Skip to content
VerifAIer
Enterprise

Standardise governance across every AI system you run.

One evidence model, inside your own perimeter, for the whole estate. What one surface reports, another can prove, and an auditor can check without us in the room.

In brief

A one-minute read for the person deciding whether the rest of this page is worth their time.

What it is
A governance runtime that sits beside the AI systems an organisation already runs. It records what each operation was allowed to do and what it actually did, and turns that into evidence a third party can check. It installs into existing tooling rather than replacing it, and it runs entirely inside the organisation’s own perimeter.
Why organisations standardise
Because governance assembled from separate tools produces separate records, and reconciling them is the work. One evidence model across every AI system removes that work permanently. Executive, audit, engineering and compliance all read the same record rather than keeping their own.
Why it is different
It refuses to answer questions it cannot support. There is no composite trust score, no severity ranking and no trend line, because nothing in the platform computes them. What it reports instead is what it examined, what it could not reach, and why. That is the part that survives an audit.
Deployment
Your infrastructure. Four postures.
Data egress
None required to operate.
Starting scope
One agent, one repository.
Operator requires
No specialist role.
Executive overviewWhat changes when it is in place?

Three things become true.

01 · Scale

One evidence model, not one per tool.

Every AI system writes into the same records, so governance does not fragment as the estate grows.

02 · Audit

Every claim carries the file that proves it.

A finding is not a statement about the past. It is a record with a digest, and the digest can be recomputed.

03 · Independence

Verification does not require us.

Records export in open formats and verify offline. Removing VerifAIer does not invalidate what it already produced.

Canonical product UI · Executive CenterSituation illustrated · coverage read from the registry
Situation · am I safe

Nothing to flag.

Ready

16 capabilities were checked. 14 answered. Two could not be reached, and are reported as unknown rather than as failures.

Confidence · coverage

14 / 16 answering

flight and governance declare no operation an assessment can run, so they answer nothing. A ratio, not a grade. No composite score is computed anywhere in this platform.

Executives read a situation, a confidence and one recommendation. Everything technical sits below, collapsed, one click away. Two of the seven questions the executive surface asks are refused outright, because no baseline is stored and improvement over a period cannot be derived from records that were never a time series.
ArchitectureWhere does it run?

Inside your perimeter. All of it.

Your infrastructure
SourceAI systemsAgents, assistants, pipelines, services
RuntimeSentinel RuntimeSees the operation, records what it did
CoreEvidence layerEnvelopes, receipts, provenance, posture
ReadSurfacesExecutive, Evidence, Trust, SDK, API

No outbound call is required to answer.

OutsideVerifAIer, the company. Not in the path of an assessment, and not required to verify one.
Architectural facts
Server-rendered HTML
No client-side framework, and no build step in the path of a page.
Works without JavaScript
Navigation is links. Mutation is form posts. The product is usable with scripting disabled.
No external asset
No CDN, no webfont and no third-party request from any product surface.
Synchronous execution
An assessment completes before the page renders. There is no queue and no worker to operate.
Fixed surface area
21 destinations in 9 groups, one route table, asserted by the test suite.
DeploymentHow does it arrive?

Four postures, stated plainly.

Posture 01Available today: AVAILABLE

Self-hosted

Runs on infrastructure you already own and already govern.

Posture 02Holds because of how the system is built: BY CONSTRUCTION

Disconnected

No outbound dependency exists to remove, so an isolated network changes nothing.

Posture 03Not declared yet: PENDING

Container image

A packaged container path is not yet declared. This page will not claim one until it is.

Posture 04Deliberately not offered: NOT OFFERED

Hosted service

There is no hosted service in the path of an assessment, and no plan to put one there.

Note

Two vocabularies sit in that row and answer different questions. AVAILABLE and PENDING are maturity: whether a capability exists yet. BY CONSTRUCTION and NOT OFFERED are deployment posture: how a capability is delivered, or that it is deliberately not. A posture is never a maturity, and NOT OFFERED in particular is a decision rather than an open question. Deployment specifics sit on the Trust Center.

Evidence lifecycleWhat survives the run?

From operation to something an auditor can check.

Operation

An agent is about to act. The runtime sees it first.

Sentinel Runtime
Envelope

The operation is sealed into a record with a digest over its bytes.

