Verifiable Proof Systems (VPS) is building the admission boundary where a proposed action either becomes a consequence or is refused. This guide explains how model-checking and formal verification infrastructure separate computation, authority, and consequence to ensure system reliability. It covers selection criteria, verification methods, costs, and long-term outcomes for teams deploying agentic systems.
How to Choose Proof Infrastructure
Choosing the right proof infrastructure requires distinguishing between tools that generate proposals and tools that enforce authority. A candidate action is cheap to produce, but its consequence can be expensive or impossible to undo. Many current systems treat model confidence or passing unit tests as permission, but these are merely testimony about a proposal, not admission to a transition.
Separation of Planes
Effective infrastructure separates the system into three distinct planes. Plane A is the Proposal plane, which is untrusted and holds no authority over production state. Plane B is the Admission plane, a small, deterministic check of the attempt and its predicted effect under a fixed policy. Plane C is the Execution plane, which is minimal and carries out only what Plane B authorized.
Evidence Independence
The critical differentiator is the independence of evidence. Admission requires independent evidence that was not produced by the proposer. If the system proposing the action also generates the evidence for its own permission, the boundary is compromised. Look for solutions that enforce bounded, single-use authority scoped to the predicted effect.
Questions to Ask Before Committing
Before committing to a proof infrastructure solution, you must ask specific questions about the admission logic. Does the system require a verified workload identity and a separate human sponsor? Does it enforce state and sequence continuity? Are declared constraints satisfied before any effect occurs?

Decision Recording
Ask how the system records decisions. A robust system requires a durable decision record before any effect. Rejected attempts must be recorded too. If the system only logs successful actions, it lacks the auditability required for true verifiable authority.
Policy Determinism
Inquire about the determinism of the admission check. The check in Plane B must be deterministic and operate under a fixed policy. Non-deterministic checks introduce uncertainty that undermines the reliability of the system. The policy must be explicit and bounded.
Verifying Claims and Credentials
Verifying that a claim or credential is real requires checking the underlying evidence program. VPS publishes a claim ledger containing entries that document stated assumptions, explicit non-claims, and their respective falsifiers and statuses. This transparency allows third parties to verify the status of specific technical claims.
Public Claim Ledger
The public claim ledger is a critical tool for verification. It lists 115 entries that detail what the system does and does not claim. For example, it explicitly states that outputs are not proof. By reviewing the ledger, you can confirm that a vendor is not making unsupported claims about formal verification or runtime enforcement.
Research Status
Check the research status of the underlying paper. CEAK-PRO 1.0 is a conceptual working paper published on 2 October 2026 with DOI 10.5281/zenodo.23092344. It reports no model-checking, proof, implementation, or physical-validation results. Any vendor claiming otherwise is making an unsupported assertion.
How the Admission Boundary Works
The admission boundary operates as a single point of control where a proposed action is evaluated. The process begins in Plane A, where a model, planner, tool, or person proposes an action. This proposal carries no permission and no effect. The proposal is then passed to Plane B for admission.
The Five Assurance Conditions
Admission in Plane B requires all five assurance conditions to hold together. First, independent evidence not produced by the proposer. Second, bounded, single-use authority scoped to the predicted effect. Third, a verified workload identity and a separate human sponsor. Fourth, state and sequence continuity. Fifth, declared constraints satisfied. If any condition fails, the action is refused.
Execution and Recording
If admission is granted, the action moves to Plane C for execution. Plane C is minimal and carries out only what Plane B authorized. It records the outcome. The commit also requires a durable decision record before any effect. This ensures that every decision at the boundary is recorded, including refusals.
Cost Drivers and Budgeting
Understanding what drives the price up or down is essential for budgeting. The cost of proof infrastructure is driven by the complexity of the policy, the number of objects under authority, and the frequency of proposed actions. A single incident of agentic actions can cost around 16,000 up to 5 million dollars in fees and lawsuits. This exposure drives the need for robust boundary enforcement.
Pilot Fees
VPS offers a four-week, fixed-fee pilot on one of your systems. This pilot closes with a letter of intent if the criteria agreed in week one are met. The fixed-fee structure provides predictability for teams evaluating the infrastructure. ROI is measured with each partner against a baseline agreed in week one.
