Claims register · 20 claims · generated 2026-09-23

Every claim we make, and what backs it.

Every material capability claim CSOAI makes on a public surface, with the evidence a stranger can check and the status that claim has actually earned. A capability we plan to build is not a capability we advertise; planned work is labelled planned.

Time-anchor: The current canonical public root has a proof-derived CONFIRMED_BITCOIN OpenTimestamps witness at block 968130. It covers the exact public-root bytes only, not an individual content_id or the separate signed-card index. Cards verify by Ed25519, not Bitcoin.

LIVE5 live claimsDEVNET1 devnet claimsUNMEASURED1 unmeasured claimsPLANNED6 planned claimsRETIRED7 retired claims

Machine-readable at /claims-register.json. This page renders that exact file — there is no second copy to drift. The count above is the number of rows actually rendered below, not a number typed into the header: every status the file declares gets a section, and a status the file did not anticipate is still rendered rather than dropped.

What the statuses mean

LIVE
Shipped and checkable today.
DEVNET
Proven on a test network only — not production.
UNMEASURED
The thing exists, and we have not measured it — said plainly rather than implied away.
PLANNED
Intended. Not built, or built and not shipped.
RETIRED
Previously published, now withdrawn — with the reason.
LIVE

LIVE — 5 claims

  • Cards in /signed/card_index.json are individually Ed25519-signed over their canonical body bytes. Each card ID is the SHA-256 of those bytes, and its signed body carries a prev link. A separately signed /signed/chain.json manifest declares the sequence for offline verification against the pinned did:web:csoai.org card-attestation key.

    CR-001

    This claim is scoped to the indexed /signed/cards corpus. The index is not itself a signed sequence proof: verify the manifest and card bodies, compare predecessor links, and reconcile their IDs. This proves issuer custody and the declared order, not measurement correctness or an independent timestamp or Bitcoin anchor.

  • "Layer 0" is our foundational verification layer — identity, signing and attestation beneath governed AI.

    CR-005

    Disambiguation, because the term collides: this is NOT a blockchain Layer-0 protocol and NOT an interoperability substrate for blockchains. No protocol claim is made or implied by the name.

    Evidence/layer0
  • The GSPC measurement board is live, machine-readable, and reports UNMEASURED honestly rather than filling empty cells.

    CR-010

    Empty cells stay empty. Model-comparison point estimates are not quoted below usable n>=30. Deterministic fact rows are not model-comparison estimates; each publishes its own denominator and unit.

  • Grading is deterministic; no model judges another model.

    CR-013

    Every verdict is a deterministic predicate on frozen splits. Not LLM-as-judge.

    Evidence/methodology
  • Rating the Raters, result 001: the ARC Prize project's published human baseline for ARC-AGI-2 public evaluation has been independently recomputed from ARC's own MIT-licensed participant rows, on a single methodology criterion (RTR-A1, human-reference rule match).

    CR-019

    Deterministic arithmetic, no model in the loop. ARC's published figure reconciles exactly and its calibration claim reproduces on every pair the rows cover; the finding is that the figure computed under ARC's own two-trial machine rule is materially lower and is not published upstream. ARC never claimed otherwise and the artifact says so. Scoped to the 115 of 120 public-eval tasks the released rows cover; the rest are unmeasured. ARC's semi-private results are cited where relevant and are never restated as CSOAI-measured. Nothing here is signed, confers no status on ARC, and is not on the board.

DEVNET

DEVNET — 1 claim

  • Signed measurement evidence can be attached permissionlessly to the XRP Ledger about accounts we do not control (memo + XLS-70 credential), and a stranger can verify the attachment.

    CR-003

    XRPL DEVNET only, with a synthetic subject. Proof of capability, never an investment, a rating or a conformity mark. Mainnet is planned, not live.

UNMEASURED

UNMEASURED — 1 claim

  • Comparative rating-the-raters coverage across the evaluation landscape — LMArena, Vals AI, Artificial Analysis and other rating organisations.

    CR-020

    One organisation has been measured, on one criterion, on one benchmark. No survey of raters exists and no cross-rater comparison is published. These organisations are named on the result page solely to record that they have NOT been measured; that listing is not a ranking, a shortlist or a queue, and no finding about any of them is expressed or implied. A prior internal strategy draft asserted a figure about how many raters publish a corrections record; that figure was never measured, never appeared on any public surface, and is not published here.

PLANNED

PLANNED — 6 claims

  • Blockchain / independent timestamp anchoring of cards (OpenTimestamps, RFC-3161).

    CR-002

    Cards carry NO timestamp-authority field of any kind. A card body has exactly nine fields — accuracy, axis, created, issuer, kind, model, prev, public_framing, verify — across all 150 published cards; the string "timestamp" appears in none of them, nor in card_index.json. The only time a card carries is `created`, an ISO-8601 instant written by the minting host from its own clock and then signed: it attests that the issuer asserted that time, not that any independent party observed it. The `prev` hash-chain establishes relative order between cards, which is ordering, not time. There is no RFC-3161 token, no OpenTimestamps proof, and no Bitcoin or other chain anchor behind any card. The label will name it in the same commit it ships, never ahead of it.

