAL SDKS ARE RETIRED and were withdrawn deliberately; use the HTTP API or the command line. Nothing is published to PyPI or npm, so installation is from a checkout.

AI coding governanceNot declared yet: PENDING Pilot

Coding-agent sessions are governed and recorded through command-line hooks and a local server.

The bound

Available with pilot access, and hook-based rather than automatic.

Local governance without an accountAvailable today: AVAILABLE Available Now

The command line governs locally with no account, no organization and no server, and still produces a receipt.

The bound

A command-line receipt is NOT independently self-verifying. Verification offers proofs, readiness tokens and attestation manifests, and none of those is the same object as a check receipt.

The public siteAvailable today: AVAILABLE Available Now

The site you are reading, generated rather than hand-written, so its navigation, its footer and its sitemap cannot come to disagree about what exists. This document is part of it, and is itself generated from the same record the product's readiness is measured against.

The bound

Ninety-two pages from nine canonical generators. This dossier is one of them, and GATE DOSSIER-1 RE-DERIVES it against CERTIFIED truth, not merely measured truth: CERT-1 completed Investor Ready certification over six personas and the investor demo, and Gate 13 completed pre-production certification. FULL PRODUCTION ACTIVATION AND PUBLIC LAUNCH ARE NOT CERTIFIED: no application instance runs, and full regression and final hardening have not run. No accreditation of any kind exists for any persona, and none is claimed. These four facts are never merged into one sentence.

Part IVHow does it actually work?

How the infrastructure works

The lifecycle, and the six distinctions it depends on.

The lifecycle of one governed action
IDENTIFY · Who is asking
An authenticated human session, cookie-first, resolved to a principal and to the organization that principal belongs to. On a local MCP surface the acting agent's identity is recorded as UNSTATED, because there is none to read.
AUTHORIZE · What permits it
An activated policy assignment evaluated at the boundary. Authority is not a role and not a credential: an unassigned policy governs nothing, and a credential that reaches no governed surface confers nothing.
DECIDE · ALLOW, ASK or BLOCK
One canonical derivation, in one vocabulary, recorded once. Every surface that shows the decision reads that record rather than computing a second answer.
APPROVE · When a person must answer
The approval binds to the exact action by a fingerprint computed from the same values the next statement passes to the executor. A changed action does not match its approval and is refused.
EXECUTE · Or not
A refusal means the action never ran. This is the difference between a preventive boundary and an observer that reports afterwards.
RECORD · Sealed, not logged
The decision and its outcome are sealed, tenant-scoped and written to append-only stores, and a receipt is issued. Refusals are recorded as fully as successes.
RE-DERIVE · The decision, not the generation
The governance decision re-derives from its own recorded derivation, and a mismatch is reported as a mismatch. The model's generation does not replay.
RECONSTRUCT · What the artifacts can establish
Fourteen subjects. Six of eight supported families reconstruct completely; two are partial and NAME THE STEPS THEY CANNOT ANSWER.
UNDERSTAND · Posture over observed facts
Compliance, risk and quality composed deterministically into one explainable posture, where unobserved input returns unknown rather than zero.

Nine stages, and the list is short because a stage is here only where the implementation supports what drawing it would imply. There is no discovery stage: VerifAIer does not enumerate an estate it was not told about, and Part XI says so rather than leaving the gap for a reader to find.

Six distinctions this product refuses to collapseeach one is a claim boundary, not a nuance
Not this: Capability
This: Authority. Being able to call something is not being permitted to. Authority comes from an activated policy evaluated at the boundary, not from holding a credential.
Not this: Observation
This: Enforcement. The browser overlay observes and records. Ten server-side paths enforce. Nothing here treats the first as evidence of the second.
Not this: Logging
This: Evidence. Evidence is sealed, tenant-scoped, append-only, and joins on canonical identities. A log does none of those four things.
Not this: Evidence
This: A verifiable receipt. Thirty-two receipt kinds verify integrity. A command-line check receipt is NOT independently self-verifying, and verification offers different objects: proofs, readiness tokens and attestation manifests.
Not this: Replay
This: Re-derivation. What re-derives is the governance decision, from its recorded derivation. The model's generation is not replayed and must never be described as replayable.
Not this: Reconstruction
This: Guaranteed historical truth. Reconstruction reports what canonical artifacts can establish AND names what they cannot. A partial reconstruction is published as partial, with its missing steps listed by name.

Every one of these pairs has an inner and an outer term, and the difference between a defensible claim and an indefensible one is almost always which of the two was published.

Part VWhat can it actually stop?

Preventive governance and coverage

What is evaluated before it runs, and where the boundary ends.

The diagram is true for the paths that have an adapter or a seam. It is not a claim about every action in an estate, and this part exists to say exactly where it stops being true.

The boundary, where it exists
An agent acts
  • A model, an assistant
  • A coding agent
  • A pipeline or a service
The governance boundary
  • Identify, authorize
  • ALLOW, ASK or BLOCK
  • Seal the decision
The consequence
  • A tool runs
  • Or it does not
  • Either way it is recorded

Seventeen surfaces were classified. Ten are governed, and none of the remainder is left unclassified: each one is named, with the reason it is not an action boundary.

Class
How many
What it means
GOVERNED
How many10 paths
What it meansEvaluated before execution, can require approval, can block, fails closed. The validation pipeline, the provider router, three governed endpoints, the MCP tool surface, personal export, personal deletion, outbound contribution, and outbound message delivery.
OPERATOR_LOCAL
How many2 surfaces
What it meansCommand-line audit commands and event export run under the operator's own authority on the operator's own machine. They are not an action boundary and are not counted as governed.
ACCOUNT_ADMINISTRATION
How many1 surface
What it meansVerifAIer's own billing: an organization administrator creating a customer or starting or cancelling a subscription. It is authorised by tenancy and the administrator role, it is not an AI agent spending money, and it is not counted as governed.
NOT_AN_ACTION_BOUNDARY
How many1 surface
What it meansThe personal runtime itself, whose governed operations are counted where they occur rather than a second time here.
OUT_OF_SCOPE
How many3 subsystems
What it meansReplay and closure, the trust, risk, quality and compliance engines, and the code simulator. These read and score; they do not authorise actions.
OBSERVATION ONLY
How manythe Pill
What it meansThe browser overlay does not evaluate before execution, cannot require approval and cannot block. It observes and records, and no coverage claim is derived from it.
Where the boundary is structural

Three things cannot be governed, and the reason is structural.

Files, payments and memory have NO ACTION PRODUCER. VerifAIer cannot propose those actions, so no policy can govern them. This is reported by the product rather than left as an inference, because an unproduceable action is a permanent boundary and not a backlog item.

Bypassability, stated honestly

Governance is attached by deployment.

An installation that assigned no policy runs exactly as it did before. A record showing that an action was not governed means NOBODY LOOKED, not that somebody allowed it, and the product distinguishes the two rather than reporting an ungoverned action as a permitted one.

AI estate, adoption and valueAvailable today: AVAILABLE Available Now

A tenant-scoped inventory of the AI an organisation has actually been observed using, derived from the governed actions VerifAIer already holds evidence for, with adoption over an explicit window and a value determination beside every asset. What was REGISTERED and what was OBSERVED are two different facts and are never merged.

The bound

THIS IS NOT DISCOVERY, and the limitation this product already publishes is unchanged: nothing scans a network, a cloud account, an identity provider or a model gateway, so AI an organisation runs outside a governed seam does not appear. Three of twelve action families name an AI asset. BUSINESS VALUE IS REPORTED AS NOT DETERMINABLE for every asset, because no evidence record in this build carries a business outcome; no ROI, monetary figure or productivity percentage is published, and usage is never equated with value. No owner and no department is inferred, because neither has a producer. Call volume is not derivable and is published as not derivable.

The preventive governance boundaryAvailable today: AVAILABLE Available Now

A governed action path is evaluated BEFORE it executes. The decision is ALLOW, ASK or BLOCK, it is derived once from an activated policy, and a refusal means the action never ran rather than that it ran and was noted afterwards.

The bound

Ten governed paths, never described as universal. Governance is attached by deployment: an installation that assigned no policy runs exactly as it did before, and the record says nobody looked rather than that somebody allowed it.

Action interception and governed action kindsAvailable today: AVAILABLE Available Now

Ten action paths are governed and none is unintercepted. The product can propose eight canonical action kinds, stated by seven named producers at eight governed seams, and an operator may author policy for exactly those.

The bound

FILES, PAYMENTS AND MEMORY have NO action producer. VerifAIer cannot propose those actions, so no policy can govern them, and the product reports that rather than implying coverage it does not have. EMAIL IS NO LONGER AMONG THEM: it is governed end to end, and this sentence asserted the opposite until the product was measured rather than believed.

Human approval, bound to the exact actionAvailable today: AVAILABLE Available Now

A policy can require a person to answer before an action proceeds. The answer is bound to that action by a fingerprint computed from the same values the next statement passes to the executor.

The bound

An approval does not generalise. A changed action does not match its approval and is refused, which is what closes the gap between asking and acting.

Policy authoring, versioning and activationAvailable today: AVAILABLE Available Now

Policy is authored, versioned, immutable once published, assigned and activated. Activation is what makes a rule bind; an unassigned policy governs nothing.

The bound

The policy grammar is PRESENCE AND EQUALITY ONLY. There are no thresholds, no roles, no times and no agent identities in it. A rule requiring a fact refuses every action today because no producer supplies one, which is measured fail-closed and is reported as such by the product itself.

Runtime protection and revocationAvailable today: AVAILABLE Available Now

Standing is checked at decision time rather than at sign-in. A revoked user stops being able to act on the next governed action, not on the next session.

The bound

Enforced for human principals. A machine credential returns no standing, and a revoked one would be indistinguishable from a live one, so revocation is not claimed for machines.

