COMPANY

About Proof of Operator

Proof of Operator is a machine-verifiable assessment platform that cryptographically seals human operational readiness audits and authorship proofs.

It exists to give organisations deploying AI a defensible record of human oversight, built for EU AI Act Article 14 and Article 26.

The methodology rests on seven filed utility models covering assessment methodology, cross-reference analysis, evidence scoring, and cryptographic attestation. Each audit mints a SHA-256 sealed certificate, verifiable by any third party through the public ledger.

Proof of Operator is part of the Brainiac Ltd infrastructure stack, alongside Digital Sovereignty. Together they provide the compliance and cognitive infrastructure layer for organisations operating autonomous systems under regulatory scrutiny.

Brainiac Ltd
167-169 Great Portland Street, London, W1W 5PF
Infrastructure Stack
Ghost OS

Registered in England and Wales. Operating from Prague, Czech Republic.

Open Source

Transparency by design

The audit runs entirely in your browser using Presence.js, our open-source browser intelligence framework. 52 signals. 9 intent states. Zero cookies. Zero backend calls. Under 15 ms.

Read every line of code that touches your data. The entire framework is MIT licensed and available on GitHub.

View on GitHub
MIT License. 52 signals. Zero dependencies.
Origin

Proof of Authorship

Upload any file. ORIGIN hashes it in your browser. Presence reads your session signals at that exact moment. Both are sealed into a certificate with a timestamp that cannot be backdated.

Machine-verifiable proof that you created this, in this session, at this time. Not reconstructed. Not approximate. Cryptographic.

Seal a File
Your file never leaves your browser. Only the SHA-256 hash is recorded.
Validation

Adversarial Validation

16 September 2026, full credential and source audit. It found a leaked production key. The key was rotated and both source repositories purged the same day.

18 September 2026, three-round architecture arbitration. It found the multi-model judge panel design wrong. The panel was demoted to claim extraction and Proof of Comprehension was renamed Proof of Response.

19 September 2026, full surface enumeration against the deployed bundle. It found the rebuilt verification path calling a broken backend. It was repaired and live-tested the same day.

What This System Does

No claims beyond what is built and tested. August 20, 2026.

What exists right now

A 30-question assessment

LIVE

Thirty questions across eight domains. Each domain maps to a specific sub-paragraph of EU AI Act Article 14(4). The questions test whether a human operator of an AI system can do what the law requires: understand the system, monitor it, recognise automation bias, interpret outputs, and stop it when needed.

Status: LIVE. Mappings verified against Regulation 2024/1689, Article 14(4)(a) through (e).

The assessment runs entirely in your browser

LIVE

No data is transmitted to any server while you answer. Zero bytes. The score is computed locally. The only thing that crosses the network is the final result: a SHA-256 hash, the tier, and the date. Your answers are not stored.

Status: LIVE. Verified by network inspection.

A published scoring formula

LIVE

The complete scoring method is public. Nine steps. Every weight, every threshold, every penalty. A worked example showing the exact calculation from raw answers to final score. An auditor can reproduce the score from the inputs.

Status: LIVE. Published on the methodology page.

A SHA-256 seal stored in a public registry

LIVE

When you complete the assessment, a hash is generated and stored. The registry is public. 10 seals are currently in it. Each seal has a tier (SOVEREIGN, HARDENED, CAPABLE, STANDARD, UNVERIFIED), a score, and a timestamp.

Status: LIVE. 10 seals. Verifiable at /ledger.

Independent verification of any seal

LIVE

Anyone can verify any seal at any time. Enter the hash at /verify. The system returns the tier, the score, the date, and the full verification history. Each verification is logged and cryptographically chained to the previous one. Verification logging is currently paused while a documented recovery completes. Seals remain independently verifiable at /verify.

Status: LIVE. Seals verifiable at /verify.

A witness engine using four independent organisations

LIVE

The public company audit feature is designed so that four models from four independent organisations (OpenAI, Anthropic, xAI, Google) independently analyse the same question. Each returns findings without seeing the others. If three or more agree, convergence is green. If two agree, orange. If one, red. The result is sealed with SHA-256. The feature is currently unavailable: it was suspended after we found a defect in how it validates its inputs. Status: Suspended pending a verified fix.

Status: LIVE. Tested with 3/3 green convergence.

Bilingual support (English and Czech)

LIVE

The entire site, including the assessment, methodology, and verification pages, is available in English and Czech. Language is detected automatically.

Status: LIVE. All pages verified in both languages.

Try it yourself: Build a hash chain

This is the same mechanism that seals every assessment on auditproof.pro. Type entries below. Each entry gets a SHA-256 hash that includes the previous entry's hash. Then try tampering with an earlier entry and watch the chain break.

