For enterprises in every industry, and the integrators serving them: one independent control plane that verifies what your AI says, governs what your agents do, and proves both in a tamper-evident record. Scrutiny matched to the stakes: the full four-model cross-examination is reserved for the high-stakes decisions that warrant it.
Our own runs, reproducible — and every miss is published as an open finding, not buried. The open findings →
The problem
AI is making high-stakes decisions. Most of it goes unchecked.
Enterprises are putting large language models — and increasingly, autonomous agents — into regulated, high-consequence workflows: contracts, treasury, claims, HR, clinical operations. A single model’s answer can’t be independently verified, and an agent can move money or change a record before any human sees it. Veridect is the layer that verifies the answer, governs the action, and enforces your data-governance policy — with a record that survives an audit.
Intelligence makes your AI powerful. Trust is what lets you put it near money, patients, and contracts. Veridect is the trust layer — over any models you choose.
Models will be replaced. The bedrock stays. Veridect is built for the frontier to keep moving: swap any model and the control plane, your policies, and the tamper-evident record of every decision carry forward untouched. Changeability is what makes it permanent.
What’s different
The market sells a component. Veridect is the integrated stack.
Guardrails check whether your AI was safe. They were never built to check whether the answer was right, whether the agent was allowed to act — or to leave proof of either. Veridect starts where guardrails stop: an independent control plane above the models, where the verdict comes from cross-examination and deterministic policy, never from a model grading its own work.
It stays outside the thing it judges, whether the intelligence sits in the model or in the agent harness around it — the scaffolding that decides what an agent does next and which tools it reaches for. The agent acts through that harness; for every action sent through Veridect, the control plane governs from outside the agent harness, at the action boundary — where the next move touches money, data, or a record. One control plane built to work no matter which harness wins, so you don’t have to bet on one.
And not just any one harness — many at once. The fleet layer accumulates by tenant and agent identity, and the fabric classes check what agents declare — chains, plans, memory, messages — against the gate’s own record of who did what; neither looks at which framework produced the action. So agents built on different agent harnesses, arriving through the direct API or the tool gateway, are counted together and held to one policy in one ledger for every action they send through Veridect. Four things that layer does that edge tools don’t:
01 Verify
Answers cross-examined, not just voted.
Four frontier models from four vendors answer in parallel, then a verifier mesh has them check each other’s work before one verdict ships — with a calibrated confidence score that says when to trust the answer, when to challenge it — and where the doubt comes from. The full panel is reserved for the high-stakes calls that warrant it.
02 Govern
Hard lines the model can never override.
Your regulatory and data-governance rules run in deterministic code, escalate-only: even when the AI is wrong, those lines still force a human review. In the live gate sample, zero under-enforcement misses — every divergence was the gate being stricter, never looser.
03 Prove
A record anyone can check without trusting us.
Every verdict and every human review lands in one Ed25519-signed, hash-chained, write-once record — and when the agent acts, that downstream action is bound to its decision as a new linked record. Veridect Proof — a standalone verifier your risk team runs offline — re-checks the record’s hash and signature and re-derives the verdict itself from the sealed inputs, with no call to our servers. Edit one field of a copy and it fails the check, live, on the tour.
04 Fleet
Risk seen across the whole fleet, not one action at a time.
Hundreds of agents, every step individually fine, harm that only exists in aggregate. Veridect accumulates that exposure across the fleet, always on — and once the threshold you set is crossed, the outbound action is held for a human before the send. Exercised at ten thousand agent identities on one tenant, deterministically and then for real through the published system: after detection, every outbound step was held or blocked, and the benign control fleets drew zero fleet escalations (ten thousand identities deterministic, 300 live rulings). This August, fifteen frontier AI models, polled vendor-blind with live web search, could not identify another shipping commercial equivalent of that fleet layer.
So the question a board or regulator actually asks, was this genuinely checked?, is answered from evidence, not assurances. See all of it run live →
Platform
01
Quad-AI Consensus Engine
Verify what AI says. Four leading models answer the same question in parallel, cross-examine each other through a verifier mesh, and return one answer with weighted-consensus voting and a confidence score that attributes where any uncertainty comes from.
Govern what it does. A pre-action gate intercepts an autonomous agent’s proposed action before it executes and returns one verdict in seconds — greenlight, escalate to a human, or block — with a hash-verified audit bundle for every decision.