MCP tool governanceAvailable today: AVAILABLE Available Now

The MCP server exposes fourteen tools. Five of them start a program on the machine, and all five pass through the same preventive boundary as every other governed path, failing closed.

The bound

Five of fourteen. Never all agent tool calls, and never all MCP servers: this is VerifAIer's own MCP surface governed, not a claim about other people's.

The browser audit and the Pill overlayAvailable today: AVAILABLE Available Now

A governance scan runs locally on four AI platforms, and the Pill renders what it found as a visual overlay on the page.

The bound

IT OBSERVES AND RECORDS. IT DOES NOT INTERCEPT OR BLOCK. Preventive enforcement lives on the ten governed paths and not in the browser overlay.

Governed outbound messageAvailable today: AVAILABLE Available Now

Sending an email is a governed action. The message is authorised at one choke point before it leaves, and the invitation that carries organization membership passes through the same preventive boundary as every other governed path.

The bound

THE RECIPIENT IS GOVERNED AT DOMAIN GRAIN, which is the finest an equality-only policy grammar can act on. A policy refusal RAISES rather than being recorded as a delivery failure, because reporting our decision as their server's fault is a refusal the operator never learns about.

Preventive policy baselinesAvailable today: AVAILABLE Available Now

Three selectable postures - Safe Defaults, Enterprise and Sovereign - that an operator assigns to an organization instead of authoring a policy from nothing. A baseline is an ordinary catalog entry deployed through the ordinary activation path.

The bound

THESE ARE NOT THE TRUST POLICY PACKS. Those judge change-sets and a compliance posture, and not one line of them can produce an ALLOW, an ASK or a BLOCK on a proposed action. A baseline that requires an identified principal REFUSES the local tool surface, and the product reports that before activation rather than discovering it at runtime.

What the coverage numbers meanAvailable today: AVAILABLE Available Now

Two metrics the product computes about itself. GOVERNED ACTION COVERAGE is 8 of 12 consequential action families that can be prevented before the consequence. DEPLOYABLE POLICY COVERAGE is 8 of 8 of those preventable families for which a shipped posture can be selected rather than authored.

The bound

NEITHER IS A FRACTION OF EVERY ACTION AN AI AGENT COULD TAKE; no product can enumerate that set. Every family deferred for want of a producer STAYS IN THE DENOMINATOR, so the first number rises only by governing one. The second names its split and never merges it: six families through an operator's tenant baseline, two through a VerifAIer Me owner's own settings, which no tenant baseline reaches.

Part VIWhat can it prove?

Evidence and proof

Seals, receipts, replay, re-derivation and reconstruction.

Why this is stronger than keeping logs
Sealed at the point of decision
The seal binds a decision to the principal and to the action it was derived for, and it verifies afterwards.
Append-only, and enumerated
Twelve durable stores, eleven append-only, listed by the product itself and self-checking rather than described in a document.
Joined on canonical identities
Evidence from different surfaces about one operation joins, because they share identifiers rather than each keeping their own record.
Re-derivable by someone who was not there
The decision is recomputed from its recorded derivation. This is the difference between keeping a record and being able to defend it.

No cryptographic claim beyond integrity is made anywhere in this document. There is no zero-knowledge proof system, no chain submission, no smart contract and no external notary. What exists is content integrity, deterministic re-derivation and reconstruction that names its own gaps.

The canonical governance decisionAvailable today: AVAILABLE Available Now

One derivation, one vocabulary, recorded once. Every surface that shows a decision is reading the same record rather than computing its own.

The bound

One vocabulary means one authority. A second engine deriving a second answer is refused by construction, not by convention.

The Evidence SealAvailable today: AVAILABLE Available Now

Every governed decision is sealed and the seal verifies. The seal binds the decision to the principal and to the action it was derived for.

The bound

Integrity, not authorship. A seal proves the record was not altered after it was written; it is not a signature by an external authority.

Deterministic replay and re-derivationAvailable today: AVAILABLE Available Now

The GOVERNANCE DECISION re-derives from its own recorded derivation. Given the record, the same inputs produce the same decision, and a mismatch is reported as a mismatch rather than smoothed away.

The bound

THE MODEL'S GENERATION DOES NOT REPLAY AND IS NEVER CLAIMED TO. What re-derives is the decision about the action, not the text the model produced.

Reconstruction over fourteen subjectsAvailable today: AVAILABLE Available Now

Reconstruction answers what happened from canonical artifacts. Six of eight supported governed operation families reconstruct completely; two are partial. It is reachable over the authenticated HTTP API only, not on the SDK, the CLI or MCP.

The bound

The two partial families NAME THE STEPS THEY CANNOT ANSWER. One of them can never answer who acted, because a local stdio MCP surface has no identity to record, and that is permanent rather than pending.

Durable evidence storesAvailable today: AVAILABLE Available Now

Twelve durable stores, eleven of them append-only, enumerated by the product itself and self-checking. Evidence is tenant-scoped and joins on canonical identities.

The bound

RETENTION IS NOT DECIDED FOR ANY STORE. That is an open Owner decision and a privacy and production dependency, not an engineering gap.

Flight RecorderAvailable today: AVAILABLE Available Now

A session-level record of what a coding agent did, produced by the command line with three hooks wired, and read in the workspace under Evidence, as its own sub-surface.

The bound

Installed from a checkout, not from a package index. The command line is not published to PyPI. GATE CONV-F found the browser extension's own popup mode of this name FABRICATED and renamed it; the extension does not produce a Flight Recorder artifact of any kind. The real feature is produced from the command line and read in the workspace; it is not a second product plane.

Memory ReceiptsAvailable today: AVAILABLE Available Now

Sealing binds a time to a content digest. Any edit to the content breaks the seal, and checking it is a local operation that needs nothing from us.

The bound

CONTENT INTEGRITY, AND NOTHING MORE. A receipt proves the bytes are unaltered since sealing. It says nothing about what a model retained, reused or was affected by, and no such attribution exists in the product. GATE CONV-F found the browser extension's own popup mode of this name FABRICATED and renamed it; the extension does not produce a Memory Receipt of any kind, and the real feature is CLI-only.

Memory governanceNot declared yet: PENDING Roadmap

Deleting personal records is a governed action with an immutable owner-bound record of the outcome, including refusals. That much is enforced today.

The bound

WHAT MAY BE REMEMBERED, RETENTION AND PURPOSE ARE REPRESENTABLE AND NOT ENFORCEABLE. Memory read and write interception is not implemented, and there is NO EVIDENCE LINKING A REMEMBERED ITEM TO A DECISION: no such attribution exists and none may be claimed.

The lineage layerAvailable today: AVAILABLE Available Now

A deterministic lineage graph across Flight Recorder sessions and Memory Receipts, available from the command line.

The bound

Deterministic linkage, with no AI inference anywhere in it. It joins records; it does not interpret them.

Deep governance auditAvailable today: AVAILABLE Available Now

A public in-browser audit surface that accepts a pasted session transcript and runs entirely on the reader's own machine.

The bound

It runs on pre-computed data in the browser. It is a demonstration surface, not the governed runtime.

Selective disclosureAvailable today: AVAILABLE Available Now

Evidence can be disclosed selectively, so a reader can be given the field they are entitled to without being given the record around it.

The bound

THIS IS ARCHITECTURAL SELECTIVE DISCLOSURE, NOT CRYPTOGRAPHIC ZERO KNOWLEDGE. It must never be presented as a zero-knowledge proof system.

External anchoringPlanned, and not built yet: PLANNED Roadmap

The evidence layer is anchoring-ready: a proof identifier is sixty-four characters of calldata, which needs no smart contract to submit.

The bound

NOTHING IS ANCHORED. No chain submission happens, and no smart contract is required by the design or deployed by the product.

Incident reconstructionAvailable today: AVAILABLE Available Now

One answer to what happened, assembled from canonical artifacts: which principal acted, what authority existed, what policy applied, whether approval was required, what executed, and whether the decision re-derives. It is reachable from the command line and over the API.

The bound

A READ OVER ARTIFACTS THAT ALREADY EXIST, not a second architecture and not a second opinion. It names the relations that produced nothing rather than returning a tidy story, and a request whose tenant cannot be resolved is REFUSED rather than served unscoped.

Part VIIWho acted, and who said they could?

Identity, authority and trust

Who acts, what authorises it, and what trust is derived from.

Authenticated identity and asserted identity are different things, and nothing in this product describes self-declared metadata as an authenticated identity.

Authority, as measured
What identifies the principal
An authenticated human session, cookie-first, resolved to a person and then to their organization.
What identifies the acting agent
On a local MCP surface, NOTHING. It is recorded as unstated, and that is permanent for a local stdio surface rather than pending.
What establishes authority
An activated policy assignment evaluated at the boundary. Not a role, and not the possession of a credential.
Whether revocation is enforced
Yes for human principals, checked at decision time. NOT for machine credentials, and that capability is therefore not claimed.
Whether a tenant mismatch is caught
Yes. The principal's organization is compared against the runtime's, and identified is kept distinct from verified.
AuthenticationAvailable today: AVAILABLE Available Now

Email and password with cookie-first sessions for the web application. The local command line needs no account at all.

The bound

NOT OAUTH, NOT OIDC, NOT SSO AND NOT MFA. None of those exists in this build, and single sign-on has no enforcement point anywhere in the product.

Tenancy, roles and membershipAvailable today: AVAILABLE Available Now

Every user belongs to an organization and evidence is tenant-scoped. Three roles, invitations, member management and role assignment all ship.

The bound

Three roles and no more: administrator, analyst, viewer. Tenant identification is not tenant verification, and the product keeps those two words apart.

Machine credentials and agent identityNot declared yet: PENDING Pilot

A real revocable, organization-scoped, key-derived machine credential exists and can be issued and revoked.

