GPAI transparency obligations enforceable August 2026. CMMC Level 2 assessments mandatory November 2026. High-risk AI enforcement Dec 2, 2027 (Omnibus). Embedded AI Aug 2, 2028.
The Trust Protocol for AI

The Protocol for
Systemic AI Trust.

Agents, models, hardware, tools. One open protocol connects them all
with cryptographic proof of identity, policy, and compliance.

An agent in Hong Kong, a model serving in San Francisco, and an orchestrator in Brussels verify each other and exchange data securely -- with proof that every interaction meets EU AI Act, NIST, and CMMC requirements. No central authority. No vendor gateway. Just the protocol.

$pip install swt3-ai $npm install @tenova/swt3-ai $cargo add swt3-ai $dotnet add package swt3-ai $gem install swt3-ai
6 package registries
2,600+ monthly downloads
13 regulatory frameworks
Apache 2.0 protocol, patent pending
Trust Mesh Protocol

Your AI systems refuse to work with unverified partners. Automatically.

Three teams. Three jurisdictions. Three different regulatory requirements. Today, trust between AI systems is fragmented -- manual verification, incompatible audit formats, and no way to prove compliance across borders. Trust Mesh replaces that: every system proves its compliance posture before data flows.

Agent
Model
Orchestrator
Hong Kong
San Francisco
Brussels
SWT3 Protocol Layer
1 Brussels requires EU AI Act Article 12 logging. San Francisco requires NIST 800-53 AU-2 audit evidence. Hong Kong requires local AI governance attestation. Each system declares its own requirements. One protocol satisfies all three.
2 Before any data flows, each system presents a cryptographic credential proving its compliance posture: what it has witnessed, what clearing level it operates at, and what jurisdiction it serves. Every other system evaluates that credential against its own policy.
3 If trust is sufficient, data flows. Every exchange is recorded with jurisdiction (HK, US-CA, BE) and legal basis embedded in each witness anchor. All three regulators can independently verify without contacting each other.
4 If any system fails verification, the exchange is blocked. No data crosses the boundary. The blocked attempt is recorded as evidence. No human approval loop. No manual review. The protocol enforces what policy requires.

There is no server in the middle. Verification happens locally, with cryptographic proof that survives any audit. SWT3 is an open protocol with Apache-licensed SDKs in 6 languages. Anyone can implement it. No vendor dependency. Every partner that connects speaks the same protocol. That is the network effect.

How It Works

Four phases. No agents installed. No data retained. No central authority.

01

Witness

The SDK observes your AI inference at the point of execution. Evidence factors are captured and SHA-256 hashed locally. Raw prompts and responses never leave your infrastructure.

02

Anchor

Factors are sealed into an SWT3 Witness Anchor -- a tamper-evident receipt binding evidence to a verdict at a specific moment in time. The fingerprint formula is locked and identical across 5 languages.

03

Verify

Any party can independently verify the anchor using the open-source library or a browser. No API keys. No vendor access. SHA-256 runs locally. Just math.

04

Enforce

Policy-as-code rules declared in .swt3.yaml are evaluated at every tool call. Violations are recorded with full forensic context. The witness captures what happened and whether it matched policy.

65
AI Procedures
13
Frameworks
6
Registries
5
Languages
1,190
Tests

What We Build

Open protocol. Commercial platform. From solo developers to sovereign enclaves.

Open Protocol

SWT3 AI Witness SDK

The trust layer for AI systems. Cryptographic attestation for every inference. Trust Mesh for agent-to-agent verification. Policy-as-code attestation for tool execution. 65 AI procedures mapped to EU AI Act, NIST AI RMF, CMMC, and SR 11-7. Zero data retention. Three lines of code. SDKs in 5 languages. Works with OpenAI, Anthropic, Bedrock, LiteLLM (100+ providers), Ollama, vLLM, LangChain, Vercel AI SDK, and MCP.

