Make every autonomous AI action explainable, governable, verifiable.

Enterprises spent decades securing identities, devices, and data. Autonomous AI adds a new object to secure — the workload: a reasoning session that pulls in data, calls tools, holds authority, and commits actions, assembling an action no single control was built to evaluate. Apeiris publishes the open control and evidence model that makes those actions inspectable, governable, and independently reviewable — not to prove the model, but to show, under whose authority and over what data, what the workload actually did. 12 verification domains, 652 machine-readable controls, signed and public.

What is live today

  • All 12 domain control matrices — 652 machine-readable controls, open, CC BY 4.0
  • The Evidence Proof Map, Knowledge Graph (3,769 nodes), and a live in-browser integrity verifier
  • A signed manifest (Ed25519 over the JCS-canonical bytes) — recompute every hash yourself
  • The Apeiris Advisor — free during beta

Being built

  • Connectors that collect real runtime evidence from your systems
  • Action-level evaluation of proof obligations against that evidence
  • Assurance state + empirical attestations — the hosted platform
12 domains · 652 controls · 306 cited normative sources · open, CC BY 4.0

Corpus release 2026.08.12 · 2026-08-12 · 652 controls · 306 cited sources · signed iIcEABYKAC8WIQRYpSdP… · verify every byte →

APEIRIS EVIDENCE FABRIC Composed • Signed Actionable • Provable 01SECURITYPreventDetectRespond02MODELFit for purposeEval + drift03PRIVACYLawful data useRights + purpose04COMPLIANCEObligation fitDossier + audit05IDENTITYWho is actingDelegation06AGENTICTool + actionAuthorization07ETHICSFair + contestableRemedy08RESILIENCESafe under failureRecover + continue09FINANCEFinancial governanceMRM + controls10AUTHORITYBusiness permissionPolicy + contracts11KNOWLEDGEGrounded truthCitations12DATAIntact substrateLineage + integrity

12 domain checks compose into one signed verdict.

Evidence in action

Follow an autonomous action from actor to authority, data, knowledge, behavior, effect, and ledger.

Build AI assurance, governance, runtime security, audit, procurement, and compliance products on a shared, open, signed evidence fabric — instead of inventing the controls, evidence model, and framework mappings yourself.

Build on Apeiris →

Individual controls fail — and some failures happen even when every one works.

Controls fail the ordinary ways, and you already invest in catching those. There’s a second mode that’s easy to miss: authentication works, retrieval works, the policy engine works — and the action the workload composed from all of them still violates intent, because none of those controls was built to reason about the composed action. Apeiris defines the layer that evaluates that composed action, and the evidence it should produce — under whose authority, over what data, within what policy — not a verdict on the model and not a gate that decides for you. It’s an evidence layer, not a choke point: mapped ≠ satisfied.

Not another framework — the evidence model beneath them: an ontology, stable namespaces, and cross-domain composition, so proof travels between the frameworks you already answer to instead of restarting inside each.

The agents are already acting. The assurance model hasn’t caught up.

Four forces make composable, machine-readable AI assurance urgent now — not in the next standards cycle.

Agents act, they don’t suggest.

AI now sends, commits, and transacts without a human in every loop — each action consequential and largely irreversible.

Frameworks don’t share an evidence model.

NIST AI RMF, ISO 42001, and the EU AI Act each define controls; none defines a shared, action-level evidence model that composes across them.

Proof has to be machine-readable.

Audit-by-screenshot can’t keep pace with machine-speed action. Evidence has to be computable, and verifiable by anyone.

Governance has to compose.

One action crosses identity, authority, data, knowledge, and behavior at once — assurance has to span them in a single verdict.

Evidence in motion, not governance in slides.

Every consequential AI action creates a chain of claims. Apeiris defines how those claims become composable evidence that can be checked before action and reviewed after the fact.

Example evidence chain

Customer-service agent sends a commitment email.

Actor verifies the agent and its delegation. Authority checks business permission. Data verifies customer-record integrity. Knowledge confirms the contract source. Behavior reconciles the planned action to the observed effect. Ledger packages a signed, reviewable record.

Result: a composed, reviewable action verdict instead of disconnected logs.

What most AI governance skips.

Most control frameworks start at the model or the runtime. Apeiris also asks about the two substrates beneath the action — was the knowledge trustworthy, was the data intact — and about the action itself: did the plan, the tool calls, and the real-world effect stay aligned.

Knowledge

Was the AI grounded in authorized, current, complete, and faithfully cited sources?

Knowledge integrity is not model accuracy. It is the condition that the sources behind the conclusion were trustworthy.

Data

Was the data read at inference time classified, intact, fresh, and traceable?

Data integrity at read time becomes an authorization precondition for consequential AI action.

Action

Did the approved plan, actual tool calls, and observed external effects stay aligned?

The audit primitive is not the reasoning trace. It is the plan/action/effect record.

Twelve domains. One composed verdict.

Each domain verifies one facet of a consequential action and emits its own signed attestation. Select a domain to see what it checks — and what it contributes to the verdict.