How to Choose: Separating Good from Bad
Choosing proof infrastructure requires distinguishing between tools that merely log actions and those that enforce authority. A good solution treats a proposal as distinct from permission. It must verify that a candidate action has bounded authority before it becomes a consequence. Bad options often rely on model confidence or passing unit tests as proof of safety, which is insufficient for high-stakes environments.
The Three-Plane Model
Effective infrastructure separates the system into three planes. Plane A is the Proposal plane, where models and tools generate candidates. Plane B is the Admission plane, a deterministic check of the attempt. Plane C is the Execution plane, which carries out only what Plane B authorized. This separation ensures that intelligence may propose, but authority must be independently established.
What to Ask: Questions Before Committing
Before committing to a proof infrastructure provider, you must ask specific questions about their evidence standards. Ask if the system requires independent evidence that was not produced by the proposer. Inquire whether the authority is bounded and single-use, scoped to the predicted effect. These questions determine if the system can handle the complexity of agentic actions.
Identity and Sponsorship
You must also ask about identity verification. Does the system require a verified workload identity and a separate human sponsor? This dual requirement ensures that no single entity can both propose and authorize a consequential action. It is a critical control for preventing unauthorized state changes.

How to Verify: Checking Claims and Credentials
Verifying a claim or credential in this context means checking the decision record. Every decision at the boundary, including refusals, must be recorded. This durable record allows for post-hoc analysis of why an action was admitted or rejected. Verification is not about trusting the output, but about auditing the process that led to the output.
The Claim Ledger
VPS maintains a public claim ledger containing 115 entries. These entries document stated assumptions, explicit non-claims, and their respective falsifiers. This transparency allows stakeholders to verify the status of specific research claims. It demonstrates a commitment to falsifiability, a core principle of scientific rigor.
How It Works: The Admission Boundary
The system operates by intercepting actions at the admission boundary. When a model proposes a tool call or database write, the system checks it against five assurance conditions. These conditions must hold together for the action to be admitted. The process is deterministic and fixed, ensuring consistent behavior under policy.
The Five Assurance Conditions
Admission requires all five conditions to be satisfied. First, independent evidence not produced by the proposer. Second, bounded, single-use authority. Third, a verified workload identity and human sponsor. Fourth, state and sequence continuity. Fifth, declared constraints satisfied. If any condition fails, the action is refused and the refusal is recorded.
What It Costs: Drivers of Price
The cost of proof infrastructure is driven by the complexity of the system boundaries. VPS offers a four-week, fixed-fee pilot for design partners. This pilot closes with a letter of intent if the criteria agreed in week one are met. The cost reflects the depth of the assessment and the custom tools used to define system boundaries.
Custom Tooling
VPS uses custom tools written in DARKc, a formally verified fail-closed compiler and syntax. The AgenticX-DYE(TM) tool surfaces points where boundaries are weak, drifted, or non-existent. These specialized tools contribute to the cost but provide a detailed reality check for pre-audit scenarios.
What Goes Wrong: Common Mistakes
A common mistake is treating outputs as proof. Model confidence, fluent explanations, or signed artifacts from the proposing system are testimony about a proposal, not proof of authority. Another mistake is relying on lagging runtime telemetry. These signals are too slow to prevent consequential actions in real-time.
Boundary Drift
Boundary drift occurs when the defined limits of a system's authority change over time without proper authorization. This can lead to actions that are technically within the system's capabilities but outside its intended scope. Regular audits using tools like AgenticX-DYE(TM) help detect and correct this drift.
Versus Alternatives: Comparison of Approaches
Traditional security tools often focus on perimeter defense or signature-based detection. Proof infrastructure for model-checking focuses on the internal logic of authority. The table below compares these approaches.
| Feature | Traditional Security | VPS Proof Infrastructure |
|---|---|---|
| Primary Focus | Perimeter and signatures | Authority and consequence |
| Decision Record | Logs of events | Durable record of admissions and refusals |
| Authority Model | Role-based access | Bounded, single-use authority |
| Verification | Post-incident forensics | Pre-execution admission check |
For a Specific Situation: Agentic Actions
Pre-Audit Reality Checks
VPS provides an MVP for design partners and clients for pre-audit reality checks. This allows teams to test their systems against the five assurance conditions before facing external scrutiny. It helps identify gaps in evidence and authority before they become critical failures.
Rules and Protections: Legal and Regulatory Context
While VPS is not a certifier, its framework helps teams prepare for outside tests or audits. It produces evidence for requirements such as AIUC-1 B006, D003, and D004. VPS is not affiliated with AIUC, but its tools generate the necessary documentation for compliance preparation. This distinction is important for legal and regulatory clarity.
Local Specifics: USA and Global Reach
VPS is based in Florence, Oregon, USA. However, the principles of verifiable authority are universal. The framework applies to autonomous infrastructure regardless of geographic location. Teams in the USA and globally can use the same conceptual model to define and enforce system boundaries.
Timing: When to Act
Timing is critical when implementing proof infrastructure. The EU Cyber Resilience Act has main obligations applying from 11 December 2027. Teams should begin their assessments well before this date. Early implementation allows for iterative refinement of boundaries and evidence collection.
Results Over Time: Long-Term Outcomes
Long-term results are measured through the accumulation of decision records. Over time, these records provide a history of how the system has operated. They allow for the identification of patterns in refusals and admissions. This data is invaluable for improving system design and policy.
Key Takeaways
- Proof infrastructure separates computation, authority, and consequence at one boundary.
- Admission requires five conditions: independent evidence, bounded authority, verified identity, state continuity, and declared constraints.
- Every decision, including refusals, must be recorded in a durable decision record.
- The framework helps teams prepare for audits and regulations like the EU Cyber Resilience Act.
- VPS is a research initiative, not a certifier, and does not claim compliance with specific standards.
- ROI is measured against a baseline agreed upon in the first week of a pilot.
Frequently Asked Questions
What is the core function of VPS proof infrastructure?
The core function is to build the boundary where a proposed action either becomes a consequence or is refused. It ensures that authority is independently established before any effect occurs.
Does VPS provide certified compliance?
No, VPS is not a certifier or an accredited auditor. It produces evidence for requirements and helps teams prepare for outside tests or audits, but it does not issue certifications.
What is the cost of a VPS pilot?
VPS offers a four-week, fixed-fee pilot for design partners. The specific fee is discussed during the initial consultation, and the pilot closes with a letter of intent if criteria are met.
How does VPS handle refusals?
Refusals are recorded just like admissions. Every decision at the boundary is documented in a durable decision record, providing a complete history of system interactions.
What is DARKc?
DARKc is a formally verified fail-closed compiler and syntax used by VPS to write custom tools for defining system boundaries.
Can VPS prevent all unauthorized actions?
No, VPS does not claim to prevent all unauthorized actions. It finds and documents gaps, records each decision, and makes changes detectable. It is a tool for verification, not a guarantee of absolute safety.
Conclusion
Verifiable Proof Systems offers a rigorous approach to ensuring system reliability through model-checking and verifiable authority. By separating computation, authority, and consequence, VPS provides the tools and framework needed to manage the risks of autonomous infrastructure. To explore how this framework can apply to your systems, .
