Everything in this section post-dates the May 2026 red-team review. It is verified in source and by tests, and runs live on the narrated tour — but it is deliberately not claimed as part of the externally validated set. Each capability extends the validated gate rather than replacing it.
Constellation — accumulates sensitive-data exposure across every agent in a workflow and escalates when their combined behavior crosses a line. Escalate-only; never blocks, never alters a recorded decision.
Veridect Proof — a dependency-free standalone verifier that re-derives a stored verdict and re-checks the hash chain offline. It re-checks the record; it does not re-run the models.
Veridect Assurance — renders a stored decision as a neutral five-category evidence record, no free text and no personal data. Veridect is not an insurer; the record is not pricing, certification, or coverage.
Governance Command Center — a read-only, tenant-scoped view that reads the same tamper-evident ledger back: verdict mix, risk tiers, policy activity, consensus health, per-agent fleet view.
Consensus Independence — flags decisions where independent-looking models lined up too tightly and may share a blind spot. A reason to look closer; it never blocks and never alters the confidence score.
Oversight Quality — aggregate-only reporting on whether escalations are genuinely acted on. Never singles out an individual; refuses to report below five reviews.
Proof-of-origin signing — every bundle Ed25519-signed over its hash. Keys are versioned and rotate forward, with prior versions kept published so older bundles still verify.
Agent identity — each agent gets its own keypair, with replay-proof identity envelopes and delegation chains that can only narrow. In required mode a forged caller is refused before any model is consulted.
Regulation-mapped evidence — sealed records assembled into an article-by-article EU AI Act evidence pack with explicit non-coverage notes. Documentation support; the legal determination stays with counsel.
MCP gateway — governs tool calls in flight and writes the verdict into the response itself. A refused call is never forwarded to the tool.
Adversarial self-test, policy impact replay, dissent ledger — the models author fresh attacks against the tenant’s own policy; proposed policy changes are replayed against real recorded decisions with zero model calls; provider dissent and how humans ruled on it are kept on the record.
Near-miss ledger, case-law engine, overnight frontier, model character ledger — four read-only aggregations over the sealed ledger. Zero model calls, zero writes, tenant-scoped, and nothing applies itself.
Configuration attestation — the enforcement settings the gate actually consults are recorded in their own signed, append-only ledger, and every change is classified as a tightening or a loosening. A quiet weakening cannot pass as routine maintenance. This is Veridect attesting its own configuration — tamper-evident, not independent oversight.
Cascade seals — every gate-observed decision in a multi-agent workflow bound into one signed Merkle root, so an entire agent-to-agent-to-tool chain verifies in a single check. It proves the recorded hops are intact and in the order recorded; it does not prove completeness — an action that never reached the gate cannot appear in the seal.