Bidda Trust Hub =============== JS-free text mirror for AI crawlers. Canonical page: https://bidda.com/trust Last updated: 2026-08-04 TRUST & PROVENANCE Don’t trust us. Prove it. Guardrails prove your agent acted safely. Bidda proves what it relied on: a signed, independently verifiable record of exactly which obligation it consulted, and the source-verified version in force at that moment. You draw the legal conclusion; we give you the evidence. Verify a record Read the method THE THROUGH-LINE Resolve → Verify → Seal → Prove Four steps from a question to audit-ready evidence, each one a tool you can use today. 01 Resolve Find the exact obligation, cited to its primary source Every answer resolves to a specific instrument, article and jurisdiction, distilled from the primary legal text, not a model’s memory. Browse the registry → Compare jurisdictions → Browse by topic → Gap check → How it works → 02 Verify Check any answer against our published key, offline Each record is signed. You verify it yourself against our public keyset with no call back to us, so trust never depends on our uptime or our word. Verify a record → Signed records → Control attestation → Security model → 03 Seal Turn a whole agent run into one tamper-evident receipt Open a run, record every obligation an agent consulted and every decision it made, then seal it into a single signed, hash-chained receipt. Run receipts → Audit trail → 04 Prove Export the evidence, and know the moment a rule changes Produce an audit-ready evidence pack for a regulator or an underwriter, and get told the instant a source you rely on drifts or is withdrawn. Public transparency log → Drift check → Obligation change feed → Change alerts → Latest changes → Live status → THE PROOF The proofs behind every answer Trust is a property of the data, not a dashboard you have to watch. Each proof below is live today and something you can check yourself, no account required. Signature Ed25519, verifiable offline against our published keyset. DEFEATS TAMPERING, IMPERSONATION, MAN-IN-THE-MIDDLE Freshness Authoritative-as-of a timestamp, with a fresh / drifted / withdrawn status. DEFEATS ACTING ON STALE OR WITHDRAWN LAW Point-in-time Proof of exactly what the rule said at the moment you relied on it. DEFEATS THE "BUT THE RULE CHANGED" DISPUTE Transparency receipt Appended to a public, append-only log anyone can audit. DEFEATS QUIET, AFTER-THE-FACT EDITS BY ANYONE CONTENT INTEGRITY Screened before it’s signed Your agent treats a Bidda node as trusted reference data, so a poisoned source is a way to hijack the agent that reads it. Before any node is signed, we screen its text for indirect prompt-injection and agent-manipulation payloads, using a ruleset grounded in OWASP LLM01, MITRE ATLAS and NIST AI 100-2e. 10,099 NODES SCREENED 0 MANIPULATION PAYLOADS FOUND OWASP LLM01 MITRE ATLAS NIST AI 100-2e GROUNDED IN Screening is a pre-signing gate on the content we publish, not a runtime firewall for your own agent, and we state that boundary plainly. A small number of security-topic nodes quote attack strings as teaching examples; a human confirms those are descriptive, never served as instructions. How screening works → Every record, checkable by you Every record is something you can check yourself, and every change is something you can detect. If a record is altered, its signature fails and the public log shows it. We publish exactly what a sealed answer does and does not cover, so a security team can trust precisely what is claimed. Read the security model → Which of our cryptography quantum computers break Half of it, and we publish which half. Content integrity and the tamper-evident log are hash-based and unaffected. Record signatures are Ed25519, which is the layer on a stated migration path, and we name it rather than leave it implied. Every claim on that page comes with the command to check it. Read the cryptographic posture → ALIGNED TO EU AI Act Art. 12 & 15 → MITRE ATLAS → NIST AI RMF → ISO 42001 → CISA alignment → 10,099 obligations. Every answer, provable. Start with a record you can verify yourself, or talk to us about audit-ready evidence exports for your platform. Verify a record Seal an agent run Enterprise & evidence packs