Frequently asked

Frequently Asked Questions

Nine short answers. If your question is not here, ask it on a live call.

  1. 01

    What does Nine Mile Security Group actually do?

    We are the independent proof layer for regulated AI. We produce portable, verifiable evidence that a decision made or assisted by an AI system was authorized, controlled, and accountable at the moment it happened.

    Think of the card network. Visa is trusted because it is neither the merchant nor the bank. It sits between them and settles what actually occurred. We hold that seat between your AI platform and the parties who have to believe its output: your board, your regulator, your auditor, your insurer, your customer.

    We are not a dashboard on top of your model. We are the backstop no platform can be for itself.

  2. 02

    Our AI platform already ships governance features. Why add anything?

    Because the platform is grading its own homework.

    The same vendor is frequently the host of the workload, the identity provider that decides who and what can act, the holder of the audit log, the orchestration surface, and a commercial party with exposure in the outcome. Every one of those roles is legitimate. Holding all of them at once is the problem.

    Independence is not a criticism of your vendor's controls. It is a structural requirement. Evidence that only your vendor can produce, interpret, and revise is evidence with a conflict baked into it. Nobody accepts a financial statement audited by the company that wrote it.

  3. 03

    What is a Decision Receipt?

    A Decision Receipt is a signed, tamper-evident record of a single governed decision. Tamper-evident means any later alteration is detectable by anyone holding the record, not just by us.

    Each receipt records the action taken, the decision made, and the signature standing behind it. It is issued at the moment of the decision, not reconstructed months later during an examination.

    Receipts are cut through our governance companion, which is the interface to the proof layer rather than the product itself. One receipt is small. A year of them is the difference between asserting you were in control and demonstrating it.

  4. 04

    What happens when a model is pulled, restricted, or swapped out?

    You keep your proof.

    This is not hypothetical. In June 2026 a frontier model was suspended mid-deployment to comply with export controls, then restored weeks later. Organizations that had built their evidence trail inside that vendor's surface had a governance gap for the duration.

    A model swap is itself a governance event. It changes what your system is capable of, what it is authorized to do, and what your prior assurances were based on. Because our receipts live outside any single platform, a suspension, a deprecation, a price change, or a migration does not erase the record of how you were operating before it.

  5. 05

    Who holds the keys, and can our regulator verify proof without you?

    You hold the keys. The buyer, not the vendor, and not us.

    Receipts are cryptographically signed, meaning each one carries a mathematical signature that proves its origin and integrity. Verification is designed to run outside our systems and outside your tenant, so a regulator, auditor, insurer, or counterparty can check a receipt without holding an account with us. The verification method travels with the receipt to the counterparties you choose to give it to.

    That is the sovereignty test we hold ourselves to. If your proof only works while you are our customer, it was never proof. It was a subscription.

  6. 06

    How does this map to the frameworks we already report against?

    Receipts are designed to be the evidence layer underneath the frameworks, not a competing framework.

    ISO/IEC 42001, the international management system standard for AI, and the NIST AI Risk Management Framework, the United States voluntary risk framework, both require you to show that controls operated, not merely that policies existed. The EU AI Act tightens that further for high-risk uses with record-keeping and human-oversight obligations.

    Every one of those asks the same question in different language: prove the control fired on this decision. A control that only probably fires is not a control. Receipts answer that question in a form an assessor can check.

  7. 07

    Do you replace our auditors, our compliance team, or our security stack?

    No, and we decline work that would.

    We do not audit you, certify you, or issue opinions on your compliance posture. Doing so would put us in the same conflicted position we exist to solve. Your auditors keep their independence and get better evidence to work from.

    We are also not a model, an agent, or an AI application that competes with your platform. We are operational infrastructure that sits beside it. Applications get replaced when the model changes. A proof layer becomes more necessary, because the model change is itself the thing that needs a record.

  8. 08

    Who is this for?

    Organizations where an AI-assisted decision creates real exposure and someone has to answer for it: financial services, healthcare, education, legal, insurance, and public sector operators under active or incoming AI obligations.

    Inside those organizations the usual first callers are the executive who signs the attestation, the risk or compliance lead who has to evidence it, and the security leader who inherits the incident when it goes wrong.

    We also work through channel partners. Auditors, insurers, and advisors bring us in when a client can assert good governance but cannot yet demonstrate it.

  9. 09

    How do we start, and what does the first engagement look like?

    Start with a Decision Receipt.

    We take one real decision from your environment, the kind you would struggle to defend under examination, and cut a live receipt against it. You see the exact artifact your regulator, auditor, or board would see. No pilot committee and no year-long integration to find out whether the model fits your operation.

    From there the sequence is Identity, then Policy, then Proof. Establish what is acting and on whose authority, define what it is permitted to do, then produce evidence that the boundary held.

Still have a question? Ask it on a live call.