Back to validant.ai
AI Fairness Trust Seal · validant.ai

The AI system carries its own proof.

A digital credential attached to one specific AI system. It records which fairness test that system's law and field actually call for, what was measured, and how sure the result is. Anyone can check it, in a browser, without an account.

The organisation commissions the measurement. It never gets to write the answer.

Verifiable credential · Subject: the AI system · ES256 on P-256
Built on the same rails as the Swiss e-ID and the European digital identity wallet

Watch how it works. About three and a half minutes, following one rejected job application from the decision to the credential a person can check. One view of both credentials: the receipt a person holds, and the seal it points to on the public verifier. The photographic element is labelled as AI generated in the artwork itself.
01 · The issue

Nobody can check the thing that matters.

The person refused a job or a loan cannot test the claim that the system was fair. The organisation that ran it cannot prove the claim without opening its model and its data, which it will not do. Into that vacuum goes the badge.

Badges. Pledges. Principles pages. Self-declared compliance. They are cheap to produce, impossible to falsify, and they carry no information: an organisation asserting its own good behaviour tells you nothing you did not already have to assume.

An organisation cannot verify itself. That is not a technology gap. It is a logic gap.
02 · The turn

So we credential the machine instead.

The seal is a verifiable credential whose subject is the AI system itself. It travels with that system and is held by the operator who runs it. It reveals no model weights, no training data and no personal records. It carries the finding, not the file.

The verdict is derived, not declared.

The measurement engine signs its own output with a cryptographic key. Numbers leave that engine sealed. The issuing service checks that signature, then works out the verdict itself, on our side, from the signed numbers. The audited party pays for the assessment and receives the result. At no point can it write the result.

If the numbers arrive unsigned, nothing is issued. The service refuses, which means the failure mode of the whole system is silence rather than a false green tick.

The artefact itself. The subject of the credential is the AI system, not the company that bought it and not a brand.
01

Signed in

The measurement engine signs its metrics with its own private key. Numbers leave that engine sealed.

02

Checked

The issuing service verifies that signature before anything else happens.

03

Derived

The verdict is computed on our side, from the signed numbers. Nobody submits a verdict.

04

Refused

No signature, no seal. Not provisional, not pending, not downgraded.

Who holds what, and who can check it. The seal belongs to the system and the operator who runs it. The person affected by a decision gets a separate receipt that points back at the seal, so a verifier can follow the link and re-check both.
03 · A worked example

Maria applies for a job.

Illustrative example · Not a customer, not a real decision

The rejection email. A scannable code at the foot is the entire user interface. Nothing is asked of the person who was refused.
  1. 01

    She scans the code.

    She sees the seal for the system that screened her: which fairness test applied to a hiring decision in her jurisdiction, what was measured, and how sure the result is. She is not asked to create an account.

  2. 02

    She receives her own receipt.

    A second credential, a Decision Receipt, arrives in her wallet. It is bound to a key only her wallet holds, so nobody else can present it as though they were her, and it points back at the system's seal.

  3. 03

    It tells her what actually moved the decision.

    Which factors carried weight, and the smallest change that would have flipped the outcome: two more years in a similar role. Something she can act on, not a protected characteristic she cannot. This is the part a fairness statistic on its own can never give her.

  4. 04

    Months later, she uses it.

    At a labour office she presents the receipt and reveals only the parts that matter for the question being asked, keeping her identity to herself. The office verifies it in a browser. Nobody had to take anyone's word for anything.

Two credentials, two holders. The seal belongs to the system and its operator. The receipt belongs to the person. Enlarge to read the screens.

The same story, on film. A short piece following one decision from the rejection email to the verified receipt.

04 · How the test is chosen

What is fair for a loan is not what is fair for a job.

The fairness rule is not hardcoded. It is resolved from the case in front of it, then frozen into the seal.

Most fairness tooling makes a quiet choice on your behalf. It picks one statistical definition of fairness and applies it everywhere. That is convenient, and it is wrong, because fairness is not one question. In lending, the binding constraint may be whether qualified applicants are approved at comparable rates. In hiring, the operative standard may be an adverse impact test that regulators and courts already recognise. In healthcare triage, equal treatment of unequal need is not fairness at all. Pick the wrong measure and you can pass a test while causing exactly the harm the law was written to prevent.

So we do not pick one for everybody, and nobody gets to pick quietly.

Every assessment starts with its context: the industry, the specific use case, the jurisdiction, and the type of decision being automated. From that context the platform queries a knowledge graph to resolve which fairness tests the law and the research literature actually support in that situation. The answer comes back as an ordered list, with the primary test named, each entry traced to the statutes and the peer-reviewed work that stand behind it.

We stop short of calling that a legal command, because no statute names a formula. The measures also trade off against one another, provably: satisfy one and you can be forced to breach another. Choosing between them is a judgement, and a judgement has to belong to somebody. So the resolved profile is put in front of the system's owner as the recommendation, the owner adopts it or deliberately departs from it, and the seal records both: what was recommended and what was used.

