AWS Marketplace: DigiTrust is listed and available for customer purchase. View the listing
Public reference architecture — version 0.1 RC1

From enterprise AI action to provable, authorized use

DigiTrust is the evidence and authority system of record for enterprise AI.

This public architecture explains how the reference implementation records governed actions, preserves evidence and provenance, verifies trust deterministically, binds accountable human approval, authorizes exact use, and reconstructs the complete history independently.

Reference implementation, deployed AWS pattern, design-partner stage, limited onboarding, and production hardening in progress. DigiTrust is publicly listed in AWS Marketplace; this does not imply AWS endorsement or unrestricted production availability.

Trust chain

Capture → Preserve → Verify → Resolve → Approve → Authorize → Reproduce

Each stage preserves enough identity and context for a reviewer to understand what happened, which rules applied, what failed, how it was remediated, who approved it, and whether the exact result remains authorized.

01CaptureAuthorized evidence, actors, tools, purpose, classification, and case context.
02PreserveArtifact integrity, lifecycle, Evidence Events, Tool Invocations, provenance, and append-only history.
03VerifyEvidence quality, claim support, authority, contradiction, disclosure, and signed-input integrity.
04ResolveFailed history remains immutable while a different later run proves remediation.
05ApproveAn accountable human decision binds the exact verified subject, scope, conditions, and time.
06AuthorizeOnly the approved subject, version, report, authority, scope, conditions, and time window may be used.
07ReproduceSigned evidence, verification, approval, remediation, and authorization history is revalidated independently.
Platform layers

Four layers, one inspectable trust boundary

The platform keeps probabilistic AI execution separate from the deterministic evidence, verification, authority, approval, authorization, and audit controls required for consequential enterprise use.

Evidence Fabric

Tenant- and case-scoped services register immutable artifact metadata, link collection events and governed tool invocations, derive supersession and revocation state, project minimized provenance, and maintain append-only evidence history. Raw secrets, credentials, tool parameters, and customer evidence bytes stay outside public outputs.

Verification Engine

Strict policy, claim, plan, assertion, authority, and disclosure contracts bind exact identities and input snapshots. Deterministic rules assess eight evidence-quality dimensions, claim support, verifier authority, separation of duties, structured contradictions, disclosure policy, and signed-report integrity without free-form semantic truth inference.

Human Control Plane

Immutable approval requests bind one exact Approval Subject and one canonical authority snapshot. Append-only human decisions support approval, rejection, requested changes, expiration, and revocation. Failed verification is preserved through durable remediation and can return to approval only through a later independently verified run.

Assurance and Audit

Exact-use authorization allows only the approved subject and granted conditions. Signed audit exports reproduce evidence, verification, approval, and remediation history. The Evidence Packet QuickStart remains the commercial entry point, while durable packet-candidate issuance remains a Stage 4 production target.

Trust principles

Architecture that fails visibly

DigiTrust is designed so critical trust outcomes remain explicit, attributable, independently reproducible, and resistant to silent normalization.

Identity before interpretationTenant, case, artifact, actor, policy, plan, assertion, approval, and output identities must agree before a trust decision is accepted.
Provenance over presenceA document's existence is insufficient; its source context, lineage, event path, authority, and lifecycle matter.
Hard failures stay hardRevocation, invalid authority, separation-of-duties failure, snapshot drift, unresolved critical contradiction, prohibited disclosure, and unverifiable integrity cannot be downgraded.
Human authority remains accountableAgents, requestors, drafters, verifiers, and unauthorized people cannot create valid approval for their own consequential output.
Deterministic firstExplicit typed metadata, policy, evidence criteria, authority rules, timestamps, and hashes drive current trust decisions.
Exact-use authorizationApproval for one subject, version, report, scope, condition set, or time window cannot authorize another.
Corrections preserve historyRemediation creates new evidence, snapshots, and verification runs rather than overwriting a prior failure.
Qualify maturityImplemented reference behavior, deployed AWS patterns, design-partner activity, and future production targets are labeled separately.
Responsibility boundary

Deterministic trust controls and bounded AI assistance

Current trust outcomes do not depend on an LLM deciding whether evidence is true, sufficient, authorized, approved, or permitted for use.

Deterministic responsibilities

  • Canonical identity, hash, signature, chain, chronology, and tenant/case checks
  • Artifact lifecycle and terminal replacement resolution
  • Exact provenance paths and required evidence-event or invocation links
  • Eight evidence-quality dimensions and explicit claim-support criteria
  • Typed assertion comparison, authority resolution, and critical contradiction outcomes
  • Audience, purpose, classification, redaction, tenant, and prohibited-category disclosure policy
  • Approver authority, separation of duties, expiration, revocation, and exact-use authorization
  • Append-only remediation and independent audit reconstruction

Bounded AI-assisted responsibilities

  • Guide a user through approved evidence and review workflows
  • Summarize already-verified findings for a defined audience
  • Draft customer-safe language without changing the canonical trust outcome
  • Help explain remediation while preserving the original failed record
  • Operate only through governed tools and delegated authority
  • Keep public demonstrations synthetic and read-only

Future semantic analysis, if introduced, must remain separately bounded and cannot override deterministic hard failures or create human authority.

Evidence quality

Eight dimensions make support inspectable

DigiTrust verifies the quality of evidence, not merely whether a document exists. Current checks use declared metadata and explicit policy. DigiTrust does not infer truth from arbitrary prose.

