U.S. patents pending · software + silicon

AI that answers for every trade before it happens.

EthicVault is the deterministic governance layer between AI and the real world. Every action is measured, proof-bound, and validated in strict order — then passed, audited, or blocked. Same input, same verdict, every time. In software for the enterprise, and in silicon at the edge.

Friction Gate · IllustrativeEnforcing

Candidate action

wire.transfer.execute · $2.4M

BLOCK
Schema integrityOK
Proof anchorOK
Replay uniquenessFAIL
→ WORM ledger: digest already consumed
100%

Deterministic verdicts

0.47 ms

Mean decision latency

<1 mW

ASIC average power · pre-silicon

Policy-bound governance

We govern AI by the rules you already have.

Our Policy Compiler turns your board-approved policies — not a new framework — into a deterministic execution boundary. Purpose-built for the sectors that answer to a mandate.

01The Platform

Four modules. One chain of custody.

From the moment a model proposes an action to the moment that action touches the world, custody never leaves the architecture — measured, classified, decided, and proven.

Measure

Resonance Engine

Every AI output is scored — in a single decision — against both an approved reference and a prohibited one, with embedding-space distortion corrected first. Outputs that merely look on-topic are separated from those that are genuinely aligned.

  • Dual reference: approved vs. prohibited
  • Anisotropy-corrected coherence
  • Built from datasets or your policy
Classify

Friction Gate

A three-tier deterministic classifier — PASS, AUDIT, BLOCK — computed in fixed-point arithmetic against frozen thresholds. Hard-veto priority is non-negotiable by design.

  • Bit-identical across backends
  • Guard-band routing to audit
  • Normative floor hard veto
Decide

Policy Engine

The only component with authority to decide — and it acts exclusively on proof-bound state after schema, proof-anchor, and replay validation succeed, in strict order.

  • Ordered, non-bypassable validation
  • Single-use payload digests
  • Sector-tuned thresholds
Prove

WORM Audit Chain

Every verdict is serialized, hashed, and anchored under a Merkle root in write-once storage. Years later, an examiner replays any decision byte-for-byte.

  • Append-only, hash-chained ledger
  • Merkle-batched at full throughput
  • Regulator-ready evidence
02Why Deterministic

Governance you can replay in court.

Probabilistic guardrails give different answers on different days. EthicVault's verdicts are mathematical functions of frozen state — reproducible byte-for-byte, years later, in front of an examiner.

Architecture protected by pending U.S. patent applications — method and silicon.

10,000

basis points

Fixed-point state

Floating-point ambiguity is eliminated at the boundary: every governance variable is scaled to integers over 0–10,000. The same submission produces the same bits on any CPU, GPU, or JIT backend.

3

ordered validations

Strict sequence

Schema → proof anchor → replay. The policy engine contains no code path that reaches threshold evaluation without all three succeeding — failure anywhere is an architectural BLOCK.

Two references, one decision

Every output is scored against both — the verdict follows the margin.

PASS
Coherence · approved reference88/100
Coherence · prohibited reference14/100
Discrimination margin+74

High coherence with the approved reference, low with the prohibited — a wide, clean margin. The action passes.

Controlled ablation

A single-reference gate looks flawless — right up to the cases it was built to stop.

Same held-out set, same broad calibration, same architecture. One variable changed: whether the output is scored against an approved reference alone, or against an approved and a prohibited one in the same decision.

Single reference

Legitimate casesall passed
Prohibited cases passed4 / 10

Four prohibited cases cleared the gate while every legitimate one passed. The surface metric shows nothing wrong.

Dual reference

Legitimate casesall passed
Prohibited cases passed0 / 10

Every prohibited case blocked, with no legitimate case lost. The second reference is what closed the gap.

From the internal technical evidence report: a controlled experiment on a synthetic held-out set, prototype stage, limited sample. It is directional evidence for the architecture, not an operational accuracy estimate, and no independent party has reproduced it.

03Beyond semantic similarity

The same sentence, the same authority, and a different verdict.

Two actions can look equally safe in language and carry identical formal authorization, yet create radically different operational consequences. Before execution, EthicVault evaluates authority, evidence, dependency topology, cascade reach, exploitability and downstream consequence — none of which is a function of what the request says.

Why the decision cannot be semantic

In the internal evidence report, semantic proxies separated approved from prohibited text almost perfectly — intent and risk both at AUC 1.000. They still could not carry a decision. Across five feature families, automatic PASS on static text stayed between 0 and 10%; everything else was routed to audit rather than guessed.