What the owner declares is the case: the sector, the jurisdiction and the kind of decision. What the rule then is, for that case, we resolve ourselves at the moment of issuing, reading our own curation rather than anything sent to us. So an operator can choose which case they are in, and must live with the rule that case carries. Nobody hands us the rule they would prefer to be judged by.

So the seal does not only say that a system passed. It says which test it passed, why that test was the defensible one for that case, and where the grounding came from. The rule is signed rather than asserted, which means the choice of rule is on the record alongside the result.

One engine, many rules. The profile is data, not code, and the identity of the profile that was used is frozen into the seal.

A new sector is a new rule, not new code.

Thirteen domains are curated today, each one a ranked set of tests grounded in law and literature: five approved, eight more written and under review. Hiring is one of the thirteen. Lending, insurance, education, housing, welfare, biometric identification and immigration are others. Extending the instrument to an unfamiliar sector means adding a rule and having it reviewed, not shipping a new product. The engine does not change, which is why this is one instrument for any consequential automated decision rather than a hiring tool with ambitions.

When the answer is unclear, we say so.

If no rule matches the context, we do not improvise a plausible metric. If two applicable regimes disagree, we do not average them into something neither regulator would accept. In both cases the assessment stops and goes to a person. A guess dressed as a measurement is worse than no measurement, because it is harder to argue with.

Context in. Applicable rule out. The rule is frozen into the signed credential, so nobody can quietly change the test after seeing the result.

05 · Fairness, non-discrimination, explainability

Three questions, one signed artefact.

A consequential decision has to answer all three, and they are almost always sold separately.

Fairness

The statistical question.

Did this system produce systematically different outcomes for different groups of people, and by how much? It produces a number, an interval and a comparison, not an opinion. Fairness is where the evidence is generated.

AI fairness audits, explained
Non-discrimination

The legal standard that evidence has to satisfy.

Non-discrimination is not a synonym for fairness. It is law. The EU AI Act places decisions like these in its high-risk tier, data-protection law gives a person rights over solely automated decisions, and Swiss and European equal-treatment law sets the substantive standard. A number on its own discharges none of those duties. It has to be tied to the standard that applies, in the jurisdiction that applies, for the decision that was actually made.

Our responsible-AI policy
Explainability

Which factors mattered, and what would have changed the outcome.

A person who is refused does not primarily want a statistic about a protected group. They want to know why, and what they could have done differently. Without that, a person can be told a decision was fair and still have nothing to argue with.

The full toolset

Measured fairness without the legal standard is a statistic nobody is obliged to accept. A legal standard without measurement is a policy document. Either of them without explainability leaves the affected person with nothing to hold. Each pillar is weak alone, and each is routinely sold alone.

Taken together they are what responsible AI means in practice, and the seal is where the three of them meet as one signed artefact.

06 · Confidence

The seal says how sure it is, not just what it found.

Every measurement has a resolution, and small studies have a coarse one. If you test forty decisions, you can only reliably detect a large gap. A smaller gap hides inside the noise, and the number that comes back looks calm and means nothing.

So every seal carries the smallest difference the study could actually have detected. When a reading sits within the threshold but the study could not have found a gap that small, the seal reports it as inconclusive rather than as a clean pass.

An underpowered study does not get a clean pass. It gets an honest we could not tell.

Pass

The measured difference sits within the agreed threshold, and the study was powerful enough to have found a difference that small if it were there.

Inconclusive

The reading is within threshold, but the study could not have detected a gap this small. We say so, rather than calling it a pass.

Not issued

The threshold is breached, or the input was not properly signed. Nothing is minted.

It is worth being blunt about what this costs us. It means we sometimes hand a paying customer a result they cannot put in a press release, and it means the system's default answer, whenever it is unsure, is no. A seal that always passes is decoration. A seal that can decline is an instrument.

07 · Live and checkable

Do not take our word for any of this.

Three links. No login on any of them. This is what verifiable is supposed to mean.

The standards underneath

Selective-disclosure verifiable credentials in SD-JWT form, did:web and did:webvh identifiers, ES256 signatures on the P-256 curve, OpenID4VCI for issuance and OpenID4VP for presentation, the IETF Token Status List for revocation, RFC 8785 canonicalisation before signing, and holder binding through a key confirmation claim. The same rails the Swiss e-ID and the European digital identity wallet are built on.

Two separate keys, deliberately. The measurement engine signs its metrics with an Ed25519 key of its own, and the credential is signed with the ES256 issuing key published above. The issuer has to verify the first before it may use the second, which is the whole reason a verdict cannot be submitted.

Issued by Glinz & Company GmbH, Zurich. Legal Entity Identifier 9845009B68DN76I5F510, active and fully corroborated.

The verifier is a real screen. Signature, issuer key and revocation status, checked in the browser. There is nothing to install and nothing to sign in to.
08 · Limits, stated plainly

What this seal does not claim.

A credential that overclaims is worse than no credential, because it transfers unearned confidence. So here is what a seal is not.

  1. 01

    A seal states which rule it enforced, and one of the three is narrow.