The bound

IT IS A CREDENTIAL, NOT A GOVERNANCE PRINCIPAL, and it has no consumer in the governance path. On a local MCP surface the acting agent's identity is MEASURED IMPOSSIBLE rather than merely absent, and the product records it as unstated instead of inventing one.

Historical membershipNot declared yet: PENDING Roadmap

Asking whether somebody was a member at a past moment is a question the product answers explicitly rather than silently.

The bound

It answers UNPROVABLE. The membership table cannot record an interval by construction, and reporting that is the truthful answer rather than a gap.

Agent PassportAvailable today: AVAILABLE Available Now

A deterministic, content-derived, portable trust document composed from an identity and a trust profile, with a lifecycle: it can be registered, suspended, reinstated, revoked or left to expire, and verified.

The bound

THE LIFECYCLE IS THE DOCUMENT'S, NOT THE AGENT'S. Revoking a passport withdraws a disclosure and never a principal: it stops no agent from acting, and the preventive engine cannot read it. Verification is AUTHENTICATED and tenant-scoped, it evaluates no authority, and a standing passport is not permission to do anything. NO EXTERNAL IDENTITY FRAMEWORK IS INTEGRATED, no cross-organization trust decision is reachable end to end, and THERE IS NO AGENT TRUST NETWORK.

Trust IntelligenceAvailable today: AVAILABLE Available Now

Deterministic scoring over observed facts, composed into one explainable posture across compliance, risk and quality.

The bound

THE WEIGHTS ARE CALIBRATION, NOT MEASUREMENT. Unobserved input returns unknown rather than zero, because missing evidence is not the same as a good result.

Accreditation and certificationNot declared yet: PENDING Roadmap

The product publishes its own absence of accreditation rather than staying silent about it.

The bound

NO GOVERNMENT, SOVEREIGN, REGULATORY OR COMPLIANCE CERTIFICATION EXISTS. Nothing here is certified, accredited or approved by anyone.

Part VIIIHow independent is it?

Cross-model, cross-agent, cross-vendor

Architectural independence, and the integration coverage that exists today.

Dimension
What is true
What is NOT true
Cross-model
What is trueThe provider layer is vendor-neutral by construction: one router, one governed seam, a deterministic offline default, and live use gated three ways. GOVERNANCE DOES NOT DEPEND ON WHICH MODEL IS CALLED.
What is NOT trueThat every model is integrated or certified.
Cross-agent
What is trueTwo adapters exist and both reach the preventive boundary: outbound email at a measured level seven of eight, and MCP at six. MCP is an open protocol, so any MCP-speaking client traverses the same governed seam.
What is NOT trueThat arbitrary agents are governed. Ten named environments sit at level zero.
Cross-vendor
What is trueThe adapter contract is vendor-neutral and the boundary primitives are shared across all four audiences.
What is NOT trueThat any named vendor is adapted. Ten are recorded at level zero BY NAME.
Note

The honest formulation, and the one the product already uses: ARCHITECTURAL COMPATIBILITY IS NOT CERTIFIED INTEGRATION. VerifAIer does not claim to govern an environment it has no measured adapter for, and the adapter report states the level rather than the intention.

The governance adapter contractAvailable today: AVAILABLE Available Now

A vendor-neutral adapter contract, with a coverage maturity computed from measurements that already ran rather than declared by hand.

The bound

A CONTRACT AND TWO ADAPTERS, both reaching the preventive boundary: outbound email at level seven of eight and MCP at six. Ten named third-party environments are recorded BY NAME AT LEVEL ZERO. Architectural compatibility is not certified integration.

The MCP serverAvailable today: AVAILABLE Available Now

Fourteen tools over local stdio, speaking an open protocol, so any MCP-capable client traverses the same governed seam.

The bound

Five of the fourteen start a program and are governed. The other nine read.

The WIW contribution boundaryAvailable today: AVAILABLE Available Now

A governed artifact can be authorised, minimised, sealed and sent over a real socket to an independently governed external node, which admits it under its own law and acknowledges it with a lineage identifier that links back.

The bound

THE RECEIVER LEARNS NOTHING. The embedding is empty. There is no shared model training, no shared verdict across installations, and no network effect. Sender identity is NOT independently verified, and with the node unreachable the product stays fully operable. Refusal is fail-closed: no authority means zero network calls.

Part IXWhere does it run?

Deployment and data boundaries

Where it runs, and what each posture is certified for.

Four words are kept apart here: architecturally supported, implemented, tested, and production-certified. Only the last one is a promise about running a business on it, and NOTHING IS PRODUCTION-CERTIFIED YET.

Posture
Implemented and tested
Production-certified
Local command line, no account
Implemented and testedYes
Production-certifiedNot applicable. This is the local path.
Self-hosted server
Implemented and testedYes
Production-certifiedNO. Hardening and production activation are still ahead of it.
Hosted
Implemented and testedCode ready, and tested
Production-certifiedNO. The public site has a production origin, DNS and HTTPS; no application instance is running behind it.
Customer cloud, private, sovereign
Implemented and testedYes, the same self-hosted path
Production-certifiedNO.
Air-gapped
Implemented and testedYes, a bundle per engagement
Production-certifiedNO, and only partially tested.
Extension, local only
Implemented and testedYes
Production-certifiedNot applicable.
Extension to backend synchronisation
Implemented and testedNO, it does not exist
Production-certifiedNot applicable. No host permission is declared for any VerifAIer origin.
Note

The evidence layer is verifiable offline. An assessment requires no outbound call, and a sovereign deployment is the same software inside the operator's perimeter, which is the entire claim and the whole of it.

Local and self-hostedAvailable today: AVAILABLE Available Now

Install from a checkout and run the server. This is the path everything else is built on, and it needs no account and no network.

The bound

IMPLEMENTED AND TESTED, NOT PRODUCTION-CERTIFIED. Hardening and production activation are still ahead of it.

HostedPlanned, and not built yet: PLANNED Coming Soon

The hosted control plane is canonical IN ADDITION TO self-hosted, and its code is ready.

The bound

NO APPLICATION IS HOSTED ANYWHERE. The public site has a real origin, DNS and HTTPS; the product behind it does not. Sign-in, the workspace and the API return 404 on that origin by design, because no instance is running. The deployment manifest, entrypoint and configuration schema exist and are reproducible; what is missing is a hosting account, which is an Owner action rather than engineering. There is nothing to sign up for today.

Inside your own perimeterNot declared yet: PENDING Pilot

Enterprise, private, sovereign and air-gapped deployments are the SAME self-hosted software running inside the operator's own perimeter, verifiable with the network off.

The bound

SOVEREIGN MEANS THE SAME SOFTWARE INSIDE YOUR PERIMETER AND NOTHING MORE. There is no accreditation, no national dashboard and no separate sovereign build. Air-gapped installation is a bundle provided per engagement and is only partially tested.

Extension distributionAvailable today: AVAILABLE Available Now

The extension installs unpacked, from a documented procedure, today.

The bound

Chrome Web Store publication has not been decided or submitted, and no store listing exists.

Extension to backend synchronisationNot declared yet: PENDING Roadmap

Whether the browser extension can send what it records to a server.

The bound

IT CANNOT, AND THE REASON IS STRUCTURAL: the extension declares no host permission for any VerifAIer origin. Extension data stays on the machine.

The database underneath a deploymentNot declared yet: PENDING Coming Soon

The runtime is implemented and certified against a real PostgreSQL 16, with tenancy, authority, policy, decisions, evidence and reconstruction re-certified across it rather than assumed. A populated database is backed up, restored to a disposable location, reopened and READ BACK.

The bound

NINE STATUSES HERE ARE NOT SYNONYMS. The runtime being certified is not a service being provisioned: NO MANAGED POSTGRESQL SERVICE IS PROVISIONED, CUTOVER HAS NOT STARTED, and POINT-IN-TIME RECOVERY IS NOT CLAIMED. The hosted posture still reports SQLite as what it runs, and provider-side snapshots and their retention remain an Owner action.

Part XHow is it sold?

Commercial architecture

Three tiers, one sales-led container, and what is not priced.

Three commercial tiers, not four
Community
Free. The local path needs no account at all.
Professional
Per user, per month, seat metered from real active memberships. The figure is published on the pricing page and is stated in exactly one place on this site.
Enterprise
Sales-led, by custom commercial proposal, with no published number. Government and sovereign programmes are a persona and a posture over this container.
Note

This part explains the commercial architecture to the depth an evaluation needs and no further. It is not a pricing page, and it deliberately does not restate a figure that another page owns.

Three tiersAvailable today: AVAILABLE Available Now

Community, Professional and Enterprise, with entitlements resolved per organization. Professional carries a published per-user monthly price.

The bound

THREE COMMERCIAL TIERS, NOT FOUR. The Professional number is published on the pricing page and is deliberately not restated here, because one page owning a price is how a price stays correct.

Seat meteringAvailable today: AVAILABLE Available Now

Billable seats are counted from real active memberships, independently of privilege level, and that count is what a subscription quantity follows.

The bound

Only Professional is seat metered. Pending invitations are not seats and machine keys are not seats.

PaymentNot declared yet: PENDING Pilot

The payment path is implemented and verified against a sandbox, including the seat quantity synchronisation.

The bound

NOTHING CAN BE BOUGHT FROM A RUNNING DEPLOYMENT TODAY. Live billing is not activated: no live account, product, price, webhook or customer portal exists, quota enforcement is advisory and unwired, and neither invoicing nor a licence server exists.

Enterprise and sovereign commercial motionAvailable today: AVAILABLE Available Now

Enterprise is SALES-LED with a custom commercial proposal. A proposal is scoped from estate size, governed agents and systems, environments, usage, deployment model, isolation, support, service levels, sovereignty requirements and services. Government and sovereign programmes are a persona, a motion and a deployment posture over the Enterprise container. An operator grant path exists to deliver an entitlement once a contract is signed.

