NI-Stack turns every LLM interaction into a post-quantum-signed, browser-verifiable audit receipt — screened on-premise, on commodity CPU, mapped to EU AI Act Art. 12 / Annex IV. Peer-review-format preprints, in review. Buyer-reproducible. Available for licensing or acquisition.
Every verdict is hashed into an append-only Merkle log, signed with FIPS-204 ML-DSA-65 (real 3309-byte post-quantum signatures, not stubs), independently timestamped (RFC-3161), and exported as a W3C Verifiable Credential an auditor checks offline, in a browser — never trusting our servers.
genuine ML-DSA-65 signatures
assertions: replay, inflation & forgery all caught
browser-verifiable against a did:web key
POAW is the differentiated asset: no other guardrail ships a portable, offline-verifiable, post-quantum evidence receipt mapped to the AI Act. Self-referentially, our benchmark results themselves ship as POAW receipts — 11 metrics bound into a Merkle root; edit one digit afterwards and verification reads TAMPERED. It is what a compliance-platform vendor licenses.
We license what is measured and real, and label the frontier as frontier. Overclaiming kills IP deals in diligence — so we don't.
A sovereign injection/content cascade led by a zero-dependency Aho-Corasick automaton that blocks before any GPU spend — full-cascade median 0.92 ms, ~767 prompts/s on one CPU core (n=1,200, AMD Ryzen AI MAX+ 395, 2026-08-09). 97.7% TPR / 4.0% FPR on public corpora (95% CI 94.3–99.1, English); the prompt never leaves the premises.
The post-quantum, browser-verifiable receipt layer above. Real ML-DSA-65 signatures; tamper, replay and forgery detected across 96 assertions. Mapped to EU AI Act Art. 12 / Annex IV.
Memory & forecasting modules — under evaluation, not sold as finished.
Compliance-export & monitoring adapters (EU AI Act Annex IV, ISO 42001).
Energy-accounting module — measured claims pending.
Injection detection on public corpora (hackerprompt, jailbreakhub vs OR-Bench; n=176/150, English) — buyer-reproducible with one command.
Full-cascade median per decision on one CPU core (p95 3.1 ms, n=1,200, AMD Ryzen AI MAX+ 395) — screening cost is negligible next to any inference.
Runs on commodity CPU before any GPU; no prompt exfiltration — a data-residency win by construction.
Most vendors publish their best corpus. We publish the whole spread, with n and 95% confidence intervals (8 public corpora, n=300 each, measured 2026-08-09):
| Attack class | Detection | Reading |
|---|---|---|
| Classic injection | 99.3% [97.6–99.8] | the cascade's home turf — syntactic/instruction attacks |
| Narrative jailbreaks | 38.7–41.0% | a disclosed ceiling — story-based attacks need LLM-class semantics |
| Content-harm elicitation | 8.3–12.0% | largely a different task (harmful-content refusal, not injection) — published anyway |
| System-prompt-leak canaries (output side) | 83.3% [78.1–87.5] · 0.0% FP | n=240; verbatim/encoding transforms 100%, paraphrase 0% — bimodal, disclosed |
The AI Act's logging & record-keeping obligations (Art. 12, Art. 19, Annex IV) are today produced as human-authored documents — asserted, not proven, and stale the moment the system changes. A signed, timestamped, offline-verifiable receipt per action discharges the same duty as evidence an auditor independently checks.
Conformity is a legal determination against harmonized standards and, for high-risk systems, a notified body — which a technical artifact cannot assert on its own. Verifiable evidence is a precondition for conformity, never a substitute. Stating that line precisely is why regulated buyers and licensees take the technology seriously.
Built for AI-governance platforms, compliance SaaS, and security vendors who need a differentiated, post-quantum evidence layer their competitors don't have.
| Model | What it is | Fit |
|---|---|---|
| License + royalty | Embed POAW as your "EU AI Act evidence" module; per-deployment royalty. Non-exclusive. | Governance / compliance platforms |
| Exclusive field license | Upfront fee + royalty, exclusive in your field of use (we retain adjacent fields). | A strategic platform partner |
| Acquisition | One-time asset sale — patents, code, papers, and the browser verifier. | Strategic acquirer / corp-dev |
Data room available under NDA: patent status, buyer-reproducible benchmarks, architecture, and dependency provenance.
Licensing, royalty, or acquisition — start with a 20-minute conversation and the evidence pack.
IP@destill.ai