Methodology · v1.1.0 · May 2026

The Evidence Fabric — turning AI governance claims into verifiable artifacts.

Most AI governance tools tell you which controls to claim. The Evidence Fabric is the layer underneath: it produces signed receipts and an offline verifier your auditor runs without trusting Vertical Edge AI in the loop, with a per-session hash-linked event chain today and a cross-session transparency log on the engagement roadmap.

Vertical Edge AI LLC, Austin, TX. Reviewed 2026-07-06. Next quarterly revision August 2026.

The Evidence Fabric Methodology is a supporting control pattern for selected workflows. Work begins with the Workflow Opportunity Map; when VeilEngine is part of the design, gateway requests produce Ed25519-signed receipts and receipt claims are negative-tested against tampering.

What this methodology is

The methodology separates current registered evidence behavior from engagement-specific requirements and roadmap capability.

Three operational consequences of that promise:

  1. Signed gateway receipts. Gateway requests produce Ed25519-signed receipts; receipt claims are negative-tested against tampering.
  2. Offline verification. An auditor can verify a session export end to end, offline, using only a public key — no access to VeilEngine systems required. The synthetic sample establishes only its own signatures and hashes.
  3. Time-stamped policy history. Policy changes, key rotations, and AI provider roster updates are designed to be recorded in an append-only transparency log. Today a per-session hash-linked event chain is shipped; the cross-session transparency log is engagement-scoped roadmap.

If a governance vendor cannot show you any one of these three, they have delivered a checkbox.

Why this matters in 2026

Two facts define the 2026 AI governance environment:

  • The gap between AI pilots and audit-ready AI production is large. Cisco's RSA 2026 research reports that 85% of organizations are experimenting with, piloting, or deploying agentic AI, yet only 5% have agents in broad production. Gravitee's State of AI Agent Security 2026 Report (n=900+ executives and practitioners) reports that only 14.4% of organizations have full IT and security approval for their entire agent fleet.
  • Buyers increasingly start vendor research in AI chatbots (ChatGPT, Claude, Gemini), per G2's 2025 Buyer Behavior Report. Vendors whose claims can be retrieved, cited, and verified by an auditor have a structural advantage.

These two facts compose a single problem: AI is being deployed faster than it can be governed, and the buyers who would govern it are themselves discovering governance vendors through AI. Evidence-readiness infrastructure closes the gap.

What auditors can verify (and what they cannot)

Auditor can verify

The receipt is unmodified since signingStandalone verifier CLI; signature check
The chain of receipts is internally consistentHash-chained event log; offline replay of the per-session chain (signed-checkpoint anchoring is roadmap)
The policy version in force at request timeVersioned policy engine; recorded in the per-session event chain (immutable cross-session transparency-log entries are roadmap)
The provider routing decision and AI provider usedReceipt field; provider attestation reference
Whether redaction or tokenization applied per the policy in forceReceipt field; policy version cross-reference
Whether the per-session event chain was internally consistentHash-chain replay of the per-session chain (cross-session transparency-log inclusion evidence are roadmap)

Auditor cannot verify from this evidence alone

Whether the AI provider retained data despite zero-data-retention claimsReceipt records the assertion; vendor-side verification still requires the AI provider's own attestation
Whether the operator's policy was correct for their compliance frameworkPolicy-correctness is a framework + legal interpretation; evidence shows what was in force, not what should have been
Whether the AI's output was substantively correctEvidence Fabric is the audit trail underneath substantive evaluations (bias testing, red-teaming, output filtering); it does not replace them

See a sample receipt, manifest, and verifier transcript →

What Vertical Edge AI is, and is not

Vertical Edge AI is: an AI governance implementation boutique. We build evidence-readiness infrastructure — signed receipts, offline verifiers, and per-session audit-export packages — with a cross-session transparency log on the engagement roadmap. Customer, counsel, and auditor requirements are documented as workflow constraints; public framework mappings are not claimed.

Vertical Edge AI is not:

  • An audit firm. We do not issue independent audit opinions, attestations, or certifications. Your external auditor remains the opinion issuer.
  • A legal opinion source. Mapping evidence to a framework is not legal advice. Your counsel interprets compliance.
  • A substitute for substantive AI evaluation. Red-teaming, bias testing, and output filtering are separate disciplines.