The bound

THOSE ARE VARIABLES, NOT A FORMULA. No minimum, floor, list price or per-seat Enterprise rate is published, and none may be derived from them. There is no Government or Sovereign PLAN. The grant path is an operator tool on the host, not a checkout, and it CANNOT ISSUE A PERMANENT GRANT.

Annual pricingNot declared yet: PENDING Roadmap

Whether Professional is offered annually.

The bound

NOT OFFERED AT LAUNCH. There is no public or self-service annual rate and no discount, and the seeded development fixture is not a price. Individually negotiated multi-year Enterprise terms are unaffected and create no catalog price.

The VerifAIer Me commercial postureAvailable today: AVAILABLE Available Now

VerifAIer Me is FREE FOR LAUNCH. No personal paid tier exists and none was invented.

The bound

FREE FOR LAUNCH, NOT FREE FOREVER. Whether Personal is ever priced is deferred to measured activation, usage, retention and willingness to pay.

Usage meteringNot declared yet: PENDING Roadmap

The product MEASURES adapter count, estate size, governed agents and systems, governed actions, receipt volume, policy volume, API usage, runtime calls and evidence volume wherever it already measures them.

The bound

NONE OF IT IS BILLED. Nothing is metered commercially, no included quota exists and no overage price exists. MEASURED, NOT PRICED.

Part XIWhat is it not?

Current limitations and coverage boundaries

Published because an evaluator needs them, not despite it.

This part is here because an evaluator who finds a limitation themselves stops believing the rest of the document. Every item below is drawn from the same measurement as the capabilities above it.

Runtime coverage is not universal
Ten governed paths. Files, payments and memory cannot be governed at all because nothing can propose them as actions. Coverage grows adapter by adapter.
Spend cannot be limited
A policy can refuse an action whose declared maximum charge is above what it authorises, and NOTHING IN THIS BUILD DECLARES ONE, so such a rule refuses every action for want of the fact rather than for a figure. There is no budget, no running total of spend and no price. A refusal prevents an economic consequence; a permission does not cap one, because no executor here accepts a ceiling and no call can be stopped in flight.
The browser overlay does not enforce
It observes and records on four AI platforms. It cannot intercept and cannot block, and no enforcement claim is derived from it.
There is no estate discovery
VerifAIer governs what it is connected to. It does not enumerate the AI systems in an organisation that it was not told about.
Integration breadth is two adapters
Outbound email at level seven of eight and MCP at six. Ten named third-party environments are recorded at level zero by name, and architectural compatibility is not integration.
Machine principals are not governed
A revocable machine credential exists and has no consumer in the governance path. It is a credential, never a principal, and revocation is not claimed for it.
Agent identity on a local surface is impossible, not missing
On a local stdio MCP surface there is no identity to read. It is recorded as unstated, and one reconstruction family can never become complete for that reason.
Agent Passport is a document, not a credential
A passport can be registered, suspended, revoked or left to expire, and is verified through an authenticated, tenant-scoped API, but it is a disclosure document and never a principal, and verification evaluates no authority. No external identity scheme is integrated. A trust decision exists as a foundation and is bound to no runtime decision. THERE IS NO AGENT TRUST NETWORK.
A memory cannot be tied to a decision
Memory Receipts are content integrity. Nothing here establishes that a remembered item affected an action, and read and write interception is not implemented.
Personal governance is partial
Eight of sixteen personal capabilities are enforceable. A Personal owner is still placed in a manufactured organization as its administrator, which is an open data-model question rather than a rendering defect.
Evidence retention is undecided
Twelve durable stores, and no retention decision for any of them. It is an open question with privacy and production consequences.
Nothing is production-certified
The public site has a production origin, DNS and HTTPS, and NO APPLICATION INSTANCE RUNS BEHIND IT. The PostgreSQL runtime is certified and backup, restore and a recovery drill are done, but NO MANAGED DATABASE SERVICE IS PROVISIONED, cutover has not started and point-in-time recovery is not claimed. Hardening and adversarial certification have not run.
Nothing can be bought
The payment path is implemented and sandbox-verified. Live billing is not activated, quota enforcement is advisory and unwired, and neither invoicing nor a licence server exists.
Single sign-on does not exist
Email and password with cookie-first sessions. No OAuth, OIDC, SSO or MFA, and single sign-on has no enforcement point in the product.
Nothing is accredited
No government, sovereign, regulatory or compliance certification exists, and the government surface publishes that absence rather than staying silent.
The distribution surface is narrow
The extension installs unpacked and is not on the Chrome Web Store. The command line installs from a checkout and is not on PyPI. Both official SDKs were retired.
The contribution boundary is narrow on purpose
A governed artifact reaches an independently governed external node and is admitted under that node's law. THE RECEIVER LEARNS NOTHING, sender identity is not independently verified, and no network effect exists.
Note

None of these is a defect discovered by a reader. Each is published by the product's own reports, and several of them are permanent rather than pending: an action nothing can propose cannot become governable, and an identity that does not exist on a surface cannot be recorded from it.

Part XIIIs anything missing?

Capability index

Every material capability, with its status and its bound.

