Pilot Logistics

What does the pilot cost?
$10,000 USD, single invoice, net-30 terms.
How long is the pilot?
10 working days from the date of the kickoff session.
What is included?
One AI system integration, three 60-minute working sessions, Enclave-tier tenant with 365-day retention, auditor portal access, Compliance Passport, OSCAL Assessment Results, and EU AI Act conformity checklist.
What is NOT included?
Custom code, on-site visits, multi-system integration, production SLA, documentation drafting, or regulatory filing.
Is the fee refundable?
If you terminate before the mid-point session, you receive a pro-rated refund. After the mid-point session, no refund is due.
Who should attend the working sessions?
Your technical lead and compliance stakeholders. TeNova provides one engineer. All sessions are remote.
Can we evaluate more than one AI system?
The pilot covers one system. Additional systems require an Enclave subscription ($9,500/month) or a separate pilot engagement.
What if we need more than 10 days?
Extensions are available by mutual agreement at $1,000 per additional working day.
Do we need to sign a separate NDA?
No. The Pilot Agreement includes mutual confidentiality provisions covering a 2-year term.

Technical

What latency does the SDK add?
Near zero. Witnessing happens asynchronously after the inference returns. Your application is never blocked.
Does TeNova see our prompts or responses?
No. At Clearing Level 1 and above, raw prompts and responses never leave your infrastructure. Only cryptographic hashes and numeric factors are transmitted.
What is a clearing level?
A privacy control that determines what metadata crosses the network boundary. Level 0 retains hashes and model info, Level 1 strips provider details, Level 2 strips guardrail names, Level 3 retains only numeric factors.
Does the SDK work offline?
The SDK buffers anchors locally and flushes when connectivity is restored. For permanently air-gapped environments, contact us about the Sovereign tier.
Which AI providers are supported?
OpenAI, Anthropic, AWS Bedrock, vLLM, Ollama, LiteLLM (100+ providers), Vercel AI SDK, NVIDIA Dynamo, Cerebras, and any OpenAI-compatible endpoint.
Are there API rate limits?
The witness endpoint accepts up to 500 anchors per batch. There is no per-second rate limit during the pilot.
How large is the SDK?
Python: approximately 50KB with zero external dependencies. TypeScript: approximately 40KB with zero external dependencies.
What Python or Node versions are required?
Python 3.9 or later, or Node.js 18 or later.
Can I use the SDK in a Docker container?
Yes. Set the SWT3_DSN environment variable and the SDK auto-configures. Works with Docker, Kubernetes, and Terraform.
Does the SDK support streaming responses?
Yes. Both Python and TypeScript SDKs handle streaming transparently (OpenAI stream=True, Vercel AI SDK streamText).
What happens if the witness endpoint is unreachable?
The SDK buffers anchors locally and retries automatically. Your application continues without interruption.

Compliance and Legal

Who owns the witness anchors?
You own all compliance evidence, exports, and anchors generated during the pilot. TeNova owns the protocol and platform.
Is this GDPR compliant?
Yes. At Clearing Level 1 and above, no personal data is processed by TeNova beyond account credentials.
What compliance frameworks are supported?
NIST 800-53, CMMC, NIST AI RMF, EU AI Act, FedRAMP, SR 11-7, NIST 800-171, and 6 additional frameworks. 13 total.
Can our auditor verify anchors independently?
Yes. The public verification page requires no login. Auditors can verify any anchor using only the token string and SHA-256.
Is TeNova a security product?
No. TeNova is an independent witness. It creates attestation records, not enforcement policies. Think notary, not bodyguard.
When do EU AI Act high-risk obligations take effect?
December 2, 2027 for high-risk AI systems. General-purpose AI transparency obligations are already enforceable.
Can SWT3 evidence be used in a formal conformity assessment?
Yes. SWT3 anchors provide continuous, cryptographic evidence for EU AI Act Articles 9, 11, 12, and 14. The evidence complements your existing assessment process.
Is the SWT3 protocol proprietary?
The protocol specification is open source under Apache 2.0. The Axiom platform and enterprise features are proprietary. Patent pending.
Do you have a SOC 2 report?
We have completed an internal SOC 2 readiness assessment and maintain technical controls aligned with Trust Services Criteria. A formal SOC 2 Type II audit is planned. Contact engineering@tenovaai.com for our current security documentation.
Where is the data hosted?
The Axiom platform runs on US-based infrastructure (Vultr VPS) with database services hosted by Supabase (AWS us-east-1). All data in transit is encrypted with TLS 1.3. For EU data residency requirements, contact us about sovereign deployment options.
What happens if TeNova is acquired or ceases operations?
All witness anchors are independently verifiable using the open-source SWT3 protocol -- no TeNova infrastructure required. Your data remains exportable via JSON, CSV, and OSCAL formats. The Pilot Agreement guarantees 90 days of export access in the event of service discontinuation.
What is a Compliance Passport?
A self-contained HTML or signed JSON document summarizing your compliance posture, designed for sharing with auditors, regulators, or business partners.

