Certisyn does not only comply with standards. It writes them, files them, and publishes the tests that let anyone else check whether an implementation — including its own — conforms.
Everything on this page is on a public record you can open yourself. Nothing on it is a plan.
The ACSC Essential Eight is a national security baseline with no standards body behind it, so maturity is self-asserted. A negative forensic finding is stated as a claim about the universe when what was established is a claim about a bounded set. An agentic AI operator asserts control claims that no counterparty can falsify.
In each case the gap is the same and it is not technological. There is no form in which the claim can be stated so that it becomes checkable. Certisyn writes that form, files it with the body that owns the area, and ships the test alongside it.
All four specifications below are individual submissions to the IETF. None has been adopted by a working group. “Intended status: Standards Track” is declared by the author, not conferred by anyone. A monitoring process runs daily whose sole function is to prevent that distinction from softening: a specification no body has taken up is shown as founder-held and cannot advance on this page without a verifiable event, even where advancing it on paper would be trivial.
Bodies we have applied to but not yet joined are not listed. Work offered but not yet taken up is not listed. Correspondence that is not on a public record is not listed. A verification company that rounds its own numbers up has nothing to sell.
Establishes whether an accountable principal stands behind an autonomous agent, reconciled against sovereign registers with minimum disclosure. Section 6.4 binds every read of the settlement ledger to a request and answers it with a signed response carrying the sequence number and head digest it was served against. A not-entitled read and a not-found read return the same response, so no endpoint becomes an existence oracle.
Agentic AI governance made checkable rather than asserted: the control claims an operator makes about an agent, and the cryptographic evidence that must exist before a third party can accept them. Written against the EU AI Act general-purpose obligations and ISO/IEC 42001, which specify what must be governed but not what a third party may verify.
A verification standard for the ACSC Essential Eight Maturity Model. The Essential Eight is a national security baseline with no standards body behind it; maturity is self-asserted and, today, unfalsifiable. The same construction applies to any sovereign framework that names requirements without providing an instrument to test them.
Makes a negative finding falsifiable. “This message is not present” is a claim about the universe; what was established is a claim about a bounded artefact set examined to a stated depth. Rule 6 refuses an absence claim that does not carry the population it is an absence from. Rule 7 refuses a clean verdict from a run that failed, exhausted, or became unavailable partway. Rule 1 refuses any remainder that reconciles only by arithmetic. None of it requires the generative step to be deterministic, which is what makes it usable where AI sits in the workflow.
Every filed draft resolves at datatracker.ietf.org under its draft name. Source and conformance classes are published at github.com/Certisyn-Inc/certisyn-drafts.
Author means normative text filed under Certisyn's name. Filed means a comment or submission entered on a public docket. Member means an accepted membership listed in that body's own directory. Presented means a talk given at a published programme.
| Body | Role | What is on the record |
|---|---|---|
| IETF | Author | Four Internet-Drafts filed and live on the Datatracker, one of them with intended status Standards Track in the SCITT area. All are individual submissions; none has been adopted by a working group. Beyond authoring: a Last Call review submitted on draft-ietf-scitt-receipts-ccf-profile-04, in the public working group archive. |
| FCC | Filed | Participated in both rounds of the Next Generation 911 rulemaking. Comments filed 9 August 2026 and Reply Comments filed 26 August 2026, in PS Docket 21-479 (Facilitating Implementation of Next Generation 911 Services) and PS Docket 13-75 (Improving 911 Reliability), against Commission document FCC 26-39. Both are retrievable from the Commission's Electronic Comment Filing System. |
| DFRWS USA 2026 | Presented | Presented at the Digital Forensic Research Workshop, George Mason University. Five substantive contributions followed to speakers within the fortnight, each answering a specific open question put to the room rather than restating a capability. |
| Hashgraph Online | Member | Partner programme member, participating in the Registries Subcommittee. HOL is part of the Hiero Project under Linux Foundation Decentralized Trust. Certisyn has volunteered to run a conformance-and-vectors workstream so that every standard ships with a runnable class, negative controls and declared coverage gaps. |
| DAIAA | Member | Member of the Decentralized AI Agent Alliance, active in the Agent Privacy and Security subgroup. |
One consequence worth stating. A cross-check during this work surfaced an interoperability trap reaching well past any single document: a widely used CBOR library, in its canonical mode, applies a different map-ordering rule than the RFC the specification pins. An implementation that imports it ships non-conforming bytes and receives no error saying so. Findings of that kind surface only when a specification is testable and someone has been invited to attack it.
A working group can adopt a specification and discover eighteen months later that two conforming implementations do not interoperate. A conformance class shipped with the text moves that discovery to the week of publication. Certisyn has volunteered to run exactly this workstream inside the Hashgraph Online registries programme.
Most verification vocabularies have a word for pass and a word for fail and nothing precise for the third case. Certisyn's work across the Coverage Attestation Profile and the reconciliation protocol is the same argument in different settings: indeterminacy has to be expressible, or it gets reported as one of the other two.
Every specification listed here is implemented in a platform operating in production, certified to ISO/IEC 27001:2022 and ISO 9001:2015. Text and running code are filed together because a body evaluating a proposal should not have to take the author's word for whether it can be built.
This is the whole list. If a statement about Certisyn cannot be checked from one of these, treat it as unverified until it can.
datatracker.ietf.org — each draft by name, with revision history and posting dates.
FCC Electronic Comment Filing System — PS Docket 21-479 and PS Docket 13-75.
keys.certisyn.com/vao/ — active and superseded keys, with the verification procedure and worked examples.
registry.certisyn.com — resolves an issued certificate without contacting Certisyn.
USPTO serial 99720190, CERTISYN, filed 23 March 2026.
ISO/IEC 27001:2022 certificate 260626050102 and ISO 9001:2015 certificate 260626010101, issued by ARS Assessment Private Limited (CB-MS-3923), registered 26 June 2026, expiring 25 June 2029.
hol.org partner programme — HOL is part of the Hiero Project under Linux Foundation Decentralized Trust.