Part III · The four experiences9 areas
Capability
Status
What is true, and its bound
VerifAIer Me
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundSee, control, approve and prove what an AI did with your data. Personal disclosure and deletion are governed action kinds, decisions are ALLOW, ASK or BLOCK, and every outcome including a refusal leaves an owner-bound record. EIGHT OF SIXTEEN personal capabilities are enforceable today. Three are representable with no interception, three are future and two do not apply. The Pill observes and does not block. A Personal owner is still placed in a manufactured organization as its administrator, which is a known open defect and is disclosed rather than navigated around.
The Sentinel browser extension
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA Manifest V3 Chrome extension that audits AI platform sessions locally, produces local Session Marker and Memory Marker artifacts, and ships a local receipt viewer that reads only the extension's own storage. INSTALLED UNPACKED. It is not on the Chrome Web Store, submission is an undecided Owner question, and the extension declares no host permission for any VerifAIer origin, so it cannot talk to a backend. GATE CONV-F renamed Session Marker and Memory Marker from "Flight Recorder" and "Memory Receipts": each hashes PAGE METADATA ONLY (hostname, tab id, a timestamp) and captures no content, and the earlier names collided with the real, server-verified features of the same name.
The authenticated web application
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundThe governance workspace where the loop actually runs, over real data: onboarding, assessment, policy and governance, evidence, receipts, installation, developer and personal surfaces. This is a different surface from both the local receipt viewer and the Control Center demonstration, and confusing them is the most likely way to mis-read this product.
The Control Center
StatusNot declared yet: PENDING Pilot
What is true, and its boundAn enterprise review workspace with executive and administrative views. DEMONSTRATION MODE, MOCK DATA ONLY. Live data integration does not exist and requires a backend synchronisation layer that has not been built.
Developer surfaces
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA command line with fifty-two top-level commands, an HTTP API of six hundred and eight routes with a machine-readable contract, and a developer surface inside the authenticated workspace. BOTH OFFICIAL SDKS ARE RETIRED and were withdrawn deliberately; use the HTTP API or the command line. Nothing is published to PyPI or npm, so installation is from a checkout.
AI coding governance
StatusNot declared yet: PENDING Pilot
What is true, and its boundCoding-agent sessions are governed and recorded through command-line hooks and a local server. Available with pilot access, and hook-based rather than automatic.
Local governance without an account
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundThe command line governs locally with no account, no organization and no server, and still produces a receipt. A command-line receipt is NOT independently self-verifying. Verification offers proofs, readiness tokens and attestation manifests, and none of those is the same object as a check receipt.
The public site
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundThe site you are reading, generated rather than hand-written, so its navigation, its footer and its sitemap cannot come to disagree about what exists. This document is part of it, and is itself generated from the same record the product's readiness is measured against. Ninety-two pages from nine canonical generators. This dossier is one of them, and GATE DOSSIER-1 RE-DERIVES it against CERTIFIED truth, not merely measured truth: CERT-1 completed Investor Ready certification over six personas and the investor demo, and Gate 13 completed pre-production certification. FULL PRODUCTION ACTIVATION AND PUBLIC LAUNCH ARE NOT CERTIFIED: no application instance runs, and full regression and final hardening have not run. No accreditation of any kind exists for any persona, and none is claimed. These four facts are never merged into one sentence.
Personal recommended settings
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA VerifAIer Me owner moves all eight enforceable settings from no rule at all to a governed posture in ONE STEP. The preview is what they agree to, each row states what it would change and why, and applying it writes ordinary permission records to the owner's own store. NOTHING IS APPLIED ON ANYONE'S BEHALF. An owner who never presses keeps no rule everywhere, a stale preview is refused, the batch is all-or-nothing, and BLOCK remains settable on every row. The set invents no number: no window, no amount, no limit.
Part V · Preventive governance and coverage11 areas
Capability
Status
What is true, and its bound
AI estate, adoption and value
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA tenant-scoped inventory of the AI an organisation has actually been observed using, derived from the governed actions VerifAIer already holds evidence for, with adoption over an explicit window and a value determination beside every asset. What was REGISTERED and what was OBSERVED are two different facts and are never merged. THIS IS NOT DISCOVERY, and the limitation this product already publishes is unchanged: nothing scans a network, a cloud account, an identity provider or a model gateway, so AI an organisation runs outside a governed seam does not appear. Three of twelve action families name an AI asset. BUSINESS VALUE IS REPORTED AS NOT DETERMINABLE for every asset, because no evidence record in this build carries a business outcome; no ROI, monetary figure or productivity percentage is published, and usage is never equated with value. No owner and no department is inferred, because neither has a producer. Call volume is not derivable and is published as not derivable.
The preventive governance boundary
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA governed action path is evaluated BEFORE it executes. The decision is ALLOW, ASK or BLOCK, it is derived once from an activated policy, and a refusal means the action never ran rather than that it ran and was noted afterwards. Ten governed paths, never described as universal. Governance is attached by deployment: an installation that assigned no policy runs exactly as it did before, and the record says nobody looked rather than that somebody allowed it.
Action interception and governed action kinds
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundTen action paths are governed and none is unintercepted. The product can propose eight canonical action kinds, stated by seven named producers at eight governed seams, and an operator may author policy for exactly those. FILES, PAYMENTS AND MEMORY have NO action producer. VerifAIer cannot propose those actions, so no policy can govern them, and the product reports that rather than implying coverage it does not have. EMAIL IS NO LONGER AMONG THEM: it is governed end to end, and this sentence asserted the opposite until the product was measured rather than believed.
Human approval, bound to the exact action
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA policy can require a person to answer before an action proceeds. The answer is bound to that action by a fingerprint computed from the same values the next statement passes to the executor. An approval does not generalise. A changed action does not match its approval and is refused, which is what closes the gap between asking and acting.
Policy authoring, versioning and activation
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundPolicy is authored, versioned, immutable once published, assigned and activated. Activation is what makes a rule bind; an unassigned policy governs nothing. The policy grammar is PRESENCE AND EQUALITY ONLY. There are no thresholds, no roles, no times and no agent identities in it. A rule requiring a fact refuses every action today because no producer supplies one, which is measured fail-closed and is reported as such by the product itself.
Runtime protection and revocation
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundStanding is checked at decision time rather than at sign-in. A revoked user stops being able to act on the next governed action, not on the next session. Enforced for human principals. A machine credential returns no standing, and a revoked one would be indistinguishable from a live one, so revocation is not claimed for machines.
MCP tool governance
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundThe MCP server exposes fourteen tools. Five of them start a program on the machine, and all five pass through the same preventive boundary as every other governed path, failing closed. Five of fourteen. Never all agent tool calls, and never all MCP servers: this is VerifAIer's own MCP surface governed, not a claim about other people's.
The browser audit and the Pill overlay
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA governance scan runs locally on four AI platforms, and the Pill renders what it found as a visual overlay on the page. IT OBSERVES AND RECORDS. IT DOES NOT INTERCEPT OR BLOCK. Preventive enforcement lives on the ten governed paths and not in the browser overlay.
Governed outbound message
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundSending an email is a governed action. The message is authorised at one choke point before it leaves, and the invitation that carries organization membership passes through the same preventive boundary as every other governed path. THE RECIPIENT IS GOVERNED AT DOMAIN GRAIN, which is the finest an equality-only policy grammar can act on. A policy refusal RAISES rather than being recorded as a delivery failure, because reporting our decision as their server's fault is a refusal the operator never learns about.
Preventive policy baselines
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundThree selectable postures - Safe Defaults, Enterprise and Sovereign - that an operator assigns to an organization instead of authoring a policy from nothing. A baseline is an ordinary catalog entry deployed through the ordinary activation path. THESE ARE NOT THE TRUST POLICY PACKS. Those judge change-sets and a compliance posture, and not one line of them can produce an ALLOW, an ASK or a BLOCK on a proposed action. A baseline that requires an identified principal REFUSES the local tool surface, and the product reports that before activation rather than discovering it at runtime.
What the coverage numbers mean
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundTwo metrics the product computes about itself. GOVERNED ACTION COVERAGE is 8 of 12 consequential action families that can be prevented before the consequence. DEPLOYABLE POLICY COVERAGE is 8 of 8 of those preventable families for which a shipped posture can be selected rather than authored. NEITHER IS A FRACTION OF EVERY ACTION AN AI AGENT COULD TAKE; no product can enumerate that set. Every family deferred for want of a producer STAYS IN THE DENOMINATOR, so the first number rises only by governing one. The second names its split and never merges it: six families through an operator's tenant baseline, two through a VerifAIer Me owner's own settings, which no tenant baseline reaches.
Part VI · Evidence and proof13 areas
Capability
Status
What is true, and its bound
The canonical governance decision
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundOne derivation, one vocabulary, recorded once. Every surface that shows a decision is reading the same record rather than computing its own. One vocabulary means one authority. A second engine deriving a second answer is refused by construction, not by convention.
The Evidence Seal
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundEvery governed decision is sealed and the seal verifies. The seal binds the decision to the principal and to the action it was derived for. Integrity, not authorship. A seal proves the record was not altered after it was written; it is not a signature by an external authority.
Deterministic replay and re-derivation
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundThe GOVERNANCE DECISION re-derives from its own recorded derivation. Given the record, the same inputs produce the same decision, and a mismatch is reported as a mismatch rather than smoothed away. THE MODEL'S GENERATION DOES NOT REPLAY AND IS NEVER CLAIMED TO. What re-derives is the decision about the action, not the text the model produced.
Reconstruction over fourteen subjects
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundReconstruction answers what happened from canonical artifacts. Six of eight supported governed operation families reconstruct completely; two are partial. It is reachable over the authenticated HTTP API only, not on the SDK, the CLI or MCP. The two partial families NAME THE STEPS THEY CANNOT ANSWER. One of them can never answer who acted, because a local stdio MCP surface has no identity to record, and that is permanent rather than pending.
Durable evidence stores
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundTwelve durable stores, eleven of them append-only, enumerated by the product itself and self-checking. Evidence is tenant-scoped and joins on canonical identities. RETENTION IS NOT DECIDED FOR ANY STORE. That is an open Owner decision and a privacy and production dependency, not an engineering gap.
Flight Recorder
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA session-level record of what a coding agent did, produced by the command line with three hooks wired, and read in the workspace under Evidence, as its own sub-surface. Installed from a checkout, not from a package index. The command line is not published to PyPI. GATE CONV-F found the browser extension's own popup mode of this name FABRICATED and renamed it; the extension does not produce a Flight Recorder artifact of any kind. The real feature is produced from the command line and read in the workspace; it is not a second product plane.
Memory Receipts
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundSealing binds a time to a content digest. Any edit to the content breaks the seal, and checking it is a local operation that needs nothing from us. CONTENT INTEGRITY, AND NOTHING MORE. A receipt proves the bytes are unaltered since sealing. It says nothing about what a model retained, reused or was affected by, and no such attribution exists in the product. GATE CONV-F found the browser extension's own popup mode of this name FABRICATED and renamed it; the extension does not produce a Memory Receipt of any kind, and the real feature is CLI-only.
Memory governance
StatusNot declared yet: PENDING Roadmap
What is true, and its boundDeleting personal records is a governed action with an immutable owner-bound record of the outcome, including refusals. That much is enforced today. WHAT MAY BE REMEMBERED, RETENTION AND PURPOSE ARE REPRESENTABLE AND NOT ENFORCEABLE. Memory read and write interception is not implemented, and there is NO EVIDENCE LINKING A REMEMBERED ITEM TO A DECISION: no such attribution exists and none may be claimed.
The lineage layer
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA deterministic lineage graph across Flight Recorder sessions and Memory Receipts, available from the command line. Deterministic linkage, with no AI inference anywhere in it. It joins records; it does not interpret them.
Deep governance audit
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA public in-browser audit surface that accepts a pasted session transcript and runs entirely on the reader's own machine. It runs on pre-computed data in the browser. It is a demonstration surface, not the governed runtime.
Selective disclosure
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundEvidence can be disclosed selectively, so a reader can be given the field they are entitled to without being given the record around it. THIS IS ARCHITECTURAL SELECTIVE DISCLOSURE, NOT CRYPTOGRAPHIC ZERO KNOWLEDGE. It must never be presented as a zero-knowledge proof system.
External anchoring
StatusPlanned, and not built yet: PLANNED Roadmap
What is true, and its boundThe evidence layer is anchoring-ready: a proof identifier is sixty-four characters of calldata, which needs no smart contract to submit. NOTHING IS ANCHORED. No chain submission happens, and no smart contract is required by the design or deployed by the product.
Incident reconstruction
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundOne answer to what happened, assembled from canonical artifacts: which principal acted, what authority existed, what policy applied, whether approval was required, what executed, and whether the decision re-derives. It is reachable from the command line and over the API. A READ OVER ARTIFACTS THAT ALREADY EXIST, not a second architecture and not a second opinion. It names the relations that produced nothing rather than returning a tidy story, and a request whose tenant cannot be resolved is REFUSED rather than served unscoped.
Part VII · Identity, authority and trust7 areas
Capability
Status
What is true, and its bound
Authentication
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundEmail and password with cookie-first sessions for the web application. The local command line needs no account at all. NOT OAUTH, NOT OIDC, NOT SSO AND NOT MFA. None of those exists in this build, and single sign-on has no enforcement point anywhere in the product.
Tenancy, roles and membership
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundEvery user belongs to an organization and evidence is tenant-scoped. Three roles, invitations, member management and role assignment all ship. Three roles and no more: administrator, analyst, viewer. Tenant identification is not tenant verification, and the product keeps those two words apart.
Machine credentials and agent identity
StatusNot declared yet: PENDING Pilot
What is true, and its boundA real revocable, organization-scoped, key-derived machine credential exists and can be issued and revoked. IT IS A CREDENTIAL, NOT A GOVERNANCE PRINCIPAL, and it has no consumer in the governance path. On a local MCP surface the acting agent's identity is MEASURED IMPOSSIBLE rather than merely absent, and the product records it as unstated instead of inventing one.
Historical membership
StatusNot declared yet: PENDING Roadmap
What is true, and its boundAsking whether somebody was a member at a past moment is a question the product answers explicitly rather than silently. It answers UNPROVABLE. The membership table cannot record an interval by construction, and reporting that is the truthful answer rather than a gap.
Agent Passport
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA deterministic, content-derived, portable trust document composed from an identity and a trust profile, with a lifecycle: it can be registered, suspended, reinstated, revoked or left to expire, and verified. THE LIFECYCLE IS THE DOCUMENT'S, NOT THE AGENT'S. Revoking a passport withdraws a disclosure and never a principal: it stops no agent from acting, and the preventive engine cannot read it. Verification is AUTHENTICATED and tenant-scoped, it evaluates no authority, and a standing passport is not permission to do anything. NO EXTERNAL IDENTITY FRAMEWORK IS INTEGRATED, no cross-organization trust decision is reachable end to end, and THERE IS NO AGENT TRUST NETWORK.
Trust Intelligence
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundDeterministic scoring over observed facts, composed into one explainable posture across compliance, risk and quality. THE WEIGHTS ARE CALIBRATION, NOT MEASUREMENT. Unobserved input returns unknown rather than zero, because missing evidence is not the same as a good result.
Accreditation and certification
StatusNot declared yet: PENDING Roadmap
What is true, and its boundThe product publishes its own absence of accreditation rather than staying silent about it. NO GOVERNMENT, SOVEREIGN, REGULATORY OR COMPLIANCE CERTIFICATION EXISTS. Nothing here is certified, accredited or approved by anyone.
Part VIII · Cross-model, cross-agent, cross-vendor3 areas
Capability
Status
What is true, and its bound
The governance adapter contract
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA vendor-neutral adapter contract, with a coverage maturity computed from measurements that already ran rather than declared by hand. A CONTRACT AND TWO ADAPTERS, both reaching the preventive boundary: outbound email at level seven of eight and MCP at six. Ten named third-party environments are recorded BY NAME AT LEVEL ZERO. Architectural compatibility is not certified integration.
The MCP server
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundFourteen tools over local stdio, speaking an open protocol, so any MCP-capable client traverses the same governed seam. Five of the fourteen start a program and are governed. The other nine read.
The WIW contribution boundary
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundA governed artifact can be authorised, minimised, sealed and sent over a real socket to an independently governed external node, which admits it under its own law and acknowledges it with a lineage identifier that links back. THE RECEIVER LEARNS NOTHING. The embedding is empty. There is no shared model training, no shared verdict across installations, and no network effect. Sender identity is NOT independently verified, and with the node unreachable the product stays fully operable. Refusal is fail-closed: no authority means zero network calls.
Part IX · Deployment and data boundaries6 areas
Capability
Status
What is true, and its bound
Local and self-hosted
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundInstall from a checkout and run the server. This is the path everything else is built on, and it needs no account and no network. IMPLEMENTED AND TESTED, NOT PRODUCTION-CERTIFIED. Hardening and production activation are still ahead of it.
Hosted
StatusPlanned, and not built yet: PLANNED Coming Soon
What is true, and its boundThe hosted control plane is canonical IN ADDITION TO self-hosted, and its code is ready. NO APPLICATION IS HOSTED ANYWHERE. The public site has a real origin, DNS and HTTPS; the product behind it does not. Sign-in, the workspace and the API return 404 on that origin by design, because no instance is running. The deployment manifest, entrypoint and configuration schema exist and are reproducible; what is missing is a hosting account, which is an Owner action rather than engineering. There is nothing to sign up for today.
Inside your own perimeter
StatusNot declared yet: PENDING Pilot
What is true, and its boundEnterprise, private, sovereign and air-gapped deployments are the SAME self-hosted software running inside the operator's own perimeter, verifiable with the network off. SOVEREIGN MEANS THE SAME SOFTWARE INSIDE YOUR PERIMETER AND NOTHING MORE. There is no accreditation, no national dashboard and no separate sovereign build. Air-gapped installation is a bundle provided per engagement and is only partially tested.
Extension distribution
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundThe extension installs unpacked, from a documented procedure, today. Chrome Web Store publication has not been decided or submitted, and no store listing exists.
Extension to backend synchronisation
StatusNot declared yet: PENDING Roadmap
What is true, and its boundWhether the browser extension can send what it records to a server. IT CANNOT, AND THE REASON IS STRUCTURAL: the extension declares no host permission for any VerifAIer origin. Extension data stays on the machine.
The database underneath a deployment
StatusNot declared yet: PENDING Coming Soon
What is true, and its boundThe runtime is implemented and certified against a real PostgreSQL 16, with tenancy, authority, policy, decisions, evidence and reconstruction re-certified across it rather than assumed. A populated database is backed up, restored to a disposable location, reopened and READ BACK. NINE STATUSES HERE ARE NOT SYNONYMS. The runtime being certified is not a service being provisioned: NO MANAGED POSTGRESQL SERVICE IS PROVISIONED, CUTOVER HAS NOT STARTED, and POINT-IN-TIME RECOVERY IS NOT CLAIMED. The hosted posture still reports SQLite as what it runs, and provider-side snapshots and their retention remain an Owner action.
Part X · Commercial architecture7 areas
Capability
Status
What is true, and its bound
Three tiers
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundCommunity, Professional and Enterprise, with entitlements resolved per organization. Professional carries a published per-user monthly price. THREE COMMERCIAL TIERS, NOT FOUR. The Professional number is published on the pricing page and is deliberately not restated here, because one page owning a price is how a price stays correct.
Seat metering
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundBillable seats are counted from real active memberships, independently of privilege level, and that count is what a subscription quantity follows. Only Professional is seat metered. Pending invitations are not seats and machine keys are not seats.
Payment
StatusNot declared yet: PENDING Pilot
What is true, and its boundThe payment path is implemented and verified against a sandbox, including the seat quantity synchronisation. NOTHING CAN BE BOUGHT FROM A RUNNING DEPLOYMENT TODAY. Live billing is not activated: no live account, product, price, webhook or customer portal exists, quota enforcement is advisory and unwired, and neither invoicing nor a licence server exists.
Enterprise and sovereign commercial motion
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundEnterprise is SALES-LED with a custom commercial proposal. A proposal is scoped from estate size, governed agents and systems, environments, usage, deployment model, isolation, support, service levels, sovereignty requirements and services. Government and sovereign programmes are a persona, a motion and a deployment posture over the Enterprise container. An operator grant path exists to deliver an entitlement once a contract is signed. THOSE ARE VARIABLES, NOT A FORMULA. No minimum, floor, list price or per-seat Enterprise rate is published, and none may be derived from them. There is no Government or Sovereign PLAN. The grant path is an operator tool on the host, not a checkout, and it CANNOT ISSUE A PERMANENT GRANT.
Annual pricing
StatusNot declared yet: PENDING Roadmap
What is true, and its boundWhether Professional is offered annually. NOT OFFERED AT LAUNCH. There is no public or self-service annual rate and no discount, and the seeded development fixture is not a price. Individually negotiated multi-year Enterprise terms are unaffected and create no catalog price.
The VerifAIer Me commercial posture
StatusAvailable today: AVAILABLE Available Now
What is true, and its boundVerifAIer Me is FREE FOR LAUNCH. No personal paid tier exists and none was invented. FREE FOR LAUNCH, NOT FREE FOREVER. Whether Personal is ever priced is deferred to measured activation, usage, retention and willingness to pay.
Usage metering
StatusNot declared yet: PENDING Roadmap
What is true, and its boundThe product MEASURES adapter count, estate size, governed agents and systems, governed actions, receipt volume, policy volume, API usage, runtime calls and evidence volume wherever it already measures them. NONE OF IT IS BILLED. Nothing is metered commercially, no included quota exists and no overage price exists. MEASURED, NOT PRICED.
Note

