VIAS — Trusted Proof Protocol
VIAS-1.0 · The Evidence Plane for Autonomous Agents

Control plane stops what an agent can do.VIAS proves what it did.

Runtime controls constrain autonomous behaviour. VIAS captures and seals execution events outside the agent runtime, creating tamper-evident evidence a third party can independently verify once it's been provided. That's evidence beyond internal platform logs.

When autonomous systems act, who preserves independently verifiable evidence of what happened?

▸Evidentiary separation: Captured outside the agent runtime and sealed separately from the system that acted.
▸Independent verification: A third party can verify a signed verdict using only the public key and the verdict payload — no live VIAS service required.
▸Focused integration: Connects alongside existing agent workflows without replacing the model, runtime or security stack.
Explore the 6-Vector Spec

Control governs. Evidence proves.

The Separation of Autonomous Risk Infrastructure

Runtime controls constrain behaviour. Independent evidence preserves what occurred.

RUNTIME PLANE

Agent execution — Model providers, framework engines and agent orchestrators that run the autonomous action.

“What is executing, and under whose authority?”

CONTROL PLANE

Runtime containment — Sandboxes, circuit breakers, policy enforcement and hardware watchdogs.

“Can we prevent or contain unauthorised behaviour?”

EVIDENCE PLANE

VIAS — VIAS captures and seals execution events as they occur.

“Can we independently verify the evidence of what the agent executed?”

LIABILITY PLANE

Governance, investigation, dispute resolution, audit and underwriting — Consumes the evidence plane to investigate, audit, insure and defend the outcome.

“Where does liability sit, and on what evidence?”

VIAS connects the control plane to the liability plane. The platform operates the controls. The institution bears the consequences. VIAS preserves a separately sealed record for the parties that must investigate, audit, insure or defend the outcome — whether that is a regulator, an external auditor, a board or a court.

Coverage Statement · What Is Independently Verifiable Today

"Independent" is two axes, not one. Here is exactly where each stands.

A general counsel or underwriter who hears "independent verification" and assumes retrieval will feel misled in diligence. So we split the claim. Custody is live. Suppression-detection is live in mechanism, pending in field validation. Retrieval is pending. Stated plainly, because a hedged version of this statement would be worse than not having it.

Custody independence
LIVE

The sealed record is held and bound outside the operator. Any retroactive edit is independently detectable. A third party can verify a signed verdict using only the public key and the verdict payload — no live VIAS service required.

Suppression-detection independence
MECHANISM LIVE · FIELD VALIDATION PENDING

When expected submissions stop arriving, the absence itself becomes a sealed, detectable gap — silence is not invisible. The continuity-bond detector is deployed and catches synthetic failure cases — silence and a spoofed-but-stale heartbeat — in the test environment. Performance against real gaps in a live deployment is not yet field-verified.

Retrieval independence
PENDING

VIAS verifies what it is given. Content access still runs through operator cooperation or VIAS-published verdicts. VIAS does not extract evidence from the agent runtime without the operator today. The open boundary is partial submission — what the operator chooses to submit — not retroactive alteration of what has been submitted, which is independently detectable.

Why the gap and the wedge are the same boundary

The reason VIAS deploys alongside existing stacks without re-architecture is the same reason retrieval independence is pending: capture is submission-based, not extraction-based. If we promised retrieval, we would be promising rip-and-replace. The property that makes us deployable today is the property that bounds our independence today — and here is the sequence that closes it: ingress-verified submission, then hardware-bound retrieval. A competitor making a stronger retrieval claim cannot honestly match the deployment profile.

The Distinction

Control planes determine what agents may do.Evidence planes preserve what agents did do.

VIAS creates independently verifiable evidence of captured agent execution, sealed as it happens.

The unresolved question is no longer only who controls the agent. It is who can provide credible evidence when the agent's actions are disputed.

Why evidentiary custody matters

Most records are gathered after an incident occurs.

VIAS seals captured execution events before a claim, investigation or dispute exists.

The evidentiary value comes not only from integrity, but from preservation before incentives to alter the record emerge.

One Evidence Problem · Many Consequential Contexts

From autonomous action to consequential decision

The same evidence problem appears whenever AI actions create legal or financial consequences. One product, one category — applied across the contexts where execution evidence becomes load-bearing.

Security incidents

What did the agent attempt, and what controls intervened?

Claims and underwriting

What record existed before liability arose?

Payments

Did execution remain within the authority originally granted?

Administrative decisions

What inputs, authority and process produced the outcome?

Audit and governance

Can the evidence be verified without relying solely on the operator’s systems?