Integration

Can I integrate SWT3 into CI/CD pipelines?
Yes. The SDK runs in any environment with Python or Node.js. Use the SWT3_DSN environment variable for container-based workflows.
Does SWT3 export to SIEM tools?
Yes. The SDK includes an OpenTelemetry exporter for Jaeger, Grafana, and Datadog. The platform also supports HMAC-signed regulatory webhooks to any HTTP endpoint.
Can I witness multiple models?
Yes. Each model produces its own anchors. The AI Witness dashboard provides per-model KPIs, drift detection, and posture trends.
Does SWT3 work with multi-agent systems?
Yes. Each agent can have its own identity, signing key, and tool/access witnessing. The AI-CHAIN.1 procedure tracks multi-agent handoffs with cycle detection.
Can we define custom procedures?
Custom procedures are not available during the pilot. They are available at the Sovereign tier for organizations with domain-specific witnessing requirements.
How do regulatory webhooks work?
The platform sends HMAC-signed HTTP POST events to your configured endpoint when compliance events occur, such as verdict changes, drift detection, or new anchors.
Is there an MCP server?
Yes. @tenova/swt3-mcp provides Model Context Protocol integration for AI development tools. Install from npm or the MCP registry (io.tenova/swt3-witness).
Can we run this in our own VPC or air-gapped environment?
The SDK runs entirely within your infrastructure -- only cryptographic hashes leave your boundary. For fully air-gapped deployments with on-premises anchor storage, contact us about the Sovereign tier.
Can SWT3 evidence support a CMMC Level 2 or FedRAMP assessment?
Yes. SWT3 witness anchors map to NIST 800-53 controls and CMMC Level 2 practices. The platform generates OSCAL-validated exports (SSP, AR, POA&M) validated against NIST oscal-cli. The pilot can be scoped to any supported framework.

Post-Pilot

What happens to our data after the pilot ends?
Your Enclave-tier tenant remains active with 365-day retention. Data is not deleted unless you request it.
What are the subscription options after the pilot?
Pro ($499/month, 90-day retention), Enclave ($9,500/month, 365-day retention), or Sovereign ($125,000 for a full ATO sprint). Annual discounts available for Pro and Enclave.
Can I keep my tenant ID and API keys?
Yes. Your tenant, anchors, and configuration carry forward to any paid tier with no migration required.
Is the pilot fee credited toward a subscription?
No. The pilot fee is a standalone engagement fee.
Are volume discounts available?
Yes, for multi-system Enclave deployments. Contact engineering@tenovaai.com for details.
How does the logo usage clause work?
Upon converting to a paid tier, you grant TeNova permission to reference your organization on our website. Either party can revoke this with 30 days notice.
What uptime SLA do paid tiers include?
Pro includes 99.5% uptime. Enclave includes 99.9% uptime. Sovereign includes dedicated support with a custom SLA.
Can we run a second pilot for a different AI system?
Yes. Each pilot covers one AI system. Contact us to scope additional evaluations.