Enforce your rules. The policy layer inside the gate holds every agent to the authority it was granted and to seventeen deterministic checks — from money over a limit, protected personal data, and regulated health data to delegation chains, shared memory, message buses, and the whole fleet’s pattern over days — so a sensitive action escalates to a person, and one reaching past its authority is blocked, before it ever runs.
Before an autonomous agent moves money, sends data, or changes a record, Veridect intercepts the proposed action, runs it through the consensus engine, and returns one verdict in seconds.
Gate mechanisms and integration
Most guardrails see only the prompt. Veridect governs the whole action lifecycle — before, during, and after. Veridect is the trust spine, not the plumbing — it doesn’t replace your identity, retrieval, or data pipes; it governs and proves the decision that runs through them.
●Data-governance enforcement. Every agent is held to the scope it was granted and to seventeen deterministic checks, with four red-team-validated regulatory classes at the floor. An action that reaches past an agent’s authority is blocked outright; actions over a set dollar limit, changing protected personal data, weighing a protected-class-adjacent factor, or reaching regulated health data escalate to a human — and the same escalate-only discipline now reads delegation chains, maker-checker collisions, shared memory, message buses, and the whole fleet’s pattern over days. Never silently allowed through.
◆Action introspection. The gate inspects the structure of the action — the verb, the target system, the parameters — not just the text. Scrutiny scales with risk.
◉Session-aware exfiltration defense. Beyond single-action rules, the gate tracks how much sensitive data an agent has read across a session — so a slow, multi-step attempt to siphon data out, where each step looks fine on its own, escalates on the outbound move.
✦Delegated authority, attested. When one agent hands work to another, the hand-off carries its own Ed25519-signed delegation link — the gate verifies the whole chain and scope can only narrow along it. A hop that widens authority, or an action outside the final grant, is recorded in the decision’s evidence — and in strict identity mode, refused before a single model is consulted.
□Tamper-evident audit. Every verdict produces a SHA-256-chained bundle — the proposed action, each model’s vote, and the verdict with its calibrated confidence — written to a write-once store that rejects edits and deletes, and re-verifiable independently.
↻Framework adapters. Native integration for MCP, OpenAI Assistants, and Anthropic Computer Use.
Scope violations — an agent reaching past its authority — are stopped before they execute.
Human-review evidence and oversight quality
Oversight quality · anti-rubber-stamp
An escalation is only real oversight if a human actually looked.
Routing a risky action to a human is the easy half. The hard half is proving the human genuinely reviewed it — instead of waving it through in three seconds. Veridect records each human resolution of an escalated action as a tamper-evident row in the same hash chain as the verdict, and reads, across a team’s reviews, when the pattern starts to look like rubber-stamping. It turns human-in-the-loop from a box on a policy document into a control you can prove is working.
●The facts of each review, recorded. The resolution, whether a reason was logged, and how long it took — read straight from the audit chain, not self-reported, so the timing can’t be gamed.
◆A rubber-stamp risk read, in aggregate. Across a team’s reviews it weighs the telling cases heaviest — the escalations your models actively disagreed on that got approved unchanged — reading the pattern across the team, never any single review.
□Detect, never prevent. It never overrides a verdict. It makes the question a board or a regulator actually asks — was this genuinely reviewed, or waved through? — answerable from a tamper-evident record, in opaque codes that keep free-text out of the chain.
The record
Every decision leaves a bundle an auditor can replay.
In shortEvery decision leaves a tamper-evident, SHA-256-chained bundle in a write-once store — Ed25519-signed, independently re-verifiable offline, and exportable four ways.SHA-256-chainedEd25519-signedwrite-once store4 export formatsGRC-ready feedlive ServiceNow push
Each verdict writes a single, tamper-evident bundle — SHA-256-chained to the one before it — into a write-once store: the database rejects edits and deletes at the trigger level, and when the agent acts, that downstream action is cryptographically bound to its decision by appending a new linked record, never by mutating the original. The chain re-verifies independently: each record’s hash is recomputed from its own content and every link to the prior record is checked. Nothing is reconstructed after the fact; the decision and the evidence behind it are captured at the moment the action is gated.