Operational Accountability · VIAS-1.0

Once captured and sealed, subsequent alteration through the platform is detectable. Full independence from a privileged operator is provided by external anchoring, in progress.

Internal logs are telemetry; VIAS is custody. VIAS seals each captured execution event as it occurs.

VIAS adds evidentiary custody by sealing captured events as execution occurs — before an incident, claim or investigation creates an incentive to curate the record. VIAS does not interpret whether an action was good or bad; it preserves evidence of what was captured.

Proof of integrity, not interpretation. Evidence, not introspection. Custody, not trust.

Coverage statement: VIAS verifies the integrity of the events it captures. Completeness depends on the integration boundary and deployment architecture.

Attestation Vectors · VIAS-1.0

Six complementary attestation vectors

Each captured action can be sealed across six complementary dimensions, preserving evidence of input, origin, response, handoff, scope and authorisation outside the host platform.

Vector-01 · Input

Binds declared inputs to the inputs presented for execution.

Vector-02 · Origin

Records declared model identity, version or hash, origin and relevant jurisdictional metadata.

Vector-03 · Response

Seals the canonical execution record and resulting output hash.

Vector-04 · Handoff

Links captured events across multi-agent execution chains.

Vector-05 · Scope

Records declared authority and observed system-access events within the integration boundary.

Vector-06 · Authorisation

Seals the policy grant, approval event and associated authorisation evidence.

Evidentiary separation

Why separation from the actor matters

A system's internal logs remain valuable operational telemetry. But when its actions are challenged, investigators may also need evidence captured and sealed outside the decision environment. VIAS provides that separate evidence layer.

Location

PlatformInside the operating environment
VIASCaptured outside the agent runtime

Purpose

PlatformOperations, debugging and monitoring
VIASEvidence preservation and independent verification

Record handling

PlatformDetermined by the platform configuration
VIASSequential, tamper-evident sealing

Verification

PlatformMay require access to the platform
VIASVerifiable from an exported evidence package

Intended use

PlatformOperational telemetry
VIASAudit, investigation, claims and review

Portable evidence under your control — verifiable independently of the system that acted

Vendor Independence · VIAS-1.0

Out-of-band from the agent is not the same as independent of the vendor

Hardware containment tools

Hardware containment tools from the leading chip vendor are control-plane measures — valuable, and increasingly required. But they run on the vendor's own silicon and are verified by the vendor's own tooling. They are out-of-band from the agent, but not independent of the vendor.

VIAS evidence custody

VIAS evidence is captured and sealed independently of both the agent runtime and the underlying compute vendor. The custody boundary is the actor, not the infrastructure provider — so the evidence survives even if the vendor's own tooling is the thing later disputed.

Evidentiary separation from the actor is one boundary. Vendor-independence from the infrastructure provider is another. VIAS holds the first by design; the second is the distinction this section exists to make clear.

Deployment · VIAS-1.0

Designed for focused integration alongside existing workflows. Deployment timing depends on boundary coverage, environment and assurance requirements.

Evidentiary independence reduces platform lock-in and avoids dependence on a specific model or agent runtime. The same HTTP endpoints integrate across every deployment model.

API Integration

Standard HTTP interfaces, with no model migration or re-platforming.

Dedicated Instance

An isolated, single-tenant deployment for sensitive workloads.

Sovereign / On-Prem

Deployment options designed to support data-sovereignty, controlled-network and air-gapped requirements.

Auditors and investigators can verify an exported evidence package without relying on the system that executed the action.

Regulatory Alignment · Platform-Ready

Aligned with emerging AI governance frameworks

VIAS evidence architecture is designed to support emerging requirements for AI record-keeping, operational resilience, transparency, and independent assurance across global and state-level frameworks.

EU AI Act · DORA · ISO 42001

Core European regulatory anchors for AI governance, operational resilience, and management-system assurance.

NIST AI RMF · UK ICO Guidance

US and UK risk-management and data-protection frameworks governing trustworthy AI deployment.

Emerging Requirements — AI Assurance

AI Record-Keeping

Emerging requirements for independent AI execution records and auditability.
▸VIAS provides tamper-evident execution records captured outside the agent runtime.

Operational Resilience

Frameworks requiring operational resilience and incident reporting for AI systems.
▸VIAS produces tamper-evident execution records suitable for incident disclosure.

Transparency & Assurance

Growing mandates for AI transparency, independent assurance, and auditability.
▸VIAS provides tamper-evident evidence designed to support audit, investigation and regulatory review — independently verifiable by auditors.

VIAS connects at the governance layer through reference architectures designed for major agent platforms — no re-architecture required. Platform-side configuration simply routes execution records to VIAS.