Evidence kinds
Thirteen primitives.
Each mapped to articles.
The substrate emits 13 discrete kinds of evidence. Each is a primitive — a verifiable property with explicit guarantees + explicit limits. Regulations engage these primitives in different combinations: the same L12 receipt chain underwrites AI Act Art. 12 + HIPAA §164.312(b) + GDPR Art. 32 + DORA Art. 17 + NIS2 Art. 23.
Each page below names what the primitive does + what it doesn't. No vendor inflation; the gaps are explicit.
Cryptographic primitives
Spec hash commitment
Every L12 entry includes a SHA-256 of the active RuntimeAISpec, making silent spec drift detectable.
Open →
OpenTimestamps Bitcoin anchor
Bitcoin blockchain commitment of a chain head, providing third-party timestamp evidence.
Open →
Model identity pin
Each L12 entry binds the exact provider + model + version that decided.
Open →
Ed25519 attestation
Per-entry Ed25519 signature using the operator's workspace signing key.
Open →
Operator-managed signing key
The Ed25519 private signing key is generated + held operator-side, never escrowed by Promethean.
Open →
Structural primitives
Input-hash-only (PII-safe)
Only SHA-256 hashes of inputs enter the L12 chain — raw PII never crosses the audit-trail boundary.
Open →
Schema validation result
Per-entry record of whether the model output satisfied the spec's closed-enum schema.
Open →
RuntimeAISpec (the spec)
The closed-enum contract one LLM-in-the-loop feature operates under.
Open →
Process primitives
Audit outputs
L12 receipt chain
Hash-chained, Ed25519-signed log of every LLM-in-the-loop decision a Promethean-built product makes.
Open →
Audit bundle
Operator-downloadable .zip containing verifier + workspace identity + chain metadata + framework handoff.
Open →
Operator-supplied control (gap)
Honest acknowledgement of obligations the substrate doesn't directly cover.
Open →