Standards and regulatory position

Where the standard gets written.

Certisyn does not only comply with standards. It writes them, files them, and publishes the tests that let anyone else check whether an implementation — including its own — conforms.

Everything on this page is on a public record you can open yourself. Nothing on it is a plan.

4
Internet-Drafts filed
1
Standards Track
2
FCC dockets
0
Adopted by a working group
The position

A framework can name what must be governed without providing any instrument by which a third party can test whether it was.

The ACSC Essential Eight is a national security baseline with no standards body behind it, so maturity is self-asserted. A negative forensic finding is stated as a claim about the universe when what was established is a claim about a bounded set. An agentic AI operator asserts control claims that no counterparty can falsify.

In each case the gap is the same and it is not technological. There is no form in which the claim can be stated so that it becomes checkable. Certisyn writes that form, files it with the body that owns the area, and ships the test alongside it.

Core proposition
A standard that cannot be tested is an opinion with a document number. The contribution Certisyn makes to any body it joins is not the text. It is the test that comes with it.
A word on this page

Filed is not adopted, and we say which is which.

All four specifications below are individual submissions to the IETF. None has been adopted by a working group. “Intended status: Standards Track” is declared by the author, not conferred by anyone. A monitoring process runs daily whose sole function is to prevent that distinction from softening: a specification no body has taken up is shown as founder-held and cannot advance on this page without a verifiable event, even where advancing it on paper would be trivial.

Bodies we have applied to but not yet joined are not listed. Work offered but not yet taken up is not listed. Correspondence that is not on a public record is not listed. A verification company that rounds its own numbers up has nothing to sell.

The instruments

Four specifications. Each exists because a claim was being made in a context where nobody could test it.

Attestation Reconciliation Protocol
Intended status: Standards Track · SCITT area · Individual submission

Establishes whether an accountable principal stands behind an autonomous agent, reconciled against sovereign registers with minimum disclosure. Section 6.4 binds every read of the settlement ledger to a request and answers it with a signed response carrying the sequence number and head digest it was served against. A not-entitled read and a not-found read return the same response, so no endpoint becomes an existence oracle.

AI Governance Verified
Informational · Individual submission

Agentic AI governance made checkable rather than asserted: the control claims an operator makes about an agent, and the cryptographic evidence that must exist before a third party can accept them. Written against the EU AI Act general-purpose obligations and ISO/IEC 42001, which specify what must be governed but not what a third party may verify.

Essential Eight Verified
Informational · Individual submission

A verification standard for the ACSC Essential Eight Maturity Model. The Essential Eight is a national security baseline with no standards body behind it; maturity is self-asserted and, today, unfalsifiable. The same construction applies to any sovereign framework that names requirements without providing an instrument to test them.

Coverage Attestation Profile
Informational · Individual submission · Posted 20 August 2026

Makes a negative finding falsifiable. “This message is not present” is a claim about the universe; what was established is a claim about a bounded artefact set examined to a stated depth. Rule 6 refuses an absence claim that does not carry the population it is an absence from. Rule 7 refuses a clean verdict from a run that failed, exhausted, or became unavailable partway. Rule 1 refuses any remainder that reconciles only by arithmetic. None of it requires the generative step to be deterministic, which is what makes it usable where AI sits in the workflow.

Every filed draft resolves at datatracker.ietf.org under its draft name. Source and conformance classes are published at github.com/Certisyn-Inc/certisyn-drafts.

On the public record

Where Certisyn sits, stated at the level the record supports and no higher.

Author means normative text filed under Certisyn's name. Filed means a comment or submission entered on a public docket. Member means an accepted membership listed in that body's own directory. Presented means a talk given at a published programme.

BodyRoleWhat is on the record
IETF Author Four Internet-Drafts filed and live on the Datatracker, one of them with intended status Standards Track in the SCITT area. All are individual submissions; none has been adopted by a working group. Beyond authoring: a Last Call review submitted on draft-ietf-scitt-receipts-ccf-profile-04, in the public working group archive.
FCC Filed Participated in both rounds of the Next Generation 911 rulemaking. Comments filed 9 August 2026 and Reply Comments filed 26 August 2026, in PS Docket 21-479 (Facilitating Implementation of Next Generation 911 Services) and PS Docket 13-75 (Improving 911 Reliability), against Commission document FCC 26-39. Both are retrievable from the Commission's Electronic Comment Filing System.
DFRWS USA 2026 Presented Presented at the Digital Forensic Research Workshop, George Mason University. Five substantive contributions followed to speakers within the fortnight, each answering a specific open question put to the room rather than restating a capability.
Hashgraph Online Member Partner programme member, participating in the Registries Subcommittee. HOL is part of the Hiero Project under Linux Foundation Decentralized Trust. Certisyn has volunteered to run a conformance-and-vectors workstream so that every standard ships with a runnable class, negative controls and declared coverage gaps.
DAIAA Member Member of the Decentralized AI Agent Alliance, active in the Agent Privacy and Security subgroup.
The discipline

