Trust Framework
From software to a trust framework.
Assurance is a graduated property. These five proposed levels describe how far an organisation's AI evidence can be trusted, and by whom.
Proposed levels
Five assurance levels
- 01
Recorded
A defined evidence record exists for AI events.
- 02
Reconstructable
Historical information and system state can be reconstructed.
- 03
Verifiable
Cryptographic controls provide evidence-integrity assurance.
- 04
Independently Auditable
Authorised independent parties can interrogate evidence.
- 05
Sovereign Assured
Deployment satisfies defined jurisdictional, governance and infrastructure requirements.
The final Safe Haven assurance framework would be developed with appropriate governmental, regulatory, legal, technical and industry stakeholders.
Verifiability
Evidence should be verifiable, not merely stored.
- Hardware Security Modules (HSMs)
- Protected signing keys
- Digital signatures
- Immutable / WORM storage
- Evidence hashes
- Hash chains or Merkle structures
- Trusted timestamping
- Strong administrator separation and role segregation
Architecture target: support for FIPS 140-3 Level 3 hardware-backed cryptographic key protection where required. Deployed FIPS compliance is not claimed until the final architecture and validated components are in service.
Strategic engagement
Government, banking or technology stakeholder?
We are currently developing the Safe Haven architecture and exploring potential pilot, policy, infrastructure and funding partnerships.