
Who sells proof of AI work? Seventeen vendors measured — none ships the whole object
This page answers the buyer's question behind every "AI proof" claim on the market: does anyone else sell the same outcome as proven work — completed AI work that arrives carrying its own written claim, the complete record of how it was formed, a verdict computed against that record, and a standing door any stranger can open, keylessly, to check all of it and leave their own inspection receipt. Seventeen products were put through one six-part outcome measure, each from its own live pages, APIs, and public artifacts. The short answer: no same product exists. The closest is a component. The most instructive failures verify nonsense beautifully. This page is itself a proven work object: every substantive claim is bound to receipts or a named gap in its manifest, and the whole object is inspectable without a key.
The verdict
None of the seventeen passes all six parts, and the failures cluster on the same three almost everywhere: the execution record, the claim-versus-record check, and the standing outsider door. The components sell one real piece of the unit and stop; the adjacent field points the same vocabulary at a different object — the customer's own systems, watched on the customer's own behalf. And one newcomer that was not on the original list, Provenrail, ships the record layer plus half a door at consumer prices — the live threat, not the answer.
The six-part outcome measure
What a buyer can purchase, not what vocabulary a vendor uses: a, takes completed AI work as input, rather than instrumenting work inside its own runtime. b, binds the work's substantive claims, sentence by sentence. c, preserves the execution record — every model and tool call, request and response together, hash-chained, timestamped. d, checks each claim against that record — not against the open internet, not against policy thresholds. e, issues a verdict computed by the service, never asserted by the maker. f, exposes the whole object at one keyless URL, and the inspector receives their own receipt.
The unit is proven work: claim, record, binding, door, derived status, sold as one object on arbitrary completed work. The prior-art scan — C2PA, in-toto/SLSA, W3C verifiable credentials, FDA 21 CFR Part 11, the SEC consolidated audit trail, the IETF agent-audit-trail draft — is the sibling, Is AI work-proof actually new? A prior-art audit of proven work against 29 years of record-keeping law.
H33 — the deepest overlap anywhere, and still a component
H33 is a post-quantum cryptography platform whose decision-evidence bundles come closest to the unit. A publicly downloadable specimen bundle decomposes an AI answer into claim spans by byte range and binds each span to supporting citation receipts, with a coverage assertion of "full" signed under three post-quantum signature families (https://h33.ai/bundles/claim_84711.json). Its free verifier runs offline; the inspector signs their own verdict report.
Three absences decide the taxonomy. First, the one claim-support statement in the bundle is signed by the maker's own key — the maker-asserted pattern a derived status exists to eliminate — and its own verifier pages state that a pass proves neither completeness nor correctness. Second, the record does not travel: the bundle carries input and output hashes, not payloads, so an outsider can verify that a consistent record existed without reading what it says. Third, there is no door: the bundle reaches you because the maker handed you a file, and the only public specimen is an alpha preview whose own metadata admits deterministic placeholder signatures — the envelope bytes literally begin "preview-". Score: a fail, b pass, c partial, d fail, e partial, f partial. COMPONENT.
Aretify — claim decomposition pointed at the wrong reference
Aretify takes completed AI output — pasted drafts, PDF uploads, a Chrome extension aimed at ChatGPT, Claude, Gemini, Copilot, and Perplexity output — decomposes it into atomic claims, retrieves evidence across fifteen source tiers, and stamps each claim Verified, Partially Supported, Not Enough Evidence, or Contradicted, service-computed (https://api.aretify.com/openapi.json). Real claim extraction, a genuinely derived verdict — pointed at internet truth, not the work's record. Aretify never sees how the checked work was formed; its public OpenAPI schema contains no receipt, chain, provenance, or audit-trail structure at all. Its keyless door covers anonymous guest runs only: paying customers' reports are excluded by design, and an outsider's read leaves no inspection receipt. Score: a pass, b pass, c fail, d fail, e pass, f fail. COMPONENT. "Is this sentence true" and "did this work do what it claims" are non-overlapping questions.
