Live · current four-model lineup
Veridect · The verdict layer for enterprise AI

Trust what your AI says.
Govern what it does.

Verify. Govern. Prove.

For enterprises in every industry, and the integrators serving them: one independent control plane that verifies what your AI says, governs what your agents do, and proves both in a tamper-evident record. Scrutiny matched to the stakes: the full four-model cross-examination is reserved for the high-stakes decisions that warrant it.

Proposed action
Veridect
One verdict
  • Greenlightcleared to proceed
  • Escalatehuman review required
  • Blockrefused before execution
See a signed record from this decision path →
Claude Opus 4.5 GPT-5.1 Gemini 2.5 Pro Sonar Pro
Proven in education · In production across the Fortune 100  ·  Provider-agnostic  ·  Calibrated confidence  ·  SHA-256 audit trail

Evidence

Answer benchmark
85.0%
MMLU-Pro consensus (N=100) — +3.0pp over the best single model, current lineup
Method: our own run, raw outputs reproducible →
Live gate sample
0
Under-enforcement misses in the live consensus sample — every divergence was the gate being stricter, never looser
Method: stratified 40-scenario sample through the real gate →
Deterministic conformance
4,697
Deterministic policy scenarios at 100% conformance — policy harness, zero model calls
Method: deterministic harness at volume — the coverage record →
Record integrity
SHA‑256
Tamper-evident, chained audit bundle on every answer and every action
Method: canonical-hash chain, Ed25519-signed decisions →

Our own runs, reproducible — and every miss is published as an open finding, not buried. The open findings →

The problem

AI is making high-stakes decisions. Most of it goes unchecked.

Enterprises are putting large language models — and increasingly, autonomous agents — into regulated, high-consequence workflows: contracts, treasury, claims, HR, clinical operations. A single model’s answer can’t be independently verified, and an agent can move money or change a record before any human sees it. Veridect is the layer that verifies the answer, governs the action, and enforces your data-governance policy — with a record that survives an audit.

Intelligence makes your AI powerful. Trust is what lets you put it near money, patients, and contracts. Veridect is the trust layer — over any models you choose.

Models will be replaced. The bedrock stays. Veridect is built for the frontier to keep moving: swap any model and the control plane, your policies, and the tamper-evident record of every decision carry forward untouched. Changeability is what makes it permanent.

What’s different

The market sells a component. Veridect is the integrated stack.

Guardrails check whether your AI was safe. They were never built to check whether the answer was right, whether the agent was allowed to act — or to leave proof of either. Veridect starts where guardrails stop: an independent control plane above the models, where the verdict comes from cross-examination and deterministic policy, never from a model grading its own work.

It stays outside the thing it judges, whether the intelligence sits in the model or in the agent harness around it — the scaffolding that decides what an agent does next and which tools it reaches for. The agent acts through that harness; for every action sent through Veridect, the control plane governs from outside the agent harness, at the action boundary — where the next move touches money, data, or a record. One control plane built to work no matter which harness wins, so you don’t have to bet on one.

And not just any one harness — many at once. The fleet layer accumulates by tenant and agent identity, and the fabric classes check what agents declare — chains, plans, memory, messages — against the gate’s own record of who did what; neither looks at which framework produced the action. So agents built on different agent harnesses, arriving through the direct API or the tool gateway, are counted together and held to one policy in one ledger for every action they send through Veridect. Four things that layer does that edge tools don’t:

01 Verify

Answers cross-examined, not just voted.

Four frontier models from four vendors answer in parallel, then a verifier mesh has them check each other’s work before one verdict ships — with a calibrated confidence score that says when to trust the answer, when to challenge it — and where the doubt comes from. The full panel is reserved for the high-stakes calls that warrant it.

02 Govern

Hard lines the model can never override.

Your regulatory and data-governance rules run in deterministic code, escalate-only: even when the AI is wrong, those lines still force a human review. In the live gate sample, zero under-enforcement misses — every divergence was the gate being stricter, never looser.

03 Prove

A record anyone can check without trusting us.

Every verdict and every human review lands in one Ed25519-signed, hash-chained, write-once record — and when the agent acts, that downstream action is bound to its decision as a new linked record. Veridect Proof — a standalone verifier your risk team runs offline — re-checks the record’s hash and signature and re-derives the verdict itself from the sealed inputs, with no call to our servers. Edit one field of a copy and it fails the check, live, on the tour.

