How it runs

The work runs inside your environment. We deploy a harness into your infrastructure (your CI, your cloud account, or an ephemeral VM we destroy afterwards) and it never leaves. We retain the receipt, not the material.

This is the market standard for enterprise AI evaluation, and it is also the difference between a buyer who must vet us as a data processor and one who has nothing to vet.

The five steps

  1. Capture (your environment). Extract the claims the system makes about its own effect, from its logs, its reports and its self-declarations.
  2. Re-execute (your environment). Independently re-run the effect against ground truth: the reconciliation math, the code, the data transform.
  3. Falsify (your environment). Adversarially probe for the claim-vs-effect gap.
  4. Adjudicate. For claims with no answer key, signed expert judgment.
  5. Sign and deliver. Ed25519-sign each verdict, content-address it, and hand you the receipts. We publish nothing of yours.

The one honest exception

Some claims have no answer key and need a human expert to read material. If that expert is ours, content moves, and calling it anything else would be a lie. The three options are:

  • scope the engagement to deterministic claims only,
  • have the expert work inside your environment as well, or
  • disclose the transfer explicitly in the data-processing agreement.

We tell you which one applies to your engagement before you sign, not after. We will not describe a judgment engagement as “your data never leaves” when it does.

What we never hold

Your data, your model, your prompts, your outputs and your customer records. What we keep is the receipt: a signed record of what was checked, what the effect was, and when. The receipt contains no customer material.

Why this shape

Taking custody of your data would make us a processor. That means a data-processing agreement, a security questionnaire, retention and deletion obligations, and a buyer who must audit us before they can buy. Not taking custody means there is nothing to audit.

For a firm with no SOC 2 and no security team, that is not a legal nicety. It is the difference between being sellable now and needing an audit budget first.

Getting a harness into your environment

The real gate on a first engagement is deployment access, and it will be the slowest part. We start with the deterministic, low-sensitivity workflows (reconciliation math, not live trading) so that the first deployment into your CI or cloud account is a small one.

Ready to scope an engagement?

START WITH A PILOT