Signing, key rotation, storage and exports
What that means in practice. Your audit trail shows what your agent actually did — not just what it was cleared to do. The decision and the action it authorized stay linked in one record, so a reviewer sees intent and outcome together.
Signed at the source. Beyond the hash chain, every bundle is signed the moment it’s sealed — an Ed25519 proof-of-origin signature over its own hash. The hash proves the record wasn’t altered; the signature proves it came from us, and it can’t be forged without our private key. Pin our published public key once, and any bundle you download verifies offline, forever — on your own machine, no call back to us. The decision proves itself.
NewKeys roll; the record still checks out. The signing key rolls forward to a fresh version whenever you need it to — and every bundle ever signed keeps verifying, against the exact key version it was sealed under. Each bundle carries its own version and we publish the full key history, so an auditor confirms a signature offline years later, long after the key has moved on. Rotating the key never invalidates a single past decision.
i
Built to integrate. Four exports ship today: a normalized governance JSON for programmatic ingestion, a flat CSV for spreadsheets and BI tools, a print-ready HTML report that saves to a board-ready PDF straight from your browser, and an OpenLineage event feed your SIEM or data-governance tooling can ingest directly. And for the platforms your risk team already lives in: a GRC-ready evidence feed — flat, versioned rows built for the scheduled imports ServiceNow GRC, Archer, and similar platforms already run, with a published field dictionary and integrity checks precomputed on every row. And the serious-incident handoff is demonstrated, not just documented: the Article-73-style package pushes end-to-end into a live ServiceNow instance, landing as a standard incident record through the core Table API every instance ships with — no GRC module required — with the disclosure language and the package’s integrity fingerprint carried into the record itself.
01The proposed action — verb, target, and parameters, plus the calling agent and the scope it declared
02Per-model vote register — which models answered, which errored, and a summary of each one’s response
03Consensus evidence — the method, providers used, total latency, and trace ID
04Verdict & calibrated confidence — with the escalation route and any recommended modification
05Governance policy record — which policy class(es) the action triggered and the basis for the verdict
06Integrity hashes — payload and verdict hashes binding the inputs to the outcome
07SHA-256 chain — the hash linking this record to the one before it
08Ed25519 proof-of-origin signature — the bundle’s hash signed with Veridect’s key, verifiable offline against our published public key
Session, workflow, fleet
Session → workflow → fleet: the same escalate-only discipline at every horizon — one agent’s conversation, one workflow’s crew, and now the whole fleet over days.
Session
Beyond single-action rules, the gate tracks how much sensitive data an agent has read across a session — so a slow, multi-step attempt to siphon data out, where each step looks fine on its own, escalates on the outbound move.
Inside a declared crew, Constellation: exfiltration split across agents so that no single one looks wrong is caught at the workflow level and escalated with per-agent attribution on the record.
We call that layer the coordination fabric: Veridect seeing coordination the agents themselves never declared — same sensitive category, same action shape, same target — across identities that share no session and no workflow.
Escalation thresholds are per-tenant policy, off until you set them. If fleet state is ever unavailable, the call falls back to the normal per-action verdict.
Risk can span agents that share no workflow. Hundreds of agents, every step individually fine, harm that only exists in aggregate — seen and held for a human before the send happens.
This August, fifteen frontier AI models, polled vendor-blind with live web search, could not identify another shipping commercial equivalent of that fleet layer.
Exercised at ten thousand identities. One tenant, one proposed step each, zero model calls: the first outbound step held for a person came from identity #30, all 1,496 that followed were held or blocked, a benign fleet of ten thousand drew zero fleet escalations, and the layer rebuilt its own memory from the sealed ledger after its fast state was wiped. Then the same swarm went through the published system for real: ten thousand live rulings, each signed, every outbound step after detection held or blocked, a benign control fleet of 300 rulings all cleared. The figures and the record →
In shortAn independent Fortune 100 model-risk reviewer ran a battery of adversarial scenarios live on this system — the gate matched its pre-stated behavior on every one.adversarial scenarios, run livematched pre-stated behavioron the live system, not a slide
In May 2026, a credentialed Fortune 100 model-risk reviewer ran adversarial scenarios — across legal, finance, HR, supply chain, multi-jurisdiction, and healthcare — live on these public tools. The gate matched its pre-stated behavior on each: holding boundaries, escalating at the right thresholds, and decomposing failure modes correctly — independent, adversarial proof, run live on the system rather than asserted on a slide.
