Sovereign AI needs sovereign governance.
Governance software is procured, operated and eventually replaced. Governance infrastructure is installed once and outlives the systems it governs. VerifAIer runs inside your own perimeter and produces evidence an assessor can check without contacting us. No hosted service sits between a national AI operation and the record of what it did.
The deployment is the perimeter.
It runs where you install it
The runtime is installed into your own infrastructure. Nothing about its operation depends on a network path to a vendor, so there is no jurisdiction to negotiate over where the software executes.
The evidence stays put
Records are written where the operation happened and read from there. There is one evidence layer and no second copy held elsewhere, so residency is a property of the install rather than a contractual assurance.
No vendor in the path
An assessment reaches its result without a remote call. We are not a dependency of your own oversight, and we cannot be compelled to produce something we never held.
Local-first is a property of the architecture, not a deployment option offered at a higher tier. There is no hosted mode in which the evidence layer sits with us instead.
Regulation is adopted, not applied to you.
A policy pack is a set of capabilities an organisation adopts.
Adoption is an act, and the act is recorded. Nothing is enforced that was not adopted, and nothing that was adopted is enforced silently. The operation that was evaluated and the pack it was evaluated against sit in the same record.
A pack is not a document the organisation interprets separately per team.
The same operation against the same pack returns the same result. No model interprets the rule.
EU AI Act
eu_ai_act
Ships today, as metadata your organisation adopts. Nothing is enforced without you adopting it.
NIST AI RMF
nist_ai_rmf
The same evidence, read against a different framework. No second ledger is created.
ISO/IEC 42001
iso_42001
Management-system alignment, drawn from records that already exist.
Packs are not a public-sector feature. The same mechanism carries an enterprise obligation and a national one, which is the point: a sovereign programme adopts a mechanism already exercised at scale rather than a catalogue built for it alone and exercised nowhere else.
Nothing outside the deployment.
The interface loads no external stylesheet, script, font or image. There is no request to make.
Nothing is reported outward. There is no telemetry channel to disable.
A run completes before a result renders. No queue, no worker, no background job.
The interface is server-rendered and usable without JavaScript. Nothing is hidden behind a script that has to run.
Why this matters in a closed network
Software that expects the internet fails quietly in an environment that does not have it: a missing font, a blocked analytics call, a script that never loads. An interface with no external reference behaves identically inside the perimeter and outside it, and that identical behaviour is what makes it assessable.
What is not claimed
Air-gap compatibility is a property of the architecture. It is not an accreditation, and no classified environment is claimed as certified. Those are assessments somebody else performs, on a specific deployment, using the evidence it produces.
They check the evidence, not us.
●Ready The receipt matches the envelope it refers to.
- envelope
ev_bf6442d03d1d4…89a3b708bbd19d28- receipt
rcpt_711e51de6f0…b3c82256fdeca7c3- checked by
local · no remote call
14 / 16 capabilities answered
Two capabilities return Cannot tell, each with a stated reason. That is reported as an answer, not rounded into the 14.
Every answer is one of 8 states: ●Ready◐Partly done○Nothing yet?Cannot tell and 4 more. The word carries the meaning and the glyph is decoration, so no state is distinguished by colour alone.
There is no government specific product surface.
The product declares a Government group and leaves it empty. An empty group is never rendered, so nothing in the authenticated product is labelled for the public sector.
The reason recorded in the module is that the regulatory content is a set of policy packs enterprises adopt too. A public-sector heading would state something untrue: that there is a separate machinery behind it.
taxonomy.in_group( GROUP_GOVERNMENT ) == ()
- Not an accreditation. No certification, authorisation to operate or national approval is claimed. Those are granted by an authority, against a specific deployment.
- Not legal advice. Findings are evidence about what happened. Deciding what an obligation requires stays with your counsel.
- Not a national dashboard. Nothing aggregates across deployments. Each install holds its own evidence, and there is no layer above them.
- Not a trend line. No posture is written to a time series, so no improvement or decline over a period can be reported.
Government is a way in, not a product line.
A public-sector institution adopts the same architecture, the same packs and the same evidence layer as everybody else. An oversight regime that depends on a vendor building something separate for it has a dependency, not a guarantee. Nothing here assumes an institution’s authority: the regulator still rules, the auditor still audits and the ministry still decides. What changes is that each of them is reading a record instead of a report.
Owning the stack does not produce governance.
Sovereign AI capability and sovereign AI governance are different disciplines, built by different teams, on different timelines. A national programme can complete the first and still have nothing to show an assessor about the second.
Owning the infrastructure does not create governance.
Control over where a system runs establishes jurisdiction. It does not establish what the system was permitted to do inside it.
Owning the models does not create evidence.
Weights held domestically are an asset, not a record. Nothing about possession explains what a deployed model did on a particular day.
Owning the compute does not create trust.
Capacity answers what can be run. Trust is a separate question asked by somebody outside the programme, and it is answered with proof.
Five different environments. One unanswered question, and it is the same question in all five.
None of them is replaced by a governance architecture, and none of them produces one on its own. The runtime installs into whichever of these already exists, governs the operations that pass through it, and leaves behind a record the environment’s own overseers can check. Sovereign capability decides what a state is able to do. Sovereign governance decides what it can prove afterwards.
Sovereignty is decided at install time.
A sovereign deployment is not a configuration of a hosted service, and it is not a contractual promise about where data will be kept. It is the consequence of an architecture that had nowhere else to put anything in the first place.
Everything on this page follows from that one property. The perimeter, the packs, the closed-network behaviour and the independent check are not four features assembled for the public sector. They are what an architecture looks like once it has no path out.
It is adopted the way infrastructure is adopted: one system first, then a directorate, then a ministry, with no step that requires re-platforming what came before. A record written under one administration remains readable under the next, and a model retired next year leaves its evidence behind intact. There is nothing here to procure. The next step is an assessment run inside your own environment, against a deployment you control, producing a record you keep.
The five questions.
- What is VerifAIer?
- Governance infrastructure that runs inside your own perimeter and produces evidence an assessor can check without contacting us.
- Why does it exist?
- Because an institution is answerable for what its AI systems did, and today it cannot show what that was to anyone outside the programme that ran them.
- Why is it different?
- The evidence layer is where the operation happened. Residency is a property of the install rather than a contractual assurance, and no vendor sits in the path.
- Why should I trust it?
- Because nothing here is an accreditation. The limits sit on the page beside the claims, and the records are readable without the product that produced them.
- What should I do next?
- Run an assessment inside your own environment, or read the deployment model first.
