CSOAI — how it works

From a description to a signed card

We measure, sign, and publish what we cannot measure. The card is not a certificate, not a conformity mark, and not legal advice. We measure against regulation — we do not enforce it, and only a regulator can. We do not remediate.

  1. 1
    Describe the system

    At /assess you describe the system — purpose, domain, or a URL — as text. Free, and no account is required. Verification is free forever and a grade is never sold.

    Get measured ->
  2. 2
    A keyword classifier runs

    The assess function is a deterministic EU AI Act keyword classifier (Annex III / Art 5). It does not fetch or probe an endpoint and it is not a GSPC bench run.

    Open /assess ->
  3. 3
    You get a signed card

    The artefact carries the tier, the gaps against the fixed Art 9–15/50 control set, and what could not be determined. Empty cells stay empty. It is signed with Ed25519 when the signing key is provisioned, and when it is not the report says alg: UNSIGNED out loud rather than showing you a signature that is not there — so you can always see exactly what you hold. Verify is free at /gspc-verify.

    Verify a record ->
  4. 4
    A bench run is a different thing, and is not yet self-serve

    The classifier reads your description; it never contacts your system, so it cannot tell you how your model behaves. A GSPC bench run — your system answering a frozen, published bank, graded by deterministic code, ending in a card that joins the signed chain — is arranged with us directly. The honest reason it is not a button is capacity, not policy.

    Ask about a bench run ->
  5. 5
    The living board is separate

    Published GSPC totals live at GET /api/gspc, and the card-chain counts at GET /api/state. We do not type axis, card or model counts into this page. Ties are ties. Empty cells stay empty.

    GET /api/gspc ->
Ready to get measured?

No public prices. A grade is never sold. Verify is free forever.

Get measured ->