Who checks the verifier
Nothing accredits Turiya. This page is what we can prove about our own independence, and what we cannot, written before the standard we are measuring against exists.
A self-assessment is a self-signed certificate.
That is not a figure of speech. It is the exact failure this company exists to name. An AI system's report of its own success proves it said so, not that it happened. A verifier's report of its own independence proves the same thing about us. So this page is built in two halves. The first is what we claim about ourselves, and you should discount it accordingly. The second is what you can check without believing us, and it is the half that matters.
We have no third-party attestation of anything on this page. We would like one. We cannot buy one, and we would not trust one we had bought from the people we pay.
Self-assessment against the reported criteria
California enacted an independent-verification framework on 9 September 2026, with criteria due 1 January 2028 and an auditor registry due 1 January 2029. The criteria do not exist yet. These are seven criteria as reported in secondary coverage, not independently verified against the final implementing rules. We have not read the statutory text, and where our reading is an interpretation, it is marked.
| Criterion as reported | Position | Basis |
|---|---|---|
| 1 No auditing a system the verifier designed or operated in the prior 12 months | MET | Turiya has never designed, built, operated, sold or resold an AI system. Every receipt we publish is about a system someone else built. We are not a lab, not an agent vendor, and we hold no stake in anything we assess. |
| 2 Compensation may not be contingent on findings | MET | No success fees, no commission on findings, no royalties tied to a verdict. Pricing is a fixed engagement fee. No engagement has ever been priced on outcome, and this binds future pricing. |
| 3 Must disclose evidence gaps | MET | We publish our own failures by design: a withdrawn-receipts page, an errata section on the homepage, and a document listing every receipt we cannot verify, with the cause recorded as not established rather than guessed. |
| 4 Must identify deficiencies and remedies | MET | Section 3 below is a deficiency-and-remedy list about us, not about a client. The same audit was run against our own catch record and found zero additional publishable catches. |
| 5 Independence from the subject of verification | MET | We take no money from the vendors whose systems we assess, no money from model providers, and hold no inventory, resale agreement, referral fee or equity in anything we verify. |
| 6 Registration under the state criteria (due 1 January 2028) | NOT MET | The criteria do not exist yet. We cannot be assessed against a standard that has not been published, and we will not imply otherwise. We commit to assessing against them and publishing the result, whichever way it goes. |
| 7 Registry listing (due 1 January 2029) | NOT MET | The registry does not exist. We are not currently eligible. See section 3. |
Five met, two not met. The two that fail, fail because the standard and the registry do not exist. We would rather leave them failing than score ourselves against a document nobody has written.
Independence is a list of things you do not have
What we are independent of: no relationship with the model providers we test against, no contract or grant or compute credit from them, no resale agreement, no referral fee, no equity in anything we assess, and no customer-contingent verdicts. We have published the adverse finding as the flagship artefact of this company. A verifier whose business depends on pleasing the vendor does not do that.
The conflicts we do have, stated plainly:
So is every financial auditor. It is the structural weakness of the whole profession, and it is why the profession grew mandatory rotation, ethical walls and independent oversight. We have none of those three, because we have no clients yet. It is the first thing to build once we do.
A verifier that picks its own test set can pick its own results. Our mitigation is that we verify against the claimant’s own stated claim and the project’s own test suite, never a metric we invented, and that the raw test output is published beside the verdict.
Concentration of judgement is a real independence risk, separate from a conflict of interest, and no policy fixes it. The remedy is institutional: staff, rotation, eventually an independent board. None of that is available today.
What we fail
Reported criteria require a verifier to identify its own deficiencies and remedies. Here they are, about us.
| Deficiency | Remedy | Status |
|---|---|---|
| No accreditation Not accredited by any ISO/IEC 17021-1 body, and not assessed against ISO/IEC 42006, the standard for bodies auditing AI management systems. | Singapore’s AI TAP scheme accredits testing firms, launches Q3 2026, and charges no fees. It is the only route reachable without capital. | Open |
| No independent legal entity Holynt Technologies Pvt Ltd is a company of one. The verification function has no separate governance, key custody or board. | Incorporation of the verification function on five named triggers. See section 5. | Gated |
| No financial independence Revenue is zero. Independence from clients is a function of scale, not of policy. | No remedy that is honest. This is the hardest gap on the list. | Open |
| No external timestamp authority at scale RFC 3161 timestamps are issued by FreeTSA alone. | A multi-TSA pool, with fallback across independent authorities. | Open |
| No public transparency log Receipts are signed and content-addressed, but not anchored in an append-only public log. | Sigstore Rekor anchoring. Attempted; blocked on a scheme so client receipts can be anchored too. | Deferred |
| One verifier, no second opinion Nobody re-runs our work independently. | Publish the harness so any verdict can be re-run by a stranger. | Open |
We are also not ISO/IEC 42001 certified and do not claim to be. That standard applies to organisations developing or using AI systems. We are neither.