56 capability areas, grouped by the part that explains them. This index is GENERATED from the same record the product's readiness is measured against, reconciled in both directions: a capability the product gains and this page omits fails a guard, and so does a capability this page names that the record does not carry. It cannot be shortened for editorial convenience.

Part XIIIWhere is this going?

The road ahead

Planned, in development and conditional. Nothing in this part is available today.

This part PRESENTS the canonical roadmap. It is not a second roadmap: every area below names the canonical section it comes from, and one that named nothing could not be published here.

The rule this part is read under

Nothing in this part is available today. Sequence is stated and calendar dates are not, because no date is approved and an invented one is a commitment nobody made. A row marked CONDITIONAL carries the evidence that would promote it, and until that evidence exists the row is an option rather than a plan.

Horizon 1 · Full launch and operate ready25 areas · 8 conditional
Final hardeningPLANNED

HARD-1 CLOSED over the PRE-EXPANSION product: fail-closed semantics, bypass prevention, tampering and concurrency validation, stale approvals and stale policies, timeout and degraded-mode behaviour, a clean install, and a security review. What remains forward is the SAME class of hardening run again, over the product this amendment expanded: final security, adversarial, privacy and tenancy hardening, after Feature Freeze and before Full Launch + Operate Ready certification.

Hosting, domain, DNS and HTTPSPLANNED

A running application instance. The public site is served from a real origin over HTTPS, and the canonical origin is now declared once in the product rather than in a build script -- but no APPLICATION is hosted, which is what makes the hosted posture unavailable rather than untested. The manifest and the environment schema are written; the hosting account is not.

Production database: managed PostgreSQL, backups and restorePLANNED

THE RUNTIME IS CERTIFIED; THE MANAGED SERVICE IS NOT, AND THE TWO ARE NOT SYNONYMS. LF-1, LF-2 and LF-3 certified the PostgreSQL 16 runtime, its schema, migration, backup, restore and a recovery drill for the self-hosted path - a populated database is backed up, restored into a disposable location, reopened and READ BACK, because a file that exists is not a database anyone can serve from - and Part IX states that. What remains forward, and IS REQUIRED PRODUCTION HARDENING BEFORE FULL LAUNCH rather than an option held open: PROVISIONING A MANAGED POSTGRESQL SERVICE for the hosted posture, which still runs SQLite in write-ahead logging on a persistent volume behind a single always-on instance today. Cutover has not started and point-in-time recovery is not claimed. The migration carries its own acceptance scope, and tenancy, authority, policy, runtime decisions, evidence, receipts and reconstruction are re-certified across it rather than assumed. Provider-side snapshots and their retention remain an Owner action.

