ISNAD Cloud

ISNAD Cloud — the evidence layer AI has to show

The 1,200-year-old algorithm for proving where a claim came from.

Every claim your AI makes now carries a signed, tamper-evident chain of custody — so when the EU AI Act's high-risk obligations come into force in August 2027, "show me the evidence" has a verifiable answer.

An LLM gives you an answer. Where did it come from? Today the honest answer is nobody knows. ISNAD Cloud grades every transmitter in the chain — model, tool, corpus, retriever, agent — propagates the weakest link to a decision, and emits a signed, tamper-evident evidence record for every claim. No "92.3% confidence." Just who vouched for what, and how reliable they are.

Apache-2.0 · arXiv:2607.24117 · 1,000+ tests in public CI · κ = 0.871 on 575,060 graded chains

Verifiable, not vibes — every figure traces to a primary source

arXiv:2607.24117

Single-author preprint · cs.AI · 25 pp

κ = 0.871

575,060 graded chains · human ceiling κ = 0.331

1,000+ tests

Collected in public CI on every commit

PyPI + npm

isnad v2.23.0 · Apache-2.0 · Python ≥3.11

Adapters

LangChain · LangGraph · CrewAI · LlamaIndex · MCP · OTel

Zenodo DOI

10.5281/zenodo.21216873 · archived citation

Honest footnote: every number above is measured on the methodology's home turf — hadith chains — not your LLM stack. We say exactly where each number comes from, and the transfer to live LLM pipelines is being validated in the open. We will publish the result even if it is not flattering. That is the whole point.

The problem

Your AI makes claims. You can't prove where they came from.

01

Every output is an unprovenanced assertion

An LLM gives you an answer. Where did it come from? Today the honest answer is nobody knows. Observability tools log what happened — they don't grade who handled the claim. You're shipping assertions with no chain of custody.

02

Multi-agent chains obscure, they don't reassure

A claim that survives five hand-offs isn't more reliable — it's more obscured. Correlated agents that share one bad source don't cancel the error out; they amplify it. By generation time, nobody can say which link broke.

03

The deadline is real

The EU AI Act's high-risk obligations land in August 2027 — record-keeping (Art. 12), transparency (Art. 13), human oversight (Art. 14), Annex IV documentation. Screenshots of logs won't hold up. You need signed, hash-chained, exportable evidence.

How it works

Three steps from "who said that?" to signed evidence.

Step 1

Grade your transmitters

Register every model, tool, corpus, and retriever, and give each a grade — reliable / acceptable / weak / ungraded — on two axes (integrity & precision) per domain and role. You bring the grades; ISNAD applies the discipline. Grades are operator-assigned priors — stated openly.

Step 2

Route every claim through the chain

Every claim carries its full chain of custody. ISNAD propagates the weakest link and routes to one of four decisions: serve · caveat · review · quarantine. Corroboration discounts transmitters that share a source, so "three agents agree" isn't mistaken for independent confirmation.

Step 3

Emit signed, tamper-evident evidence

Every decision produces an AuditRecord: RFC-8785 canonicalized, SHA-256 self-hashed, HMAC/Ed25519-signed, and appended to a tamper-evident Merkle log. Export a PDF audit report in one click — and prove, later, that nothing changed.

Product

The open-source engine, productized for teams that need it to just work.

Live dashboard

Every claim, chain, grade, and routing decision in one place — filter by org, domain, narrator, and verdict. Stop grepping logs.

Signed evidence records

Every decision is hash-chained and signed (HMAC/Ed25519) with an append-only Merkle log. Auditable by anyone, tamper-evident by construction.

One-click audit reports

Export a PDF evidence package — chains, grades, signatures, log proofs — ready for a regulator, auditor, or internal review board.

Alerts

Get notified the moment a weak or ungraded link enters a chain you care about — before the claim ships.

Multi-tenant orgs, SSO & RBAC

Isolate products, departments, and clients with scoped API keys, per-org evidence boundaries, SAML/SCIM, and role-based access.

Key-management UX

Rotate signing keys, respond to a compromise, and prove the signing path — without calling the founder. The crypto exists in the library; the lifecycle UX is what you pay for.

Honest scope: the grading engine is Apache-2.0 and stays free forever. ISNAD Cloud is the hosted, multi-tenant, auditable product around it — and the team that runs it for you.

Compliance & security

Evidence infrastructure. Not a certification.

We say this plainly: ISNAD produces the tamper-evident records your auditor will collect. We do not certify EU AI Act conformity, ISO/IEC 42001 certification, or NIST AI RMF alignment — and we will not claim we do until a lawyer has signed a mapping for your specific deployment. What you get is the evidence you need to argue your case.

EU AI Act

Maps onto Art. 12 (record-keeping), Art. 13 (transparency), Art. 14 (human oversight), and Annex IV (technical documentation). The signed, hash-chained claim record is the evidence artifact those clauses ask for.

ISO/IEC 42001

Versioned registry, per-link hashes, signed records — the controlled, documented evidence an audit collects.

