ProductsSolutionsPlatformTrustCompanyBook a demo
Trust & claims

What we claim — and what we don't.

We build verification tools — so our own words get the same test. If anything here reads stronger than its evidence, treat it as a bug and tell us.

What we do claim

  • Our tools do the specific operations described — sandboxing, SBOM/CVE scans, behavioural UI checks, evidence-based diagnosis, signed verdicts.
  • Signed outputs are independently verifiable, by the method described.
  • Figures describe what was actually measured — never a market size dressed as a track record.
  • Estimates are labelled, with their basis shown.
  • Our commercial model — including affiliate referrals — is disclosed.

What we don't claim

  • That anything is unbreakable or compromise "impossible". Security is measured, never absolute.
  • Certifications we haven't completed. No badge is displayed before it's earned.
  • Invented customers, logos or case studies. Scenarios are labelled illustrative.
  • That findings are legal determinations. They're engineering signals for your review.
  • That our tools act on your systems. They advise; you decide.
Claim → evidence → limit

Each headline, with its proof and its boundary.

For every product, the claim we make, what backs it, and where it stops. Nothing here should surprise a security or procurement team doing due diligence.

VerditNxtGen

"Signed evidence about an open-source AI tool before you deploy it."

Evidence: Docker sandbox · syft SBOM · grype CVE · OWASP LLM checks · Ed25519-signed quorum reports.
Limit: Certifies a specific version under a specific test — evidence for review, not a warranty.

Verdit CLI

"Flags risky checkout-UI patterns in CI, fully offline."

Evidence: Static + behavioural checks · zero egress · SARIF and exit codes.
Limit: QA signal, not a legal determination; no headline accuracy number until the corpus supports one.

Causa

"Diagnoses why an AI incident happened, from payload-free telemetry."

Evidence: Payload-free OTel ingestion · evidence graph · air-gapped deterministic verify engine.
Limit: Diagnosis is a hypothesis for engineers, not auto-remediation; seeded knowledge is labelled.

Axiom

"A signed risk verdict a smart contract can verify — advisory only."

Evidence: Quorum-proven inputs · replay-proof signatures · real-EVM-tested contract (solc 0.8.24).
Limit: Advisory, never a kill-switch; unprovable inputs return UNKNOWN.

BizOpsTool

"Estimates SaaS-stack waste and ranks open-source swaps."

Evidence: Transparent per-seat × team × overlap calc · client-side calculator · repo-signal rankings.
Limit: Directional estimate, not an audited figure; referral links disclosed.

Interactive proof

Don't take our word for it — take the signature.

This is what verifying one of our evidence bundles looks like. Press the button and watch each check run.

evidence-bundle.json
subjectagent-framework@2.4.1
verdictVERIFIED
digestsha256:7b3e…f10c
signered25519:9f3c…a1d4
nonce5
Canonicalise the bundledeterministic
Recompute SHA-256 digestmatches
Fetch signer public keypublished
Check Ed25519 signaturevalid
Confirm contributor quorum3 / 3
Signature valid — bundle unmodified since signing. Verified without contacting OneZero.

Interactive walkthrough of the real verification sequence, using an illustrative bundle.
The same steps run offline against our published public keys.

Certifications & audits

We'd rather be verifiable than badged.

Formal certifications are valuable, but a logo is not evidence — and displaying one before it's earned is exactly the kind of claim we build tools to catch. So we keep this simple and honest.

Our position today

  • We publish no certification badge we have not completed. If you don't see one here, we don't hold it — and we won't imply otherwise.
  • We describe our actual security practices factually, in plain terms, rather than through the visual language of accreditation.
  • When we begin or complete a formal audit, we'll state its exact status and scope here — not before.

For your due diligence

  • Several products run air-gapped, with zero-egress code paths — so you can inspect their behaviour inside your own environment.
  • Signed outputs are verifiable independently, without trusting our servers.
  • Technical detail for a security review is available under NDA. Start a conversation →
Hold us to it

If a claim outruns its evidence, tell us.

We mean the standard on this page literally. Bring a system for us to run against, or a question about any claim we've made — both get a straight answer.