PRODUCT · ATTESTED MIRROR
Frontier weights with cryptographic provenance, witness panel review, and a Merkle log that any independent verifier can validate. Built for organizations that can't ship "trust us" as a security architecture.
the problem
Where did those weights come from? What was the training corpus? Have they been modified since publication? When the model behaves unexpectedly in production, can you prove what version was running? On HuggingFace, the answer to all four questions is "we don't know." For most internal experiments that's fine. For ATO, FDA SaMD, IEC 61508, or NERC-CIP, it's a stop-work.
the solution
CLOSED → QUARANTINE → HARDENED. Promotion to Hardened requires that we hold the weights, verify their SHA-256 against the publisher's hash, and pass a supply-chain scan mapped to NIST AI RMF / COSAIS — signed by our own key. Demotion is a single revocation signature; cascades are automatic.
Every artifact promoted to Hardened is scanned on our own infrastructure and the findings mapped to NIST AI RMF and COSAIS controls. The scan report is signed and anchored alongside the weight hash, so an auditor can read the control mapping rather than take a badge on faith.
Every promotion, demotion, and cosignature appended to a Merkle log with full inclusion proofs. Cross-mirror gossip propagates checkpoints. Independent verification at any time.
The sf-verify tool ships as a 465-line Python script with no Apex dependencies. Your security team can validate every claim without trusting our infrastructure.
INT8 / INT4 / FP8 derivatives chain back to their sealed FP16 base through signed compile manifests. The trust chain doesn't break when the airframe needs a 4-bit quant.
Reverification runs on schedule. Witness rotation, key compromise, and revoked publishers are caught and propagated automatically. Your customers see the demotion the moment it lands.
who it's for
JADC2, CDAO, and program offices that need attested AI under DoD SWFT and ATO frameworks. Mirror runs in your VPC; signatures roll up to your audit pipeline.
Hospital systems, medical device manufacturers, and clinical research organizations bound by FDA SaMD, HIPAA, and the EU AI Act high-risk classification.
Grid operators (NERC-CIP), water utilities, financial institutions, and national AI initiatives where the provenance posture is itself a procurement requirement.
pricing
Pricing reflects the curation work, not the storage cost. Every customer gets the full catalog, full witness coverage, full audit trail.
First-year pilot for a single program of record. Full catalog, single VPC deployment.
Standard tier for production deployments across multiple programs or regions.
National-scale deployments, classified networks, or regulated industries with bespoke witness requirements.
See the live demo. Run the verifier. Audit the source. Then talk to us about the version that fits your network.