RESOURCES — THE RECORD

Inspect the evidence. Read the limits.

Architecture, current product state, technical artifacts, and postmortems — published for scrutiny.

START HERE — THE RECORD, IN READING ORDER
FOR YOUR SECURITY TEAM: TRUST + COMPLIANCE · FOR YOUR ENGINEERS: WHITEPAPER + BLOG · FOR YOUR CONTRACTING OFFICER: TRUST + POSTMORTEMS
MISSION BRIEFS & FIELD NOTE — UNGATED, NO FORM
THE EVIDENCE CENTER — ARTIFACT INDEX

The documents above are the argument. These are the artifacts — cryptographic material you can check yourself, in your own browser, without talking to us.

ARTIFACT WHAT IT CAN ESTABLISH
Gateway receipt integrity package One isolated page containing the local verifier, staging sample and tamper test, format documentation, and published staging key. It recomputes the receipt hash, verifies the Ed25519 signature against that key, and checks continuity of the supplied chain segment. It does not re-run policy, prove chain completeness beyond the supplied segment, or establish production deployment or authorization. Receipt checks run locally; the verifier makes no outbound data requests and never uploads receipt data. No account.
AARM Core self-attestation Per-requirement conformance record against CSA's AARM v1.0 — including the gaps. The public attestation document is the controlling record.
Agent Governance Toolkit comparison Where Microsoft's Agent Governance Toolkit and an in-path enforcement layer do different jobs — control-plane governance versus a deterministic ruling at the action seam.
Enforcement & audit evidence The canonical assurance record — product-specific decision-record profiles, current availability, limitations, and the milestone status behind every claim on this site.
RECEIPTS, PER PRODUCT
MISSION AUTHORIZATION GATEWAY · FLAGSHIP
The Gateway staging build emits Ed25519-signed, per-organization hash-chained receipts at the edge seam. The browser verifier checks receipt integrity, the published staging key, and continuity of the supplied segment.
AGENT GOVERNANCE
The connected proxy issues HMAC-signed decision records, verified inside the deployment. Product scope and current status are stated on Trust.
AI CHAT FIREWALL
Every ruling writes an audit-ready, tamper-evident receipt — feeding the compliance program you already run.
The browser verifier and published staging key are Mission Authorization Gateway artifacts. It checks receipt integrity, signer key, and supplied-segment continuity; it does not re-run policy.
SEEN THE RECORD?

Now watch it rule on your workflow.

Request a 30-minute Boundary Review

Bring one AI workflow, one consequential action, or one data boundary.