Verify this page without believing it
This is the only section that does not depend on our honesty. Every row is a live number or a link to the artefact itself.
| Claim | Check it yourself |
|---|---|
| We publish adverse findings | The board carries 10 signed receipts. 10 of them carry a verdict of falsified, the adverse finding. That is every one of them, and it is not a coincidence: the board is a catalogue of catches, so its contents are adverse by construction. We do not sign a receipt for a system that succeeded, because succeeding is not a catch. Open the board and read any of them. |
| Our receipts are not fabricated after the fact | Each is content-addressed (SHA-256 over a canonical payload) and Ed25519-signed. The build fails and stops if a published receipt is tampered with. Verify any receipt in your browser on the receipts board. |
| Every receipt names its signing key, and you can recompute that name | Key ids are not assigned by us. An id is the first 16 hex characters of the SHA-256 of the public key, so you can derive it from any receipt yourself. Every published receipt carries 251b14346af43d1d. That raises a fair question about our key design, and it is answered in full in the note below this table. |
| We publish our rejects | 6 withdrawn receipts are live at /receipts/rejected. They are the negative, not the record. |
| We publish our own errors | The homepage carries an errata section, and the methodology page lists the false catches we destroyed rather than published. |
| We did not build the systems we assess | Every receipt is against one of 6 public repositories: click, fastapi, httpx, jinja, rich, sympy/sympy. We have no commit in any of them. |
| We do not claim our verdicts are correct | Re-running our work is possible in principle and not yet packaged. Until it is, you are trusting our judgement on the substance while being able to verify our record on the process. That is a real gap and it is listed above. |
One thing that looks wrong, and is not.
Check the receipts and you will find the same key id on every one of them: 251b14346af43d1d. Key ids are not assigned by us. An id is the first 16 hex characters of the SHA-256 of the public key, so you can recompute it yourself. Our key design says an offline master certifies rotating signing keys and never signs a receipt. If that id is the master's, something is inconsistent. Here is the whole of it.
Before 13 September 2026 there was no master. There was one key, and it signed everything, because there was nothing yet to separate. That day the roles were split: the key that had been signing was designated the company's identity and taken offline, and a new everyday key was minted to sign from then on. The harvest that produced these receipts ran earlier the same day. So the rule binds from the split forward, not retroactively. The master did not sign these receipts, because the master did not exist as a role when they were signed.
We did not re-sign them and we will not. Quietly re-signing published evidence is what we would end an auditor's engagement over. The history stays on the old key, and this paragraph is the announcement. The permanent cost, stated plainly: the private key that signed these receipts is the same key now designated catastrophic-if-leaked. If it is ever compromised, these receipts are retroactively in question. Not because they were wrong, but because the key attesting them would no longer be trustworthy. There is no fix for that.
When we split the verification function out
A second company owned entirely by the same person, controlled by the same person and staffed by the same person is not more independent than the first one. It is the same person with two name tags. Independence is a function of people and relationships, not of paperwork.
So we are not claiming that incorporating today would make us independent. It would not. We are committing to something narrower and checkable: naming the events after which a single entity can no longer hold both the verification function and whatever else the company does, in advance, so the decision is made in public rather than discovered later.
The conflict stops being hypothetical. This is the rule that made the big audit firms sell their consulting arms.
Consulting, system building, resale, brokerage or advisory. The moment there is a second thing to sell, a client can pressure the first thing.
Investors acquire a stake in the entity whose independence we are asserting. Their interest and the verifier’s independence are not the same interest.
Real independence requires someone who can disagree with the founder and be right. Filing this trigger is admitting a one-person verifier is a structural limit, not a stage.
Singapore’s AI TAP, an ISO/IEC 42006 assessor, or the California criteria due 1 January 2028. The first time the requirement would be externally defined rather than self-imposed.
This is not a promise that we will be independent. Triggers 1 to 3 concern conflicts. Only trigger 4 begins to touch independence, and one additional person is a start, not a solution. It is also not a promise about timing: if none of the five fires, remaining one entity is the correct outcome, because paperwork imposed before there is anything to separate is ceremony.
What binds us, whether or not the standard requires it
- We will publish any verdict that falsifies a claim, including our own.
- We will not take compensation contingent on a finding, in any form, ever.
- We will not assess a system we or our affiliates built or operated.
- We will publish our rejects. The negative is part of the record.
- We will re-issue this page within 90 days of the state criteria being published, including if the answer is that we fail.
- We will not describe ourselves as accredited, certified, registered or approved until a body with the standing to say so has said so.
This page is not a certification, an accreditation, a registration or an audit. Nothing here has been checked by anyone but us. It is a statement of position, published early, with its own weaknesses volunteered, on the theory that the only way a verifier earns the right to verify others is by being visibly willing to be verified.
We are the witness, not the judge. Our verdicts are falsified, not_falsified, certified or indeterminate. We never say "true". The same asymmetry applies here: this page can be falsified, and it cannot be proven.
version 1.0 · issued 2026-09-14 · Holynt Technologies Pvt Ltd · re-issued within 90 days of the state criteria being published, or on any material change.