
Evidence that holds up when outcomes are appealed.
AI GOLD is a programme-scoped duty-of-care evidence workflow referenced by a Good Proof Stamp. It helps you prove what was considered, within scope, within an evidence window — without dumping sensitive data.
Not a certification. Scope-limited verification. Acceptance depends on counterparty or programme requirements.

Appeal-ready evidence
Structured artifacts that hold up when outcomes are challenged.
Minimal disclosure by default
No raw prompts, logs, or PII unless programme requires.
Verifiable outside your perimeter
Counterparties check the Status Link—no portal, no login.
AI GOLD
A programme-scoped duty-of-care evidence workflow that produces structured evidence referenced by a Good Proof Stamp. Not a model; not a certification.
Evidence Window
The time-bounded period during which the evidence bundle applies (start/end timestamps).
Evidence Bundle
The structured set of evidence items produced by AI GOLD for a given action, referenced by the Stamp.
Minimal Disclosure
Default mode where raw prompts, logs, and PII are excluded. Disclosure is scope-limited and buyer-configurable.
IDA Evidence Pack
A time-stamped snapshot of evidence artifacts that can be forwarded to counterparties without portal access.
Status Link
The machine-checkable verification endpoint returning current status (VALID, NEEDS_REFRESH, WITHDRAWN, EXPIRED, NOT_VERIFIED).
A structured evidence workflow that produces a duty-of-care evidence bundle referenced by the Stamp.
Not a model. Not a certification. Not a guarantee of correctness. Not a replacement for clinical/legal judgment.
Minimum set (no sensitive content exposed by default).
scope_hash bindingsigner, verified_at, and expires_atstamp_idscope_hash matches expected evidence bindingDisclosure is scope-limited and buyer-configurable. Programmes define what must be captured for their duty-of-care lane.
This supports DPA-friendly data minimization; buyers define what must be captured for their duty-of-care lane.
High-impact action classes that benefit from duty-of-care evidence.
Hardship determinations
Eligibility decisions affecting access to essentials
Irreversible actions with human impact (closures, bans, denials, disconnections)
Exceptions/overrides where a human would normally be expected
Appeal-required outcomes
Claims adjudication (life-impact / hardship-linked claims)
High-value transfers when a duty-of-care obligation exists (e.g., vulnerability protections, safeguarding rules)
From manual proof gathering to structured, verifiable evidence.
What a reviewer actually checks, cites, and how fail-closed applies.
Reviewer queries the Status Link
Checks: status == VALID, scope matches action, expires_at > now. No login required.
Confirms scope + evidence window + signer authority
Validates the decision was within defined boundaries at time of action.
Cites the IDA Evidence Pack in the appeal record
Time-stamped snapshot filed as audit evidence. stamp_id, scope_hash, verified_at all referenced.
If NOT_VERIFIED, NEEDS_REFRESH, WITHDRAWN, or EXPIRED
Decision cannot be relied on. Reviewer escalates or blocks reliance. Fail-closed.
AI GOLD is referenced by Good Proof Stamps and can be required for selected action classes in your vendor agreements. When you require AI GOLD-backed Stamps, you're requiring structured duty-of-care evidence with verifiable chain-of-custody.
See Clause Pack for template language including evidence windows, scope binding, and minimal disclosure terms.
Sample RFP language (paste-ready):
"High-impact action classes SHALL require AI GOLD-backed Stamps with verifiable Status Link and IDA Evidence Pack. Actions taken without VALID status SHALL be treated as unverified."
Reference alignment to common control frameworks. Mapping only; not a certification claim.
| Control | Family | AI GOLD Mapping |
|---|---|---|
| CC7.1–7.2 | Change Management | Evidence bundle versioning, NEEDS_REFRESH triggers |
| CC7.3–7.4 | Logging & Monitoring | Evidence window, verification metadata |
| CC6.1–6.3 | Logical Access | Scope binding, minimal disclosure |
| CC8.1 | System Operations | Status transitions, withdrawal events |
| Control | Family | AI GOLD Mapping |
|---|---|---|
| A.8.15–8.16 | Logging & Monitoring | Evidence bundle, audit metadata |
| A.5.19–5.23 | Supplier Relationships | Verification references, scope binding |
| A.8.24 | Communications Security | Status Link integrity, HTTPS-only |
| Control | Family | AI GOLD Mapping |
|---|---|---|
| AU-* | Audit & Accountability | Evidence bundle, verification logs |
| CM-* | Configuration Management | Policy/model versioning, refresh triggers |
| AC-* | Access Control | Scope-limited disclosure, programme-gated access |
| SC-* | System & Comms Protection | Status Link integrity, chain-of-custody |
| SI-* | System & Info Integrity | Fail-closed semantics, withdrawal propagation |
Not a certification. This mapping shows alignment with control families. Good Proof does not claim SOC 2, ISO 27001, or FedRAMP certification. Buyers should assess fit-for-purpose based on their own compliance requirements.
Status Link resolves and verifies from Official Verifier
Evidence window + scope match the action class
Evidence bundle integrity checks pass (hash/signature reference)
If NEEDS_REFRESH / WITHDRAWN / NOT_VERIFIED: stop-rely and re-verify
Define your high-impact action classes. Require the Stamp. Let the Status Link do the rest.
Not a certification. Scope-limited verification. Acceptance depends on counterparty or programme requirements.