CABIER Global Assurance · Assurance API

    Assurance API and evidence egress

    How telemetry comes in and how regulator-ready evidence goes out, through one evidence store.

    Reference architecture. Describes the design; not a claim of live production connections.

    Ingestion

    Runtime traces

    Agent and model traces in the OpenTelemetry GenAI conventions, attached to the TrustGraph object that produced them.

    Runtime and compute isolation

    Quarantine and containment events from software sandboxes and out-of-band hardware supervisors. They enter as deterministic signals to the Security and Resilience Trust Gates.

    Control and test results

    Assessment results in NIST OSCAL, linked to the control and the obligation they answer.

    Supply chain

    CycloneDX ML-BOM for models, datasets and dependencies.

    Egress

    Supervisory pack

    A dated, signed bundle per obligation: control, test, result, owner and disposition history. Read-only and reproducible.

    Board and investor extracts

    The same evidence summarised for a board pack or a diligence data room, never a second copy of the facts.

    Disposition webhooks

    Each of the five dispositions (ALLOW, ALLOW WITH CONDITIONS, HUMAN REVIEW, BLOCK, ESCALATE) is emitted with its evidence ID.

    AssureMark credential

    A verifiable credential with expiry and revocation, pointing back to the evidence it rests on.

    Rules

    One store

    Everything ingested lands in one evidence store; every export is a view of it.

    Integrity

    Each evidence record is hashed and time-stamped, so a supervisor can check that nothing changed after the event.

    Least exposure

    Exports carry only what the recipient is entitled to see; proprietary scoring detail stays inside the platform.

    Deployment modes and the connector catalogue.

    Open the Integration Hub