Core Evidence Engine
Receipt

A receipt is issued against the envelope and bound to its hash.

Memory Memory Receipts
Verification

Posture is derived from the records, never from an opinion about them.

Trust Trust Intelligence
Export

Records leave in open formats and verify without the platform present.

No lock-in by design
Attached along the way
Capture

Flight Recorder

Keeps enough of the run to re-examine a decision later.

Identity

Agent Passport

Says which agent acted, under which identity and version.

One receiptproof/receipt.json
Bound envelope
ev_bf6442d03d1d4…89a3b708bbd19d28
Receipt
rcpt_711e51de6f0…b3c82256fdeca7c3
Produced by
evidence_engine
Verification
MATCH
GovernanceWhat are the rules?

Policy packs, adopted deliberately.

eu_ai_act

EU AI Act

Ships today, as metadata your organisation adopts. Nothing is enforced without you adopting it.

nist_ai_rmf

NIST AI RMF

The same evidence, read against a different framework. No second ledger is created.

iso_42001

ISO/IEC 42001

Management-system alignment, drawn from records that already exist.

Governance Simulator

Ask what a policy would have done, before it governs anything real. Exploratory by design, and never a verdict.

Note

Three compliance packs ship today, and the same evidence is read against each of them. Custom packs are declared in the plan model and are not yet implemented. SSO is the other one, and both are named in entitlements/models.py as unimplemented rather than advertised as available.

Security & accessWho sees what?

Access is stated, not implied.

Roles and permissions

Actions a role cannot take render as unavailable with the reason on screen, rather than disappearing.

Not available to you

Selective Disclosure

Prove a property of a record to an outside party without handing over the record itself. Architectural selective disclosure, not a zero-knowledge proof system, and it says so where it is implemented.

Security

Entitlements

The plan model distinguishes a feature that is not in your plan from one that is in your plan and not yet built. Both are shown.

Not in plan In plan · not implemented

Data movement

None is required. Evidence is produced, stored and read inside the perimeter it was produced in.

Local-first · no telemetry in the path of an assessment
OperationsHow do teams run it?

Four modes, and what none of them claim.

Quick

A first read of the estate, on demand.

6 capabilities · start here

Standard

Broader capability selection, same evidence model.

13 capabilities

Deep

Widest selection. Still a selection, and it says which.

16 capabilities

Continuous

Planning semantics for repeated invocation. There is no scheduler, worker or queue behind it, and selecting it does not switch monitoring on.

13 capabilities
What an assessment does not establish
  • A mode name is not a verdict.
  • COMPLETE means the selected mode succeeded, not that the platform was assessed.
  • No mode computes a score of any kind.
  • Findings carry no severity, because nothing in the platform ranks them.

Runs are local and synchronous

By the time the page renders, the run is over.

Reads are bounded

Evidence tables stop at 25 rows by design, and say so.

Results are not persisted

Which is why the platform refuses to report a trend.

Getting startedHow does it start?

One agent first. Never the estate.

Run an assessment
No account, nothing installed, nothing to configure. It finishes before the page renders.
Install the runtime beside one agent
One team, one editor, one codebase. The blast radius of a mistake is one repository.
Read what it produced
Receipts, envelopes, provenance. Verify one offline before trusting the rest.
Adopt a policy pack
Read the same evidence against the framework your auditors already use.
Give executives the read
A situation, a confidence and one recommendation. Nothing they have to interpret.
Not claimed today
  • There is no packaged Sentinel installer. Three surfaces install; the rest do not.
  • No composite trust score exists, and the product refuses to compute one.
  • No baseline is stored, so improvement over a period cannot be reported.
  • Marketplace distributes metadata. It never executes or downloads anything.
  • Billing is not configured. Nothing on the pricing page can be purchased yet.
UsabilityWho has to operate it?

Governance nobody uses is not governance.

Most governance platforms are adopted by a programme and operated by specialists. This one is adopted by a team and operated by whoever is already there.

What it does not require
  • A cluster to provision. The runtime installs beside an agent, not in front of one.
  • A data migration. Evidence is produced where the operation happens.
  • A specialist operator. An assessment is one action with nothing to configure.
  • A training programme. Every screen states its own limits in plain language.
  • A consulting engagement to begin. The first assessment needs no account at all.
What it does require
  • One editor with the runtime installed. Two install today.
  • A decision about which policy packs apply to you.
  • Somebody willing to read one screen. Once.