IntegrityAre record identity, structure, hashes, signatures, and linked histories intact?
AuthorityDid an allowed source and exact authorized verifier act within approved scope?
ProvenanceDoes a complete case-scoped path connect the artifact, declared event or invocation, and trust context?
FreshnessIs the signed collection time within the explicit threshold for its type and classification?
LifecycleIs the evidence active, stale, superseded, revoked, or replaced by a verified active terminal?
RelevanceDo declared types, sources, media, controls, and mappings match the claim's explicit criteria?
CompletenessAre required metadata fields and the minimum number of usable evidence items present?
IndependenceAre drafting and verification duties assigned to distinct, exact actor identities when required?

Structured contradiction and disclosure controls extend the quality model. Comparable typed assertions are evaluated under explicit scope, time, lifecycle, authority, and classification rules. Proposed external outputs are checked against explicit audience, purpose, tenant, classification, reference-mode, redaction, and prohibited-category policy.

Human authority and remediation

Consequential use requires exact, attributable approval

Approval is not a free-form note. It is an immutable, signed decision bound to the exact verified subject and the canonical case authority that reviewed it.

Approval subject

Binds tenant, case, subject type, identifier, version, ordered content, findings, limitations, verification run and report, disclosure result, actors, classification, and subject hash.

Authority snapshot

Derived from the canonical case record and rechecked at decision time. The assigned human approver must remain current, authorized, and separate from request, drafting, and verification roles.

Decision chain

Approve, reject, request changes, expiration, and revocation are append-only durable outcomes. Changed replay requests fail closed; concurrent conflicting decisions cannot both commit.

Durable remediation

The original failed verification and selected findings remain immutable. Progress references same-scope Evidence Events. Completion requires a different later independently verified run, and result events must occur strictly after opening and before the snapshot that binds them.

Exact-use authorization

The authorization boundary revalidates the approval chain, subject hash, verification report, Stage 3B2 result, authority, case state, expiration, revocation, scope, conditions, and evaluation chronology. Any mismatch fails closed.

Security and privacy boundaries

Bind what matters. Expose only what is needed.

Reference controls demonstrate the architecture without claiming production identity, non-repudiation, certification, or full production availability.

Current reference safeguards

  • Tenant- and case-scoped durable records
  • Append-only evidence, verification, approval, and remediation histories
  • Canonical SHA-256 hashes and demo HMAC signatures
  • Governed tool authorization and explicit delegation scope
  • Deterministic contradiction, disclosure, approval, and authorization controls
  • Minimized provenance and customer-safe output patterns
  • Synthetic, read-only public ChatGPT demonstration

Explicit exclusions

  • No production KMS, HSM, or hardware-backed signing claim
  • No production identity-provider integration or non-repudiation claim
  • No independent certification, audit opinion, or legal determination
  • No production customer evidence in the public demo
  • No free-form semantic truth inference; contradiction checks use typed structured assertions
  • No durable Evidence Packet or packet-candidate approval claim yet
  • No claim that assurance replaces customer legal, audit, procurement, security, or compliance judgment
Current maturity

Implemented reference controls and a deployed AWS pattern

DigiTrust currently demonstrates governed agent and tool execution, immutable evidence and lifecycle records, provenance, deterministic eight-dimension verification, durable verification operations, structured contradiction and disclosure controls, durable human approval, remediation, exact-use authorization, and signed audit reconstruction.

The control plane is deployed on AWS through GitHub Actions. Commercial work remains in design-partner and limited-onboarding stages. Production identity, signing, cloud-native persistence, customer connectors, durable Evidence Packets, operating controls, retention, and notification workflows remain future milestones.

Known limitations

  1. 1
    Reference persistenceSQLite demonstrates durable behavior and transaction boundaries but is not the target production data architecture.
  2. 2
    Reference signingDemo HMAC validates binding logic but is not production KMS signing, HSM-backed non-repudiation, or identity attestation.
  3. 3
    Declared metadata boundaryEvidence relevance and disclosure classification use explicit typed metadata and literal patterns rather than unrestricted semantic inference.
  4. 4
    Packet boundaryDurable Evidence Packets and packet-candidate approval remain unavailable until Stage 4 implements a reproducible packet snapshot.
Deployed AWS reference pattern

AWS runtime and Marketplace availability

DigiTrust completed AWS partner onboarding, validated the reference architecture through the AWS engagement, and deployed the control plane on AWS through GitHub Actions.

Marketplace status: DigiTrust passed the AWS AWS solution review and is publicly listed for customer purchase in AWS Marketplace. View the listing. Marketplace availability does not imply AWS endorsement or certification of every product claim.

Deployed reference path

  1. 1
    Deliver through GitHub ActionsOIDC-based AWS access, CodeBuild, Amazon ECR, and Amazon ECS Fargate provide automated deployment.
  2. 2
    Govern Amazon Bedrock executionApproved model paths, evidence mapping, baseline controls, and fail-closed route posture make model selection inspectable.
  3. 3
    Use AWS data and security servicesAmazon DynamoDB, Amazon S3, AWS IAM, AWS KMS, and AWS Step Functions support the deployed architecture pattern.
  4. 4
    Operate and recoverAmazon CloudWatch, AWS CloudTrail, EventBridge, SQS, SNS, and AWS Backup support telemetry, lifecycle events, alerts, and recovery.

Review the architecture against one consequential AI decision

Choose a workflow, evidence source, approval boundary, or cloud integration and request a scoped walkthrough with DigiTrans.