Secrets, session hardening and cross-origin policyPLANNED

Production secret management. The cross-origin policy is now set against a real declared origin and a wildcard allow-list is refused in production -- the application will not start with one. What remains is the secrets themselves: generating, storing and rotating them is an operator act that no repository can perform for itself.

Observability, monitoring, alerts, rollback and runbooksPLANNED

Operational instrumentation, alerting, an incident runbook, a rollback path, and a decision on log retention alongside the evidence retention question.

The evidence retention decisionPLANNED

Retention is undecided for all twelve durable stores. It is an Owner decision with privacy and production consequences, and it is named here because a dossier that lists eleven append-only stores without it would be overstating.

Continuous integration, delivery and environment isolationPLANNED

Pipeline hardening and separation of environments, so a deployment is reproducible and a rollback is a routine action rather than an event.

Billing activationPLANNED

Live payment activation, webhooks, the customer portal, the subscription lifecycle including cancellation, seat quantity in production, and invoicing and tax where required. The path is implemented and sandbox-verified; activation is blocked behind hosting.

Account and communication activationPLANNED

Transactional email, password recovery, and persistence of assessment results so a returning account finds its own evidence. Each is a self-serve requirement rather than a pilot one.

Hosted and self-hosted copy reconciliationPLANNED

The public copy that currently denies a hosted tier has to change on the day hosting exists, and it is sequenced first because it is the cheapest and the most visibly wrong.

AI estate, adoption and value intelligenceCONDITIONAL

AEV-1 ALREADY DELIVERS the base of this: a tenant-scoped estate derived from governed-action evidence, published in Part V as the current `ai-estate` capability. What remains forward is everything that base measurement explicitly could not determine - relating an asset to a real business outcome, an owner or a department it was never given a producer for, and coverage across the nine action families that name no AI asset today - so that adoption, redundancy and value can be reasoned about rather than guessed, beyond what is guessed against already.

The condition

WHERE VALUE CANNOT BE DETERMINED FROM EVIDENCE, THE ANSWER IS NOT DETERMINABLE. Return on investment is never invented, business value is never inferred from activity, and usage is never equated with value. It also does not become estate discovery: VerifAIer still governs what it is connected to.

AI Cost Intelligence and the Cost ScoreCONDITIONAL

ECON-1 ALREADY DELIVERS a vocabulary, an admissibility rule and a refusal: four cost classes over ten evidence bases, none of which reaches OBSERVED in this build, and a published Cost Score CONTRACT with no Cost Score. It is BUILT and not claimable, because every cost is UNKNOWN. What remains forward is understanding what AI costs and judging how economically appropriate that cost appears to be, given evidence this build does not yet hold - across a response, a session and a task, and adapted to each audience rather than rendered identically for all of them.

The condition

FOUR COST CLASSES THAT MAY NOT BE COLLAPSED - OBSERVED, CALCULATED, ESTIMATED AND UNKNOWN. An estimate never becomes an actual, and an API-equivalent figure is not what a subscription user was actually charged. The score requires a published contract and confidence semantics BEFORE it computes anything, and no universal formula may be hardcoded to make a number appear.

Cost as a contextual browser surfaceCONDITIONAL

Whether the browser companion gains a fourth contextual mode beside Audit, Session Marker and Memory Marker, at whatever grain the surface can actually evidence.

The condition

THE SHIPPED EXTENSION HAS NO COST CAPABILITY AND CANNOT SEE A BILL. It declares no host permission for any VerifAIer origin. This row is conditional on the surface being technically able to carry the claim at all, and until then Cost is absent from the browser companion by construction.

Economic authority and spend governanceCONDITIONAL

Extending the distinction the product already enforces - ability to consume is not authority to spend - so that approved providers, model tiers, autonomous cost limits and budgets are governed before consequential spend, deciding ALLOW, ASK or BLOCK and, where appropriate, authorising a lower-cost routing class.

The condition

AUTHORISING A ROUTING CLASS IS A GOVERNANCE DECISION; PERFORMING THE ROUTING IS EXECUTION. VerifAIer does not become a model gateway or an inference provider. The grammar question this work had to answer first has been answered and the answer was no - presence and equality cannot carry a ceiling - so a single monetary rule kind exists and nothing in this build can yet state the fact it needs: every economic ceiling refuses on an unestablished fact. There is no budget, no spend accumulator and no payment producer, and a refusal prevents an economic consequence while a permission does not cap one.

Cost optimisation intelligenceCONDITIONAL

Identifying defensible waste - premium-model overuse, oversized or repeated context, retry loops, duplicate inference and retrieval, redundant agents and overlapping products - and proposing alternatives against a versioned pricing catalog that carries its own provenance and freshness.

The condition

A CHEAPER ALTERNATIVE IS NOT A RECOMMENDATION. Where only price is known the honest classification is CHEAPER CANDIDATE, NOT VALIDATED. Not every one of those wastes is observable today, and classifying which are was the first deliverable rather than an afterthought - and it has now been done. Seventeen inefficiency classes are classified against twenty pieces of evidence, each measured by a predicate that runs rather than by a label somebody typed, and NONE of the seventeen is derivable from what this build holds: the engine runs and returns NO DEFENSIBLE OPTIMISATION FINDING for every subject, with the missing evidence named. Suitability is evaluated BEFORE price - the function that decides it has no price parameter at all - across fourteen dimensions, six of which bind whatever a workload says, and none of the fourteen has a producer, so no candidate can reach VALIDATED SUITABLE and the word recommended is unreachable rather than merely unused. No saving is computed, because eight prerequisites must hold and a price delta is not one of them. The pricing catalog is still empty, and its emptiness now blocks three named classes rather than merely being stated.

Recommendation integrity, separate from commercial relationshipsCONDITIONAL

A product-integrity rule rather than a feature: a commercial relationship may never alter a cost score, a suitability score, a ranking, an estimated saving, a confidence value or a technical recommendation. A partner offer may be disclosed beside a candidate whose technical standing was derived without reference to it.

The condition

THE COMMERCIAL TERMS OF ANY SUCH PROGRAMME ARE AN UNDECIDED OWNER QUESTION, and no affiliate marketplace is designed or implied. The separation is now mechanical rather than promised in prose, and it is a SHAPE rather than a prohibition: the organic result is computed by functions that have no parameter a commercial relationship could enter, and a disclosure attaches to an ALREADY FINISHED result and carries it unchanged. There is no call site at which commercial data and an un-computed organic question exist together, so the contamination has no place to happen rather than a rule against happening. Nothing in this build records a commercial relationship of any kind - that is measured, not assumed - and NO product state was created to hold one.

Final product, experience and structure convergenceCONDITIONAL

CONV-F CLOSED, having re-audited the expanded product as ONE infrastructure: every audience, every surface, navigation, information architecture, terminology, responsiveness and accessibility, and the separation of what exists from what is planned. Its acceptance question was whether the expanded product was still intuitive, and the answer was one nav entry: `scg.flight` already existed as a canonical evidence producer and the deep link was the whole repair. It also found and renamed a naming collision - the browser extension's fabricated "Flight Recorder"/"Memory Receipts" popup modes, now Session Marker and Memory Marker.

The condition

DEFERRED: `api_gateway.js::buildAuditResponseEnvelope` defaults an absent extension confidence value to `0`, feeding no authority decision. It is left for a future gate that touches the extension's detection surface, and breadth is not answered by adding navigation items.

Final self-onboarding convergenceCONDITIONAL

ONB-F CLOSED, having re-derived onboarding from the completed product so that every entry intent - governing AI, governing agents, proving compliance, understanding an estate, understanding spend, developer integration, personal control - arrives at the same infrastructure rather than at a separate product. It found that the onboarding census's own anti-drift guarantee held for three of its four sources and not the fourth, and repaired the classification of two already-closed, already-governed routes rather than building a page. Truthful first value was preserved throughout: a person is never asked to configure a capability that does not exist.

The condition

TWO ITEMS NAMED BY THIS GATE ARE STILL FORWARD, FOR A FUTURE GATE WITH A NAMED DEMAND: `routing_inputs()` suggests `enterprise` for every self-signup account regardless of the form a person used, and a tenant-scoped MCP execution count was refused because no tenant-scoped enumeration contract exists anywhere on this platform. Neither is built, and neither is promised on a date.

Six-persona certificationPLANNED

CERT-1 CLOSED, having certified the end-to-end journeys rather than the units underneath them, once, over the pre-expansion product: Personal, Developer, Community, Professional, Enterprise and Government, each against the discover through decision-replay chain. Journey certification found defects that tens of thousands of unit tests did not, which is why it was a gate and not a review. What remains forward is re-running that same certification over the product this amendment expanded: AKP-2, PPB-1, IR-1, PRD-1, Agent Passport, trust protocol, the economics family, PGC-1, CONV-F, ONB-F and this dossier re-derivation.

Investor demo certificationPLANNED

CERT-1 CLOSED, having certified that the product could be demonstrated end to end from a real deployment, against the claims the dossier published at that baseline. What remains forward is the same certification re-run against the product that actually launches, as part of Full Launch + Operate Ready certification, over the claims THIS dossier publishes rather than the earlier one.

Dossier re-certification against certified truthPLANNED

TWO DOSSIER BASELINES EXIST, AND THEY ANSWER DIFFERENT QUESTIONS. The one published at SITE-1 was generated from MEASURED truth and named its own absence of certification. DOSSIER-1 RE-DERIVES the same two tables and the same generator against CERTIFIED truth - Investor Ready, certified by CERT-1 - and states what remains uncertified rather than restating the earlier sentence. The mechanism did not change; the baseline it is measured against did.

