← Back to licet

THE RECORD AND THE WEBSITE

Security & verification

Claims should be inspectable. Demonstrations should say what they demonstrate.

Evidence crosswalk

Evidence crosswalk · licet’s mapping
ReferenceAccountability focusRecord evidenceScope
AIUC-1
E004.1 ↗
Change approvals and accountable leadsNamed approver; sign-off; versioned conditionsEvidence contribution; no certification claim
ISO/IEC 42001
A.3.2 · 5.3 ↗
AI roles, responsibilities and authoritiesApproving roles; named risk acceptor; signed historySystem record; not a management system assessment
NIST AI RMF
GOVERN 2.3 ↗
Executive responsibility for AI risk decisionsRisk acceptance tied to scope, conditions and durationDecision evidence; signer’s authority established separately
DSA
Article 37 ↗
Independent audits of designated very large platforms and search enginesExportable history; cited obligations; evidence referencesAudit input; not an audit opinion

The working prototype.

The working prototype canonicalizes authorization records, signs them with Ed25519, and supports offline verification with the standalone verifier and supplied public keys. Revalidation connects the authorization to changes in the system, policy, and applicable authorities.

What is live on this website.

This is a public marketing website with a server-backed introduction form. The homepage uses fictional demonstration data and product screenshots. Its content-moderation scenario and evaluation attachment are illustrations, not customer results or runtime enforcement. The browser verifier checks the embedded MER-2026-0001 snapshot’s canonical digest and four Ed25519 approval signatures against the published demonstration public keys. The same signed artifact is available to download. This checks integrity, not real-world signer identity or current authorization status. The website is not connected to a live Registry, signing service or enforcement point.

Authorization records institutional permission. Control effectiveness is not assessed by the record review, and legal compliance is not determined. External executor integration is required to enforce a permission decision in a production workflow.

Three distinct questions.

AuthorizedDid the institution complete its authorization lifecycle?
VerifiedDid a verifier actually check these bytes and signatures against a trusted key?
Allow / denyWhat does an enforcement point decide about a particular action in a particular context?

This website does not substitute one result for another.

Access.

This marketing website is publicly accessible. Access to the licet application is separate. This website does not provide access to platform records or production systems. Contact submissions are stored separately from the licet application; email alerts are attempted only after storage succeeds.

Reporting a concern.

Contact david@licet.ai with a nonconfidential description. Please do not send secret keys or sensitive platform records.