    Amended 2026-08-26
    Superseded wording, kept visible rather than deleted: this note previously read "Cards declare timestamp_authority: \"none\"." That was false as a statement about the bytes — zero of the 150 published cards contain a timestamp_authority field, so the register asserted a positive declaration as its evidence for the absence. The substance was always honest (there genuinely is no timestamp authority); the defect was that a page whose entire purpose is claim-to-evidence fidelity described a field that does not exist. Caught by an outside SCITT/COSE audit of the live site on 2026-08-26 (finding D8), not by us. Adding an explicit timestamp_authority: "none" to the card schema would be the stronger answer — an explicit "none" is worth signing — but it cannot be retrofitted to these 150: each card id is the SHA-256 of its own body, so a new field re-mints every id and invalidates every published signature. It is recorded here as a schema change for the next card format, not as a thing already done. See /api/corrections C-2026-0826-07.

  • XRP Ledger mainnet attestation.

    CR-004

    Not deployed. Attesting is permissionless; authorisation inside any permissioned domain still requires the relying party to trust our issuer key.

    Evidence/xrpl-attest
  • Post-quantum ML-DSA-65 (FIPS-204) signing.

    CR-006

    Planned and scaffolded only. No ML-DSA signer or runtime is built or published, and nothing published today is ML-DSA-65 signed.

    Evidence/methodology
  • C2PA / Content Authenticity conformance for published artefacts.

    CR-012

    Contributor, conformance in progress. Artefacts today carry Ed25519 provenance, not C2PA conformance.

  • ISO 27001, ISO 42001 and SOC 2 Type II certification.

    CR-016

    All three are marked In Progress because they are genuinely in progress. No assessor's letter exists for any of them; when one does it will be published. We are not certified to SOC 2 or ISO/IEC 42001 and do not claim to be.

  • Per-region data residency selection (EU / US / APAC).

    CR-018

    Designed, not yet offered. The public site is served from Cloudflare's edge; the measurement backend is first-party, self-hosted UK/EU. The card will name regions and safeguards on the day it ships, not before.

RETIRED

RETIRED — 7 claims

  • A 33-seat council with a 23-of-33 supermajority delivers fault-tolerant, decorrelated review.

    CR-007

    Retracted under DR-0007. The historical numeric result is unbound because its cited results/n_eff.json artifact is absent from this repository, so it is not treated as independently reproducible. The latest published point experiment at /interop/council-independence.json measured rho=1 and n_eff=1 across three nominal legs; it also does not demonstrate independent review or fault tolerance. The 33/23 structure is a DESIGN figure, not a live property, and the guarantee remains withdrawn.

  • CSOAI certifies, accredits, or issues conformity marks for AI systems — retired: we never certify.

    CR-008

    We measure; we never certify. The Academy issues course-completion records, which attest training and not conformity. No CSOAI output is a conformity assessment under any regulation.

  • CSOAI measurement is recognised under mutual-recognition agreements with named regulators (CISA, NCSC, ANSSI, BSI, BEREC, ENISA, ICMM, CRMA, national transport / mining / AI oversight authorities).

    CR-009

    Removed 2026-08-26. This appeared on five sector pages and was never substantiable: CSOAI holds no mutual-recognition agreement with, and is not endorsed or accredited by, any of these bodies. The pages now say only that we crosswalk our measurement output to those compliance pathways, which is what we actually do.

  • Live component probing on our status page (withdrawn while the route is quarantined for content review).

    CR-011

    Withdrawn 2026-09-04: /status is quarantined for content review and is not a live public status surface, so this capability cannot currently carry live status. The prior implementation labelled rows with no public health endpoint "not probed from this page" and corrected a tool-fleet row that had presented a catalogue snapshot as deployed inventory. Those historical corrections do not make the quarantined route live. Restore this claim only after the route is reviewed, publicly reachable, and rechecked against its probes.

    Evidence/status
  • A £20 million scholarship / scholarship fund.

    CR-014

    Checked 2026-08-26 across the codebase, the built bundle and the live site: no such claim is published on any CSOAI surface, and no such fund exists. Recorded here so the claim cannot quietly reappear. The Charter's diversity provision mentions scholarships as an aspiration with no monetary figure attached.

  • CSOAI carries Professional Indemnity Insurance up to £5,000,000.

    CR-015

    Withdrawn under C-2026-0902-06: no policy document is on file, so no cover, limit, insurer, broker or term is currently claimed. Restore only when the evidence is filed.

  • "GDPR Compliant" as an attained, badge-level status shown beside certification rows.

    CR-017

    Reworded 2026-08-26. GDPR compliance is a self-assessed posture, not a certification, and a green Compliant badge sitting next to ISO and SOC 2 rows implied an audit that does not exist. The row now reads GDPR / Self-assessed and says so. The Article 17 line no longer claims "full compliance" or "instant" deletion; it states erasure on request within the statutory one-month window.

Found one that does not hold?

If a claim here does not match what you can verify, that is a defect. Report it at nicholas@csoai.org and it goes to the corrections feed at /api/corrections.

The refutation ledger → is where claims we withdrew are recorded, with the measurement that killed them.