Public launchPLANNED

The point at which the product is publicly available rather than available to pilot partners, and the point after which the growth programme begins by default.

Agent Passport, beyond its own lifecyclePLANNED

Lifecycle, revocation and authenticated external verification SHIP. What remains forward is interoperability with identity frameworks this build does not implement, and cross-organization trust decisions: a passport carrying principal, issuer, provable model family where that is feasible, governance profile, tools, data class, action and financial limits, and policy, that a second organization can act on.

An agent trust protocolPLANNED

A vendor-neutral interoperability direction around identity, issuer, claims, authority, permissions, policy, revocation, evidence, trust outcome and receipt. A FOUNDATION EXISTS: a deterministic admissibility decision, by scheme, issuer, subject, purpose and instant, that keeps identity, trust and authority apart. It is bound to no runtime decision, exposes no route, stores no policy, and one identity scheme is implemented, VerifAIer's own. Runtime attestation is not implemented, and no external scheme is integrated.

The remaining path from the current state to public launch.

Horizon 2 · Growth and revenue7 areas · 3 conditional
A dedicated motion for Developers and AI BuildersPLANNED

A developer-specific acquisition surface, onboarding and self-service path, distributed through developer-native channels. Vendor neutrality is a product constraint here rather than a marketing preference: the motion may not collapse into governance for one model or one editor.

Developer discovery and willingness to payPLANNED

A discovery gate that runs BEFORE material paid acquisition, testing pain, urgency, comprehension, first value, willingness to pay, packaging and retention intent. It exists to stop the programme spending on a proposition nobody has confirmed wanting.

The bottom-up enterprise hypothesisCONDITIONAL

That an individual developer becomes a team, an engineering organization and eventually an enterprise contract, so developer adoption serves both direct revenue and distribution.

The condition

A HYPOTHESIS TO MEASURE, NOT A CLAIM. It may not appear as established fact until the growth programme's own measurement supports it.

A dedicated motion for VerifAIer MePLANNED

A consumer and prosumer acquisition surface, low-friction onboarding and distribution appropriate to the actual product format. Consumers are not given enterprise compliance language as their first proposition.

The bootstrap hypothesisCONDITIONAL

That Personal and Developer self-service revenue may arrive on a faster cycle than Enterprise and Government sales, and may help fund infrastructure, development and the longer sales cycle.

The condition

A STRATEGIC HYPOTHESIS, NOT A GUARANTEED OUTCOME AND NOT A FUNDING PLAN. It may not be presented as established until measurement supports it.

Segment-specific messaging over shared product truthPLANNED

Acquisition language may differ by segment. Every claim in every segment's language must still resolve to the same measured capability, and no marketing surface may invent a capability because another segment would value it.

Growth metricsCONDITIONAL

Acquisition, activation, time to first value, conversion, willingness to pay, retention, expansion and revenue contribution, each measured against a real baseline.

The condition

NO TARGET VALUES EXIST. Targets are set by that programme's own opening gate against real baselines, and none is published here.

Segmented acquisition, and two hypotheses recorded as hypotheses.

Horizon 3 · Coverage and ecosystem8 areas · 1 conditional
Governed action coveragePLANNED

The strategic metric is the proportion of relevant consequential AI actions actually governed. Coverage grows through controlled adapters in roughly this order: MCP, then software and HTTP interfaces, then coding agents, then the browser, then enterprise integrations, then the personal runtime, then additional frameworks. WHAT IS COVERED IS WHAT HAS AN ADAPTER.

Adapters for named environmentsPLANNED

Ten named third-party environments are recorded at level zero today. Each becomes claimable only when its own adapter is built and measured, one at a time and evidence-gated.

Policy and governance packsPLANNED

A signed and versioned pack format, with install, update, compatibility and rollback, and enterprise policy packs over it.

A governance marketplaceCONDITIONAL

A distribution surface for packs authored outside VerifAIer.

The condition

CONDITIONAL ON A REAL ECOSYSTEM. A marketplace without third-party authors is a directory of our own work, and it is not built before the ecosystem exists.

Enterprise integrations and connectorsPLANNED

Additional enterprise connectors, additional AI coding surfaces, and public interfaces broad enough for an estate rather than a repository.

Managed enterprise SentinelPLANNED

Signed policy packages, local enforcement, and selective evidence upstream, preserving the local-first and privacy characteristics wherever that is technically possible.

Deployment breadth, expanded on demandPLANNED

Multi-tenant, dedicated, private cloud, customer cloud, on-premises, sovereign and air-gapped targets, expanded as demand requires rather than pre-built.

Runtime memory governancePLANNED

Memory policies, permissions, lifecycle and audit, extending memory governance from integrity and deletion toward what may be remembered and why.

Governed action coverage, packs, and deployment breadth expanded on demand.

Horizon 4 · Platform moat5 areas · 4 conditional
Delegated authorityCONDITIONAL

Acting on behalf of another principal, with the delegation itself governed and recorded rather than assumed.

The condition

DEFERRED. No real executor flow requires it yet, and it is promoted when one does.

An agent trust ecosystemCONDITIONAL

The network in which passports issued by one party are meaningful to another.

The condition

REQUIRES EXTERNAL ADOPTION AND IS NOT A CAPABILITY WE CAN BUILD ALONE. Protocol implementation is not network effect, and a network is never claimed because code exists.

Incident reconstruction, widenedPLANNED

THE SURFACE ITSELF NOW EXISTS and has moved into the current product, where Part VI describes it. What remains here is breadth rather than existence: reconstruction over a population of related operations rather than one at a time, and over the families whose artifacts cannot yet answer every step.

Aggregate and multi-agent governanceCONDITIONAL

Governance that reasons about a population of agents rather than one action at a time.

The condition

DEFERRED. Aggregate and multi-agent ANALYSIS exists in the command line today; runtime governance of it is not required for the first version.

WIW Contributor ModeCONDITIONAL

A possible mode in which eligible governed signals are contributed voluntarily in exchange for a benefit, preserving the chain of authority and consent, eligibility, minimisation, contribution, acknowledgement and lineage, with enterprises and governments able to prohibit contribution outright.

The condition

AN UNDECIDED OWNER DECISION, AND NEVER SILENT COLLECTION. Contribution must be explicitly understood by the person contributing, the product must not depend on it, and no privacy property may be claimed that measurement has not established.

Agent trust interoperability, and incident reconstruction over existing primitives.

Horizon 5 · Market-validated expansion12 areas · 11 conditional
Personal continuityPLANNED

Continuity of a personal account across browser, device, account and local state, with its policies, receipts, evidence, runtime state and recovery.

Family and householdCONDITIONAL

Household membership, shared and family policies, shared evidence, guardian and dependent patterns, delegated authority within a household, and the privacy boundaries between its members.

The condition

ONLY IF VERIFAIER ME DEMONSTRATES DEMAND, RETENTION AND VALUE.

MobileCONDITIONAL

An iOS and Android presence for personal governance and approvals.

The condition

ONLY IF ACQUISITION, RETENTION, APPROVAL WORKFLOWS OR PERSONAL GOVERNANCE ECONOMICS JUSTIFY IT. No store is required because another store was used.

DesktopCONDITIONAL

A local application for Windows, macOS and Linux.

The condition

ONLY IF RUNTIME COVERAGE, PERSONAL, DEVELOPER OR LOCAL ENFORCEMENT VALUE JUSTIFIES IT.

Consumer ecosystem packagingCONDITIONAL

Consumer packaging, personal integrations and connectors, and a consumer marketplace.

The condition

CONDITIONAL, AND DOWNSTREAM OF A MEASURED PERSONAL MOTION.

Chrome Web Store publicationCONDITIONAL

Publishing the extension through the store rather than as an unpacked install, which requires a developer account, artwork and listing assets.

The condition

AN UNDECIDED OWNER DECISION. It blocks nothing else and is sequenced independently.

The personal agent eraCONDITIONAL

A personal agent runtime with supervision, approval chains, permission policies and continuous protection, for assistants that act rather than answer.

The condition

NOT AVAILABLE TODAY AND NOT A COMMITMENT. VerifAIer Me is an audit and control product, not an agent runtime.

Deeper interface and integration breadthCONDITIONAL

Wider language and framework coverage than the current interfaces provide.

The condition

DEFERRED. Both official SDKs were retired deliberately, and breadth is rebuilt on demand rather than restored on principle.

Cryptographic zero-knowledge proofsCONDITIONAL

Genuine zero-knowledge proof machinery over evidence, distinct from the architectural selective disclosure that exists today.

The condition

DEFERRED BY THE OWNER. It requires material enterprise, government or regulatory demand, strategic differentiation, and specialist external cryptographic engineering.

A public annual priceCONDITIONAL

An annual rate for Professional.

The condition

DEFERRED BY THE OWNER UNTIL REAL CONVERSION, RETENTION, CHURN AND WILLINGNESS-TO-PAY EVIDENCE EXISTS.

A personal paid tierCONDITIONAL

Monetisation of VerifAIer Me.

The condition

DEFERRED BY THE OWNER. Free for launch is not free forever, and any future price must be led by measured activation, usage, retention, governed-action behaviour and willingness to pay.

Usage as a commercial dimensionCONDITIONAL

Pricing that follows adapters, estate size, governed agents and systems, governed actions, receipts, policies, interface usage, runtime calls or evidence volume.

The condition

DEFERRED BY THE OWNER UNTIL REAL CUSTOMER AND USAGE EVIDENCE EXISTS. THIS DEFERS PRICING, NEVER MEASUREMENT: every one of those is still measured wherever the product already measures it.

Conditional. Each row states the evidence that would promote it.

Read it, then check it.

Every claim in this document is one the product publishes elsewhere and measures somewhere. The fastest way to test that is to run the thing.