For AI providers - step 2 of 3

Stop rebuilding the same AI evidence pack
for every buyer.

A Ripple turns evidence about one AI system into a structured record that can be reused across buyer and reviewer requests. When something is not demonstrated, the passport says so.

Created once, reusable across reviewsNo raw data or weights requestedA passport record that expires

Asked at every review

Six questions that decide whether your system is cleared.

Deployers in health, financial services, and minor-facing services now carry personal obligations under the EU AI Act and GDPR that your assurance cannot discharge. They need a record they can hold up - and be held to. The passport is that record, and it is yours to issue before they ask.

"Which special-category data does the system reach - GDPR Art. 9?"
"Is our data used to train or fine-tune the model?"
"How was bias examined under AI Act Art. 10? Show the result."
"How is human oversight designed under Art. 14 - who can override, and on what basis?"
"Has accuracy held since validation, or has the population shifted - Art. 15?"
"If you swap the model behind the endpoint, how would we know?"

What the passport records

Nine sections. Each tied to the article the reviewer must satisfy.

A passport records what is proven about a system - never how it is built. It is built from evidence you supply, never from weights, prompts, corpora, or training data.

System identity, provider, and intended purpose
Data categories - Art. 9, Art. 8, financial profiling
Model and provider stack, with changes recorded
Legal basis - GDPR Art. 6, 9, 22 · DPIA under Art. 35
Data governance and bias examination - AI Act Art. 10
Human oversight design - AI Act Art. 14
Accuracy and robustness under shift - AI Act Art. 15
Event logging and traceability - AI Act Art. 12
Evidence Records, expiry, and the visas in force

How it works

Build. Record. Present. Carry.

1

Issue the passport

Complete the Ripple: purpose, data categories, legal basis, oversight design, and the model actually running behind the endpoint.

2

Record the diagnostics

Supply bias examination, accuracy-under-shift, and exposure results as evidence - documents, summaries, results. The data, the corpus, and the weights are never requested.

3

Present it as a Wake

An assembled export goes to the reviewer - DPO, CISO, procurement, or a competent authority - readable without a login.

4

Carry the credential

"Carries a Ripple" - dated and expiring. The reviewer views the passport's recorded status at a public link rather than trusting a logo.

The evidence request

The deployer requires a passport. You issue it.

When a procurement team refuses access to an unpassported system, you receive a direct request. Issue the Ripple against it and the review can proceed - with the evidence already recorded.

The gate holds

Procurement refuses access to a system carrying no passport.

The request arrives

You receive a direct link to issue the Ripple for that deployer.

The visa is granted

With the passport in hand, the deployer clears one context - and states its expiry.

Step 2 - the passport

Issue the passport your system carries.

One Ripple answers the health trust, the bank, and the supervisory authority from the same record - with the diagnostic results recorded, the model version stated, and the expiry date on its face.

Technical evidence record. Not certification, notified-body conformity assessment, or regulatory approval.