decision_id "dec_9a3f21b4" system "underwriting.v3" risk_tier "high" # EU AI Act Annex III outcome "decline" confidence 0.873 inputs_hash 9a3f…21b4 model_hash 7c41…9d2e # model card v3.2.1 policy_set 0xf8a2… # 14/14 checks passed human_review "required · pending" jurisdiction "EU · DE" timestamp "2026-04-25T10:14:08Z" signature ed25519: 4f8c…7b2a tlog_inclusion planned · not live
Deploy AI
you can defend.before regulators, auditors, and courts demand proof.
Veridra is building a cryptographic evidence layer for regulated AI. The controlled alpha signs synthetic records and verifies their integrity; complete log-backed proof remains in development.
The moment AI becomes a liability.
A bank, insurer, health system, or government agency uses AI to make a consequential decision. A customer disputes the outcome. An auditor, regulator, or court asks:
- Which model made the decision?
- Which policy applied?
- What data was used?
- Who approved it?
- Can you prove it was not changed?
Today, most teams only have logs. Logs are not evidence.
A widely reported AI-agent incident ended with a production database deleted and the agent writing a confession that it had bypassed its own safety rules. The confession was still just text: no signed record, no verifiable evidence, and no independent proof of intent, scope, or permission state.
In a small SaaS workflow, that meant hours of reconstruction. In a bank, insurer, health system, or public-sector AI deployment, the same evidence gap becomes examiner action, litigation exposure, and disputed decisions no one can prove cleanly.
Existing tools report. Veridra proves.
Compliance automation, AI governance, and observability each solve a real problem. None of them produce decision-level cryptographic evidence. That is a different category.
| Capability | Compliance automation | AI governance | Observability | Veridra |
|---|---|---|---|---|
| Decision-level evidence | — | — | — | ✓ Per-decision signing |
| Cryptographic proof | — | — | — | Alpha: Ed25519 integrity check |
| Auditor workflow | — | — | — | Target: offline evidence packs |
| Verifiable without vendor | — | — | — | ✓ Open-source CLI |
| Per-decision audit trail | — | — | — | Target: signed, exportable records |
These categories solve adjacent problems. Veridra solves a different one — and the tools above are deployed alongside it, not replaced by it.
Banking AI first.
Highest regulatory pressure. Largest evidence budget. Fastest examiner cycle. Banking is where decision-level proof becomes mandatory first.
Banking AI
Credit · AML · fraud · underwriting · adverse-action workflows. SR 11-7 model risk management, ECB TRIM guidance, CFPB and state DFS AI supervision. Examiners require defensible model evidence and increasingly reject log-only responses. Banking deploys signed evidence first.
Insurance
Claims, pricing, underwriting models with defensible audit trails.
Healthcare
Clinical decision support and triage with HIPAA-grade decision accounting.
Government
Public-sector AI with sovereign data residency and procurement compliance.
From AI decision to defensible proof.
Veridra does not ask a regulator to trust a dashboard. It captures the decision record, signs it, logs it, and produces something another party can verify independently.
Decision happens
A model, workflow, or agent participates in a regulated outcome that may later need audit, legal, or examiner review.
Veridra captures the record
Inputs, model version, policy checks, human approvals, and operating context are canonicalized into one decision receipt.
The receipt is signed and logged
The current alpha produces Ed25519-signed records. Transparency-log inclusion is the next proof-kernel milestone.
Another party can verify it
Risk, audit, regulators, customers, or courts can inspect the record and verify integrity without trusting Veridra to interpret it for them.
2026
EU AI Act high-risk obligations become enforceable.
Articles 9, 12, 14, 15, and 72 — risk management, record-keeping, human oversight, accuracy and robustness, and post-market monitoring — apply to every high-risk AI system deployed in or serving the European Union.
Banks, insurers, and healthcare providers deploying AI into regulated decisions need decision-level evidence starting in four months. The enforcement date is fixed. The evidence infrastructure is not yet built. That is what Veridra is.
The cost of unverifiable AI.
For regulated enterprises, the question isn't whether AI assurance costs money. It's how much a single audit failure, discrimination claim, or board escalation costs without it.
Veridra exists so those headlines never reach your legal department.
A decision you can hand to a regulator.
This synthetic example shows the target evidence format. The current alpha signs and verifies record integrity; transparency-log anchoring and long-term retention remain gated work.
Do not trust the dashboard. Verify the proof.
Verification matters only if another party can inspect the receipt without asking Veridra to narrate what happened. The proof path has to survive outside the dashboard.
In the current alpha, the receipt signature and canonical hash can be checked independently. Transparency-log anchoring, checkpoints, witnesses, and complete offline proof verification remain under development.
Five verbs. One platform.
Every feature Veridra ships strengthens one of these five. Everything else is integration.
One proof loop works in controlled alpha. The broader modules remain roadmap work.
Govern
Planned framework mapping, risk register, and policy-as-code workflows.
Attest
Internal-alpha signing and verification, with transparency-log and evidence-pack work in development.
Watch
Continuous evaluation, drift detection, signed incident records. Always-on assurance.
Agents
Agent identity governance. Scoped permissions, tool-call audit, human-approval gates.
Verify
Model lineage and C2PA-ready content authenticity. For every model, every output.
Attest is the entry wedge — the signing and evidence layer. Govern and Watch expand the account after deployment.