Protocol Specification →
Commercial Platform

Axiom Sovereign Engine

The accountability platform powered by SWT3. Continuous compliance evidence for NIST 800-53, CMMC, FedRAMP, and 10 more frameworks. 225 controls scanned, adjudicated, and anchored. Read-only auditor portal with finding register, decision chain visualization, and Annex V conformity reports. Agentless. Cloud, on-prem, or air-gapped. OSCAL-validated exports.

Explore the Dashboard →

The Clearing Engine

Cross-border trust requires cross-border privacy. The clearing engine strips sensitive content before it leaves your jurisdiction. The proof survives. The data doesn't.

L0

Analytics

Full context: hashes, factors, model ID, provider, guardrails. For internal R&D and pre-deployment testing.

L1

Standard

Default. Hashes and factors only. No raw prompts or responses cross the wire. Production-grade privacy.

L2

Sensitive

Hashes, factors, model ID only. No provider metadata. Built for healthcare, legal, and PII workloads.

L3

Classified

Numeric factors only. Model ID hashed. Zero metadata. Built for defense, sovereign cloud, and air-gapped environments.

Regulatory Coverage

Native mapping to the frameworks that matter. Not a crosswalk bolted on after the fact.

EU AI Act NIST AI RMF NIST 800-53 CMMC v2.0 FedRAMP DoD RMF NIST 800-171 SR 11-7 ISO 42001 HIPAA / 21 CFR FedRAMP HIGH ASL-4 (Anthropic RSP) GPAI Code of Practice

Give Your Auditor Their Own Portal

Read-only, time-limited, cryptographically verified. The auditor sees exactly what they need and nothing they should not.

Finding Register

Auditors annotate findings with severity classification (Major / Minor / Observation) per EU AI Act Article 43. Every finding is linked to SWT3 anchors.

Agent Subway Map

Multi-agent decision chains with cryptographic proof at every node. Swimlane visualization showing human, orchestrator, and worker interactions. Policy violations flagged inline.

Conformity Report

One-click Annex V conformity report. Pulls findings, checklist status, and corrective actions into a print-ready document with its own SWT3 anchor.

See Live Auditor Portal →

Proxies monitor traffic. We witness execution.

AI Governance Proxies

Sit between your app and the model. Can be bypassed. Cannot see inside private enclaves. Store prompts and responses on their servers. Single point of failure. Cannot operate cross-border without a central server.

SWT3 Protocol (SDK-Level)

Embedded in your execution logic. Cannot be bypassed. Works inside private enclaves, air-gapped networks, and sovereign clouds. Stores only cryptographic proofs. Agents verify each other directly. No central server. No borders.

Implementation Paths

Start with the protocol. Scale with the platform. Every path leads to auditor-grade evidence.

Open Protocol
For every team shipping AI
Install the SDK and start witnessing in 3 lines of code. Full protocol access, Trust Mesh, policy enforcement, 5 language SDKs, public anchor verification.
  • Python, TypeScript, Rust, C#, Ruby SDKs
  • Trust Mesh agent-to-agent verification
  • Policy-as-code attestation via YAML
  • OpenAI, Anthropic, Bedrock, LiteLLM, Ollama, vLLM, LangChain
  • MCP compliance server
  • Open protocol specification (Apache 2.0)
View on GitHub
Regulatory Advisory
For firms navigating compliance
Compliance architecture review aligned to your regulatory obligations. Framework mapping, evidence gap analysis, and implementation guidance from the team behind the protocol.
  • EU AI Act conformity mapping
  • GPAI Code of Practice alignment
  • NIST 800-53 / CMMC / FedRAMP alignment
  • SR 11-7 model risk overlay
  • Evidence chain architecture review
  • Notified Body preparation guidance
Contact Engineering

See the evidence before you commit.

Click through a live audit portal with real compliance evidence. No signup, no sales call. If the evidence speaks for itself, install the SDK or schedule an architecture review. The protocol is free and open.