04 Fleet

Risk seen across the whole fleet, not one action at a time.

Hundreds of agents, every step individually fine, harm that only exists in aggregate. Veridect accumulates that exposure across the fleet, always on — and once the threshold you set is crossed, the outbound action is held for a human before the send. Exercised at ten thousand agent identities on one tenant, deterministically and then for real through the published system: after detection, every outbound step was held or blocked, and the benign control fleets drew zero fleet escalations (ten thousand identities deterministic, 300 live rulings). This August, fifteen frontier AI models, polled vendor-blind with live web search, could not identify another shipping commercial equivalent of that fleet layer.

So the question a board or regulator actually asks, was this genuinely checked?, is answered from evidence, not assurances. See all of it run live →

Platform

01

Quad-AI Consensus Engine

Verify what AI says. Four leading models answer the same question in parallel, cross-examine each other through a verifier mesh, and return one answer with weighted-consensus voting and a confidence score that attributes where any uncertainty comes from.

How verification works →
02

Agentic Trust Layer

Govern what it does. A pre-action gate intercepts an autonomous agent’s proposed action before it executes and returns one verdict in seconds — greenlight, escalate to a human, or block — with a hash-verified audit bundle for every decision.

How the gate works →
03

Data Governance

Enforce your rules. The policy layer inside the gate holds every agent to the authority it was granted and to seventeen deterministic checks — from money over a limit, protected personal data, and regulated health data to delegation chains, shared memory, message buses, and the whole fleet’s pattern over days — so a sensitive action escalates to a person, and one reaching past its authority is blocked, before it ever runs.

How your policy is enforced →
Find your path

Built for the people in the room — start where you own the risk.

CEO & the executive team The five questions every executive asks — how it helps the company, how it integrates, how long it takes, how it makes money, and why us rather than a big well-known name — answered plainly in two minutes, with a one-page brief to forward. Five questions, plain answers → Finance & the board Verification spend follows risk, not volume — the full panel is spent only on the high-stakes call. Every decision leaves a record, so what AI cleared alone, what needed a person, and where the risk sat is counted, not estimated. Why four models isn’t four times the bill → Technology leadership Governance built for the pace and scale of adoption: one control plane over every model and vendor — swap a model generation as a configuration change, keep your policies and the record — and a coverage map of what you meant to govern against what actually ran. What’s governed, at a glance → Model risk & validation Independent cross-provider challenge, calibrated confidence, and the live red-team record — built for SR 11-7 model-governance review. Independent validation → Security & procurement Data handling, compliance mappings, and the diligence checklist — the full security read in one place. Trust & Security center → Integrators & platforms Per-tenant isolation, keys, quotas, and audit chains — the substrate for running Veridect across many clients at once. Built for scale → Engineering & integration One REST endpoint behind four models, framework adapters, and the path from first call to a tenant live in your stack. How you adopt it →
One governed action and its signed record

A pre-action gate for autonomous agents.

Before an autonomous agent moves money, sends data, or changes a record, Veridect intercepts the proposed action, runs it through the consensus engine, and returns one verdict in seconds.

Gate mechanisms and integration

Most guardrails see only the prompt. Veridect governs the whole action lifecycle — before, during, and after. Veridect is the trust spine, not the plumbing — it doesn’t replace your identity, retrieval, or data pipes; it governs and proves the decision that runs through them.