Five rules govern everything above. They exist because the commercial value of a verification instrument collapses the moment its author is found to have overstated it.

1
Every normative claim ships with a test
Each specification is published with an executable conformance class. One command, no network access, nothing to install. Coverage gaps are declared in the run record before anyone runs it rather than discovered afterwards.
2
The document is checked against the issuing authority, not against itself
Certisyn's filing register asks the IETF which revisions are actually posted, fails on any the register omits, fetches each filed text from the authority's own archive and fails unless the local copy is byte-identical. It exits non-zero when the authority is unreachable, on the principle that an unreachable authority is not a pass. Its first run found two posted revisions nobody had recorded.
3
Independent reproduction is invited, not tolerated
Two external reviewers executed the conformance class on their own machines, on macOS and on Linux, and reproduced the deterministic rows. Both then attacked the evidence rather than the protocol. Their findings are closed and now carried as standing rules, so the same class of gap cannot reappear.
4
The instrument is pointed at its author first
The Coverage Attestation Profile was run against Certisyn's own engine before it was offered to anyone. It refused: 227 catalogued check identifiers, 6 examined, 221 unaccounted. The engine was changed, not the specification.
5
Filed is tracked separately from adopted
A monitoring agent runs daily whose sole function is to prevent overclaim. A specification that has been filed is shown as filed. A specification no body has taken up is shown as founder-held and cannot advance without a verifiable event, even where advancing it on paper would be trivial.
Governing logic
Certisyn seals what can be verified and refuses to seal what cannot. A company that will not round its own numbers up is the one an institution can trust with someone else's.

One consequence worth stating. A cross-check during this work surfaced an interoperability trap reaching well past any single document: a widely used CBOR library, in its canonical mode, applies a different map-ordering rule than the RFC the specification pins. An implementation that imports it ships non-conforming bytes and receives no error saying so. Findings of that kind surface only when a specification is testable and someone has been invited to attack it.

What Certisyn brings to a body

Three things, in the order they are usually needed.

Normative text that carries its own test

A working group can adopt a specification and discover eighteen months later that two conforming implementations do not interoperate. A conformance class shipped with the text moves that discovery to the week of publication. Certisyn has volunteered to run exactly this workstream inside the Hashgraph Online registries programme.

A vocabulary for what could not be determined

Most verification vocabularies have a word for pass and a word for fail and nothing precise for the third case. Certisyn's work across the Coverage Attestation Profile and the reconciliation protocol is the same argument in different settings: indeterminacy has to be expressible, or it gets reported as one of the other two.

An implementation that already runs

Every specification listed here is implemented in a platform operating in production, certified to ISO/IEC 27001:2022 and ISO 9001:2015. Text and running code are filed together because a body evaluating a proposal should not have to take the author's word for whether it can be built.

Where to check

Every claim on this page resolves somewhere we do not control.

This is the whole list. If a statement about Certisyn cannot be checked from one of these, treat it as unverified until it can.

Filed specifications

datatracker.ietf.org — each draft by name, with revision history and posting dates.

Source and conformance classes

github.com/Certisyn-Inc/certisyn-drafts

Regulatory filings

FCC Electronic Comment Filing System — PS Docket 21-479 and PS Docket 13-75.

Signing keys and transparency record

keys.certisyn.com/vao/ — active and superseded keys, with the verification procedure and worked examples.

Certificate registry

registry.certisyn.com — resolves an issued certificate without contacting Certisyn.

Trademark

USPTO serial 99720190, CERTISYN, filed 23 March 2026.

Certification

ISO/IEC 27001:2022 certificate 260626050102 and ISO 9001:2015 certificate 260626010101, issued by ARS Assessment Private Limited (CB-MS-3923), registered 26 June 2026, expiring 25 June 2029.

Partner listing

hol.org partner programme — HOL is part of the Hiero Project under Linux Foundation Decentralized Trust.