Independent, neutral, verifiable

The Independent Trust Layer for Regulated AI.

The backstop no platform can be for itself.

Founder holding a Decision Receipt as it is cut in two.Founder holding a Decision Receipt as it is cut in two.
Decision Receipt
Decision
ALLOW
Signature
ed25519:7f3a...c91e

Who has to trust it later

The Reliance Gap

The decision takes a second, and everyone who has to answer for it shows up later.

They all need the same record, and the only one that exists is kept by the company with the most to lose if it looks bad.

  • Auditor has to sign off on controls he can't test.
  • Underwriter has to put a price on a risk she can't look at.
  • Lender has to explain one decision on one file, long after it was made.
  • Counsel has to defend it in a fight, using records the other side kept.

Almost nobody who has to trust an AI-assisted decision was in the room when it was made.

Four different jobs, four sets of pressure, one thing none of them can get. The problem was never how carefully the record is kept, but who keeps it.

That gap cannot close from the inside. It closes from outside, or it stays open.

See how this lands in your chair

The reliance gapThe reliance gap
Two people seated across a dark table under a spotlight, a green-glowing folder between them, a guard behind a neon-green wall frame.Two people seated across a dark table under a spotlight, a green-glowing folder between them, a guard behind a neon-green wall frame.

The problem

Someone has to answer, and it cannot be the platform that decided.

AI is moving into decisions that carry real consequence: the trade that executes, the claim approved or denied, the action an agent takes at 2am with nobody in the building.

Ask a model the same question twice and it can answer two ways, but even a model that never did that would still be the player grading its own play.

The proof has to come from somebody who is not in the game, and that is the receipt we keep.

the evidence

Claim. The model can't be its own proof.

  1. 1. NOT REPEATABLE BY DEFAULT One prompt run 1,000 times at temperature 0 produced dozens of different outputs, caused by how requests batch on the graphics processing unit (GPU), floating-point order, and model routing, not by sampling randomness.

  2. 2. DETERMINISM IS ACHIEVABLE, AND BESIDE THE POINT It can be forced with batch-invariant kernels and pinned hardware at roughly 34 to 62 percent throughput cost, and it is neither the default nor available in shared cloud serving.

  3. 3. THE MODEL IS STILL THE THING BEING CHECKED Reproducibility was never the requirement, and independence was.

Source: Thinking Machines Lab, "Defeating Nondeterminism in LLM Inference," September 2025.

One incident

A Tuesday in the claims queue.

02:14, a Tuesday in March

Representative scenario. No client named.

A banded stack of cash dissolving into particles against black.A banded stack of cash dissolving into particles against black.

Direct loss

$780,000

Sequence of events

  1. 02:14

    An AI agent approves 1,900 claims in nine minutes. Nobody is watching.

  2. That night

    A model update shifts how one field, the date of loss, is read.

  3. Undetected

    Forty-one claims fall outside their coverage window. Approved anyway.

  4. On review

    The platform re-runs the prompt. Same input, different output.

  5. Too late

    By the time a person notices, the money is gone.

  6. 3 weeks later

    The regulator asks who approved these, and on what basis. No independent proof exists.

Every action was logged and every log said ALLOW, but none of them said why and none could be replayed.

When the insurer asked the platform to prove the decision, it re-ran the prompt and got a different answer, and nothing had broken: the system behaved exactly as designed.

The direct loss was $780,000, and the larger cost was the answer nobody had to who approved these and on what basis, because the insurer held a complete record of what happened and no independent proof of why.

That is the failure that matters. Not a breach, not an outage, but a quiet and fully authorized decision that nobody can stand behind.

An independent receipt cannot stop a model from drifting, but it catches the drift, ties it to an identity, and produces proof every side can trust.

The one held picture, sharpened

Visa isn't the merchant. Or the bank.

The card network is trusted by both sides for exactly one reason: it is neither of them, so neither the merchant nor the bank grades its own transaction.

