A certification is audited over a handful of days and valid for three years. A questionnaire is self-reported. A vendor's log is the vendor's log.
None of that is dishonest. It's structurally the wrong direction for evidence to travel.
| Actor | Identity |
|---|---|
| Person | Device certificate, tied to an individual |
| Device | Node certificate |
| CI run | Scoped, time-bound identity per run |
| AI agent or script | Scoped, time-bound identity — not an inherited credential |
The last row is where most tooling has nothing to say. Rules written for people — including Vietnam's Circular 09, which requires that individual responsibility be determinable at every moment of use — don't yet have an answer for what happens when an automated process acts.
We're not going to pretend this is solved. It isn't — not by us, not by anyone. Our take is narrow: the same primitive that gives a person an identity gives a script or an agent one too. That's it, and we'd rather be corrected than flattered on it.
That second column matters for adoption. A standard your vendors resist isn't a standard. Tell them directly: the ledger records access and release events, not their internal development rhythm.
The server-side invariants — including the append-only ledger — run in production and are checked by an open test harness. They have not been through independent third-party audit.
The client agent is open source and Cosign-signed, so your team can review what runs on your own nodes rather than take our word for it.
Defining the scope of the first independent audit is one of the things we're asking design partners to do with us. If that's a conversation you'd want a seat in, that's the conversation.