ISNAD Cloud — the evidence layer AI has to show
Every claim your AI makes now carries a signed, tamper-evident chain of custody — so when the EU AI Act's high-risk obligations come into force in August 2027, "show me the evidence" has a verifiable answer.
An LLM gives you an answer. Where did it come from? Today the honest answer is nobody knows. ISNAD Cloud grades every transmitter in the chain — model, tool, corpus, retriever, agent — propagates the weakest link to a decision, and emits a signed, tamper-evident evidence record for every claim. No "92.3% confidence." Just who vouched for what, and how reliable they are.
Apache-2.0 · arXiv:2607.24117 · 1,000+ tests in public CI · κ = 0.871 on 575,060 graded chains
Verifiable, not vibes — every figure traces to a primary source
arXiv:2607.24117
Single-author preprint · cs.AI · 25 pp
κ = 0.871
575,060 graded chains · human ceiling κ = 0.331
1,000+ tests
Collected in public CI on every commit
PyPI + npm
isnad v2.23.0 · Apache-2.0 · Python ≥3.11
Adapters
LangChain · LangGraph · CrewAI · LlamaIndex · MCP · OTel
Zenodo DOI
10.5281/zenodo.21216873 · archived citation
Honest footnote: every number above is measured on the methodology's home turf — hadith chains — not your LLM stack. We say exactly where each number comes from, and the transfer to live LLM pipelines is being validated in the open. We will publish the result even if it is not flattering. That is the whole point.
The problem
An LLM gives you an answer. Where did it come from? Today the honest answer is nobody knows. Observability tools log what happened — they don't grade who handled the claim. You're shipping assertions with no chain of custody.
A claim that survives five hand-offs isn't more reliable — it's more obscured. Correlated agents that share one bad source don't cancel the error out; they amplify it. By generation time, nobody can say which link broke.
The EU AI Act's high-risk obligations land in August 2027 — record-keeping (Art. 12), transparency (Art. 13), human oversight (Art. 14), Annex IV documentation. Screenshots of logs won't hold up. You need signed, hash-chained, exportable evidence.
How it works
Register every model, tool, corpus, and retriever, and give each a grade — reliable / acceptable / weak / ungraded — on two axes (integrity & precision) per domain and role. You bring the grades; ISNAD applies the discipline. Grades are operator-assigned priors — stated openly.
Every claim carries its full chain of custody. ISNAD propagates the weakest link and routes to one of four decisions: serve · caveat · review · quarantine. Corroboration discounts transmitters that share a source, so "three agents agree" isn't mistaken for independent confirmation.
Every decision produces an AuditRecord: RFC-8785 canonicalized, SHA-256 self-hashed, HMAC/Ed25519-signed, and appended to a tamper-evident Merkle log. Export a PDF audit report in one click — and prove, later, that nothing changed.
Product
Every claim, chain, grade, and routing decision in one place — filter by org, domain, narrator, and verdict. Stop grepping logs.
Every decision is hash-chained and signed (HMAC/Ed25519) with an append-only Merkle log. Auditable by anyone, tamper-evident by construction.
Export a PDF evidence package — chains, grades, signatures, log proofs — ready for a regulator, auditor, or internal review board.
Get notified the moment a weak or ungraded link enters a chain you care about — before the claim ships.
Isolate products, departments, and clients with scoped API keys, per-org evidence boundaries, SAML/SCIM, and role-based access.
Rotate signing keys, respond to a compromise, and prove the signing path — without calling the founder. The crypto exists in the library; the lifecycle UX is what you pay for.
Honest scope: the grading engine is Apache-2.0 and stays free forever. ISNAD Cloud is the hosted, multi-tenant, auditable product around it — and the team that runs it for you.
Compliance & security
We say this plainly: ISNAD produces the tamper-evident records your auditor will collect. We do not certify EU AI Act conformity, ISO/IEC 42001 certification, or NIST AI RMF alignment — and we will not claim we do until a lawyer has signed a mapping for your specific deployment. What you get is the evidence you need to argue your case.