One integration.
Every decision, proved.
Wrap your model call. Veridra captures the decision, canonicalizes it, signs with your key, logs to a transparency tree, and produces evidence on demand.
One line in your model call — OpenAI, Anthropic, Bedrock, Vertex, or your own.
v.attest(...)RFC 8785 canonical JSON. Deterministic across regions, languages, and time.
sha256:e4d1...b8a3Ed25519 via your KMS. Your key stays in your custody — we never see it.
ed25519.sign(...)Planned append to a tenant-scoped Merkle log with a verifiable inclusion proof.
target: inclusion_proofRegulator asks. You hand them a signed evidence pack. CLI verifies it offline.
veridra-verify pack.zipThe production design uses tenant-scoped KMS signing. The current alpha uses a development key and must not be treated as a customer-key deployment.
Evidence is verifiable without Veridra. Our CLI is open-source, Apache 2.0. If we shut down tomorrow, your signatures still verify with math alone.
Python is the primary alpha SDK. One second SDK will be certified against the same conformance suite before a design-partner launch.
Every evidence pack maps to the specific articles, sections, and obligations your regulators will actually check.
Articles 9, 12, 14, 15, 72 alignment.
Govern, Map, Measure, Manage — full function coverage.
Model risk management controls for US bank examiners.
AI management system controls mapped to Veridra evidence workflows; certification remains on the roadmap.
Healthcare AI decision accounting and software-as-medical-device oversight.
Automated decision-making transparency and human oversight rights.
Ten founding institutions. Defining the evidence layer together.
Ten regulated enterprises will define Veridra's production platform, framework crosswalks, and evidence standards. Founding partners receive direct founder access, roadmap influence, and long-term pricing.
Early technical discovery is open · pilot availability depends on readiness gates
Enterprise Assurance Programs.
Veridra engages with regulated organizations through structured programs — not self-serve SaaS. Every deployment begins with an executive conversation and an assurance review.
Assurance Review
Initial audit of one production AI system. Framework mapping, gap report, and remediation roadmap.
- ✓EU AI Act or NIST RMF mapping
- ✓Executive risk report
- ✓Evidence pack template
- ✓Fixed timeline delivery
- ✓Board-ready readout
Design Partner Program
Early enterprise deployment for regulated organizations building defensible AI infrastructure with us.
- ✓Up to 10 AI systems governed
- ✓Framework crosswalks included
- ✓Cryptographic attestation
- ✓Continuous monitoring
- ✓Founder-led implementation
- ✓Roadmap influence
Enterprise Assurance Platform
Global deployment across business units and jurisdictions. Built for institutions with governance obligations at scale.
- ✓Reference architecture planning
- ✓Scoped system inventory
- ✓Private deployment design
- ✓Founder-led technical review
- ✓Executive risk workshop
- ✓Pilot readiness plan
Controlled access. Evidence before claims.
Product details, implementation topology, delivery dates, and customer-specific deployment designs are shared only through scoped diligence.
Controlled alpha
Synthetic demonstration and technical evaluation only.
Security review
Deployment details are released only after qualification and mutual diligence.
Scoped engagement
Capabilities and commitments are documented for the approved use case.
Built on defense-grade primitives.
Veridra is architected for the highest-assurance environments — regulated banks, healthcare systems, and government contractors. Full trust center, SOC 2 readiness, and architecture documentation at veridra.io/trust.
Security review
Detailed controls and architecture are provided only during qualified diligence.
Data handling
Processing boundaries are documented for each approved engagement.
Deployment controls
No deployment model or infrastructure topology is exposed on the public site.
Retention
Retention and deletion requirements are established contractually for the approved scope.
Incident readiness
Coordinated disclosure is available through security.txt.
Independent review
Evidence claims are scoped to demonstrated capabilities and supporting materials.
What buyers actually ask.
How is this different from an AI observability tool?
+
Do we have to change our existing AI stack?
+
What's the performance overhead?
+
Is Veridra certified — is our data secure?
+
How long until we're audit-ready?
+
Do you work with non-US and non-EU regulators?
+
AI governance tells companies what they should do.
Veridra proves what their AI actually did.
Trust Signals
Trust signals for regulated AI.
Each trust signal is labeled with its current status so buyers can distinguish active work, internal framework mapping, and future roadmap items.
SOC 2 TYPE II
Independent audit readiness work underway.
ISO 27001
Internal ISO 27001 control mapping is available on request for diligence and procurement reviews.
ISO 42001
Internal ISO 42001 control mapping is available on request for diligence and procurement reviews.
GDPR
Product and policy posture are designed against GDPR principles; supporting materials are available on request.
EU AI Act
Internal article-level mapping for high-risk AI obligations is available on request.
NIST AI RMF
Internal NIST AI RMF function mapping is available on request.
What each status means
Active readiness or audit preparation is underway.
Planned certification or framework work; not yet completed.
Veridra maintains internal control mappings to framework requirements; supporting materials are available on request.
Product and policy posture are designed to follow the framework's principles; supporting materials are available on request.
Only used after independent certification is complete.
Important: Mapped and aligned statuses indicate internal framework mapping, not third-party certification. Request supporting materials if you need them for diligence.
Our commitment
We are transparent about where we are today and where we are headed. New certifications and published mapping materials will be added as we achieve them.