What we do
We check AI systems against what they claim. That means verifying the model actually serving a request rather than the one named in the contract, re-running the evaluation that produced the headline number, tracing how a decision was reached six months after it was made, and testing whether the controls around the system hold when someone tries to get past them.
The output is a written assessment with the method attached, so your board, your auditor or your customer can follow the reasoning rather than trust the conclusion.
Why this is suddenly a procurement question
Under the DPDP Act the Board can levy penalties from 13 November 2026, and the EU AI Act is phasing obligations in over the same period. Both ask the same thing in different words: show that the system behaves as described, and show the evidence was produced as it ran rather than assembled afterwards.
Most organisations discover the gap at the point someone outside the company asks the question. By then the evidence either exists or it does not, and it cannot be backfilled honestly.
Where we are independent, and where we are not
We publish open measurement standards under our own name, free for anyone to run. Agent memory integrity, served-model fidelity, silicon-level correctness under radiation, and residency attestation. The rulebooks are public and the results are re-runnable.
If we built a system, we do not also certify it. That separation is the whole value of the assessment, and we would rather lose the engagement than blur it.
WHAT THIS RESTS ON
Four open standards
Published rulebooks, re-runnable by anyone, maintained in the open
Regulated delivery
GxP quality systems, HIPAA platforms and APRA CPS 230 assurance already shipped
Disclosure first
Findings go to the vendor privately before anything is published
Questions we hear before engagements
Can you assess a system you did not build?
That is the normal case and the stronger one. We work from the running system, the evaluation harness and whatever documentation exists, and we say plainly where the evidence runs out.
What if the assessment finds something serious?
You hear it first and in private, with the reasoning and the measurement behind it. We follow the same disclosure rule on client work that we follow on our open standards.
Is this a compliance certificate?
No. It is a technical assessment with evidence attached. It supports a compliance position, and it is often what a regulator or an acquirer actually asks to see, but we do not issue certificates for systems we engineered.
Related capability
If your system has to be right, let’s talk.
Start the conversation →