Frequently asked
Frequently Asked Questions
Nine short answers.
01
What does Nine Mile Security Group actually do?
We are the independent proof layer for regulated AI.
We produce portable, verifiable evidence that a decision made or assisted by an AI system was authorized, controlled, and accountable at the moment it happened, and we are not a dashboard sitting on top of your model.
Think of the card network, where Visa is trusted because it is neither the merchant nor the bank but sits between them and settles what occurred. We hold that seat between your AI platform and the parties who have to believe its output: your board, your regulator, your auditor, your insurer, your customer.
02
Our AI platform already ships governance features. Why add anything?
Because the platform is grading its own homework.
The same vendor is frequently the host of the workload, the identity provider deciding who and what can act, the holder of the audit log, and a commercial party with exposure in the outcome, and every one of those roles is legitimate on its own while holding all of them at once is the problem.
Independence is not a criticism of your vendor's controls but a structural requirement, because evidence that only your vendor can produce, interpret, and revise carries the conflict inside it, and nobody accepts a financial statement audited by the company that wrote it.
03
What is a Decision Receipt?
A signed, tamper-evident record of a single governed decision.
Tamper-evident means any later alteration is detectable by anyone holding the record rather than only by us, and each receipt captures the action taken, the decision made, and the signature standing behind it.
It is issued at the moment of the decision rather than reconstructed months later during an examination, and while one receipt is small, a year of them is the difference between asserting you were in control and demonstrating it.
04
What happens when a model is pulled, restricted, or swapped out?
You keep your proof.
In June 2026 a frontier model was suspended mid-deployment to comply with export controls and then restored weeks later, and organizations that had built their evidence trail inside that vendor's surface carried a governance gap for the duration.
A model swap is itself a governance event, because it changes what your system can do and what your prior assurances rested on, and since our receipts live outside any single platform, a suspension or a deprecation or a migration does not erase the record of how you were operating before it.
05
Who holds the keys, and can our regulator verify proof without you?
You hold the keys, the buyer, not the vendor and not us.
Receipts are cryptographically signed, meaning each carries a mathematical signature proving its origin and integrity, and verification runs outside our systems and outside your tenant so a regulator, auditor, or insurer can check one without holding an account with us.
That is the sovereignty test we hold ourselves to, because if your proof only works while you are our customer, it was never proof but a subscription.
06
How does this map to the frameworks we already report against?
Receipts are the evidence layer underneath the frameworks, not a competing framework.
ISO/IEC 42001, the international management system standard for AI, and the NIST AI Risk Management Framework, the United States voluntary risk framework, both require you to show that controls operated rather than that policies existed, and the EU AI Act tightens that for high-risk uses with record-keeping and human-oversight obligations.
Every one of those asks the same question in different language, which is whether the control fired on this decision, and a control that only probably fires is not a control.
07
Do you replace our auditors, our compliance team, or our security stack?
No, and we decline work that would.
We do not audit you, certify you, or issue opinions on your compliance posture, because that would put us in the same conflicted position we exist to solve, and your auditors keep their independence while getting better evidence to work from.
We are also not a model, an agent, or an application competing with your platform, and where applications get replaced when the model changes, a proof layer becomes more necessary, because the model change is itself the thing that needs a record.
08
Who is this for?
Anyone who has to answer for an AI-assisted decision they did not personally make.
That means financial services, healthcare, education, legal, insurance, and public sector operators under active or incoming AI obligations, and inside them the usual first callers are the executive who signs the attestation, the risk or compliance lead who has to evidence it, and the security leader who inherits the incident.
We also work through channel partners, where auditors, insurers, and advisors bring us in once a client can assert good governance but cannot yet demonstrate it.
09
How do we start, and what does the first engagement look like?
Start with a Decision Receipt.
We take one real decision from your environment, the kind you would struggle to defend under examination, and cut a live receipt against it, so you see the exact artifact your regulator, auditor, or board would see without a pilot committee or a year-long integration.
From there the sequence is Identity, then Policy, then Proof: establish what is acting and on whose authority, define what it is permitted to do, then produce evidence that the boundary held.
Still have a question? Ask it on a live call.