An AI decision log on your own servers is self-attested — editable by you, discounted by examiners, and impossible to notarise after the fact. Rubric anchors every decision as a 32-byte cryptographic fingerprint on a public ledger the moment it happens. Customer data and model logic never leave your network — and verification never requires us.
The only post-quantum AI attestation network on a public ledger · Offline verifier on npm — proofs outlive the company · Evidence to the FRE 902(13)/(14) standard
Your records do not depend on Rubric staying in business, trustworthy, or online. Every attestation is mathematically verifiable by anyone, at any time, with nothing but the public key and the ledger. By design.
Multisig attestations are signed by three of five federation nodes across five jurisdictions — the highest-assurance lane, available for any decision. No single party, including Rubric, can forge one: compromise requires breaching three sovereign data centres simultaneously. Every attestation on every lane is ML-DSA-65 signed and ledger-anchored.
Merkle roots are written to the Hedera Consensus Service — a public, immutable distributed ledger with ten-year operational history. Your proof outlives any vendor relationship. An auditor in 2033 can verify an attestation made today, whether Rubric still exists or not.
Signed with ML-DSA-65, the NIST FIPS 204 post-quantum standard. RSA and ECDSA signatures written today will be forgeable within the record retention window. Rubric signatures will not. The proof you make now still verifies in 2040.
No vendor lock-in. No trust required. Verifiable by math.
What leaves your network is a 32-byte commitment — never the decision, the data, or the model. Rubric embeds at the framework level — every decision is captured with a single non-blocking call, then signed and anchored asynchronously in the background. Works alongside any existing AI infrastructure or trust layer.
Every AI decision is captured the moment it happens — one non-blocking call, designed to stay off your pipeline's critical path. The decision is then handed to the federation for signing and anchoring, entirely outside your request flow.
NIST FIPS 204 · Post-QuantumDecisions flush from the SDK to the federation in batches — on the sixty-second anchor window, or immediately for high-risk decisions like credit denials and medical triage. Each attestation is ML-DSA-65 signed; the 3-of-5 independent multisig path is available where the decision warrants quorum assurance.
Zero latency impactDecisions are batched into Merkle trees, so a single HCS transaction anchors many decisions at once. Each batch root is written to the public ledger. Every path is independently verifiable: direct and multisig attestations against the ledger record, and batched (tiered) attestations via zero-knowledge inclusion proof against the on-chain root.
SHA3-256 · Hedera HCSZero-knowledge proofs are live. Every tiered attestation carries a Poseidon2 Merkle inclusion proof against an on-chain root. Beyond inclusion, Rubric generates zero-knowledge policy proofs: demonstrate that a decision came from the claimed system with confidence above a threshold and risk below a ceiling — without revealing the decision data, the exact confidence, or the risk score. Proofs verify at a public endpoint, independently of Rubric.
Noir · Poseidon2 · BN254The SDK is the fastest path — but it is a veneer over a plain REST API. If your stack speaks HTTP, MCP, or already forwards logs to a SIEM, you can attest without installing anything. And if the stack cannot be changed at all, the gateway attests it from the outside.
Add one line at app startup. Rubric auto-detects your frameworks and patches them at the class level — OpenAI, Anthropic, LangChain, LlamaIndex, AutoGen, CrewAI, LangGraph, DSPy, Agno, Azure AI Agents, and more. Every LLM call, every agent decision, every tool use is cryptographically attested. No per-decision code. No codebase audit. Complete by construction.
instrument() injects a callback handler into LangChain's CallbackManager at startup — every LLM call, chain output, and agent finish is attested automatically.
instrument() patches Completions.create at the class level — every chat completion, sync or async, is attested automatically. No wrapper, no code changes.
Auto-instrumentation for 11 frameworks: OpenAI, Anthropic, LangChain, LangGraph, LlamaIndex, AutoGen, CrewAI, DSPy, Pydantic AI, Google ADK, and the OpenAI Agents SDK. Zero required dependencies. Additional integrations ship in the order enterprises ask for them.