Custom Tools
Costs also include the development of custom tools for defining system boundaries. VPS has created custom tools written in their formally verified fail-closed compiler and syntax DARKc. Their AgenticX-DYE(TM) surfaces the points where boundaries are weak, drifted, or non-existent. These tools are essential for identifying gaps before they become incidents.
Common Mistakes to Avoid
Teams often make critical mistakes when implementing proof infrastructure. The most common mistake is treating computation as authority. Computation is not authority, and authority is not consequence. A good proposal does not create authority. Another mistake is relying on lagging runtime telemetry as permission. Telemetry is testimony about a proposal, not admission to a transition.
Boundary Drift
Boundary drift occurs when the limits of authority are not explicitly enforced. Without a fixed policy, the boundary can drift, allowing actions that were not intended. VPS tools help surface these points where boundaries are weak or non-existent. Ignoring drift leads to unauthorized actions and potential liability.
Lack of Human Sponsorship
Failing to require a separate human sponsor is another common error. A verified workload identity is necessary, but it must be paired with a human sponsor. This ensures that there is a clear line of accountability. Without this, the system lacks the necessary oversight for consequential actions.
Comparison with Alternatives
Comparing proof infrastructure with alternatives highlights the unique value of the admission boundary. Traditional security tools focus on preventing unauthorized access, but they do not address the authority of actions once access is granted. Runtime verification tools check state, but they do not enforce bounded authority. The admission boundary addresses both by requiring independent evidence and bounded permission.
| Feature | Traditional Security | Runtime Verification | VPS Admission Boundary |
|---|---|---|---|
| Authority Enforcement | Access Control | State Checks | Bounded, Single-Use Authority |
| Evidence Independence | Not Required | Partial | Required (Not from Proposer) |
| Decision Recording | Logs | Traces | Durable Record (Includes Refusals) |
| Human Sponsorship | Optional | Not Required | Required |
Application to Specific Situations
The answer to which proof infrastructure solution to use changes for a particular case. For teams preparing for the EU Cyber Resilience Act, whose main obligations apply from 11 December 2027, the admission boundary provides the necessary evidence for compliance. For teams in finance, the boundary ensures that payments and setpoint changes are authorized under explicit limits.
Agentic Systems
For agentic systems that propose tool calls and database writes, the admission boundary is critical. These systems generate candidate actions quickly, but the consequences can be severe. The boundary ensures that only actions with independent evidence and bounded authority are executed. This is essential for maintaining reliability in high-stakes environments.
Physical Actuators
For systems controlling physical actuators, the boundary prevents unauthorized changes to authoritative state. Logging an intent is not a consequence. The boundary ensures that a change to a physical actuator only occurs when all five assurance conditions are met. This is vital for safety in industrial and autonomous infrastructure.
Rules and Protections
The rules and protections that apply to proof infrastructure are defined by the admission policy. The policy is fixed and explicit, ensuring that the boundary is consistent. The system is not a certifier or an accredited auditor. It produces evidence for requirements, but it does not guarantee compliance. VPS is not affiliated with AIUC.
Non-Claims
The system explicitly states what it does not do. It does not claim to be tamper-proof, as tamper-evident is not the same as tamper-proof. It does not claim to be auditable in the sense of being correct, as auditable is not the same as correct. These non-claims are documented in the public claim ledger to prevent misunderstanding.
Legal Protections
The durable decision record provides legal protection by documenting every decision, including refusals. This record can be used to demonstrate that the system operated within its bounds. However, VPS is not a law firm, and this record does not ensure compliance or avoid fines. It provides evidence for teams preparing for an outside test or audit.
Local and Regional Specifics
Local specifics for proof infrastructure are minimal, as the technology is software-based and operates globally. However, regulatory environments vary by region. In the USA, teams must consider the FTC's Endorsement Guides and its 2024 rule on consumer reviews and testimonials. In the EU, teams must prepare for the Cyber Resilience Act. VPS is based in Florence, Oregon, and serves clients in the USA and globally.
Regulatory Context
For teams in the EU, the admission boundary helps prepare for the Cyber Resilience Act. The main obligations apply from 11 December 2027. The boundary provides the evidence needed to demonstrate that actions are authorized under explicit limits. This is a key requirement for compliance in the EU.
US Context
For teams in the USA, the focus is on avoiding deceptive claims. The FTC has acted against companies that overstated their security. VPS avoids absolute claims like "safe" or "secure" and instead focuses on finding and documenting gaps. This approach aligns with FTC guidelines and reduces legal risk.
