Claims register · 18 claims · generated 2026-08-26

Every claim we make, and what backs it.

Every material capability claim CSOAI makes on a public surface, with the evidence a stranger can check and the status that claim has actually earned. A capability we plan to build is not a capability we advertise; planned work is labelled planned.

LIVE6DEVNET1PLANNED6RETIRED5

Machine-readable at /claims-register.json. This page renders that exact file — there is no second copy to drift.

What the statuses mean

LIVE
Shipped and checkable today.
DEVNET
Proven on a test network only — not production.
PLANNED
Intended. Not built, or built and not shipped.
RETIRED
Previously published, now withdrawn — with the reason.
LIVE

6 claims

  • Every published measurement card is signed with Ed25519 over a SHA-256 hash chain and can be verified offline against did:web:csoai.org, without our servers or our permission.

    CR-001

    This is the whole trust path. No blockchain and no timestamp authority sits in it.

  • "Layer 0" is our foundational verification layer — identity, signing and attestation beneath governed AI.

    CR-005

    Disambiguation, because the term collides: this is NOT a blockchain Layer-0 protocol and NOT an interoperability substrate for blockchains. No protocol claim is made or implied by the name.

    Evidence/layer0
  • The GSPC measurement board is live, machine-readable, and reports UNMEASURED honestly rather than filling empty cells.

    CR-010

    Empty cells stay empty. Nothing is quoted below n>=30.

  • Our own status page probes components live and marks the ones it cannot honestly check.

    CR-011

    Rows with no public health endpoint are labelled "not probed from this page" rather than painted green, and the incident log is not backfilled. CORRECTION 2026-08-26: this claim was briefly FALSE in a way the page itself could not see. The tool-fleet row probed /api/tools, received a real 200, and reported "operational" — but the number inside was a 291-row registry snapshot rendered as "governed MCP tools (deployed)" under a caption reading "live from the Council engine". The probe was real; the figure it surfaced was a catalogue. The endpoint had always labelled it total_kind=catalogue-snapshot and the UI discarded that field. Each figure now carries its own provenance and only a genuine probe result may be called reachable.

    Evidence/status
  • Grading is deterministic; no model judges another model.

    CR-013

    Every verdict is a deterministic predicate on frozen splits. Not LLM-as-judge.

    Evidence/methodology
  • CSOAI carries Professional Indemnity Insurance up to £5,000,000.

    CR-015

    Policy number on request. CSOAI LTD, UK Companies House 16939677.

DEVNET

1 claim

  • Signed measurement evidence can be attached permissionlessly to the XRP Ledger about accounts we do not control (memo + XLS-70 credential), and a stranger can verify the attachment.

    CR-003

    XRPL DEVNET only, with a synthetic subject. Proof of capability, never an investment, a rating or a conformity mark. Mainnet is planned, not live.

PLANNED

6 claims

  • Blockchain / independent timestamp anchoring of cards (OpenTimestamps, RFC-3161).

    CR-002

    Cards declare timestamp_authority: "none". There is no RFC-3161 timestamp and no Bitcoin anchor behind any card. The label will name it in the same commit it ships, never ahead of it.

  • XRP Ledger mainnet attestation.

    CR-004

    Not deployed. Attesting is permissionless; authorisation inside any permissioned domain still requires the relying party to trust our issuer key.

    Evidence/xrpl-attest
  • Post-quantum ML-DSA-65 (FIPS-204) signing.

    CR-006

    Built, not shipped. Nothing published today is ML-DSA-65 signed.

    Evidence/methodology
  • C2PA / Content Authenticity conformance for published artefacts.

    CR-012

    Contributor, conformance in progress. Artefacts today carry Ed25519 provenance, not C2PA conformance.

  • ISO 27001, ISO 42001 and SOC 2 Type II certification.

    CR-016

    All three are marked In Progress because they are genuinely in progress. No assessor's letter exists for any of them; when one does it will be published. We are not certified to SOC 2 or ISO/IEC 42001 and do not claim to be.

  • Per-region data residency selection (EU / US / APAC).

    CR-018

    Designed, not yet offered. The public site is served from Cloudflare's edge; the measurement backend is first-party, self-hosted UK/EU. The card will name regions and safeguards on the day it ships, not before.

RETIRED

5 claims

  • A 33-seat council with a 23-of-33 supermajority delivers fault-tolerant, decorrelated review.

    CR-007

    Retracted under DR-0007. We measured how independent the seats actually were and got n_eff 1.21 of 3 against 3 nominal legs. The 33/23 structure is a DESIGN figure and is labelled as one wherever it appears; the fault-tolerance guarantee is withdrawn, not reworded.

  • CSOAI certifies, accredits, or issues conformity marks for AI systems.

    CR-008

    We measure; we never certify. The Academy issues course-completion records, which attest training and not conformity. No CSOAI output is a conformity assessment under any regulation.

  • CSOAI measurement is recognised under mutual-recognition agreements with named regulators (CISA, NCSC, ANSSI, BSI, BEREC, ENISA, ICMM, CRMA, national transport / mining / AI oversight authorities).

    CR-009

    Removed 2026-08-26. This appeared on five sector pages and was never substantiable: CSOAI holds no mutual-recognition agreement with, and is not endorsed or accredited by, any of these bodies. The pages now say only that we crosswalk our measurement output to those compliance pathways, which is what we actually do.

  • A £20 million scholarship / scholarship fund.

    CR-014

    Checked 2026-08-26 across the codebase, the built bundle and the live site: no such claim is published on any CSOAI surface, and no such fund exists. Recorded here so the claim cannot quietly reappear. The Charter's diversity provision mentions scholarships as an aspiration with no monetary figure attached.

  • "GDPR Compliant" as an attained, badge-level status shown beside certification rows.

    CR-017

    Reworded 2026-08-26. GDPR compliance is a self-assessed posture, not a certification, and a green Compliant badge sitting next to ISO and SOC 2 rows implied an audit that does not exist. The row now reads GDPR / Self-assessed and says so. The Article 17 line no longer claims "full compliance" or "instant" deletion; it states erasure on request within the statutory one-month window.

Found one that does not hold?

If a claim here does not match what you can verify, that is a defect. Report it at [email protected] and it goes to the corrections feed at /api/corrections.

The refutation ledger → is where claims we withdrew are recorded, with the measurement that killed them.