Home · Platform · Security & Trust
Platform · Security

Built to be inspected, not trusted.

AskLedger is fully open, so your security team can verify every claim for themselves. No proprietary cryptography, no black boxes.

Security & trust

Everything a security review asks for.

HSM-backed keysSigning keys never leave AWS KMS, Azure Key Vault, GCP KMS, or PKCS#11, with a FIPS-mode path.
Independent verificationAny third party verifies a receipt with only the public key, no dependency on AskLedger or the AI vendor.
Zero Trust alignedNIST SP 800-207 architecture, SPIFFE workload identity, and OPA policy decisions written into receipts.
Threat-modelledSTRIDE + LINDDUN threat model, a machine-checked hardening checklist, and a mutation-based fuzz suite.
Supply-chain integrityPublished to npm with cryptographic provenance, a CycloneDX SBOM, and Sigstore image signing.
Open sourceApache-2.0, an open specification, and five conformance-tested SDKs. Read the code and the threat model yourself.
Data handling

Provable evidence, without copying your data.

A receipt records a hash of the input and output, not the raw content. The private signing key stays inside your HSM, and verification needs only the public key. Nothing confidential is exposed to produce or verify a receipt, and AskLedger runs as a library inside your own environment, no data routed to a third party.

Standards

Open specification, open code, open verification.

No vendor lock-in and no proprietary cryptography. Every claim is verifiable against published RFCs and the public specification. The RFCs below are established standards; the receipt format is our own open specification, Apache-2.0 licensed and published as a candidate for standardisation.

RFC 8785JSON Canonicalization Scheme
RFC 8032Ed25519 signatures
RFC 3161Trusted timestamping
RFC 9162Certificate Transparency v2
NIST SP 800-207Zero Trust Architecture
ISO/IEC 42001AI Management Systems

Send this to your security team.

Everything here is inspectable. Explore the code, the threat model, and the conformance suite, or talk to us.