One architecture. Seven products on top of it.
There are seven products because governance has seven distinct jobs. There is one architecture because the record underneath them is written once, so what one surface reports, another can prove.
Where the operation is watched.
Sentinel Runtime
Available today: AVAILABLESits beside an AI coding agent, sees the operation before it happens, and records what it did.
- For
- Enterprise engineering teams running coding agents
- Delivery
- An MCP server installed into the editor
- Surfaces
- Claude Code, Cursor
VerifAIer Me
Your personal AI agents, on the same platform. Seal what an assistant did for you, and check it later.
- For
- Individuals using personal AI assistants
- Available today
- Import a past conversation, seal it, verify it later
- Planned
- Desktop, App Store, Google Play, after VerifAIer v1
Two products, one evidence layer. Sentinel Runtime governs agents that act on a codebase. VerifAIer Me governs assistants that act for a person. They are adopted separately because those estates differ, not because the architecture does, and they are not editions of each other.
What the operation becomes.
Evidence Engine
Turns an operation into a sealed envelope.
Flight Recorder
Keeps the session so a decision can be re-examined later.
Memory Receipts
Issues the receipt that binds a hash to a moment.
Agent Passport
Records which agent acted, and under what identity.
Trust Intelligence
Derives posture from the records, without a score.
Five products. One record.
ev_bf6442d03d1d461589a3b708bbd19d28 → rcpt_711e51de6f00491fb3c82256fdeca7c3 match
None of the five keeps its own copy. Remove a product and the record is unchanged. Add one and it reads what is already there. That is what makes them separable without being separate: seven jobs, one record, no reconciliation between them.
Evidence EngineFlight RecorderMemory ReceiptsAgent PassportTrust Intelligence
They do not. It is one architecture.
An operation enters at the top and leaves as something an executive can act on and an auditor can check. Each stage reads what the one above it wrote. No stage keeps its own ledger.
- Operation
- An agent or assistant is about to act. This is the only point at which the platform can see intent rather than aftermath.
- Evidence
- The operation is sealed into a record with a digest over its bytes.
- Receipt
- A receipt is issued against that record and bound to its hash.
- Identity
- Which agent acted, under which identity and which version.
- Trust
- Posture derived from the records, never from an opinion about them.
- Governance
- The same records read against whichever policy pack you adopted.
- Audit
- Records leave in open formats and verify without the platform present.
- Compliance
- A consequence of the evidence, not a separate exercise run beside it.
- Executive decision
- A situation, a confidence and one recommendation, each expandable to the record beneath it.
- Improvement
- What the decision changes is enforced at the runtime, where the next operation begins. The architecture closes on itself.
Where people read it.
Executive Center
Seven questions about the estate, two of which it refuses to answer.
Evidence & Receipts
The canonical inventory, with EMPTY and UNKNOWN kept apart.
Assessment
Four modes, one marked as the place to start. No account needed.
Governance Simulator
Try a policy change before it governs anything real.
What you hand to someone else.
Four artifacts a third party can check without access to your systems.
None of these is a grade. Each states what was examined and what it could not reach.
- Trust SLA
- What the platform commits to, and what it does not.
- Certification
- A statement about a scope, issued against evidence.
- Trust Passport
- A portable identity for a system, with its history.
- Benchmark
- Compare against a reference. Educational, never a league table.
Ways to reach it yourself.
- SDK
- 11 typed services over the same runtime. No duplicated engines, no new auth, no code generation.
- CLI
- Run an assessment, read evidence and verify a receipt from a terminal.
- Integrations
- Observe, protect, verify or extend. Every integration belongs to one of the four.
- Marketplace
- Policy packs organised by intention. Distributes metadata only. It never executes or downloads.
- API reference
- Every capability the surfaces read, documented against the same records.
What every label on this page means.
Shipping today, with a real install path in the repository.
Declared in the repository, not built. No date attached.
Not verified. We would rather say so than round it up.
If a product does not carry a label on this page, it is available. We would rather name a gap than blur one.
Enterprise governance. Without enterprise complexity.
There is no cluster to provision, no agent fleet to roll out and no data to migrate. The runtime installs beside one editor, and the evidence layer is already underneath it.
Install
One command adds the runtime to an editor that already exists.
Connect
The editor restarts. There is no console to configure and no key to distribute.
Run
An assessment completes locally, synchronously, before the page renders.
Govern
Adopt a policy pack. The records you already have are read against it.
Two editors install today. There is no packaged installer for the rest, and this page will not describe one until there is.
Seven reasons organisations choose it.
- The whole lifecycle, not a slice
- One architecture from the operation to the executive decision. Nothing is stitched between vendors.
- One evidence architecture
- Every product reads the same records, so there is no reconciliation exercise between tools.
- It runs where the data already is
- Local-first, with no hosted service in the path of an assessment and nothing to send outward.
- Evidence produced at runtime
- Not logs interpreted afterwards. The record exists because the operation happened, not because someone wrote it down.
- It refuses to overstate
- No composite score, no severity ranking, no invented trend. What it cannot answer, it says it cannot answer.
- It survives its own removal
- Records export in open formats and verify without the platform present. Adoption is not a dependency.
- One layer for agents and for people
- Sentinel Runtime governs what acts on the codebase. VerifAIer Me governs what acts for a person. Same records underneath.
Every claim above is a property of the architecture rather than a promise about it. Each one is checkable on the page it comes from.
Assembled tools produce assembled evidence.
Each tool defines its own record, in its own format.
Evidence is reconciled afterwards, by hand, at audit time.
A gap in one tool is invisible to the others.
Policy is applied to reports, after the operation has run.
Replacing a tool takes its history with it.
One record, written once, at the moment the operation runs.
Every surface reads that record. Nothing is reconciled later.
A gap is a state the platform names: unknown.
Policy is applied to the operation itself, before it completes.
Retiring a surface leaves every record intact.
- One runtime
- Governs the operation as it happens.
- One evidence layer
- Records what it did, once.
- One governance model
- Policy packs read the same records.
- One trust architecture
- Every claim resolves to a receipt.
New capabilities inherit the architecture. They do not extend it.
The runtime
A new product governs operations through the same runtime, or it is not a VerifAIer product.
The evidence model
It writes the same envelope and the same receipt. It does not define a second record.
The trust model
The same eight states. No new vocabulary, and still no composite score.
The governance model
Existing policy packs read it on the day it ships. Nothing is re-authored.
The platform grows by adding surfaces over one architecture, not by adding architectures. A capability that cannot be expressed in the existing evidence model is a capability that belongs outside the platform. Any one of these products can be resembled on its own. What cannot be added afterwards is the shared record beneath them, because it is decided at the runtime, before any product reads it.
- Adoption order is yours.
- The layers do not depend on each other.
- What does not exist yet is labelled, not implied.
- The maturity vocabulary already covers it.
- Records written today are readable by products that do not exist yet.
VerifAIer is not a collection of products. It is an operating architecture for AI governance.
Start with something you can verify yourself.
An assessment runs on your own infrastructure and needs no account.