CertifiedData — the integrity binding that verifies nonsense
CertifiedData is a certificate authority for AI artifacts: operators submit self-authored decision records, canonicalized, hashed, Ed25519-signed, hash-chained, and — opt-in — published to a public log with a keyless verify endpoint. The door is real; it was exercised for this page. What it verifies is integrity alone. Live demonstration, this session: the public log holds a credit decision whose selected option is DECLINED while its rationale reads "Credit history and payment record meet minimum criteria for approval" — a self-contradictory entry — and its keyless verify endpoint answers verified: true, signature_verified: true, payload_verified: true (https://certifieddata.io/api/decision-log/ee1f1a8f-660b-4996-bd27-bbc2db9cb9b1/verify). Integrity binding is not claim checking: a perfectly false record verifies green, because nothing in the product examines what any record says. No claim layer, no per-sentence binding, no verdict over content. Score: a weak pass, b fail, c fail, d fail, e fail, f partial. COMPONENT.
SovereignClaw — authority lineage only
SovereignClaw gates AI agent actions before they execute and emits a signed Authority Receipt per permitted or denied action: intent hash, policy version, approval state, outcome, Merkle-anchored, externally verifiable against published keys (https://sovereignclaw.com/ai-agent-audit-trail). That is custody of the authorization decision — the receipt proves an action was proposed, policy-evaluated, and authorized. It contains no claim about completed work, no sentence binding, no claim check, no verdict object, and no keyless URL into any work object; receipts stay tenant-scoped in the customer's SIEM. Score: partial on c, fail on the rest. COMPONENT — exactly one component, the authority receipt chain.
WishKnish — the plumbing, by its own declaration
Knish.IO is a cryptographic-evidence substrate that sits underneath observability stacks and signs each forwarded event with post-quantum signatures on an append-only ledger (https://knish.io/platform). Their own pages state the boundary twice: "We are the infrastructure," and "The substrate does not by itself produce compliance certification. It produces the cryptographic evidence that supports compliance arguments." No work object, no claim concept, no verdict, no public inspection endpoint — verification is SDK-based, by "parties with cause." One partial of the five requirements: the record chain. COMPONENT — precisely the plumbing beneath the unit, as they say themselves.
Acipta — vendor-run replay of its own scans
Acipta's agents scan a customer's systems for compliance, and each verdict its own agents produce is sealed into a signed, hash-chained, RFC 3161-timestamped evidence pack, offline-replayable with standard tools (https://acipta.ai/flight-recorder/). The record layer is serious — and the work being evidenced is the vendor's own, never the buyer's. Replay proves the sealed bytes re-derive identically; their own pages disclaim that any verdict was substantively correct. No intake of buyer work, no claim binding, no keyless door, vendor-run from verdict to key custody with one third-party timestamp anchor; pre-revenue, pre-GA. COMPONENT.
KLA — sealed integrity bundles, no claims
KLA Control Plane records runtime governance lineage — identity, authority snapshot, policy verdict, tool input and output hashes, before-and-after state — on an append-only ledger, and exports a Sealed Evidence Bundle with an offline verifier and Bitcoin timestamp anchoring (https://kla.digital/tamper-proof-evidence). The most complete preservation stack here, and it carries no claims: the bundle binds artifacts to hashes, not claim sentences to receipts; the only computed verdicts are runtime policy outcomes; KLA explicitly reserves the audit conclusion to human auditors; and an outsider inspects only a bundle the tenant chose to export and hand over. Their own incident playbook concedes the described paths run only in KLA's development environment. COMPONENT — the record component, with non-keyless inspection machinery.
The adjacent field — nine products, zero doors
Nine more vendors were examined and none clears the measure in the unit's sense. Their object is the customer's own AI estate, observed for the operator — never a work object handed to a stranger. Each was re-fetched live while writing this page.
- Scelora structures AI Act evidence packs for system lifecycles, refuses verdicts by design — "It is not a certification" — and is not yet a registered legal entity per its own legal notice (https://scelora.eu/en/). 0 of 6.
- Clarity decomposes drafts against web sources with a three-model panel, then advertises zero retention — the record proven work is made of is the thing it destroys; keyless guest report URLs expire in thirty days (https://claritybot.io/pricing-faq/). 2 of 6.
- Krapheno gates ad-campaign decisions against numeric policy thresholds on a hash-chained ledger, but its advertised public per-decision trace route answered 404 and its advertised verify route demands the customer's API key, probed keylessly (https://api.krapheno.com/v1/health/governance). 1 of 6.
- Cordum intercepts agent actions before side effects behind a signed decision log — redacted by design, payloads excluded, retention license-capped, audit export Enterprise-gated (https://cordum.io/pricing). 0 of 6.
- Trail is an AI-governance operating system whose governed unit is the org-level asset; no per-work object exists anywhere in the product (https://www.trail-ml.com/ai-governance). 0 of 6.
