Integration runbook
Second-line functions answering to SR 26-2, the EU AI Act, or internal model governance.
Be able to say what data the AI used, with evidence that does not rest on trusting the vendor.
Each step below says which surface carries it and whether it works today. Every "Works today" step was probed against the live API on 2026-08-21; the rest say what is missing. Nothing here is written in the present tense because it is planned.
Every MCP query has a query_id, and replay returns the bytes that were served plus a hash. Three states: found; too_large (it was served but exceeded the size ceiling — the hash is still authoritative, so a copy you hold can still be checked); and not_found (never recorded or pruned, so the citation cannot be resolved).
The verifier runs in your environment and reports PASS, FAIL or UNPROVEN, keeping 'the signature is valid' separate from 'the contents are true'. The first can be established; the second cannot.
It is all official public disclosure, which keeps privacy review light. The TDCC shareholding data is an aggregate distribution, not person-level records.
The CAIQ and SIG-Lite self-assessments are published in the trust centre and can be taken from there.
Export a period's receipts, attestations, datasheets and coverage history in one go, with a regulation mapping table.
Not served.
SOC 2, ISO 27001 and third-party penetration testing.
None of them yet. The trust centre states the position as it stands. SLA and DPA templates are also still being drafted.
What we provide is data-layer evidence. Governance of the model and reasoning layer — prompts, weights, output review — sits with you, not with us, and any vendor claiming to cover both is worth questioning.
For how the proofs map onto published standards, see Standards & Interop.