Audience: Notified Body leadership, conformity assessment teams, AI Act technical assessors. This document defines the problem, the evidence SWT3 provides, and the evaluation engagement.
1. The Problem
EU AI Act Articles 9, 11, 12, and 14 require continuous evidence of risk management, technical documentation, record-keeping, and human oversight for high-risk AI systems.
Current conformity assessments rely on point-in-time snapshots: documentation reviews, interviews, and manual artifact collection. Between assessments, there is no continuous evidence stream proving ongoing compliance.
The Solution
SWT3 is an open witness protocol that produces per-inference cryptographic anchors. Each anchor records three compliance factors, a clearing level, and a tamper-evident fingerprint.
SWT3 does not enforce policy. It creates an independent, continuous evidence record that Notified Bodies can verify against EU AI Act requirements at any point in time.
2. Evidence You Get
3. How It Works
- Install the SDK --
pip install swt3-aiornpm install @tenova/swt3-ai. Five languages, six package registries. - Wrap the AI client -- Three lines of code. The SDK intercepts inference calls, computes SHA-256 hashes locally, and transmits only hashes and numeric factors.
- Evidence flows to auditor portal -- Notified Body assessors get read-only access to real-time compliance posture, exportable as Compliance Passport, OSCAL AR, or conformity checklist.
4. Pilot Scope
Included
- Dedicated Enclave-tier tenant with 365-day anchor retention, full ledger access, and regulatory export suite
- SDK integration support for one AI system under assessment (Python or TypeScript, any provider)
- Three structured working sessions (remote, 60 minutes each):
- Kickoff: tenant provisioning, SDK installation, first anchor verification
- Mid-point: evidence review, auditor portal walkthrough, clearing level configuration
- Findings: export review, gap identification, transition discussion
- Auditor portal access with real witness evidence from the integrated AI system
- Compliance Passport export (HTML + signed JSON) for Art. 11 technical documentation evidence
- OSCAL Assessment Results export (NIST-validated)
- EU AI Act conformity checklist with article-level evidence mapping
Not Included
- Custom SDK adapters or bespoke integrations
- Technical documentation drafting (Art. 11 narrative)
- On-site personnel or production SLA
- Multi-system integration (pilot covers one AI system)
5. Timeline
| Days | Phase | Activities |
|---|---|---|
| 1-3 | Setup | Tenant provisioning, SDK installation, first inference witnessed, kickoff session |
| 4-7 | Evidence Generation | Live inference witnessing, clearing level tuning, auditor portal populated, mid-point session |
| 8-10 | Review | Export generation, evidence walkthrough, findings session, transition discussion |
6. Investment
The pilot investment covers all deliverables listed in Section 4, including Enclave-tier platform access for the duration of the engagement. Pilot investment is not credited toward subscription fees.
7. Success Criteria
- All applicable AI procedures produce verdicts from live inference data
- The auditor portal displays accurate, real-time witness evidence
- At least one export package (Compliance Passport, OSCAL AR, or conformity checklist) is reviewed by the assessment team
- The NB assessment team can articulate how SWT3 evidence strengthens their conformity assessment process
8. Data Sovereignty
All data remains within the NB's tenant boundary. TeNova does not access, inspect, or retain prompt content, model outputs, or business data. Only cryptographic hashes (SHA-256, truncated) and numeric compliance factors cross the network boundary. The clearing protocol provides four levels of data protection (0-3), configurable per deployment.
Raw prompts and responses never leave the deployment infrastructure.
9. Transition Path
- Ongoing Enclave subscription ($9,500/month or $102,000/year) for continuous assessment evidence across multiple AI systems
- Sovereign engagement ($125,000) for full ATO sprint with dedicated support, mock assessment runner, and production SLA
- Recommend to providers: NB assessment teams can recommend SWT3 integration to AI system providers as a conformity evidence mechanism
10. Contact
To schedule a pilot or request a 20-minute walkthrough:
- Email: engineering@tenovaai.com
- Live demo: sovereign.tenova.io/audit-demo
- SDK documentation: sovereign.tenova.io/docs