Boundaries flipped at the exact policy threshold — reproducible right now on the live system.
Calibrated confidence
A confidence score that means something.
Confidence is discounted by the kind of ambiguity, not just disagreement count. Anchors observed in the external testing set:
74%
Resolvable ambiguity
The question has a defensible answer once a single missing detail is pinned down.
68%
Single-axis ambiguity
One genuine dimension of uncertainty remains — scored lower, surfaced clearly.
62%
Multi-dimensional overlap
Jurisdictional or multi-factor conflict. Discounted hardest — exactly where a human should look.
CLASS 01
Monetary threshold
Spend above a configured ceiling flips from clear to escalate.
CLASS 02
PII modification
Writes that change personal data require a second set of eyes.
CLASS 03
Protected-class adjacency
Actions near protected-class factors are held for review.
CLASS 04
PHI access / transmission
Health-data access and transmission route to the highest-risk tier.
The pre-action gate feels like the part that’s going to get serious attention from global systems-integrator and tier-1 bank buyers — this has enterprise-grade realism.
Attestation and cascade seal. Configuration attestation is Veridect attesting its own configuration — tamper-evident by construction, not independent third-party oversight. A cascade seal proves the hops the gate observed are intact and in the order recorded — not that nothing else happened; an action that never reached the gate cannot appear in it. And the external validation record covers the pre-action gate’s decision wire — capabilities shipped since, including these two, are verified in source and by tests, not claimed as part of that set.
Fleet classes. Accumulation is name-only — field-name categories, verbs, and hashes, never data values — and records for every governed action out of the box; escalation thresholds are per-tenant policy, off until you set them, so nothing about your existing verdicts changes until you decide it should. If fleet state is ever unavailable, the call falls back to the normal per-action verdict — the primary gate keeps running no matter what. These are the newest policy classes on the layer, additive beside the validated per-action record: the gate they extend is untouched.
Integration and buyer artifacts
From a vendor in your stack to the policy enforcement point in it.
The four providers are already collapsed behind one interface, with circuit breakers, automatic failover, and caching built in. That structural choice is the speed — it removes most of the integration work you’d take on building your own consensus layer. You integrate once, against standard auth patterns, instead of wiring up four vendors with four rate limits, four error patterns, and four auth models.
01 One integration, not four
Claude Opus 4.5, GPT-5.1, Gemini 2.5 Pro, and Sonar Pro sit behind a single REST endpoint. Circuit breakers, automatic failover, and caching are already built — far less integration work than rolling your own consensus layer.
02 Every engagement is its own tenant
Each buyer gets API keys you provision and revoke on demand, durable per-tenant policy overrides, isolated audit records, and usage limits — enforced by tenant-scoped storage, strict tenant-ID validation, authenticated-tenant resolution, and per-tenant rate limiting. The full isolation inventory is available under NDA.
03 Routing tuned to your vertical
Department- and industry-adaptive consensus weights, tuned to the decisions your sector actually makes — finance, insurance, healthcare, legal — not a one-size-fits-all model.
What an engagement includes
Adoption is a scoped engagement. Every buyer gets:
01A dedicated endpoint your engineers hit with your own data
From public docs to a trial in your own environment.
No long procurement runway just to see whether this fits. You can go from reading the docs to running Veridect on your own data in three steps.
Step 1 · No NDA
Start in the open
Run the live system yourself and read the public integration guide, white paper, and independent validation summary. Everything you need for a first technical read is public — no sign-up, no call required.
Step 2 · White-glove trial
White-Glove Enterprise Trial
When you’re ready to see it on real work, we stand up a dedicated trial in an environment you control — your data, your workflows, your team — before any commercial discussion.
Step 3 · On board
Private integration
Once we’re working together, a mutual NDA opens a private integration document built to your specs, followed by hands-on working sessions to wire Veridect into your stack.
How long does it take? A private sandbox in a day; production typically about two weeks — the pace is set mostly on your side (security review, key provisioning, access approvals), and our side is ready on day one. The five questions every executive asks, answered plainly →
Talk to us
See it on your own workflows.
Run the system yourself first. When you’re ready to put it in front of your own data and team, we’ll set up a working session in an environment you control.