Data-governance enforcement. Every agent is held to the scope it was granted and to seventeen deterministic checks, with four red-team-validated regulatory classes at the floor. An action that reaches past an agent’s authority is blocked outright; actions over a set dollar limit, changing protected personal data, weighing a protected-class-adjacent factor, or reaching regulated health data escalate to a human — and the same escalate-only discipline now reads delegation chains, maker-checker collisions, shared memory, message buses, and the whole fleet’s pattern over days. Never silently allowed through.
Action introspection. The gate inspects the structure of the action — the verb, the target system, the parameters — not just the text. Scrutiny scales with risk.
Session-aware exfiltration defense. Beyond single-action rules, the gate tracks how much sensitive data an agent has read across a session — so a slow, multi-step attempt to siphon data out, where each step looks fine on its own, escalates on the outbound move.
Delegated authority, attested. When one agent hands work to another, the hand-off carries its own Ed25519-signed delegation link — the gate verifies the whole chain and scope can only narrow along it. A hop that widens authority, or an action outside the final grant, is recorded in the decision’s evidence — and in strict identity mode, refused before a single model is consulted.
Tamper-evident audit. Every verdict produces a SHA-256-chained bundle — the proposed action, each model’s vote, and the verdict with its calibrated confidence — written to a write-once store that rejects edits and deletes, and re-verifiable independently.
Framework adapters. Native integration for MCP, OpenAI Assistants, and Anthropic Computer Use.
Run a live verdict →
Greenlight

High-confidence, in-scope actions clear automatically, so your team only sees what needs them.

Escalate

Uncertain, high-risk, or out-of-policy actions route to a human with the full reasoning attached.

How each review is evidenced →
Block

Scope violations — an agent reaching past its authority — are stopped before they execute.

Human-review evidence and oversight quality
Oversight quality · anti-rubber-stamp

An escalation is only real oversight if a human actually looked.

Routing a risky action to a human is the easy half. The hard half is proving the human genuinely reviewed it — instead of waving it through in three seconds. Veridect records each human resolution of an escalated action as a tamper-evident row in the same hash chain as the verdict, and reads, across a team’s reviews, when the pattern starts to look like rubber-stamping. It turns human-in-the-loop from a box on a policy document into a control you can prove is working.

The facts of each review, recorded. The resolution, whether a reason was logged, and how long it took — read straight from the audit chain, not self-reported, so the timing can’t be gamed.
A rubber-stamp risk read, in aggregate. Across a team’s reviews it weighs the telling cases heaviest — the escalations your models actively disagreed on that got approved unchanged — reading the pattern across the team, never any single review.
Detect, never prevent. It never overrides a verdict. It makes the question a board or a regulator actually asks — was this genuinely reviewed, or waved through? — answerable from a tamper-evident record, in opaque codes that keep free-text out of the chain.
The record

Every decision leaves a bundle an auditor can replay.

In short Every decision leaves a tamper-evident, SHA-256-chained bundle in a write-once store — Ed25519-signed, independently re-verifiable offline, and exportable four ways. SHA-256-chainedEd25519-signedwrite-once store4 export formatsGRC-ready feedlive ServiceNow push

Each verdict writes a single, tamper-evident bundle — SHA-256-chained to the one before it — into a write-once store: the database rejects edits and deletes at the trigger level, and when the agent acts, that downstream action is cryptographically bound to its decision by appending a new linked record, never by mutating the original. The chain re-verifies independently: each record’s hash is recomputed from its own content and every link to the prior record is checked. Nothing is reconstructed after the fact; the decision and the evidence behind it are captured at the moment the action is gated.

Signing, key rotation, storage and exports

What that means in practice. Your audit trail shows what your agent actually did — not just what it was cleared to do. The decision and the action it authorized stay linked in one record, so a reviewer sees intent and outcome together.

Signed at the source. Beyond the hash chain, every bundle is signed the moment it’s sealed — an Ed25519 proof-of-origin signature over its own hash. The hash proves the record wasn’t altered; the signature proves it came from us, and it can’t be forged without our private key. Pin our published public key once, and any bundle you download verifies offline, forever — on your own machine, no call back to us. The decision proves itself.

NewKeys roll; the record still checks out. The signing key rolls forward to a fresh version whenever you need it to — and every bundle ever signed keeps verifying, against the exact key version it was sealed under. Each bundle carries its own version and we publish the full key history, so an auditor confirms a signature offline years later, long after the key has moved on. Rotating the key never invalidates a single past decision.

i

Built to integrate. Four exports ship today: a normalized governance JSON for programmatic ingestion, a flat CSV for spreadsheets and BI tools, a print-ready HTML report that saves to a board-ready PDF straight from your browser, and an OpenLineage event feed your SIEM or data-governance tooling can ingest directly. And for the platforms your risk team already lives in: a GRC-ready evidence feed — flat, versioned rows built for the scheduled imports ServiceNow GRC, Archer, and similar platforms already run, with a published field dictionary and integrity checks precomputed on every row. And the serious-incident handoff is demonstrated, not just documented: the Article-73-style package pushes end-to-end into a live ServiceNow instance, landing as a standard incident record through the core Table API every instance ships with — no GRC module required — with the disclosure language and the package’s integrity fingerprint carried into the record itself.

