I'm looking at this as:
Sovereign LLM Trust Infrastructure · Licensable IP

Provable AI Act compliance,
as infrastructure — not a PDF.

NI-Stack turns every LLM interaction into a post-quantum-signed, browser-verifiable audit receipt — screened on-premise, on commodity CPU, mapped to EU AI Act Art. 12 / Annex IV. Peer-review-format preprints, in review. Buyer-reproducible. Available for licensing or acquisition.

97.7% injection TPR @ 4.0% FPR · English · CI 94.3–99.1 Post-quantum FIPS-204 ML-DSA-65 2 IEEE-format preprints · in review On-prem · prompt never leaves
The EU AI Act gold nugget

POAW — Proof-of-Agent-Work receipts

Proven & measured

Every verdict is hashed into an append-only Merkle log, signed with FIPS-204 ML-DSA-65 (real 3309-byte post-quantum signatures, not stubs), independently timestamped (RFC-3161), and exported as a W3C Verifiable Credential an auditor checks offline, in a browser — never trusting our servers.

3309-byte

genuine ML-DSA-65 signatures

96

assertions: replay, inflation & forgery all caught

Offline

browser-verifiable against a did:web key

▶  The NI-Stack story (90 sec)▶  POAW in 60 secondsAll 5 POAW use cases →

POAW is the differentiated asset: no other guardrail ships a portable, offline-verifiable, post-quantum evidence receipt mapped to the AI Act. Self-referentially, our benchmark results themselves ship as POAW receipts — 11 metrics bound into a Merkle root; edit one digit afterwards and verification reads TAMPERED. It is what a compliance-platform vendor licenses.

The stack — honestly scoped

Two proven subsystems, and a research portfolio

We license what is measured and real, and label the frontier as frontier. Overclaiming kills IP deals in diligence — so we don't.

AEGIS
Proven

AEGIS — CPU-first guardrail

A sovereign injection/content cascade led by a zero-dependency Aho-Corasick automaton that blocks before any GPU spend — full-cascade median 0.92 ms, ~767 prompts/s on one CPU core (n=1,200, AMD Ryzen AI MAX+ 395, 2026-08-09). 97.7% TPR / 4.0% FPR on public corpora (95% CI 94.3–99.1, English); the prompt never leaves the premises.

LEDGER
Proven

LEDGER / POAW — audit substrate

The post-quantum, browser-verifiable receipt layer above. Real ML-DSA-65 signatures; tamper, replay and forgery detected across 96 assertions. Mapped to EU AI Act Art. 12 / Annex IV.

Research

ORACLE · AUGUR

Memory & forecasting modules — under evaluation, not sold as finished.

Research

SCRIBE · SIREN

Compliance-export & monitoring adapters (EU AI Act Annex IV, ISO 42001).

Research

JOULE

Energy-accounting module — measured claims pending.

Proof, not assertion

Everything here is measured and reproducible

97.7% [94.3–99.1] / 4.0% FPR

Injection detection on public corpora (hackerprompt, jailbreakhub vs OR-Bench; n=176/150, English) — buyer-reproducible with one command.

0.92 ms · 767 prompts/s

Full-cascade median per decision on one CPU core (p95 3.1 ms, n=1,200, AMD Ryzen AI MAX+ 395) — screening cost is negligible next to any inference.

Sovereign · on-prem

Runs on commodity CPU before any GPU; no prompt exfiltration — a data-residency win by construction.

The spread we volunteer — detection is attack-class-dependent

Most vendors publish their best corpus. We publish the whole spread, with n and 95% confidence intervals (8 public corpora, n=300 each, measured 2026-08-09):

Attack classDetectionReading
Classic injection99.3% [97.6–99.8]the cascade's home turf — syntactic/instruction attacks
Narrative jailbreaks38.7–41.0%a disclosed ceiling — story-based attacks need LLM-class semantics
Content-harm elicitation8.3–12.0%largely a different task (harmful-content refusal, not injection) — published anyway
System-prompt-leak canaries (output side)83.3% [78.1–87.5] · 0.0% FPn=240; verbatim/encoding transforms 100%, paraphrase 0% — bimodal, disclosed
Test Stage-1 live — in your browser →Preprints & manifests
Honest scope — this is why buyers trust us. AEGIS + POAW are proven; a two-number evaluation methodology is a third contribution. We publish gaps in the same breath — the per-class spread above is volunteered, not extracted in diligence; the headline 4.0% false-positive rate is English-tuned: measured per language (2026-08-09), Spanish benign text is over-blocked at 34.7% [28.0–41.9] vs English 7.2% [5.6–9.1] — a 4.8× gap with non-overlapping CIs; key custody is software-only today (hardware roadmap); and the research modules are labelled as such. We retired our own hyped modules when measurement didn't hold them up. Verifiability is the product.
Why now — EU AI Act

The record-keeping duty, discharged as a machine-checkable artifact

The AI Act's logging & record-keeping obligations (Art. 12, Art. 19, Annex IV) are today produced as human-authored documents — asserted, not proven, and stale the moment the system changes. A signed, timestamped, offline-verifiable receipt per action discharges the same duty as evidence an auditor independently checks.

  • Maps to Art. 12 / 19 logging & Annex IV record-keeping
  • Sovereign / on-prem — satisfies data-residency (GDPR, sector rules)
  • Portable evidence that never depends on the vendor's servers
We claim a mapping, not conformity.

Conformity is a legal determination against harmonized standards and, for high-risk systems, a notified body — which a technical artifact cannot assert on its own. Verifiable evidence is a precondition for conformity, never a substitute. Stating that line precisely is why regulated buyers and licensees take the technology seriously.

For licensees & acquirers

This IP is available to license or acquire

Built for AI-governance platforms, compliance SaaS, and security vendors who need a differentiated, post-quantum evidence layer their competitors don't have.

ModelWhat it isFit
License + royaltyEmbed POAW as your "EU AI Act evidence" module; per-deployment royalty. Non-exclusive.Governance / compliance platforms
Exclusive field licenseUpfront fee + royalty, exclusive in your field of use (we retain adjacent fields).A strategic platform partner
AcquisitionOne-time asset sale — patents, code, papers, and the browser verifier.Strategic acquirer / corp-dev

Data room available under NDA: patent status, buyer-reproducible benchmarks, architecture, and dependency provenance.

Let's talk

Partner with us on provable trustworthiness

Licensing, royalty, or acquisition — start with a 20-minute conversation and the evidence pack.

 IP@destill.ai
Request the evidence pack