BitProofevidence for AI underwriting
Live demo Sign in Get a free report

For AI vendors in procurement and insurance review

Answer the AI questionnaire once, with evidence they can check themselves.

You are forty questions into a security review written for software, about a system that behaves like a probability distribution. BitProof compiles the answers into one evidence pack across eight assessed domains, seals every run it executes with a signature, and gives the underwriter, broker or auditor a free read-only workspace to check those signatures — without trusting us, or you. One domain runs live today; we label the rest rather than dress them up.

Creating an account is self-serve and free: you get a workspace, the live engine and a shareable pack immediately. The demo needs no account at all. Prefer email? Write to platform@vbounds.com — that address is on this page so you can copy it if your machine has no mail client configured.

What is in a pack v1 · signed
  • 01Eight assessed domains Mapped to AIUC-1 control areas, cross-mapped to EU AI Act Annex IV headings.
  • 02One live attested run Computational integrity: signed, bit-exactly re-verifiable. LIVE
  • 03Seven domains shown as sample data Labeled sample everywhere a score appears. Not measured yet. sample
  • 04A gap list, from the documentary workflow Governance and data-provenance items a questionnaire will ask for and you cannot answer today, with severity. Collected as documents — not scored.
  • 05A relying-party workspace link Read-only, scoped to one pack version, expiring, revocable.
  • 06A reliance letter on request Named party, purpose-limited, liability capped.
Nothing in a pack is presented as measured unless it was measured.

What you get

One assessment, one evidence pack, one link to share.

The pack is built to be read by someone who is deciding whether to insure you, buy from you, or sign next to your name — so every claim in it carries its source, its date and the model version it was measured against.

Eight domains, standards-mapped

Eight machine-tested domains, organized against AIUC-1 control areas and cross-mapped to EU AI Act Annex IV headings — so a European buyer's technical-documentation request and a US insurer's application are answered from the same evidence, not from two separate scrambles. Governance and data provenance are handled by a separate documentary workflow that produces the pack's gap list; they are not scored domains.

Mapping means the evidence is filed against a published standard and cited to it. It is not certification, and we are not an accredited body.

Sealed runs

LIVE

Every engine run emits a signed attestation: harness version hash, input-sample commitments, environment fingerprint, results. Ed25519 over domain-tagged canonical JSON — the same receipt format the referee has used since v0.

Change one character of the signature and verification fails. The demo lets you do exactly that and watch the check turn red.

A relying-party workspace

Share one link. The underwriter opens a read-only workspace: scores per domain, drill-down to the raw run, and the receipt they can verify in their own browser. No account with us, no membership in your org, no PDF round-trip.

Links are scoped to one pack version, they expire, and you can revoke one at any time.

Reliance letters

When an insurer or auditor needs to formally rely on the pack, we issue a letter to a named party: purpose-limited, point-in-time, pinned to a model version, with liability capped at the fee or our professional-indemnity limits.

The pattern is borrowed from environmental and structural reliance letters, because blanket disclaimers do not survive contact with a known relying party.

All eight domains — what each measures, and what runs today
#DomainProduced byToday
01Performance & accuracy Metrics on your defined test sets, plus per-subgroup accuracy. Enginesample
02Hallucination rate Grounded-reference benchmarks and a third-party-style harness. Enginesample
03Robustness Perturbation suites: casing, OCR noise, distribution shift. Enginesample
04Adversarial resistance Prompt injection, jailbreak and red-team batteries. Enginesample
05Data leakage PII, credential and proprietary-content leak probes. Enginesample
06Bias & fairness Selection rates and impact ratios (Local Law 144 formulas), score gaps. Enginesample
07Security posture Endpoint exposure, unsafe tool-call probes, agent identity. Enginesample
08Computational integrity Signed proof that this model version, on this hardware, produced these results on these samples — re-verifiable bit for bit, with divergence localised to a single primitive operation. EngineLIVE

Domain 08 is the one that runs for real today. The other seven are sample data and are labeled sample wherever a score is shown — in the demo, in the console and in the pack. There is no ninth or tenth domain: a pack contains these eight rows and nothing else.

Alongside them, a documentary workflow. Governance and human oversight (accountable owner, risk taxonomy, change management, incident-response plans and the incident log) and data, legal and regulatory provenance (training-data datasheets, DPAs and processing map, terms and AI addenda, vendor due diligence) are collected as documents, not measured. Today the workflow does one thing: it lists what is missing as severity-tagged gaps on the pack, so a relying party sees the holes rather than guessing at them. Those gaps carry no score, and we do not present them as a domain result.

How the standards mapping works

AIUC-1 is the spine. Each domain maps to AIUC-1 control areas and every artifact carries its control reference, so an auditor working to that standard finds evidence where they expect it rather than reading our taxonomy first.

The same artifacts are cross-mapped to EU AI Act Annex IV headings — system description, development process, monitoring, and test reports that are dated and signed. The signed run attestation is what upgrades "test reports, dated and signed" from a filing convention into something a third party can check.

What mapping is not: it is not an assessment against a standard we are accredited to certify, and it is not a statement that any regulation requires this pack. It is your evidence, organized the way the people asking for it already think.

