Cryptographic sequence verifiability
Third-party-verifiable ordering and membership of recorded events — hash chaining is one admissible mechanism, not the only one.
VeritasChain Standards Organization (VSO)
An open meta-framework for making the records of AI systems tamper-evident, completeness-checkable, and attributable — after the fact.
VAP v1.26 domain profiles5 IETF Internet-DraftsCC BY 4.0
Why this exists
Legal and governance instruments across jurisdictions increasingly require logging and human oversight of AI systems. They specify the obligation — not how compliance can be independently verified after the fact. And the hardest part of that verification is not detecting records that were altered. It is detecting records that were never created.
Classical integrity technology — signatures, WORM storage, audit logs — proves things about records that exist. VAP is designed around the other problem: making the absence of a record inspectable by a third party, at a declared granularity, with disclosed limits.
| Tier | Condition | Status under VAP |
|---|---|---|
| Tier 1 | The event was never measured — nothing crossed the observation boundary | Permanently unrecoverable by design. VAP is silent; no mechanism reconstructs it, and no deployment may represent otherwise |
| Tier 2 | Measured, but the record was lost before anchoring | Bounded and disclosed — the gap itself is recorded as an anchor-gap event with its bounds |
| Tier 3 | Anchored, then omitted from what is presented | Third-party detectable via the Completeness Invariant (INT-008): omission / split-view detection |
Scope, stated plainly
“…does not warrant the correctness, fairness, or safety of the underlying AI decisions — only the integrity, completeness (at anchor granularity), and attributability of their records. VAP generates evidence; competent authorities and courts evaluate it.”
Mechanisms
Third-party-verifiable ordering and membership of recorded events — hash chaining is one admissible mechanism, not the only one.
Merkle batching and external anchoring of signed roots is required at all conformance levels in v1.2, with a documented anchor-continuity plan.
Any verifier holding an anchor can detect post-anchor omission and split-view presentations: each AnchorRecord binds event count, first/last event IDs, and the governing policy identifier.
Refusals, denials, and negative decisions are recorded with the same rigor as approvals. Systems that only log successes prove nothing about what they declined.
A portable, self-verifying bundle for offline third-party verification — records, proofs, anchors, and keys, checkable without access to the producing system.
Declared observation scope up front; independent cross-referenced logging by multiple parties (XREF) so no single actor’s record stands alone.
The family
VAP itself is never a protocol. Profiles bind the framework to sector semantics; the Protocol designation belongs to exactly one document — VCP.
Finance / algorithmic trading — the audit-standards profile for capital-markets AI. The only document in the family carrying the Protocol designation.
A verifiable evidence layer for AI workflows involving content and intellectual property — ingestion, training, generation, transformation, export — for games, film, animation, publishing, and music.
Provenance for media captured by a device the operator controls (first-party capture). Sibling of OAP.
Clinical and benefits workflows: AI outputs, human review, override, and sign-off records made tamper-evident and third-party inspectable.
Records of third-party web resources observed at a URL — material published by someone else, preserved because it may later be disputed, deleted, edited, or denied.
Credit scoring, welfare determination, immigration, recruitment AI. The Investigative-Decision Vocabulary fragment (v0.2 draft) is the first published track.
All profiles, cross-cutting capabilities, and the registry →
Standards engagement
Five active drafts socialize the framework’s constructs in the IETF RATS and SCITT areas. VSO also tracks and assesses adjacent work in ISO/IEC JTC 1/SC 42 and ITU-T SG17 under pre-registered assessment protocols.
draft-kamimura-vap-framework-01 — The VAP framework event and anchoring modeldraft-kamimura-scitt-vcp-03 — VCP alignment with the SCITT architecturedraft-kamimura-scitt-refusal-events-03 — Refusal / denial events in transparency servicesdraft-kamimura-rats-behavioral-evidence-02 — Behavioral evidence in the RATS architecturedraft-vso-cpp-core-03 — CPP core (capture provenance)Honest baseline
As of August 2026: zero external implementations, zero paying customers, and zero Evidence Packs accepted in any proceeding. Every VSO document carries this disclosure. We publish what does not yet exist as clearly as what does — a provenance framework that overstated its own record would be self-refuting.
Specifications are open (CC BY 4.0) and developed on GitHub. Implementers and reviewers are welcome: standards@veritaschain.org.