Make every autonomous AI action explainable, governable, verifiable.
Enterprises spent decades securing identities, devices, and data. Autonomous AI adds a new object to secure — the workload: a reasoning session that pulls in data, calls tools, holds authority, and commits actions, assembling an action no single control was built to evaluate. Apeiris publishes the open control and evidence model that makes those actions inspectable, governable, and independently reviewable — not to prove the model, but to show, under whose authority and over what data, what the workload actually did. 12 verification domains, 652 machine-readable controls, signed and public.
What is live today
- All 12 domain control matrices — 652 machine-readable controls, open, CC BY 4.0
- The Evidence Proof Map, Knowledge Graph (3,769 nodes), and a live in-browser integrity verifier
- A signed manifest (Ed25519 over the JCS-canonical bytes) — recompute every hash yourself
- The Apeiris Advisor — free during beta
Being built
- Connectors that collect real runtime evidence from your systems
- Action-level evaluation of proof obligations against that evidence
- Assurance state + empirical attestations — the hosted platform
12 domain checks compose into one signed verdict.
Evidence in actionFollow an autonomous action from actor to authority, data, knowledge, behavior, effect, and ledger.
Build AI assurance, governance, runtime security, audit, procurement, and compliance products on a shared, open, signed evidence fabric — instead of inventing the controls, evidence model, and framework mappings yourself.
Build on Apeiris →Individual controls fail — and some failures happen even when every one works.
Controls fail the ordinary ways, and you already invest in catching those. There’s a second mode that’s easy to miss: authentication works, retrieval works, the policy engine works — and the action the workload composed from all of them still violates intent, because none of those controls was built to reason about the composed action. Apeiris defines the layer that evaluates that composed action, and the evidence it should produce — under whose authority, over what data, within what policy — not a verdict on the model and not a gate that decides for you. It’s an evidence layer, not a choke point: mapped ≠ satisfied.
Not another framework — the evidence model beneath them: an ontology, stable namespaces, and cross-domain composition, so proof travels between the frameworks you already answer to instead of restarting inside each.
The agents are already acting. The assurance model hasn’t caught up.
Four forces make composable, machine-readable AI assurance urgent now — not in the next standards cycle.
AI now sends, commits, and transacts without a human in every loop — each action consequential and largely irreversible.
NIST AI RMF, ISO 42001, and the EU AI Act each define controls; none defines a shared, action-level evidence model that composes across them.
Audit-by-screenshot can’t keep pace with machine-speed action. Evidence has to be computable, and verifiable by anyone.
One action crosses identity, authority, data, knowledge, and behavior at once — assurance has to span them in a single verdict.
Start here.
Six steps from “what is this” to “wired into your pipeline.” Everything runs in your browser — no login, nothing to install.
- What is Apeiris?
The one-page answer — what exists today, what's being built, and the four things the name covers.
- Understand it
How Apeiris fits your stack — GRC, SIEM, gateway, agents, CI/CD.
- Browse the domains
All 12 domains — each control with its evidence and blocking posture.
- See a verdict
Walk one AI action from actor to a composed, reviewable verdict.
- Assess your gaps
Declare your stack; get maturity, framework coverage, and a roadmap.
- Integrate
Fetch → verify → use. The API is the data; MCP for agents.
Use the fabric, don’t just read about it.
Every tool here runs in your browser over the same open, signed artifacts — no login, nothing to install.
Prove an obligation
Pick a framework obligation, mark the evidence you hold, and watch it resolve live — coverage (mapped) vs evidence (satisfied). mapped ≠ satisfied, made executable.
Explore the graph
Walk 3,769 nodes with provenance on every edge — from a control to its threats, frameworks, and normative sources.
Verify integrity
Recompute every SHA-256 and check the Ed25519 signature live in your browser. Don’t trust — recompute.
Run the Apeiris Advisor
Declare your stack and get a maturity read, authority-labeled framework coverage, and a phased roadmap. Free during beta; answers stay in your browser.
Build on the corpus
Quickstart, the fetch → verify → use pattern, the MCP servers, and how to cite a control. The API is the data.
Build on Apeiris
Use the open, signed corpus as the control-and-evidence substrate under your governance, runtime, audit, or agent product. Free, CC BY 4.0.
Jump to anything · ⌘K
Press ⌘K anywhere to jump to any of 652 controls, an obligation, a source, or a graph node.
Evidence in motion, not governance in slides.
Every consequential AI action creates a chain of claims. Apeiris defines how those claims become composable evidence that can be checked before action and reviewed after the fact.
Agent identity and delegation.
Policy, approval limit, contract.
Untampered, current, traceable.
Authorized, cited sources.
Plan, tool calls, effect match.
Signed, tamper-evident record.
This is the composition model — every link’s evidence in a single signed attestation, checkable before the action and reviewable after. Producing it from real runtime evidence is the platform, in development.
Customer-service agent sends a commitment email.
Actor verifies the agent and its delegation. Authority checks business permission. Data verifies customer-record integrity. Knowledge confirms the contract source. Behavior reconciles the planned action to the observed effect. Ledger packages a signed, reviewable record.
Result: a composed, reviewable action verdict instead of disconnected logs.
What most AI governance skips.
Most control frameworks start at the model or the runtime. Apeiris also asks about the two substrates beneath the action — was the knowledge trustworthy, was the data intact — and about the action itself: did the plan, the tool calls, and the real-world effect stay aligned.
Was the AI grounded in authorized, current, complete, and faithfully cited sources?
Knowledge integrity is not model accuracy. It is the condition that the sources behind the conclusion were trustworthy.
Was the data read at inference time classified, intact, fresh, and traceable?
Data integrity at read time becomes an authorization precondition for consequential AI action.
Did the approved plan, actual tool calls, and observed external effects stay aligned?
The audit primitive is not the reasoning trace. It is the plan/action/effect record.
Twelve domains. One composed verdict.
Each domain verifies one facet of a consequential action and emits its own signed attestation. Select a domain to see what it checks — and what it contributes to the verdict.