#1
SHA-256:bc15d2bafb246031bb8e717d1c6601d7...
#2
SHA-256:7cfc403b67904ceea2ead31dc2b98979...
#3
SHA-256:89290b9ead20e8113cf41fee825860f3...

Chain format: hash = SHA-256(previousHash + "|" + entryText). Initial previous hash: GENESIS.

The witness engine, evaluated by itself

On August 20, 2026, we submitted the framework behind this system to the three AI witnesses for independent evaluation. This is what they said.

3/3 Convergence - GREEN

Three witnesses from three independent providers. None could see the others' responses.

Grok-4.3 (xAI) - Philosophical Soundness: 8/10

"Strong application of Popper's falsificationism and verisimilitude to treat truth as a resilient trajectory rather than absolute certainty. The framework is philosophically coherent and technically plausible in high-stakes domains."

Qwen-3.6-27B (Alibaba via Groq)

Verified the six-level architecture as a coherent progression from temporal integrity to epistemic convergence. Identified outcome verification as the key dependency requiring external data sources.

Gemini-3.6-Flash (Google)

Confirmed the framework's philosophical grounding. Identified the main bottleneck as potential correlated training-data bias across AI witnesses.

SHA-256 SEAL: 42ec7c16694965e8e00b4216175055b66f00527d75b1d8821b68e51b81ee640b

TIMESTAMP: 2026-08-20T21:17:02Z | WITNESSES: 3/3 VERIFIED | CONVERGENCE: GREEN

What we are building next

These are specific engineering tasks, not vision statements. Each has a reason.

Evidence binding

Right now the system records what you say. We are adding the ability to upload a document alongside each answer. The document gets its own SHA-256 hash linked to the answer. A verifier can request the document, check it against the hash, and decide whether it supports the claim. This moves from recording what people say to recording what people can show.

Status: Designed. Next to build.

Rotating question pool

Today there are 30 fixed questions. We are expanding to a pool of 60. Each assessment randomly selects 30. Two companies taking the assessment on the same day answer different questions. Same methodology, same scoring, different specific questions. This makes preparing answers in advance harder.

Status: Designed. Next to build.

Periodic re-assessment

A seal today says what your oversight looked like when you took the test. We are building a 90-day re-assessment cycle. Your seal will show your score history over time. A company that has maintained SOVEREIGN across three consecutive assessments is different from one that scored SOVEREIGN once and never tested again.

Status: Designed. Next to build.

Outcome tracking (when data is available)

The EU AI Act requires incident reporting under Article 73. When that database becomes public, we will connect to it. A seal from a company with zero incidents will carry more confidence than a seal from a company with incidents. This feature depends on external infrastructure that does not exist yet. Status: Architecture designed. Blocked on EU Article 73 data availability.

Status: Designed. Next to build.

What this system does NOT do

It does not certify legal compliance

The assessment produces evidence of oversight capability. It is not a legal certification. A SOVEREIGN seal is not proof you will not be fined. It is evidence you can show a regulator.

It does not guarantee the answers are honest

The assessment is self-reported. The hash chain proves the answers have not changed since they were sealed. It does not prove they were true when given. The scoring formula includes penalties for overconfidence and uniformity, but it cannot eliminate self-reporting bias.

It does not monitor your ongoing operations

The seal is a point-in-time record. It does not track whether your oversight has improved or degraded since the assessment. The 90-day re-assessment cycle is designed to address this.

It does not replace a lawyer or a consultant

The gap report identifies weaknesses. It does not tell you how to fix them in your specific legal context. For that, you need a lawyer or a consultant.

It has not been endorsed by any regulator

No EU regulator or standards body has reviewed this methodology. It is grounded in the published law, but whether a regulator accepts it as sufficient evidence is their judgment, not ours.

What it costs

Free

Assessment

30 questions. No login. No data collected.

EUR 25-100

Attestation

Sealed report with score, domain breakdown, and SHA-256 seal.

EUR 870

Gap Report

Detailed report showing weak domains and what to fix.

EUR 2,900+

Consultancy

Help implementing fixes. Human interpretation. Brainiac Ltd.

Everything in "What exists right now" was verified against the live system on August 20, 2026. Everything in "What we are building next" is designed but not yet built. We will update this page as each feature ships. If anything stated here is not true, the seal hash and verification log will show it.

Compliance

We Audit Ourselves First

Brainiac Ltd's public AI oversight compliance record. The company selling verification verifies itself.

Company: Brainiac LtdPublished: 2026-08-18Version: 1.2Status: ACTIVE
Article 14 Status

EU AI Act Article 14(4)(a)-(e) - Human Oversight Requirements

Art. 14(4)(a)
Monitoring
DOCUMENTED

Backend function logs reviewed weekly. Witness engine tested against known targets before production use. Named operator: Thomas Krojzl.