This separation is intentional and load-bearing. Auditor independence rules prohibit firms from auditing systems they remediated. We sit before or after the audit — never inside it.

What remains your responsibility

The Evidence Fabric produces evidence. Acting on that evidence remains your responsibility:

  • Choosing the right policy for your framework. We help operationalize the framework; the framework itself is your legal and compliance choice.
  • Selecting AI providers that meet your BAA, DPA, and data-residency requirements. We record the routing decision; we do not pick providers for you.
  • Interpreting evidence as evidence. Evidence is what a system did. Your auditor and counsel interpret what it means.
  • Maintaining the policies and key material over time. We supply versioning; you supply the operational discipline to update.
  • Verifying receipts during audits. The verifier runs on the auditor's machine; the auditor uses it.

Framework requirements buyers may bring

The Evidence Fabric is framework-agnostic at the primitive level. The buyer’s counsel, compliance team, and auditor define applicable obligations. This list identifies requirement topics to scope; it does not claim control mapping, conformance, or certification.

FrameworkRequirement topics to confirm
NIST AI RMF 1.0 + AI 600-1 (GenAI Profile) Govern, Map, Measure, Manage functions; particularly Me 4.2 (provenance + traceability) and Ma 2.2 (incident response evidence)
EU AI Act (Regulation 2024/1689) Article 50 transparency obligations enter application 2 August 2026 per the EC implementation timeline; Annex III high-risk rules also enter application 2 August 2026 on the published timeline; a Digital Omnibus simplification proposal is active that may revise some high-risk deadlines and is not yet codified
HIPAA Security Rule (45 CFR 164) Audit controls 164.312(b), integrity 164.312(c), transmission security 164.312(e)
Reg S-P (SEC, 17 CFR 248) Customer information protection rules apply to SEC-registered investment advisers; signed receipts and the per-session event chain surface the protection trail (cross-session transparency log on the roadmap)

Framework boundary notes at Trust Center →

These topics are planning inputs. Any mapping or substantive audit opinion requires separate evidence and the buyer’s qualified reviewers.

Anti-patterns we refuse

Practices we see in the AI governance market and explicitly reject:

  1. "Trust us, we redact PII." Without a receipt, a hash-linked event chain, and an offline verifier, that is a claim, not evidence.
  2. "Look at our nice dashboard." A vendor UI check-mark is not independently checkable evidence. A signed receipt with an offline verifier is.
  3. Audit theater via demo trust. Shipping cryptographic evidence to prospects in a sales demo creates the trust-theater pattern the methodology is built to solve. Demo trust and forensic trust are distinct modes and must not be conflated.
  4. Single-vendor verification lock-in. If the auditor needs the vendor's SDK to verify the vendor's receipts, the verification is not auditor-independent.
  5. Quantitative claims without first-party data. "Reduces audit time by X%" with no customer measurement is a hypothesis. We label hypotheses as such and remove them from external copy until measured.

How to engage with Vertical Edge AI

We work with operations-heavy teams, from founder-led businesses to regulated mid-market organizations. There is one commercial entry path:

  1. Workflow Opportunity Map. One fixed-scope operational workflow, five deliverables, typically two to four weeks, with the schedule confirmed before work begins. You keep every deliverable whether we build or not.
  2. Possible next decision. Build, reshape, or stop. Implementation and operating support are separately scoped only after the map establishes a justified path.
  3. Framework constraints. When a selected workflow has framework requirements, those customer-defined constraints are documented inside the Workflow Opportunity Map and implementation brief; they are not a separate public entry engagement.

Industry and control requirements are treated as workflow constraints, not separate public offers. They are scoped inside the same map and implementation decision.

What sets the scope of an engagement, and why there is no price list, is published in full: how scope is set.

The sample evidence package and a one-page topic crosswalk are publicly downloadable. The verifier CLI runs against the package with Python 3 plus the cryptography library.

For the Map, Build, Operate, and Measure cycle, the required buyer roles, and the decision gates, see how we work.

Sources

This methodology was last reviewed 2026-07-06 against:

Vertical Edge AI is an Austin-based AI workflow implementation firm. We publish methodology and frameworks because independently checkable evidence requires transparent methods. We are not an audit firm. Next quarterly revision August 2026.