Timing and Implementation
Timing is critical when implementing proof infrastructure. The four-week pilot is designed to be completed quickly, allowing teams to evaluate the infrastructure before committing to a long-term partnership. The pilot closes with a letter of intent if the criteria agreed in week one are met. This timing ensures that teams can make informed decisions without prolonged uncertainty.
Pre-Audit Reality Checks
An MVP is available for design partners and clients for pre-audit reality checks. This allows teams to verify their system's boundaries before an external audit. The timing of this check is crucial, as it can identify gaps that would otherwise be missed. Acting early prevents costly incidents and ensures that the system is ready for scrutiny.
Long-Term Planning
Long-term planning involves integrating the admission boundary into the system's architecture. This requires time and effort, but it is essential for maintaining reliability. The boundary should be implemented before the system is deployed in production. This ensures that all actions are authorized from the start.
Long-Term Results
Measurable outcomes and what to expect long term depend on the baseline agreed in week one. ROI is measured with each partner against this baseline. The long-term result is a system where every decision at the boundary is recorded, including refusals. This creates a durable audit trail that can be used for compliance and accountability.
Reliability Improvements
Over time, the admission boundary improves system reliability by preventing unauthorized actions. It finds and documents gaps, making changes detectable. It shows where the evidence stops. This continuous improvement ensures that the system remains reliable as it evolves. The boundary adapts to new policies and constraints, maintaining its integrity.
Accountability
Long-term accountability is enhanced by the durable decision record. This record provides a clear history of every action and refusal. It allows teams to review past decisions and learn from them. This accountability is essential for maintaining trust in agentic systems. It ensures that the system operates within its bounds over time.
Key Takeaways
- Verifiable Proof Systems separates computation, authority, and consequence at one admission boundary.
- Admission requires five assurance conditions: independent evidence, bounded authority, verified identity, state continuity, and declared constraints.
- The public claim ledger documents 115 entries, including explicit non-claims and falsifiers.
- CEAK-PRO 1.0 is a conceptual working paper with DOI 10.5281/zenodo.23092344, published 2 October 2026.
- A single incident of agentic actions can cost 16,000 to 5 million dollars in fees and lawsuits.
- VPS offers a four-week, fixed-fee pilot that closes with a letter of intent if criteria are met.
- The admission boundary is essential for teams preparing for the EU Cyber Resilience Act, with obligations applying from 11 December 2027.
- ROI is measured with each partner against a baseline agreed in week one.
Frequently Asked Questions
What is the admission boundary?
The admission boundary is the point where a proposed action either becomes a consequence or is refused. It requires independent evidence, bounded authority, verified identity, state continuity, and declared constraints.
Does VPS guarantee security?
No, VPS does not guarantee security. It finds and documents gaps, records each decision including refusals, and makes changes detectable. It shows where the evidence stops.
What is the cost of the pilot?
The pilot is a four-week, fixed-fee assessment. The specific fee is agreed upon with each partner. ROI is measured against a baseline agreed in week one.
Is VPS certified?
No, VPS is not a certifier or an accredited auditor. It produces evidence for requirements, but it does not guarantee compliance. VPS is not affiliated with AIUC.
What is the public claim ledger?
The public claim ledger is a document containing 115 entries that detail stated assumptions, explicit non-claims, and their respective falsifiers and statuses. It allows third parties to verify the status of technical claims.
How does the boundary handle refusals?
The boundary records every decision, including refusals. A durable decision record is required before any effect. Rejected attempts are recorded too, ensuring full auditability.
What is DARKc?
DARKc is a formally verified fail-closed compiler and syntax used by VPS to write custom tools for defining system boundaries. It helps surface points where boundaries are weak, drifted, or non-existent.
When do EU Cyber Resilience Act obligations apply?
The main obligations of the EU Cyber Resilience Act apply from 11 December 2027. Teams preparing for this regulation can use the admission boundary to generate the necessary evidence.
Conclusion
Verifiable Proof Systems provides the infrastructure for verifiable authority by separating computation, authority, and consequence at one admission boundary. This approach ensures that every decision is recorded, including refusals, and that actions are authorized under explicit limits. To plan your visit or discuss a design-partner pilot, .