Maps onto Art. 12 (record-keeping), Art. 13 (transparency), Art. 14 (human oversight), and Annex IV (technical documentation). The signed, hash-chained claim record is the evidence artifact those clauses ask for.
Versioned registry, per-link hashes, signed records — the controlled, documented evidence an audit collects.
Govern/Map provenance & traceability — every output traces back through its chain to its source and retrieved evidence.
Transparency, accountability, and traceability — a direct implementation of the principles.
RFC-8785 canonicalization · SHA-256 self-hash · HMAC/Ed25519 detached signatures · append-only Merkle log.
No secret → no signature-bearing claim. Records are never silently emitted unsigned.
Sleeper narrators, Sybil, grade-import — the failure modes are documented in the repo, not hidden.
Who it's for
CISO
You own the blast radius when an agent fabricates a source or leaks one. ISNAD gives you a signed, hash-chained custody record for every claim — and a compromise playbook for signing keys. You stop answering "where did that come from?" with a shrug.
Head of AI
You ship multi-agent and RAG pipelines and are accountable for what they emit. ISNAD grades the transmitters you already run, flags the weakest link before the claim ships, and treats a model version bump as a new narrator — the churn your static risk tools ignore.
Compliance
You answer the auditor. ISNAD gives you the one-click PDF evidence package — chains, grades, signatures, log proofs — mapped onto EU AI Act Art. 12/13/14, ISO/IEC 42001, and NIST AI RMF. Verifiable artifacts, not a vendor's assertion.
Pricing
$0
Apache-2.0, forever
$79/mo
or $69/mo annual
$499/mo
or $449/mo annual
Custom
from $5k/mo, annual
The open core is Apache-2.0 and stays that way — deploy it in your own VPC or on-prem and keep your data on your metal. ISNAD Cloud is the operated, multi-tenant, auditable product for teams that don't want to run it.
$5,000, two weeks. We map your pipeline, grade your transmitters, and hand you a signed evidence package — credited to your first annual contract. That is also the pilot.
Book a Trust Assessment ↗FAQ
The grading engine is Apache-2.0 and free forever — that is the point. What you pay for in ISNAD Cloud is operation, isolation, retention, and evidence: multi-tenant Postgres, signing-key custody, the append-only log, one-click PDF reports, SSO/RBAC, key rotation, and support. You can run the core yourself; the cloud exists for teams that need it to just work and just survive an audit.
No — and we will not claim it is. ISNAD is evidence infrastructure: it produces the signed, hash-chained records that Art. 12/13/14 and Annex IV ask for, and it maps onto those clauses. Whether your deployment is compliant is a legal question for your counsel. What we give you is the evidence you need to make that argument.
No. ISNAD grades who handled a claim, not whether it is true. Grades are operator-assigned priors — if you grade a source "reliable," the chain inherits that assumption. ISNAD's job is to make the provenance, the grades, and the reasoning tamper-evident and reproducible, so a human can adjudicate. That refusal to fake a confidence number is the brand.
κ = 0.871 is measured on hadith chains — the methodology's home turf — across 575,060 graded chains, against a measured human ceiling of κ = 0.331 and a shuffled control of κ = −0.007. The transfer to live LLM pipelines is real but still being validated in the open. We publish the result either way.
Yes — the Apache-2.0 core runs from a one-command Docker compose, in your VPC or on-prem, with your data on your metal. The cloud adds multi-tenancy, retention, SSO/RBAC, one-click PDF reports, the operation of the append-only Merkle log, and key-management UX. Same engine; the difference is who runs the operational surface.
ISNAD is built by a solo founder, Ali Zahid Raja, building in public. That is a fact we lead with, not hide: a solo-founder track record is a legitimate procurement question, and the way we answer it is with published adversarial docs — the threat model, the failure modes, the benchmark controls — and by welcoming your security team into the repo. Enterprise credibility is earned, and the honesty discipline is how we earn it.
Attach a signed, tamper-evident chain of custody to every claim your AI makes — before your auditor asks, and before August 2027.