TRUST · SECURITY POSTURE · 2026 Q2

the thing that records things
has to be trustworthy.

we record other people's regulatory artefacts. the bar is plainly higher than "best practice". this page lists the controls, how packages stay verifiable, and what we do not yet hold. nothing here is marketing.

Warrant is regulator-grade evidence infrastructure for AI agents in regulated industries: drop an agent's execution trace, get a record mapped to a specific EU AI Act obligation, independently verifiable in your own browser without ever contacting Warrant.

warrant is a software vendor. we are not a law firm. nothing on this site or in any PDF warrant records is legal advice. the mapping is a structured reading of public regulatory text. engaging counsel to confirm applicability remains the customer's responsibility.
warrant seal
INDEPENDENTLY VERIFIABLE · ACTIVATED 2026-05-06 every package is independently verifiable without contacting Warrant · confirm one at /verify
01 · VERIFICATION

every artefact is independently verifiable.

one production register. published, dated. if a row stops being true, this page changes the same day.

PROPERTY
independently verifiableA reader confirms any package in their own browser, without contacting Warrant. The result is binary: original-and-unaltered, or not.
AUTHOR
recorded by WarrantEach package names Warrant as its recorded author. Confirmable with no Warrant infrastructure online.
ACTIVATED
2026-05-06Activation is itself a recorded artefact. Older packages remain verifiable over time.
REFERENCE
/verifyThe verification reference is published. Cache-friendly. Nothing in the verification path requires our control plane to be online.
DURABILITY
14-day public notice on any change · older packages remain verifiableChanges are announced 14 days ahead, older packages remain verifiable, the change event is itself a recorded artefact.
02 · INDEPENDENT CONFIRMATION

every artefact checkable against an independent reference.

each package is confirmed against an independent public reference that Warrant does not control, which fixes when it existed. the artefact's existence at time T is provable forever, by anyone, without us.

# sample package
package_id        = 7de85ceaeac42a47
trace             = eu-fintech-prod
sealed            = 2026-04-29 14:23:08 UTC
recorded_by       = Warrant
status            = independently verifiable

# independent confirmation
confirmation      = confirmed
confirmed_at      = 2026-04-30 09:14 UTC

# anyone can confirm this offline, without contacting Warrant.
# confirm one at /verify
03 · FOUR INDEPENDENT CHECKS

four checks. anyone runs them.

drop a warrant PDF in at /verify. it answers four questions and reports each one's pass / fail. all reproducible offline.

CHECK 01

recorded by Warrant

is this recorded by Warrant?

the check confirms the package names Warrant as its recorded author, against Warrant's published record.

CHECK 02

original package

is this the original package?

the PDF you hold is confirmed to be the exact package that was recorded, unaltered.

CHECK 03

nothing changed

has anything changed?

the package confirms it has not been edited since it was recorded.

CHECK 04

independent confirmation

can a third party confirm without Warrant?

the package is confirmed against an independent public reference that Warrant does not control.

open verify verify sample 7de85ceaeac42a47
04 · WHAT WE DON'T HOLD

what we don't hold.

honesty over theatre. v0.4 public beta. these certifications are not in place today. the day they are, this page changes the same day.

ROADMAP · POST-COHORT

SOC 2 Type II

roadmap · post design-partner cohort [email protected]
ROADMAP · POST-COHORT

HIPAA BAA

not signed today · do not send PHI [email protected]
ROADMAP · POST-COHORT

GDPR DPA

standard DPA on request · not the default [email protected]
ROADMAP · POST-COHORT

ISO 27001

roadmap · post production cohort [email protected]
05 · STACK

the stack.

named, versioned, sub-processed. if a row changes, the changelog records it as a sealed artefact.

DATABASE
Supabase · Postgres · EU regionPer-tenant row-level security. New columns are anon-default-deny; sensitive columns are explicit GRANT only.
RUNTIME
Render · Python 3.11 · FastAPIMin replicas pinned to 1, no cold starts. Hardware-key-only operator SSO; SSH disabled in production.
SUB-PROCESSORS
Anthropic · Supabase · Render · independent reference providerLive list at /.well-known/security.txt. 14-day notice for additions.
DATA RESIDENCY
EU (Frankfurt) by defaultPinned at tenant creation. No silent migration.
06 · EVAL DISCIPLINE

the eval suite, named.

this section used to publish accuracy, precision, recall and inter-rater agreement figures. none of them had been measured. they are removed, and this is what stands in their place: an honest account of what the harness is and what it has not yet produced.

CLASSIFICATION ACCURACY
not yet measuredStage 1 assigns domain, jurisdiction, regime and risk tier. We have no measured accuracy for it and will not quote one. A measured number with named failure classes, stated denominators, and the graded set it was computed over is in progress.
CITATION PRECISION
not yet measuredThe harness has a citation-precision metric implemented. It has never been run over a graded set, so there is no precision or recall figure to report.
INTER-RATER AGREEMENT
not yet measuredNo two-annotator labelling pass has been run, so there is no inter-rater agreement statistic. The agreement figure this page carried before 2026-07-28 was not computed from data and has been withdrawn.
WHAT EXISTS ON DISK
a harness and 5 declared casesThe regression set declares 5 cases. Four of them point at fixture traces that do not exist yet, and the fixture, run and snapshot directories are empty. So the honest count of graded decisions today is zero.
FAILURE-MODE LOG
not publishedThis page previously pointed at a public failure-mode log. That page was never built and the path it named returns 404. Nothing gets published here until there is a measured run to log against.
07 · DISCLOSURE

found something? tell us.

coordinated disclosure preferred. we name researchers in the changelog with their permission. we do not chase reporters.

[email protected] /.well-known/security.txt /verify
AUTHORSHIP
recorded by Warrant
confirmable without contacting Warrant
Each package names Warrant as its recorded author. Older packages remain verifiable over time, so any artefact recorded before a change still confirms. The verification path requires no warrant infrastructure to be online; it requires only the published verification reference and the package itself. The active production register was activated 2026-05-06. Changes carry 14-day public notice; the change event itself is a recorded artefact, so the chain of custody is itself attestable.
REPRODUCIBILITY
reproducible
same result on any machine
The canonical record is deterministic. The same trace, confirmed on a different machine, produces the same result. This is the property that lets a regulator confirm the package offline and reach the same yes-or-no Warrant does. Without it, two parties confirming the same package could diverge for no substantive reason. The record binds the trace, the rendered PDF, and the package into a single confirmable artefact.
INDEPENDENCE
independent reference
confirmable by any party
The package is confirmed against an independent public reference that Warrant does not control, fixing when it existed. Independent confirmation runs offline; Warrant's infrastructure can be unreachable and the package still confirms. Confirmation for a new package typically lands within the hour. The reference is neutral and no single operator can rewrite the past. Confirmation returns synchronously; independent confirmation is appended to the record once it lands, typically within the same hour.