01The proposed action — verb, target, and parameters, plus the calling agent and the scope it declared
02Per-model vote register — which models answered, which errored, and a summary of each one’s response
03Consensus evidence — the method, providers used, total latency, and trace ID
04Verdict & calibrated confidence — with the escalation route and any recommended modification
05Governance policy record — which policy class(es) the action triggered and the basis for the verdict
06Integrity hashes — payload and verdict hashes binding the inputs to the outcome
07SHA-256 chain — the hash linking this record to the one before it
08Ed25519 proof-of-origin signature — the bundle’s hash signed with Veridect’s key, verifiable offline against our published public key

Session, workflow, fleet

Session → workflow → fleet: the same escalate-only discipline at every horizon — one agent’s conversation, one workflow’s crew, and now the whole fleet over days.

Session

Beyond single-action rules, the gate tracks how much sensitive data an agent has read across a session — so a slow, multi-step attempt to siphon data out, where each step looks fine on its own, escalates on the outbound move.

Slow-burn session →

Workflow

Inside a declared crew, Constellation: exfiltration split across agents so that no single one looks wrong is caught at the workflow level and escalated with per-agent attribution on the record.

Station 05 · Three-agent workflow →

Fleet

We call that layer the coordination fabric: Veridect seeing coordination the agents themselves never declared — same sensitive category, same action shape, same target — across identities that share no session and no workflow.

Escalation thresholds are per-tenant policy, off until you set them. If fleet state is ever unavailable, the call falls back to the normal per-action verdict.

Station 15 · Swarm convergence →
Fleet risk

Risk can span agents that share no workflow. Hundreds of agents, every step individually fine, harm that only exists in aggregate — seen and held for a human before the send happens.

This August, fifteen frontier AI models, polled vendor-blind with live web search, could not identify another shipping commercial equivalent of that fleet layer.

Exercised at ten thousand identities. One tenant, one proposed step each, zero model calls: the first outbound step held for a person came from identity #30, all 1,496 that followed were held or blocked, a benign fleet of ten thousand drew zero fleet escalations, and the layer rebuilt its own memory from the sealed ledger after its fast state was wiped. Then the same swarm went through the published system for real: ten thousand live rulings, each signed, every outbound step after detection held or blocked, a benign control fleet of 300 rulings all cleared. The figures and the record →

Watch three identities converge on sensitive data — and the outbound action escalate for human review →
Validation and known limits

We red-teamed our own trust layer — in the open.

In short An independent Fortune 100 model-risk reviewer ran a battery of adversarial scenarios live on this system — the gate matched its pre-stated behavior on every one. adversarial scenarios, run livematched pre-stated behavioron the live system, not a slide

In May 2026, a credentialed Fortune 100 model-risk reviewer ran adversarial scenarios — across legal, finance, HR, supply chain, multi-jurisdiction, and healthcare — live on these public tools. The gate matched its pre-stated behavior on each: holding boundaries, escalating at the right thresholds, and decomposing failure modes correctly — independent, adversarial proof, run live on the system rather than asserted on a slide.

See the red-team scenarios → Read the validation record →
From the validation set
$99k paymentgreenlight
$101k paymentescalate
modify HR recordescalate
out-of-scope writeblock
access PHIescalate

Boundaries flipped at the exact policy threshold — reproducible right now on the live system.

Calibrated confidence

A confidence score that means something.

Confidence is discounted by the kind of ambiguity, not just disagreement count. Anchors observed in the external testing set:

74%

Resolvable ambiguity

The question has a defensible answer once a single missing detail is pinned down.

68%

Single-axis ambiguity

One genuine dimension of uncertainty remains — scored lower, surfaced clearly.

62%

Multi-dimensional overlap

Jurisdictional or multi-factor conflict. Discounted hardest — exactly where a human should look.

