Choose — oneground
Is this the right retrieval setup for our documents?
Measured on your own documents against the right answers, before you build on it. Its most common first output is a refusal to recommend.
Evidence infrastructure for AI systems
oneproof is an evidence layer for AI systems — a way to independently reconstruct, compare and verify what a system actually did, by someone who wasn't there when it did it.
Where it sits. One record per stage — what went in, what came out, what ran. Digests, not copies. Nothing in the system above has to change its behaviour to be recorded.
Every stage logs success, because every stage succeeded. Nothing in that sequence has anything to say about the fact that one step quietly moved the sentence you needed out of reach.
A log is testimony: it tells you what a system says it did.
A record is evidence: it lets someone else check.
Every figure on this page is measured and traceable to a published file. Where each one comes from →
A routine upgrade changed what the system answered. No error, no alert, every log green. This is the record doing the work a log cannot.
Real output. 47,430 SEC filings, 19.3 GB, one configuration line changed. The full report, and the passage that was present and never read →
One discipline across all of them: measured instead of asserted, and every answer checkable by someone who does not trust us. Use one alone, or all four together.
Is this the right retrieval setup for our documents?
Measured on your own documents against the right answers, before you build on it. Its most common first output is a refusal to recommend.
What did this answer actually rest on?
A record at every stage, so an answer traces to the exact passage that produced it — and when two runs disagree, so does the place they stopped agreeing.
Was this action allowed, and who says so?
Define caps, bounds and undo windows; ratify a version; every action is then checked against that ratified snapshot — allow, review or refuse — and every verdict names the exact policy version that decided it.
Is it still the system we audited last month?
Verifiable baselines, so when something underneath you changes you hold a record that it did — evidence rather than a feeling.
Every panel below is a tool's own output from a run that happened. Where a tool cannot answer it says so in its own words rather than rounding up — and each one names where you can go and read it.
8 option(s): 0 meets, 6 fails, 2 couldnt_check No option meets every constraint, so nothing is recommended. Recommending an option whose constraints could not all be checked would be rounding couldn't-check up to a verdict. To decide latency_p95: run `oneground verify` against a real engine in the environment the constraint targets. Latency is never taken from simulation.
Eight candidate setups, measured on a real corpus. None cleared every constraint, so none is recommended — and the two it could not check are named rather than folded in.
oneground · the published report it came from →
policy ledger · payments pack transfer cap € 500 ████████ refunds cap € 300 █████ version 29e85d2c…5166 ratified every verdict names the version that decided it
Not against whatever the policy file happened to say at the time. Allow, review or refuse — and the verdict carries the exact policy version, so a decision can still be examined a year later.
onedoor v0.7.0 · the repository, Apache-2.0 →
change evidence baseline byte-identical watch 74 / 74 pins hold anchor 38ff95db… match a system that changes will say so
Verifiable baselines, pinned and re-checked, so a change underneath you leaves a record that it happened. Evidence rather than a feeling.
onewatch · public since 10 September · the repository →
the same document, under two runs baseline #0001 219 ch 3155109b RETRIEVED matches pattern candidate #0009 219 ch 3155109b not retrieved "…ninety (90) days after notice is given…"
Before the upgrade that document was cut into two passages and the right one was read. After it, the same document is cut into ten, the sentence sits at position nine — and the search never reached it. Nothing was lost and nothing errored.
onetrace · the full report →
$ python check_hosted.py https://oneproof.dev/oneground/lab verified data/MANIFEST.sha256 31314947b8df7042… verified base.bin 3,900,000 bytes verified inline.js 4,702,205 bytes verified index.html 9,196 bytes …and 5 more 9 verified · 0 contradicted · 0 couldn't-check The hosted copy is this repository's copy.
Standard-library Python, no network credentials, no account. It compares what this host serves to what the repository holds, file by file, and exits non-zero if they disagree.
oneproof · what each check needs →
Cost, risk, what leaves your building, and the limits stated before you find them.
What each tool needs, what it writes, and how to check every figure against its source.
The specifications, what they do not yet cover, and the register that tracks it in public.