The reason this matters commercially: a governance layer that only a specialist can operate is a governance layer that covers whatever the specialist has time for. Coverage is a usability problem before it is an architecture problem.

Under 1s
An assessment completes before the page renders. No spinner exists.
No account
The first assessment runs without signing up for anything.
1 command
Installing the runtime beside an agent is a single install script.
0 bytes out
Nothing leaves the perimeter. There is no hosted service in the path.
InterfacesHow many systems is this?

Every door opens onto the same runtime.

An editor, a browser, an API and a terminal are four ways into one architecture, not four products to license, integrate and reconcile. Each door carries its own maturity, stated plainly.

Door 01Available today: AVAILABLE

The editor

An MCP server beside the coding agent. Claude Code and Cursor install today.

Door 02Available today: AVAILABLE

The workspace

21 destinations in a browser. Server-rendered, no client state.

Door 03Available today: AVAILABLE

The API

12 open operations, named in one allowlist. Everything else needs a credential, and the allowlist is what makes an endpoint open.

Door 04Available today: AVAILABLE

The SDK

11 typed services. It composes the runtime; it never reimplements it.

Door 05Available today: AVAILABLE

The terminal

The vai console script and python -m vailidator.sdk. Both ship in the wheel.

Door 06Planned, and not built yet: PLANNED

The desktop

A native application. Planned for VerifAIer Me, after v1. No date.

Door 07Planned, and not built yet: PLANNED

The phone

App Store and Google Play. Planned for VerifAIer Me, after the desktop build.

Behind every doorOne runtime
One evidence layerOne governance modelOne trust architecture

The mark appears at every door because the same architecture is behind each one. It is an identity, not an interface, and nothing is verified by looking at it.

AdoptionHow does it spread?

Six steps. No architectural change at any of them.

Each step is a decision about scope, not a deployment project. Nothing is rebuilt, re-platformed or re-integrated when an organisation moves from one to the next.

  • One agent

    One editor, one install command, one person.

    no approval needed
  • One team

    The same install, repeated. A shared workspace appears.

    + shared evidence
  • One department

    A policy pack is adopted deliberately. Rules become explicit.

    + policy
  • Business units

    Scopes separate. Access is stated per unit rather than inherited.

    + scope boundaries
  • Organisation-wide

    Executive surfaces become useful because coverage is broad enough to read.

    + executive view
  • Sovereign scale

    Disconnected posture, national or sector policy packs, no change to the model.

    + deployment posture
What does not change at any step
The runtime

Step six runs the same runtime as step one.

The evidence model

A receipt produced on day one is readable on day one thousand.

The governance model

Packs are added. The way rules are stated does not change.

Where it runs

Inside your perimeter at every step, including the first.

There is no step at which an organisation must stop and re-platform. That is the property being described here, not the speed of any particular rollout, which depends on your organisation and not on ours. It is not a service commitment, and no date on this page is one.

Business caseWhat does it replace?

The cost is in the seams.

Most of what an AI governance programme costs is not the tools. It is the work of holding disconnected tools together: reconciling records, maintaining integrations, training people to operate each one, and paying somebody to explain the result.

One architecture removes that work rather than automating it. There is nothing to reconcile when there is one record.

What we do not publish

No ROI figure, no payback period, no cost-saving percentage and no benchmark against other tooling. We have not measured your organisation, and a number we cannot show the evidence for would contradict everything else on this page.

What an organisation stops needing
Reconciliation between tools
One record. Nothing to align, and nothing to explain when two systems disagree.
A governance headcount
The budget line for a dedicated governance role does not open.
Consulting to begin
No statement of work stands between the decision and the first result.
A migration project
Nothing moves. It installs beside what already runs.
Retraining per product
Adding a capability adds a surface, so the training cost is paid once.
A separate audit exercise
Evidence is produced as operations run, not assembled afterwards.

Start with something you can verify yourself.

An assessment needs no account and touches nothing. Read what it produced, then decide whether the rest is worth a conversation.

Local-first and advisory. Findings are evidence about what happened, not certification and not legal advice.