Violet Shores · Trusted-AI Infrastructure · Capability Map
Provable human authority over intelligence
A working system, a live development program, and a research track — labelled honestly. Shipped means running in production today; in development means designed, specified, and being built now; research means the science is being established with institute partners.
Running today SHIPPED
- Live multi-modal verification ceremony — face, gesture, and spoken challenge bound in real time; cloned voices and replayed video don't pass; adaptive capture coaching in the field.
- Sealed, externally verifiable decisions — tamper-evident accountability records; any holder of the receipt can verify against the chain without trusting the operator.
- Capability-narrowing delegation — authority passes downward only ever narrowed, rooted in a verified natural person.
- Trust-calibrated model routing — a closed measurement loop: challenge harnesses score models per domain; routing follows the evidence; every reply shows its provenance (model, sources, timing) one tap away.
- Multi-language operation — dual-language by design: English always, plus the user's detected or chosen language; Italian live.
- Living documents — recipient pages that never go stale.
Being developed now IN DEVELOPMENT
- The policy resolver & rails model — every decision governed by a compiled envelope: law and standards intersect as hard floors; preferences weigh within authority-set bands; the controller adapts only inside the envelope it is given.
- Rails packs — regulation as versioned, signed content: EU AI Act today, a new regime tomorrow, a sovereign department's self-authored rails in its own enclave — adopting a standard becomes a pack, not a rebuild.
- Enterprise policy at scale — attribute-based groups and policy templates (the discipline proven in 750k-endpoint smart-meter estates), with per-group variations under one SSO — no corporate blanket policy that every team suffers under.
- Work-aware security posture — the orchestration kernel classifies the risk of what you're working on and tightens posture mid-session, tighten-only, with the reason always shown: "assurance raised: task classified commercial-sensitive."
- Just-in-time authority elevation — work beyond your clearance triggers an approval signal; an approver verifies with their own live ceremony; a scoped, auto-expiring grant unblocks you in seconds — and no approver can grant beyond their own provable authority.
- Posture visibility — the provenance view extends from "which model and why" to "what security level and why": posture, rails, and step-ups readable one tap from the conversation.
- Policy-changes-as-ceremonies — the rails are governed by the rails: changing a rule is itself a sealed, authority-checked event.
Being established with research partners RESEARCH
- Formal assurance of the authority chain — safety-case-grade proofs that the envelope holds, suitable for regulators and critical infrastructure.
- Oversight-efficacy measurement — does the ceremony produce genuine informed human control? Measurable, and to our knowledge unmeasured anywhere.
- Certifiable domain test harnesses — experimental design, uncertainty-quantified trust calibration, and standardisation methodology, medical first — so a harness score becomes something an industry can rely on.
How it deploys — no rebuild required
- Retrofit at the decision points. The systems that run real operations — SCADA, digital twins, case management — are often safety-certified and decades embedded; rebuilding them is neither possible nor necessary. Provable oversight adds at their decision points through simple APIs: a seal call, a hosted verification ceremony, a delegation config, a rails pack. Weeks, not a rebuild — and the evidence each deployment produces is independently verifiable by an auditor from day one.
The governed control plane
- Sovereign AI execution. The market has begun telling CEOs to route every task through a control plane and to stop renting intelligence at the cost of their edge. This platform is that control plane, governed: you control the routing — evidence-calibrated, per task, across every credible model including the arriving open-weight wave — and you control the authority — every consequential action rooted in a verified person, inside rails you author, provable to anyone. Routing without governance is a cost tool; governance without routing is paperwork; together they are sovereignty.
Where this sits in the market
- The market is validating the category at speed: consumer AI products now ship model routers (Sylvia); Salesforce just led a $135M round into governed AI software creation (8090's Software Factory — audit trails across how software is built). Those govern the making of things. This platform governs the authority over decisions — which verified human authorised what action, under what envelope, provable to a regulator without trusting the vendor. Different object, different root: the layer beneath theirs, and the one the EU AI Act's human-oversight articles actually demand.