Certifiable Conformance Pack · Triodian

Mode B · Evidence tier

The difference between asserting conformance and demonstrating it.

Reproducible enforcement behaviour and a per-output conformance record an auditor or regulator can rely on, bound to the governing policy version, tamper-evident, replayable.

Request a sample conformance record See the regulatory mapping ↓

What the evidence layer adds

Evidence written by the system, not about it afterward.

Certifiable behaviour

Every accept/reject decision is bit-identical on re-execution: certifiable, not statistical. Re-run the input, get the same verdict, always.

The record

Every output carries a signed record naming the policy version, verdict and timestamp, evidence written by the system, not about it afterward. Rule 4 →

Regulatory context

Your framework, made checkable.

We make these checkable. We don't replace them.

EU AI Act

Its record-keeping and high-risk provisions in force from August 2026 demand evidence a system behaved as declared. The conformance record is that evidence, per output.

APRA CPS 230

Operational-risk controls over AI-driven processes require you to show the control operated. We add a replayable record beneath the control, not a new control.

ISO/IEC 42001

The AI management-system standard asks for documented evidence of control. We supply the machine-written artefact that documentation points to.

NIST AI RMF

Measure and Manage functions call for verifiable evidence over time. The record is the verifiable measurement, bound to the policy version that produced it.

The signature asset

A sample conformance record.

The record is the product's hero object: it names what governed, what was decided, and when, bound so any later tampering is detectable.

Request a sample record →
Specimen, illustrative only
Conformance record · signed
policy_versiondisclosure-grammar@4.2.1
verdictACCEPT
timestamp2026-07-23T04:18:07Z
substratesoftware / tamper-evident
signature_hash3f9a1c…e7b204 · ed25519

In practice

A regulated firm that clears the compliance gate at procurement.

The firm's permitted disclosure and suitability language is configured as grammar. Each customer communication ships with a conformance record. Provable conformance, not a policy statement about conformance, is what clears the compliance gate when procurement asks.

The honest boundary

  • Software tamper-evidence, not physical non-bypassability, strong where the requirement is an auditable record; not where a privileged insider must be structurally excluded. That rung is Hardware-Interlock Enforcement.
  • The record proves the output conformed to the grammar, not that the grammar captures every obligation. Envelope quality is the authoring tier's product: see PACE.

Adds Rules 5 and part of 6 to the software baseline; Rules 3 and 7 in full arrive at the hardware rung. The eight rules →

Request a sample conformance record.

Request →