AI assurance for enterprise deals

Evidence behind every AI promise.

Turn buyer questionnaires, AI-use schedules, repository facts and provider terms into defensible answers—and see when a later change puts those answers at risk.

Human reviewedFixed scopeFounding pilots from £750
COMMITMENT TRACEC-014
Partial

“Customer content is not retained or used to train third-party models.”

01
ObservedAPI route
src/ai/client.ts:42
02
Provider factRetention scope
product · tier · date
03
Evidence gapFeature setting
account evidence missing
Safer answer

Supported for the reviewed API path; account-level feature evidence is still required.

1 later change detected2 claims · 1 customer answer require review

Enterprise buyer asks

Evidence is scattered

Engineering loses days

Answers drift later

The deal-blocker

The buyer needs a clear answer. Your evidence lives everywhere.

A new AI schedule lands during procurement. Security asks about training, retention, subprocessors, model routes and human oversight. Sales needs the answer this week.

The real work is not drafting plausible prose. It is knowing which claims the code and evidence actually support—and refusing to overstate the rest.

01

Bound the scope. Product, repository, environment, provider route and evidence date are explicit.

02

Show the basis. Material answers resolve to evidence and limitations a reviewer can inspect.

03

Keep uncertainty visible. Unknown and contradicted claims do not become confident marketing copy.

Founding pilot

A bounded assurance pack, not another dashboard.

Initial validation covers up to ten material AI-specific buyer questions and one deliberately bounded technical evidence set.

01

Buyer-ready answer register

Scoped answers that distinguish supported, partial, unknown and contradicted claims—without smoothing over the gaps.

02

AI stack + data flow

A reviewable map of models, providers, features, data classes and relevant repository evidence at a defined snapshot.

03

Evidence + gap ledger

Every material answer links back to code, configuration, tests, customer evidence or a scoped provider source.

04

Commitment drift check

One simulated later change shows exactly which customer promises and proposed controls would need review.

TRANSPARENT BY DESIGN

See the exact shape of the output before speaking to us.

Open synthetic assurance pack

How the validation works

Fast enough for a live deal. Careful enough to show the gaps.

  1. 01

    Qualify the live request

    We check the buyer artefact, deadline, product scope and whether this service is the right intervention.

    20 min
  2. 02

    Freeze the evidence boundary

    Before review, we agree the questions, repository snapshot, provider routes, inputs, exclusions and deletion date.

    Fixed scope
  3. 03

    Compile and review

    Claims are decomposed, linked to evidence, classified and challenged before any buyer-ready wording is approved.

    Human gate
  4. 04

    Test the promise over time

    One later code or provider change is simulated to reveal which commitments and controls would need attention.

    Drift check
GOOD FIT

You have a real buyer request and a deadline.

  • Small B2B AI-native software company
  • Enterprise security, AI-use or contract questions
  • Evidence spread across engineering, policy and providers
  • Willing to expose unsupported claims rather than hide them
NOT THE JOB

You need a certification, legal opinion or broad GRC platform.

  • SOC 2, ISO or regulatory certification
  • Contract redlining or legal interpretation as counsel
  • Penetration testing or vulnerability assessment
  • Autonomous submission of answers to your buyer

Confidential qualification

Tell us about the buyer request—not your entire stack.

This takes about four minutes. Do not upload or paste contracts, source code, secrets or personal customer information here.

What happens next
  1. We review the fit within one working day.
  2. If relevant, we send a private scope and handling process.
  3. No confidential artefact is requested through this form.
Step 1 of 3About you
Who is dealing with the request?

Use a work address so we can understand the company context.

Your role*
Company size*

Before you submit

Reasonable questions, answered plainly.

Is this a security audit or legal opinion?

No. PromiseTrace is a bounded evidence-compilation and assurance-readiness service. It does not certify compliance, replace counsel, perform a penetration test or guarantee that a buyer will approve an answer.

Do you need our whole repository?

No. The validation pilot uses a deliberately bounded snapshot or selected paths. Where repository material cannot leave your environment, we will test a customer-run or local-review approach instead.

Who reviews the output?

A named human reviewer approves every buyer-facing conclusion. The reviewer and legal counterparty are disclosed privately before confidential material is shared or a paid engagement begins.

What happens to our information?

The public form collects only qualification information—never contracts or source code. Any later evidence transfer requires an agreed scope and handling process. Survey responses are ordinarily retained for no more than 90 days.