01

Authority, without embeddings

Whether the caller actually holds the right, resolved from signed grants and authorization geometry. No sentence can phrase its way into a permission it was never issued.

02

Evidence digests

A claim must cite a registered evidence ID. The engine checks that the reference exists and is bound to this action — not that the prose reads as though it were substantiated.

03

Dependency topology

What sits behind the target. The same operation against a leaf node and against a broker that forty-seven services depend on is not the same operation.

04

Cascade analysis

What fails next when the target fails. Reach is computed across the dependency graph, not inferred from the wording of the request.

05

Exploitability

Whether the resulting state opens a position an adversary can work with — gameability evaluated before that state is allowed to exist.

06

Consequence forecasting

The projected operational cost of proceeding, and of the failure proceeding would enable. It is scored as part of the verdict, not attached to it afterwards as a warning.

07

Execution restriction

The output is not a score handed to something else to interpret. It is a bound on what may run — PASS, AUDIT or BLOCK — enforced at the boundary, before the action reaches a connector. A high-consequence action does not proceed with a note attached; it does not proceed.

Reference scenario · illustrative

One instruction, three targets, two verdicts.

The same maintenance instruction, issued under the same signed authority, against three nodes. Nothing in the language differs, and nothing in the formal authorization differs.

Request text
Identical across all three
Formal authorization
Granted in all three
Semantic coherence
No material difference
  • K1

    Staging worker

    2 dependents · contained blast radius

    AUDIT
  • K2

    Edge identity broker

    47 dependents · cross-domain cascade

    BLOCK
  • K3

    Reporting replica

    5 dependents · contained blast radius

    AUDIT

Language and formal authority were constant. Topology and consequence moved one of the three to BLOCK. A gate that reads only the request cannot produce this table — it has no term for what sits behind the target.

The scenario is an illustration, not a measured result. The dimensions behind it are implemented and exercised: the internal technical evidence report records deterministic labelling and tested monotonicity across consequence, cascade, gameability, dependency and authorization geometry, at prototype stage. Real-world forecasting accuracy is not established, and no independent party has reviewed it.

04 · Assurance

Evidence, not promises.

Three layers, in the order an approval path needs them: what has been measured, what you can open and check, and what we are not claiming yet. Deployment stays yours throughout — on-premises, air-gapped, or single-tenant private VPC, with customer data never training models and keys never leaving your control. Read the security brief →

Measured now

Figures with a scope line attached

Every number here is from the internal technical evidence report, measured on one commodity workstation. Read the line under each one: a figure is worth exactly what its scope allows.

10 / 10

Live test batteries passed

The main runner completed all ten and the provenance verifier reported ALL CHECKS PASSED on the same pinned commit.

1,000 / 1,000

Identical digests on repeated runs

Same input, pinned environment. This is the claim the rest of the platform rests on.

5 × 20,000

Processes × frozen inputs, one digest

Five independent processes over twenty thousand frozen inputs reduced to a single SHA-256 digest — one distinct value across every run.

50,000

Timed decisions, tail included

Corrected full-path stress run, reported out to p99.9 with the maximum printed rather than trimmed.

0 / 10

Prohibited cases passed, dual reference

No prohibited-reference dominance violations observed. A single-reference gate passed four of the same ten.

0

Software-to-RTL mismatches

Across 3,000 single-reference and 4,000 dual-reference sampled comparisons, pre-synthesis.

Available for review

What you can open

Released under controlled review rather than published, because several of these name pinned commits and internal paths.

  • 01Technical evidence report — the full measured battery, including the figures we withdrew and why.
  • 02Provenance manifest — hashes and the pinned commit behind every result above.
  • 03Implementation conformance appendix — module-by-module path coverage, and where that coverage stops.
  • 04Stress and endurance addendum — the runs behind the tail distribution, with the harness correction stated.
  • 05Reproduction protocol — what a third party needs in order to re-run this and disagree with us.

Not yet claimed

What we will not let you assume

Taken from the report's own limitations section. If one of these matters to your approval path, it is an open item — not an oversight.

  • Independent certification. No accredited third party has reviewed or reproduced these results.
  • Production authorisation to operate. No ATO, no RMF package, no FIPS-validated cryptography.
  • Fabricated-silicon proof. The RTL is synthesisable and simulated; no physical part has been made or measured.
  • Universal predictive accuracy. Consequence and cascade mechanics are deterministic and tested; real-world forecasting accuracy is not established.
  • Zero failure. Aborted cases, unmet targets and under-powered axes are published with their reason codes.