CLASS 01

Monetary threshold

Spend above a configured ceiling flips from clear to escalate.

CLASS 02

PII modification

Writes that change personal data require a second set of eyes.

CLASS 03

Protected-class adjacency

Actions near protected-class factors are held for review.

CLASS 04

PHI access / transmission

Health-data access and transmission route to the highest-risk tier.

The pre-action gate feels like the part that’s going to get serious attention from global systems-integrator and tier-1 bank buyers — this has enterprise-grade realism.
— Credentialed Fortune 100 model-risk reviewer · independent assessment, May 2026

Known limits

Attestation and cascade seal. Configuration attestation is Veridect attesting its own configuration — tamper-evident by construction, not independent third-party oversight. A cascade seal proves the hops the gate observed are intact and in the order recorded — not that nothing else happened; an action that never reached the gate cannot appear in it. And the external validation record covers the pre-action gate’s decision wire — capabilities shipped since, including these two, are verified in source and by tests, not claimed as part of that set.

Fleet classes. Accumulation is name-only — field-name categories, verbs, and hashes, never data values — and records for every governed action out of the box; escalation thresholds are per-tenant policy, off until you set them, so nothing about your existing verdicts changes until you decide it should. If fleet state is ever unavailable, the call falls back to the normal per-action verdict — the primary gate keeps running no matter what. These are the newest policy classes on the layer, additive beside the validated per-action record: the gate they extend is untouched.

Integration and buyer artifacts

From a vendor in your stack to the policy enforcement point in it.

The four providers are already collapsed behind one interface, with circuit breakers, automatic failover, and caching built in. That structural choice is the speed — it removes most of the integration work you’d take on building your own consensus layer. You integrate once, against standard auth patterns, instead of wiring up four vendors with four rate limits, four error patterns, and four auth models.

01 One integration, not four

Claude Opus 4.5, GPT-5.1, Gemini 2.5 Pro, and Sonar Pro sit behind a single REST endpoint. Circuit breakers, automatic failover, and caching are already built — far less integration work than rolling your own consensus layer.

02 Every engagement is its own tenant

Each buyer gets API keys you provision and revoke on demand, durable per-tenant policy overrides, isolated audit records, and usage limits — enforced by tenant-scoped storage, strict tenant-ID validation, authenticated-tenant resolution, and per-tenant rate limiting. The full isolation inventory is available under NDA.

03 Routing tuned to your vertical

Department- and industry-adaptive consensus weights, tuned to the decisions your sector actually makes — finance, insurance, healthcare, legal — not a one-size-fits-all model.

What an engagement includes

Adoption is a scoped engagement. Every buyer gets:

01A dedicated endpoint your engineers hit with your own data
02A tailored API documentation pack
03An engagement manager through onboarding
04Guided tenant deployment
05A procurement-ready compliance posture
Documentation · open access

Read it before you talk to us.

New The layer now watches itself — its enforcement configuration attested to a signed ledger, and whole agent cascades sealed under one signature. See the newest capabilities →
See it live

The live system, four ways in. Nothing to install, nothing to configure.

Pick one and run it yourself. Every verdict, heatmap, and audit bundle is reproducible right now.

Evaluation next step

From public docs to a trial in your own environment.

No long procurement runway just to see whether this fits. You can go from reading the docs to running Veridect on your own data in three steps.

Step 1 · No NDA

Start in the open

Run the live system yourself and read the public integration guide, white paper, and independent validation summary. Everything you need for a first technical read is public — no sign-up, no call required.

Step 2 · White-glove trial

White-Glove Enterprise Trial

When you’re ready to see it on real work, we stand up a dedicated trial in an environment you control — your data, your workflows, your team — before any commercial discussion.

Step 3 · On board

Private integration

Once we’re working together, a mutual NDA opens a private integration document built to your specs, followed by hands-on working sessions to wire Veridect into your stack.

Start a white-glove trial →

How long does it take? A private sandbox in a day; production typically about two weeks — the pace is set mostly on your side (security review, key provisioning, access approvals), and our side is ready on day one. The five questions every executive asks, answered plainly →

Talk to us

See it on your own workflows.

Run the system yourself first. When you’re ready to put it in front of your own data and team, we’ll set up a working session in an environment you control.

Contact us →