How the assessment reaches your system

Three deployment tiers, one identical pack format. Tier one tests a hosted API endpoint. Tier two runs an agent inside your VPC. Tier three is an air-gapped runner for environments that will never allow an outbound call.

In tiers two and three only signed evidence artifacts leave your network. Model weights and API keys are never sent to us and are never stored by us — the platform has no field to put them in.

For underwriters, brokers and auditors

You should not have to take the vendor's word for it. Or ours.

The relying side pays nothing. That is deliberate: an evidence layer only works if the people who carry the risk can use it without a procurement cycle of their own.

A free workspace

Open the shared link and read the pack: scores by domain, the runs behind each score, the gap list the vendor has not closed, and the version history. Read-only, no account, no cost, now or later.

Verify the signatures yourself

Each run attestation is Ed25519-signed over canonical JSON. Check it in the workspace, or take the receipt and the public key and check it with your own tooling. A pack that has been edited after sealing fails the check — including if we edited it.

Reliance letters that mean something

Request a letter naming your organization as the relying party, scoped to the pack version and model version you read, with a stated liability cap and restricted-use terms. The vendor's own duty of care is expressly preserved, not transferred.

Where we are, stated plainly

One domain is real today. We label the rest, rather than hoping you don't ask.

An evidence company that overstates its own evidence has already failed its one job. So here is the line between what is built and what is designed, in the same place you found the sales pitch.

Live today LIVE

The computational-integrity engine. It is a bit-exact referee for a pinned inference operator at tolerance zero: given two machines that ran the same computation, it names the exact row and step where they first diverge, says which side is arithmetically correct against an IEEE-754 reference, and tells an honest hardware difference apart from a fabricated trace. It emits an Ed25519-signed receipt. It runs on real Qwen2.5-7B and TinyLlama norm tensors, compiles to WebAssembly, and produces identical hashes on x86-64 and wasm32 — held there by a golden-hash gate in the test suite. The demo executes that engine in your browser; nothing about the verdict is scripted.

Sample data sample

The other seven domains. The harnesses behind them are largely open-source assembly and are being integrated, but they are not running yet — so every score you see for them in the demo, the console and the free report is illustrative and is labeled sample at the point of display. We will not show you a sample number without that label, and we will not describe one as measured.

What we do not claim

No regulation requires this pack, and we do not pretend otherwise. The EU AI Act's high-risk obligations land later and may land differently; several US state rules have been narrowed. We are not an accredited body, we issue no certificate, and mapping to AIUC-1 or Annex IV is organization and citation, not conformity assessment. We also never build or tune a model we assess — that is the only way the neutrality claim survives inspection.

The engine's own limits

Detection is O(n). You cannot detect a wrong fused multiply-add without recomputing it, and we will not tell you otherwise. Only the dispute is O(log n): once two parties disagree, bisection over committed checkpoints settles it in a logarithmic number of queries on one primitive operation. The saving is in resolving arguments, not in avoiding the work.

More limits, including the ones that are awkward for us

Scope. Version zero of the referee adjudicates one operator (RMSNorm) on a simulated vendor fleet plus real-silicon probes. It is not yet a whole-model attestation, and one operator on one machine is a small share of any real inference bill.

Our attacks are our own. The adversarial suite proves the referee catches the attacks we thought of, including a fabricated trace that passes naive trace-checking and is still rejected by re-execution. That is evidence, not a security proof, and we would rather you knew which it was.

Nobody has relied on us yet. No unaffiliated insurer has formally relied on a BitProof pack to date. Being first is the offer and the risk, and it is priced into a first report costing nothing.

Public inputs only. The integrity receipts commit to inputs and weights that the relying party is allowed to see. Attesting over data you cannot show anyone is a different, harder problem and we are not claiming it.

Pricing

From $15,000 per year, per AI system

What that buys today: one measured domain. Computational integrity runs live and is signed; the other seven are labeled sample and are not measurements. The price reflects that, and the first report is free so you can judge it before paying anything — see Where we are, stated plainly.

The first report is free — one system, no contract, no card. After that, what moves the number is how many systems you cover, which deployment tier you need, and whether you want reliance letters issued to named insurers.

Pricing is confirmed on a call. We quote once we have seen the system, because quoting before that would be guessing at your scope and we would rather not start there. A reliance letter is separate and optional: $2,000–$5,000 one-time, invoiced to you, the assessed party — never to the insurer or auditor relying on the pack. That figure is shown to them in the workspace too, so it cannot reach you second-hand.

No mail client? The address is platform@vbounds.com — copy it from here.

Who pays, and who never does

The assessed party pays. You are the one being asked for evidence, and credible evidence protects you: a misrepresented answer on an insurance application is how claims get denied later.

The relying party pays nothing. Insurers, brokers, MGAs, reinsurers and auditors read packs, verify receipts and receive reliance letters at no charge. There is no seat fee, no viewer tier, and no plan where verification is the upsell.

Start with the free report, or start with the demo.

The demo takes about a minute and proves the one thing that is hard to fake: run the fabricated-trace scenario, verify the receipt, then flip a character in the signature and verify it again.