Forseti judges.
Every output carries its evidence. Forseti binds signed provenance, named algorithms and inspectable audit lineage to everything the enclosure produces, so an accreditor, an auditor, or you can check the claim instead of trusting the vendor.
Evidence, not attestation
Every output traces to its inputs, transforms, model and keys, and the trace is signed. A claim without its lineage does not leave the enclosure.
No step is a black box. Each operation cites the algorithm and the standard that governs it, down to the cryptography that sealed the inputs.
Audit lineage exports as an evidence pack a third party can verify independently. What an accreditor needs is a product output, not a meeting.
Replaces vendor attestation
The industry's standard answer to "how do we know?" is a vendor's signature on its own homework. Forseti inverts that: the system produces the evidence as it works, and anyone with the pack can check it without asking Veldris anything.
For buyers with accreditors, auditors and regulators to satisfy, this is the difference between a procurement argument and a verification exercise.
$ forseti attest report-2214
report-2214 · assured
inputs: 3 objects · lineage signed · ml-dsa-65
model: pinned sha256:9f31…c04a · algorithms cited
evidence pack complete · export: forseti-2214.epk
On the record
| Property | Specification |
|---|---|
| Scope | Every object and every inference output in the enclosure. |
| Provenance | signed, append-only lineage · ML-DSA-65 (NIST FIPS 204) |
| Evidence | Exportable packs, verifiable independently by accreditors and auditors. |
| First deployment | Ships alongside Midgard Core and Mimir. |
| Replaces | Vendor attestation. |