Disclosure ≠ Evidence
An AI vendor saying their model is safe is disclosure. Running OWASP LLM Top 10 red-team scans against it, scoring the findings, and signing the result is evidence. AISeal certifies the evidence — and the badge is cryptographically verifiable.
Disclosure registries
Vendors tell you what they do.
The vendor fills out a questionnaire. They describe their model, their guardrails, their data handling. The registry publishes it. The buyer reads it. There is no independent test of any of those claims.
- •Vendor self-attests · no independent test
- •Snapshot in time · drifts as the model is retrained
- •Trust the form · no cryptographic proof on the badge
- •No runtime check · the production model is never observed
Useful for transparency. Not enough for procurement.
AISeal certification
We test what they ship.
We run OWASP LLM Top 10 red-team prompts against the vendor's actual model, score the result against a defined rubric, map findings to NIST AI RMF + EU AI Act + MITRE ATLAS, and issue a tier (ACF-1 / ACF-2 / ACF-3) backed by an HMAC-signed badge and a public verify endpoint.
- •OWASP LLM Top 10 + ASI01-10 red-team scan · scored 0-100
- •HMAC-signed badge · cryptographically verifiable
- •Origin-bound verify endpoint · /api/verify/{cert_id}
- •Annual recert · Ghost99RT runtime monitoring (ACF-3 · in development)
Procurement-grade. Auditor-defensible. Forge-resistant.
Why this distinction matters
The SSL analogy
In 1995 you could put a padlock icon on your website. It meant nothing — anyone could draw one. By 1996 the industry had moved to certificates issued by a Certificate Authority that verified domain ownership. The padlock became evidence, not a claim. Browsers now refuse to show the padlock without it.
AI is in 1995. Every vendor claims their model is safe. Every vendor publishes a policy. Procurement teams have no way to distinguish “we ran red-team tests” from “we said we ran red-team tests.” Disclosure registries make the claim shareable. They do not make the claim verifiable.
AISeal is the CA layer for AI. We run the test. We score the result. We sign the badge. The badge is bound to the vendor's domain via Origin/Referer validation — if someone tries to embed it on an uncertified site, the verify endpoint flags an origin mismatch and the badge fails.
What an AISeal certification involves
Four things a disclosure form can never give you
01
Red-team scan against the live model
We send OWASP LLM Top 10 attack prompts to the production endpoint and grade the responses. Prompt injection, sensitive info disclosure, training-data poisoning, model DoS, supply-chain risk, output handling. No self-report — observed behavior.
02
Cryptographically signed badge
The SVG badge embeds an HMAC-SHA256 signature of (cert_id, vendor_domain, score, issued_date). Any byte tampered with breaks the signature. The verify endpoint regenerates it from the canonical cert record and constant-time compares.
03
Origin-bound verification
The verify endpoint checks the Origin/Referer of the request against the certified vendor domain. Embedding the badge on a site the cert doesn't cover returns origin_mismatch — every attempt is logged to verification_log.
04
Runtime monitoring (ACF-3 · roadmap)
ACF-3 is the continuous-monitoring tier on our roadmap. Ghost99RT (in development) is built to watch the production model for behavioral drift after issuance, so a cert that's earned and then quietly degrades doesn't silently stay valid. A disclosure registry captures a one-time snapshot; ACF-3 is designed to maintain a posture.
Certify the evidence.
Run a free TrustScan against your own AI to see how it scores against OWASP LLM Top 10. The ACF-1, ACF-2, and ACF-3 tiers are how the framework proposes grading that evidence.