NIST AI RMF

Govern/Map provenance & traceability — every output traces back through its chain to its source and retrieved evidence.

SDAIA

Transparency, accountability, and traceability — a direct implementation of the principles.

Tamper-evident by construction

RFC-8785 canonicalization · SHA-256 self-hash · HMAC/Ed25519 detached signatures · append-only Merkle log.

Fail-closed signing

No secret → no signature-bearing claim. Records are never silently emitted unsigned.

Published threat model

Sleeper narrators, Sybil, grade-import — the failure modes are documented in the repo, not hidden.

Who it's for

Built for the people who sign off on AI.

CISO

Chief Information Security Officer

You own the blast radius when an agent fabricates a source or leaks one. ISNAD gives you a signed, hash-chained custody record for every claim — and a compromise playbook for signing keys. You stop answering "where did that come from?" with a shrug.

Head of AI

Head of AI / Platform Lead

You ship multi-agent and RAG pipelines and are accountable for what they emit. ISNAD grades the transmitters you already run, flags the weakest link before the claim ships, and treats a model version bump as a new narrator — the churn your static risk tools ignore.

Compliance

Compliance / DPO

You answer the auditor. ISNAD gives you the one-click PDF evidence package — chains, grades, signatures, log proofs — mapped onto EU AI Act Art. 12/13/14, ISO/IEC 42001, and NIST AI RMF. Verifiable artifacts, not a vendor's assertion.

Pricing

Land free. Pay when you have evidence to protect.

Self-host

$0

Apache-2.0, forever

  • Unlimited claims (you run it)
  • Your infra, your data
  • One-command Docker compose
  • Community support
Run the open source ↗

Pro

$79/mo

or $69/mo annual

  • 50,000 claims/mo
  • 90-day retention
  • Audit report (PDF)
  • Self-serve key rotation
Get Pro ↗

Business

$499/mo

or $449/mo annual

  • 500,000 claims/mo
  • 12-month retention
  • SSO / SAML / SCIM · RBAC
  • Scheduled PDF/JSON/CSV pack
Get Business ↗
Enterprise

Enterprise

Custom

from $5k/mo, annual

  • Committed volume
  • VPC / on-prem / private cloud
  • Custom retention & SLA
  • Custom DPA & terms
Book a pilot

Data sovereignty

The open core is Apache-2.0 and stays that way — deploy it in your own VPC or on-prem and keep your data on your metal. ISNAD Cloud is the operated, multi-tenant, auditable product for teams that don't want to run it.

Trust Assessment · one-time service

$5,000, two weeks. We map your pipeline, grade your transmitters, and hand you a signed evidence package — credited to your first annual contract. That is also the pilot.

Book a Trust Assessment ↗

FAQ

Honest answers to the hard questions.

Why would I pay for something that's open source?

The grading engine is Apache-2.0 and free forever — that is the point. What you pay for in ISNAD Cloud is operation, isolation, retention, and evidence: multi-tenant Postgres, signing-key custody, the append-only log, one-click PDF reports, SSO/RBAC, key rotation, and support. You can run the core yourself; the cloud exists for teams that need it to just work and just survive an audit.

Is ISNAD "EU AI Act compliant"?

No — and we will not claim it is. ISNAD is evidence infrastructure: it produces the signed, hash-chained records that Art. 12/13/14 and Annex IV ask for, and it maps onto those clauses. Whether your deployment is compliant is a legal question for your counsel. What we give you is the evidence you need to make that argument.

Does ISNAD tell me whether a claim is true?

No. ISNAD grades who handled a claim, not whether it is true. Grades are operator-assigned priors — if you grade a source "reliable," the chain inherits that assumption. ISNAD's job is to make the provenance, the grades, and the reasoning tamper-evident and reproducible, so a human can adjudicate. That refusal to fake a confidence number is the brand.

Where do the benchmark numbers come from — and do they transfer to my stack?

κ = 0.871 is measured on hadith chains — the methodology's home turf — across 575,060 graded chains, against a measured human ceiling of κ = 0.331 and a shuffled control of κ = −0.007. The transfer to live LLM pipelines is real but still being validated in the open. We publish the result either way.

Can I self-host? What does the cloud actually add?

Yes — the Apache-2.0 core runs from a one-command Docker compose, in your VPC or on-prem, with your data on your metal. The cloud adds multi-tenancy, retention, SSO/RBAC, one-click PDF reports, the operation of the append-only Merkle log, and key-management UX. Same engine; the difference is who runs the operational surface.

Who is behind this — can you survive a security review?

ISNAD is built by a solo founder, Ali Zahid Raja, building in public. That is a fact we lead with, not hide: a solo-founder track record is a legitimate procurement question, and the way we answer it is with published adversarial docs — the threat model, the failure modes, the benchmark controls — and by welcoming your security team into the repo. Enterprise credibility is earned, and the honesty discipline is how we earn it.

Prove where it came from.

Attach a signed, tamper-evident chain of custody to every claim your AI makes — before your auditor asks, and before August 2027.