SZL HOLDINGS · HONEST BY DESIGN

Cryptographic proof infrastructure for consequential AI decisions.

When an AI decision carries real-world weight, a promise isn't enough. SZL Holdings builds the proof layer beneath consequential AI — sovereign inference, DSSE-signed receipts, and machine-checked formal methods.

receipts.in ≡ receipts.out

  • 749Lean 4 declarations
  • P-256ECDSA signed receipts
  • 3-of-4BFT witnessed
  • Sovereignfirst inference

Choose the right surface

Product, evidence, and source stay distinct.

A public URL proves where a surface is published, not what is operational behind it. Follow the labels at each destination for its current evidence and runtime boundary.

Evidence vocabulary

Read the label before the claim.

MEASURED
Captured from named instrumentation.
REPORTED
Supplied by a source, not independently measured here.
MODELED
Produced by a model or scenario, not observed deployment behavior.
UNAVAILABLE
Required evidence is absent and represented as such.
UNSIGNED
Content exists without an approved signature; it is not verified.
CONJECTURE
Stated for investigation, not presented as a closed theorem.

The thesis

Proof, not promises.

Most AI systems ask you to trust them. SZL surfaces are designed to expose what was observed, what was signed, and what remains unavailable. A receipt is evidence only when its bytes, key, and source binding verify.

01

Sovereign inference

Supports owner-controlled inference paths. Each product surface reports the runtime it actually used; this front door does not infer sovereignty from a URL.

02

Signed receipts

Receipt-aware components can emit DSSE / ECDSA P-256 evidence. Missing keys or unverifiable signatures remain UNSIGNED or UNAVAILABLE; they never become verified by presentation.

03

Machine-checked truth

The governance aggregator Λ is formalized in Lean 4 + Mathlib. We state Λ-uniqueness as Conjecture 1 — not a closed theorem. Honest about what's proven and what isn't.

04

Multi-party witnessed

Khipu contracts model 3-of-4 witnessed agreement with independently signed action hashes. Runtime use and quorum completion must be proved by the consuming surface.

The ecosystem

One doctrine. Many organs.

A family of systems across szl-holdings, grouped by the job each does. Shared contracts do not erase distinct trust roots, deployment states, or evidence boundaries. A public link does not by itself establish runtime readiness.

Full source, repo by repo, at github.com/szl-holdings.

The anatomy

Five organs, one nervous system.

The five-organ model is an architecture map: reasoning, policy, receipts, witnesses, and egress. A deployed surface may implement only part of it; its own evidence must show which stages ran and whether a signature verified.

  1. 01

    Reasoning cortex

    szl-router can expose model and provider provenance; each response must carry its own measured runtime state.

  2. 02

    Trust gate

    The Λ aggregator scores each action and an advisory policy gate admits or holds it. Λ-uniqueness is Conjecture 1 — not proven trust.

  3. 03

    Receipt bus

    The szl-receipt DSSE / ECDSA-P256 primitive, hash-chained. UNSIGNED-honest when no key is present.

  4. 04

    Consensus

    khipu-consensus defines a 3-of-4 witness contract. A quorum is claimed only when its signed witness set is present.

  5. 05

    Egress

    vsp-otel defines auditable egress records; signed status depends on the emitted record and configured trust root.

Open the living anatomy →

The frontier

Open standards, not a walled garden.

SZL uses open attestation formats where each component's contract says so. Verification depends on the exact envelope, algorithm, and public key—not on a brand label or file name.

SLSAProvenance policy — what guarantees must hold.
in-totoStatement format used by applicable provenance records.
sigstore · cosign · DSSECompatible verification families; each artifact declares its exact contract.
szl-receiptShared receipt library with explicit VERIFIED, UNSIGNED, and UNAVAILABLE states.
Aug 2, 2026

The EU AI Act gets teeth

High-risk obligations — logging, transparency, record-keeping — become enforceable. A signed, replayable receipt is exactly that infrastructure.

EU AI Act →
Formal methods

Machine-checked goes mainstream

Proof assistants are moving from niche to expected. Λ is formalized in Lean 4 — and we label its uniqueness Conjecture 1, not a theorem.

Read the formalization →
Roadmap

Confidential compute

TEE-attested inference (H100/H200, TDX) is becoming the enterprise default. Sovereign-first today; hardware-attested inference is on the roadmap — stated honestly, not shipped-as-claimed.

Ask the brain →

Verify, don't trust

Verify the receipt that actually arrived.

This panel requests a live envelope and verifies it in the browser. If the service or public key is unavailable, it shows an explicitly illustrative sample instead of a success state.

  • 749 declarations · 14 axioms · 163 tracked sorries
  • Formalized in Lean 4 + Mathlib
  • DOI 10.5281/zenodo.20434308
  • SLSA L1 honest · L2 roadmap
szl-receipt · DSSE envelope CHECKING

        
Inspect the verification path: browser verifier source szl-receipt source

Use the brain

Ask the sovereign concierge.

Live replies are requested from szl-router and display returned provenance. When the endpoint is unavailable, the interface labels its bounded local answer as an offline sample.

Sovereign-first · honest provenance · no data leaves the substrate unless you arm a fallback.

Founder & CEO

Stephen Lutar

Stephen founded SZL Holdings to build what consequential AI actually needs: not louder claims, but verifiable proof. The result is a substrate where reasoning is sovereign, every decision is signed, and the hardest guarantees are checked by machines — not marketing.

“If a decision matters, it should leave a receipt. If a guarantee matters, it should be a theorem — or honestly labeled a conjecture.”