Trust center
What we can prove, and what we cannot yet.
We sell an evidence layer, so a trust page that lists only the flattering facts would undercut the product. Below is the boundary, the key ownership, the reporting path, and an open risk register we have not finished closing.
Last updated 2026-09-17
Data flow
What crosses the boundary.
Hash only witnessing is the default. Full body ingest exists, and it is off unless you explicitly turn it on.
Leaves your environment
- A canonical SHA-256 hash of the request and of the response
- Ed25519 and ML-DSA-65 signatures over the canonical record
- The public key fingerprint you published
- Token counts, model name, latency
- Agent identity, policy version, enforcement outcome
- Transparency log inclusion proofs
Never leaves your environment
- Prompts and inputs
- Model outputs and completions
- Documents and data the agent touched
- Record bodies
- Your private signing keys
Key ownership
You hold the signing key.
You generate it, you publish the public half, and you control it. Stones AI never holds your private key and could not produce a record in your name if we wanted to.
Our own witness keys run the other direction: the public key manifest is published so an auditor can check our witness signatures without asking us for anything. The verifier refuses to read a public key out of the record it is checking, because that would be circular.
Open risks
The register we have not closed.
V1 alpha, in pre-production hardening. GA target Q1 2027. These are the things we would want to know if we were buying this.
No third-party audit yet.
SOC 2 is not complete. No independent security audit has been performed. We are targeting this alongside V1 GA and will publish the result either way.
Signing keys live in a file, not an HSM.
Key material is held in a JSON file on the customer side rather than in a hardware module or managed KMS. HSM and KMS support is V1 GA scope. If your threat model requires it today, say so early and we will tell you plainly that we are not there yet.
Record bodies are not WORM stored by default.
The witnessed hash is append only. The record body sitting in your environment is not, unless you package it for a WORM store yourself. vadr-retain exists for that, and SEC 17a-4 grade production retention is V1 GA scope.
We operate one of the two witnesses.
Stones AI runs the witnessed log. We are in the chain. The mitigation is that nobody has to trust us: the second witness is Sigstore Rekor, which is public and operated by the Linux Foundation, and disagreement between the two logs is itself the tamper signal. We would rather say this first than be asked.
Canonicalization is JCS-approximate, not strict RFC 8785.
Number formatting and UTF-16 sort order are approximated. This is fine for records produced and verified by our own toolchain, and it is a real caveat if you are writing an independent verifier. Ask us for the spec.
Certifications
Stated plainly.
- SOC 2
- Not complete. Not started as a formal engagement.
- ISO 27001
- Not held.
- ISO 42001
- Not held.
- Penetration test
- No third-party test performed yet.
We would rather publish an empty row than imply a filled one. If a certification is a hard requirement for you today, we are not the right vendor yet, and we will tell you that in the first call rather than the fourth.
Hosting
Where things actually run.
VAiDR runs inside your environment. The enforcement point and the records are deployed into infrastructure you control, which is why the boundary above holds by construction rather than by policy.
This website is a static site on AWS S3 behind CloudFront. It sets no advertising pixels, runs no session replay, and does no cross-domain identity stitching. Fonts are self-hosted, so loading a page here does not call a third-party font service.
Reporting a problem
Tell us and we will answer.
Security
security@stonesai.comReport a vulnerability here and a person reads it, not a queue. We will tell you what we find and work out timing with you. We would far rather hear about a problem from you than from someone else, and we treat research done in good faith as the favour it is.
Everything else
Security questionnaires, architecture review, or a conversation about whether this fits your threat model: use the contact page and pick the security path. You will get a person, not a portal.
The point
A vendor who publishes their open risks is telling you how they operate.
We have not been through an audit yet. Publishing the register instead is not a substitute for one, and it is the most honest thing we can hand you until there is one to publish.