AI acts now, and the platforms are trying to be merchant, bank, and referee at once, which is why somebody has to be the neutral party for what AI does.

A three-panel diagram of a card payment transaction: initiation, network authorization, and receipt.A three-panel diagram of a card payment transaction: initiation, network authorization, and receipt.

The category

What we are

  • Operational infrastructure for regulated AI.
  • The neutral party that turns AI decisions into portable, verifiable proof.

What we are not

  • Not an AI application.
  • Not software.
  • Not a dashboard.
  • Not a consultancy.

What we actually sell, three insurances

Not governance. Insurance on the governor.

A dark command center with a wall of green data visualizations and three podiums labeled Independence, Continuity, and Sovereignty.A dark command center with a wall of green data visualizations and three podiums labeled Independence, Continuity, and Sovereignty.

01 Independence

Insurance against the platform grading its own homework.

When one vendor is the agent, the enforcer, and the auditor of record at once, an outside auditor or regulator needs proof from a party that is not the one being judged.

02 Continuity

Insurance against the platform as a single point of failure.

If identity, policy, audit, and enforcement all live in one vendor's stack, an outage or an acquisition takes your whole governance posture down with it.

03 Sovereignty

Insurance against lock-in.

The record of what your AI did should be portable, held under your own keys, and verifiable outside any vendor's tenant.

Independence, continuity, sovereignty. Three things no platform can provide about itself.

A console labeled ALFRED projecting three green holographic panels: identity verified, fixed policy, and signed receipt.A console labeled ALFRED projecting three green holographic panels: identity verified, fixed policy, and signed receipt.

How it works

Identity, then Policy, then Proof.

  1. 01

    Identity

    Tie every action to an identity that can be held to account.

  2. 02

    Policy

    Check the action against fixed policy before it executes.

  3. 03

    Proof

    Preserve a signed receipt of what happened, held under your keys rather than the platform's, and verifiable outside NMSG and outside your tenant by a party that holds no account with either.

An auditor opines and an underwriter prices on the artifact, while counsel defends and a lender explains from the record rather than from a reconstruction.

Who it is for

Built for the person who has to answer.

This is for the person carrying liability for outcomes produced by AI systems they did not build, and for anyone who has learned that the failure that matters happens off-hours and at volume, when a control that only probably fires proves it was never a control at all.

It is not for developers evaluating an application programming interface (API), buyers shopping for a governance tool, or anyone looking for a demonstration, and they will know within a line.

A man seated behind a long dark desk under a single spotlight, an amber light streak across the desk.A man seated behind a long dark desk under a single spotlight, an amber light streak across the desk.
Portrait of the founder of Nine Mile Security Group, with the words Authority, Policy, Evidence, and Accountability.Portrait of the founder of Nine Mile Security Group, with the words Authority, Policy, Evidence, and Accountability.

Why me

I did not come to this from AI. I came from security, writing up other people's breaches for the people who had to act on them, and the same shape kept turning up.

The control fired or it did not, and either way the evidence went nowhere. By the time anyone needed to know what happened, the only record left belonged to the party being asked about it.

Platforms will keep getting better at enforcement, and none of it produces evidence an outsider can rely on, because a check on a system cannot be the system.

So I took the seat that is left. Infrastructure means the ordered assembly laid beneath, and what nobody sees decides what can stand above it. That is the whole job, and I intend to do only that.

W

Founder, Nine Mile Security Group

A platform can't be the independent check on itself, and we are that check: the neutral proof layer for regulated AI.

We are building the layer beneath the AI economy, the independent conscience that keeps power honest, and the agent economy does not have one yet.

Decision Receipt
Action
Execute wire transfer instruction
Decision
ALLOW
Signature
ed25519:7f3a...c91e
A person steadying a load-bearing column, standing at the edge of the light.A person steadying a load-bearing column, standing at the edge of the light.