CSOAI - for enterprises

Measure once. Show the signed card.

You face overlapping AI regimes across regions and business units. CSOAI does not sell one control set that satisfies all of them - no one honestly can. What we publish is a signed measurement board with its unmeasured slots left visible, and a dated feed of the regime texts underneath it.

Your path with CSOAI

What you can check, right now

Overlapping regimes reuse the same evidence, so the useful question is what the evidence actually says. These four rows carry the n, the interval and the separation verdict behind each figure — including where the lead is a TIE, which is not a win and is never presented as one.

AxisBenchnLeader accuracy95% CISeparation
governanceGovBench23770.0%63.9–75.5%SEPARATED p=0.0086
continuityPQCBench3360.6%43.7–75.3%TIE — indistinguishable p=1
safetyDefBench3694.4%81.9–98.5%TIE — indistinguishable p=0.6875
detector-interopDetBench3387.9%72.7–95.2%TIE — indistinguishable p=0.4531
Every figure above is read from GET /api/gspc when this page loads — none of it is written into the page. Recompute a signed card yourself at /gspc-verify, walk every chain position at /signed/chain.json, and read the rules the grades are computed under at /methodology. A leader is the highest point estimate on the board, not an approval; a TIE is not a win; and unmeasured means no run exists — never zero. We measure against these obligations; we do not enforce them and we certify nothing.

overlap

One measurement, many readers

The EU AI Act, the Cyber Resilience Act, DORA, NIS2 and UK GDPR sit in our dated corpus feed as hashed baselines watched for drift. That is a shared reference several teams can read from. It is not a claim that one control set satisfies those regimes, and we do not type a framework count into this page.

What you can check on the board

A cross-regime reader usually wants the classification axis, the resilience axis, and one that is deliberately empty.

Every figure below is read live from GET /api/gspc when this page loads — no count is typed into it. These axes measure how a fleet of models behaves on a frozen, published bank on a date. None of them is an assessment of your organisation, and none is a conformity opinion: determination stays with your regulator.

Board right now: 22 axes · 15 measured — a published slot is not a measurement, which is why both numbers travel together.

  • governanceMEASUREDGovBench

    EU AI Act risk-tier classification — the judgement that decides which duties apply to which system in your estate.

    What is graded:
    EU AI Act risk-tier classification
    n:
    237 bank items
    Leader:
    70.0% (council-embodiment-v3-light (council specialist))
    Separation:
    SEPARATED
    Frozen bank:
    csoai/gspc-gov
  • continuityMEASUREDPQCBench

    Post-quantum status of a cryptographic assumption: the long-horizon resilience question behind CRA and DORA reasoning.

    What is graded:
    post-quantum status of a cryptographic assumption
    n:
    33 bank items
    Leader:
    60.6% (council-destruction-v3-light (council specialist))
    Separation:
    TIE — the leader's lead is not statistically separated, and a tie is never counted as a win.
    Frozen bank:
    csoai/gspc-asi
  • conformanceMEASUREDMCPBench

    MCP tool conformance — how models behave against a declared tool interface, which is where most agent integrations actually break.

    What is graded:
    MCP tool conformance
    n:
    35 bank items
    Leader:
    74.3% (council-preservation-v3-light (council specialist))
    Separation:
    TIE — the leader's lead is not statistically separated, and a tie is never counted as a win.
    Frozen bank:
    csoai/gspc-mcp
  • Published as an open slot with no run behind it. It is on this page on purpose: you should be able to see where the board is empty before you rely on it.

    What is graded:
    is the governing regime declared and confirmable (MiCA / UCITS / Reg D / BVI)? (deterministic Y/N)
    n:
    0 nothing measured

Re-check it without us

Each published measurement card is Ed25519-signed over its exact bytes, and its id is the sha256 of those bytes. Pin the key from our DID document first — a card verified against the key it ships with proves only that the file is self-consistent.

Ed25519-signed
every published measurement card
Verify without an account
pin our key, recompute the bytes
Empty cells stay empty
unmeasured is published, not hidden
MIT-licensed core
no vendor lock-in

Questions, answered

How does CSOAI handle overlapping frameworks?

We measure against frozen provisions and publish the card. Overlapping regimes can reuse the same signed evidence. We do not claim a single control set satisfies every regime by itself — regulators decide conformity.

Is CSOAI locked to one vendor?

No - the core is MIT-licensed and signatures are offline-verifiable against a key you fetch yourself, so nothing here depends on a single commercial vendor staying in business.

Council OS — enterprise

Answers from published measurement, or it refuses. Your question is typed into the lobby — nothing sends until you press Ask.

Open Council OS

Deterministic pane commands · grounded /api/chat lane · consent checkpoint on consequential steps