Internal prototype evidence, not a certification. An independently reproducible package is available under controlled review — and it becomes an audit only when a third party runs it.

05 · The Silicon Line

When software isn't enough, the wire itself refuses.

A software guard shares its processor with the model it polices. Our hardware line moves the gate into the die: an execution restrictor sits electrically in series with the actuation path — non-conducting by default, completing the circuit only on a proof-bound approve disposition.

ETHICVAULTEV1-GSOC-01 A2LOT 2606A · U.S. PAT. PEND.FIXED-POINT GATEINTEGER ONLY · NO FPUPOLICY FSMORDERED VALIDATIONPROOF ENGINEMAC · MERKLE COMMITWORM LEDGERWRITE-ONCE MEMORYEXECUTION RESTRICTORFAIL-CLOSED · IN SERIES
  • 01Fail-closed by construction — power-up, reset, and every fault state decode to BLOCK
  • 02No floating-point unit: verdicts are bit-identical across vendors and process nodes
  • 03Dual-rail dispositions + redundant policy logic — no single bit-flip can open the path
  • 04Deliverable as a full SoC or a hardened IP macro (GDSII) in mandatory series placement
  • 05100 MHz closed post-route on two FPGA vendors and two process nodes, dispositions bit-identical on both

Power figures are pre-silicon estimates from an open-PDK 130 nm flow, not silicon measurements: 1.382 mW active, 7.23 µW clock-gated idle, and under 1 mW as an average over a specified duty cycle. The FPGA platforms are static-leakage dominated and are not sub-1 mW.

Implantable medical

The restrictor sits in series with the stimulation driver — a therapy pulse physically cannot fire without an approve disposition. Reversible fail-closed latch with audited re-arm.

Automotive ECU

AI driving-policy commands traverse the gate before the actuator bus. A blocked command drops the vehicle into a fail-operational safe state; every disposition is recorded.

Secure payment

Powered entirely from the reader field: transaction authorization is withheld unless the on-die risk model's output clears validation. No battery, no network, no override.

Where this stands

Built, not announced.

It runs

The gate was built on Xilinx hardware, then built again on Intel hardware — a different company, a different manufacturing process. It was given 330 test cases. Both gave the same answer to every one.

The chip is drawn

The layout is finished: about half a millimetre across, under a milliwatt to run. Every automated check a foundry requires before it will make a design came back with zero errors.

It has not been made

No wafer has been produced. The size and power figures come from the finished design, not from a chip anyone has held. We would rather you read that here than discover it later.

Engineered for regulated environments

  • SOX §302
  • MiFID II
  • DORA
  • Basel III
  • EU AI Act
  • GDPR
  • SR 11-7
  • FINRA
  • HIPAA
  • IEC 62304
  • ISO 26262
  • PCI DSS
Enterprise engagement

Start with a Boundary Assessment.

A fixed-fee engagement that maps one consequential workflow: where the consequence sits, who holds authority over it, what evidence your regulator expects, and where the governed boundary belongs. Scoped work with named deliverables — not a place in a queue.

The engagement

What you are requesting

Two fixed-scope steps, in this order. Neither is a licence commitment, and the second is only priced once the first has produced something to scope it against.

01Fixed fee

Boundary Assessment

One workflow mapped end to end — the consequence being held back, the authority model around it, the policy and evidence your oversight requires, and the threat boundary the gate has to sit on.

Produces

  • One workflow mapped end to end
  • Authority model
  • Policy and evidence requirements
  • Threat boundary
  • Pilot recommendation and scope
02Fixed scope and milestones

Governed Execution Boundary Pilot

Duration
6–8 weeks
Scope
One consequential workflow
Mode
SHADOWAUDITControlled enforcement

Deliverables

  • Authority map
  • Policy and evidence schema
  • Integration boundary
  • Deterministic gate deployment
  • Replayable evidence ledger
  • Measured pilot report

The pilot runs in SHADOW first: the gate decides, and nothing it decides is enforced. Enforcement is turned on for a named set of actions only after the shadow record has been reviewed with your team — so the first thing you see is how the gate would have ruled on your own traffic.

By submitting, you agree to our privacy policy. We do not sell data. Requests are reviewed within 2 business days.

SOC 2 — report at launch
ISO 27001 — by design
GDPR — by design