    The verdict is decided on every measure the rule marks as binding, not on one. Each is tested against its own bound in its own direction, a measure that only has to be reported can never veto, and a measure the rule requires to hold first blocks the seal outright rather than failing it, because a statistic you cannot interpret is not the same as a system you have caught. Every seal names which of three rules applied. The strongest is resolved by us from the sector and jurisdiction the assessment declares, so nobody can hand us the rule they would like to be judged by. Next is a rule the operator froze at the time of assessment. Narrowest is the single agreed measure, which is what a seal falls back to when no sector rule has been declared, and a seal in that state says so on its face. It is one system, at one moment, and it is not a substitute for a full fairness audit. It does not certify compliance with anything.

  2. 02

    Intersections are measured, carried and can fail a seal. What they cannot always do is conclude.

    Every fairness measure runs on combined group keys, so cells such as women over fifty are measured with the same confidence intervals as the headline numbers, and that reading is signed by the measurement engine and carried into the credential. The rule is deliberately asymmetric. Evidence of harm in a cell the study was actually powered to judge, surviving the correction for having tested many cells, fails the verdict outright: a clean result on each attribute separately cannot rescue it, which is the whole point, because that is exactly how the best known cases of this harm were missed. Absence of evidence is treated differently. Cells too small to judge, or suppressed because judging them would expose individuals, cannot fail a seal and instead cap the confidence it may claim, weighted by the share of people they cover, so hiding people in unjudgeable cells destroys the confidence rather than buying a pass. Attempting the analysis is not optional: a seal that carries no crossed-attribute reading is refused rather than issued.

  3. 03

    No causal claim, by construction.

    A measured difference is a difference in outcomes, not proof of what caused it. Causal identification requires assumptions our data does not support, so we do not make the claim.

  4. 04

    Our verifier is online by design, and it abstains rather than rejects.

    Two of the three checks need no network. Whether the disclosed numbers match what was signed is arithmetic over the credential itself, and the signature verifies against our published key, which anyone can hold in advance. Only revocation truly needs a network, and even that can be answered from a signed status token that stays usable for a bounded window and then refuses rather than going quietly stale. Our own verifier still fetches the key and the status list fresh every time, on purpose: one that trusts a cached key cannot see a rotated one. So checking without a network is a property of how this is built, not something you can do at our page today. And when a check cannot complete, the answer is grey and says exactly that. It is not the red answer, which says the credential may be altered or forged. Not knowing is not the same as catching a forgery, and it is not a pass either.

  5. 05

    No live public-sector deployment.

    We have applied to the Canton of Zurich sandbox and are in the matching phase. That is an application in progress, not a deployment, and we will not describe it as one until it is. Our Swiss trust-registry entry sits on the integration, or preview, environment while the federal electronic identity moves towards production, so the rails are real and the registry entry is not yet a production one.

  6. 06

    The instrument is further along than the footprint.

    The credential, the issuing service, the resolver and the public verifier all work today, and you can check that yourself in the section above. What we are not going to do is dress that up as adoption. This is early, the deployed count is small, and anyone who tells you otherwise about a system this young is selling you something.

09 · The outcome

Responsible AI, made checkable.

The claim that our AI is fair is not worth anything, from anyone, including us. What is worth something is a specific statement about a specific system, measured against a rule its law and its field can be shown to stand behind, signed by a party that cannot be overruled by the party being assessed, carrying its own confidence, and open to verification by anyone who cares to look.

That is the whole product. You can check it in the next two minutes.

If something on this page does not verify, tell us and we will fix it.

FAQ

Frequently asked questions

What is an AI fairness trust seal?
An AI fairness trust seal is a verifiable digital credential whose subject is one specific AI system. It records which fairness test that system's law and field actually call for, what was measured, and how sure the result is. Anyone can check it in a browser, without an account, at validant.ai/verify.
Can the organisation being assessed write its own fairness result?
No. The measurement engine signs its metrics cryptographically, and the issuing service verifies that signature and then derives the verdict itself before anything is minted. If the metrics arrive unsigned, nothing is issued at all. The audited party commissions the assessment but cannot assert its own result.
Which fairness test does the seal use?
It depends on the case, and the seal states which test was used. From the assessment context (the industry, the use case, the jurisdiction and the type of decision) the platform queries a knowledge graph to resolve which tests the law and the research literature actually support, and puts that ranked recommendation to the system's owner. Whatever is then used is frozen into the signed credential alongside what was recommended, so the choice of rule cannot be changed after the result is seen. If no rule matches the context, the assessment stops and goes to a person rather than guessing.
What does an AI fairness trust seal not prove?
It is not a full audit and it does not certify compliance with any regulation. A seal binds a confirmed set of fairness measures at their own thresholds and in their own directions, but the pass or fail is decided on one of them, and the example seal published today shows a single measure with no threshold. Intersecting subgroups are measured by the engine and are not yet carried into the credential, so a seal is silent on them. It makes no causal claim by construction. And our published verifier fetches the issuer key and the status list fresh on every check, so it needs a network and abstains, in grey, rather than passing when a check cannot complete.