Art. 14(4)(b)
Bias Prevention
DOCUMENTED

Three independent model families from three providers (xAI, Alibaba, Google). Provider diversity prevents single-model bias. Bias detection questions in assessment Domain 3.

Art. 14(4)(c)
Output Interpretation
DOCUMENTED

Every witness finding includes source URL and verbatim quote. Convergence matrix (3/3, 2/3, 1/3) displayed. Scoring methodology published openly.

Art. 14(4)(d)
Override Authority
DOCUMENTED

Operator reviews all witness outputs before delivery. Can reject, modify, or revoke any seal. Override threshold: all scores above 0 require human review.

Art. 14(4)(e)
Emergency Intervention
DOCUMENTED

All backend functions individually disableable. Witness engine halted by removing API keys. Fallback: manual assessment using published methodology.

POLICY DOCUMENTS

Reviewed operational documents

Incident Response Plan
PUBLISHED

3 severity levels, 7-step response procedure, emergency shutdown instructions, roles and authority.

View document
Bias Testing Protocol
PUBLISHED

5 known bias types, monthly testing procedure, 4 target categories, detection triggers, remediation process.

View document
Human Override Log
PUBLISHED

4 override scenarios, log format, integrity requirements, quarterly review process, public transparency.

View document
Incident Reporting Process
PUBLISHED

Article 73 criteria, 72-hour timeline, NUKIB and ICO contacts, report content template, voluntary reporting.

View document
AI Systems Operated

The three AI systems Brainiac Ltd operates, and how each is overseen

1
Witness Engine
Triple-AI cross-verification
Models
grok-4.3 (xAI)
qwen/qwen3.6-27b (Groq/Alibaba)
gemini-3.6-flash (Google AI Studio)
Human Oversight
All outputs reviewed by operator before delivery. Review log published.
Risk Level
Limited (produces evidence, not regulatory decisions)
2
Assessment Scoring Engine
Deterministic scoring algorithm
Models
None (rule-based)
Human Oversight
Weights designed by operator, published openly, versioned.
Risk Level
Minimal (transparent, deterministic, auditable)
3
Presence Engine
Browser signal collection
Models
None (client-side only)
Human Oversight
Signal list curated by operator. Inferred data excluded.
Risk Level
Minimal (no data transmitted, no decisions made)
Witness Engine Result

Last independent multi-model verification run against Brainiac Ltd

Operator Status

The designated human responsible for AI oversight

Governance Policy

Full AI oversight governance policy - publicly accessible

AI Oversight Governance Policy covering 3 AI systems: Witness Engine, Assessment Scoring Engine, Presence Engine. Maps to EU AI Act Article 14(4)(a)-(e).

View Full PolicyDownload PolicyPublished: 2026-08-18
Data Protection

How we handle data across our systems

Presence Engine
Zero bytes transmitted. All signals processed client-side.
Assessment Data
Hash only stored. Individual answers not retained after scoring.
Witness Data
Publicly available web pages only. No private data accessed.
Storage Location
EU infrastructure (Base44).
Pending Actions

What is still in progress - shown honestly

  • Operator assessment (Thomas Krojzl to take 30-question assessment)
  • Article 14 self-assessment (after operator assessment)
  • Professional indemnity insurance (in progress)
  • Legal review of terms and conditions (pending)
  • Backup operator designation (before first paying client)
TRANSPARENCY LOG

Revocation Transparency Log

0
Total Events
0
Seals Tracked
0
Revoked Seals
INTACT
Chain Integrity
Žádné revokace zaznamenány. Všechny pečeti aktivní.
ADMIN AUDIT TRAIL

Chronological record of admin actions

No admin actions logged
GDPR RIGHTS

Data Subject Rights

You have the right to export all your data and the right to erasure. These endpoints comply with GDPR Articles 17 and 20.

Please enter your email to proceed.

Data Export (Article 20)
GDPR Articles 17 & 20

Proof of Operator provides independent operator capability assessments. It is not a legal certification of compliance with Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, or any other regulation. Brainiac Ltd is not liable for regulatory decisions based on the seal. Companies should consult their own legal counsel regarding their specific regulatory obligations.
Brainiac Ltd - 167-169 Great Portland Street, London, W1W 5PF
© 2026 Brainiac Ltd. All rights reserved.

Brainiac Ltd is registered in England and Wales. Operating from Prague, Czech Republic. Proof of Operator is an independent AI oversight verification tool. Seals are not regulatory certifications. All methodology is publicly auditable.

Brainiac Ltd. Make your Presence felt.