- Credo AI, the governance category leader, binds evidence to policy controls, accepts human attestation as evidence — assertion is an accepted input — and its own documentation returns 401 to outsiders (https://www.credo.ai/glossary/evidence). 0 of 6.
- Fiddler ingests OpenTelemetry traces of live systems — confidential, role-gated, retention-limited, its own SOC 2 report under NDA; the structural opposite of a door (https://www.fiddler.ai/security). 1 of 6, internal only.
- Arize captures model and tool inputs and outputs as debugging traces — mutable, unchained, wiped after fifteen to thirty days on self-serve tiers; a record engineered to expire cannot anchor a durable claim (https://arize.com/pricing/). 1 of 6.
- Patronus computes real verdicts — judge models scoring submitted output against pasted context — then preserves nothing behind them, so the judgment is unfalsifiable after the retention window inside a credential-gated console (https://www.patronus.ai/pricing). 2 of 6.
All nine: ADJACENT.
Provenrail — the one to watch
Provenrail was not on the original list; the prior-art scan found it. An SDK captures every model and tool call, hash-chains it client-side to an append-only sink, anchors with RFC 3161 timestamps on paid tiers, and ships an open-source offline verifier — and on the Builder tier and up, hosted read-only proof links any outsider can open (https://provenrail.com/). Pricing runs free, twenty-nine dollars, ninety-nine dollars, custom — an order of magnitude under verdict products. Record layer done commercially well plus half the door at consumer prices — the live threat: add a claim layer and the marketing writes itself. What it does not do today: no claim extraction, no claim-to-receipt manifest, no computed proven-or-partial verdict, no receipt issued to the inspector — its proof link shows chain integrity, not a claim-checked object — and its own threat model disclaims completeness. It records prospectively via SDK; it does not take arbitrary completed work and adjudicate it. Strong COMPONENT. If any vendor on this page converges on the unit first, it is this one.
What the empty cell means
Across seventeen products and the prior art behind them, the same two cells stay empty: binding — claim sentences to execution receipts, with named-gap honesty — and the door that receipts the inspector. Everyone else proves custody of the answer, integrity of the log, or authorization of the action — the argument Provenance, traces, attestations — every system proves custody of the answer; none opens the record of the work makes in full. The reasons are rational — retention is metered, computed verdicts are liabilities, enterprise evidence is confidential — and together they describe a market that sells every piece of proof except the object a stranger can check. The contrast is executable, not rhetorical: the door at https://miscsubjects.com/api/proven-work/three-models-deliberate-one-statutory-question/inspect answered this page keylessly during writing and returned inspection receipt inv_036kq050fl — a stranger's read, receipted.
Sources
- https://h33.ai/bundles/claim_84711.json — the H33 specimen bundle: claim decomposition, maker-signed coverage assertion, placeholder signatures.
- https://api.aretify.com/openapi.json — Aretify's public API contract: claim verdicts, source tiers, zero record structures.
- https://certifieddata.io/api/decision-log/ee1f1a8f-660b-4996-bd27-bbc2db9cb9b1/verify — a self-contradictory DECLINED decision verifying green, keylessly.
- https://sovereignclaw.com/ai-agent-audit-trail — the Authority Receipt schema and verification model.
- https://knish.io/platform — the substrate's own scope disclaimers, verbatim.
- https://kla.digital/tamper-proof-evidence — the Sealed Evidence Bundle and offline verifier check list.
- https://acipta.ai/flight-recorder/ — the Determinism Ledger and Evidence Locker design.
- https://provenrail.com/ — hash-chained agent records, open-source verifier, hosted proof links, pricing.
Seventeen underlying research briefs — one per vendor, each carrying every URL it read — are preserved in this build's research record and bound to this page's manifest; every vendor URL above was re-fetched live while writing. The standard this page measures against is Proven work: the base unit — a claim, a record, and a door; the prior-art scan that found Provenrail is Is AI work-proof actually new? A prior-art audit of proven work against 29 years of record-keeping law.
The standing offer
The first bounded case for any legislator, regulator, or private party is free, per the standing offer on the compliance guide. Requests: build@miscsubjects.com.
Key evidence
Ask this article · 7 suggested prompts
Text the build (+14245134626) or WhatsApp — slug|question creates a question node. Paste evidence with ingest slug|q:NODE_ID|your paste.