Install once via npx. Exposes 8 tools: attest, verify, get_proof, register_agent, status, framework_detect, cost_estimate, and bundle_query — works in Claude Desktop, Claude Code, Cursor, Windsurf, Continue, Zed, and any MCP-compatible host.
Same surface as the TypeScript port, native Python implementation. Built on Anthropic's official mcp Python SDK. Drop into Claude Desktop, Cursor, or any MCP-compatible host — or call programmatically from a Python agent.
Every AI decision flows into your existing security and compliance infrastructure automatically. Push-based Splunk HEC streaming — native JSON or CEF for ArcSight and QRadar. Real-time webhooks for Elastic. CSV exports for ServiceNow, Archer, and OneTrust. PDF reports built to the FRE 902(13)/(14) self-authenticating standard, on demand. One API call — your team is operational in 30 minutes.
Hand us an HEC token and every attestation streams into Splunk as it anchors — native JSON or CEF 0.x for ArcSight and QRadar, each event carrying its HCS sequence and payload hash. Prefer webhooks? HMAC-SHA256 signed, ECS-compatible NDJSON. Zero polling, zero gaps.
Pull attestation data as CSV on any schedule. Maps directly to ServiceNow GRC and Archer record schemas. Filter by agent, pipeline, or date range. No transformation required.
Generate a compliance report for any time period in a single API call. SHA3-256 hash sidecar included. Suitable for regulatory submission, board reporting, and legal proceedings.
Article 12 requires high-risk AI systems to maintain tamper-evident logs of autonomous decisions. Rubric provides the complete audit trail — decision content, timestamp, cryptographic proof of integrity.
Each attested decision is cryptographically signed and anchored. Auditors can retrieve and independently verify any individual attestation. Population-completeness verification (proving no in-scope decision was omitted) is in development.
Every attestation receives an HCS sequence number and consensus timestamp from Hedera's public ledger. The timestamp cannot be altered — it's a public record verifiable on HashScan.
ML-DSA-65 signatures bind the decision content to its timestamp. Any modification to the decision after signing produces a verification failure -- detectable by anyone, without trusting Rubric.
Under the EU AI Act, high-risk obligations (Annex III) were originally set to apply from 2 August 2026. The Digital Omnibus — formally adopted June 2026 — defers this to 2 December 2027. High-risk AI systems — credit decisioning, medical triage, hiring, law enforcement — must maintain logging sufficient to enable post-market monitoring.
Rubric provides: tamper-evident decision logs, cryptographic integrity verification, publicly auditable anchoring, and an auditor portal for compliance officers — without access to Rubric's internal systems.
Read: what “outside unilateral control” means cryptographically →
Every attestation resolves to a permanent public record. Share the link with auditors, regulators, or counterparties — no login, no account. The record verifies against the public ledger with or without Rubric: offline verifier, any mirror node, forever.
This is a live attestation anchored to Hedera Consensus Service. Click to verify it independently.
Post-quantum cryptography, federation design, zero-knowledge proof architecture, and EU AI Act compliance mapping — in full technical detail.
10 sections · Technical whitepaper · April 2026
Free tier for developers. No credit card required. Upgrade when your pipeline outgrows 1,000 attestations per month.
A small cohort, on purpose.
We take deliberately few design partners so each gets direct founder attention and real engineering priority. 60 days of full Enterprise access, free — $2,500/mo after the pilot if it is working for you. Early partners shape the integration roadmap; that is the trade.
Become a Design Partner →autogen-rubric supports 17 live integrations today — 11 auto-instrumented at startup with zero required dependencies. Coming integrations ship in the order enterprises ask for them.
At billions of AI decisions per day, audit-by-replay breaks down. Rubric changes the equation: every decision your AI makes is cryptographically attested the moment it happens and anchored to a public ledger. Regulators get verifiable evidence — without ever seeing your models, your data, or your strategy. Zero-knowledge proofs are live: hold a portable proof that a decision met policy — source, confidence bounds, risk ceiling — publicly verifiable against a mainnet-anchored root, with the underlying data never disclosed.