How It Works
How ZK-AI Works
A machine acts. A receipt is created. The receipt proves itself. The chain witnesses it. The Evidence Graph makes it findable. The Sigil tells you what level of proof has been reached. That is ZK-AI — not a dashboard, not a promise, a protocol.
- 01
One receipt. All the way through.
Every machine action produces a ZK-SNAP receipt. That receipt gets a Sigil showing what level of proof it has reached. ZK-AI Chain provides governed on-log recognition when the full anchor path exists. The Evidence Graph makes it findable from the content alone. 3DVC is the program mark for operators who pass independent testing when the governed program is active. These are not separate products — they are one protocol.
- 02
What Is a ZK-SNAP Receipt?
A signed record created at the moment a machine acts. It binds the action, the content, the claim, and the signature together — then proves itself using only mathematics. No server, no network, no original platform required. If anything changes after signing, the proof breaks.
- 03
Why Not Just Use Logs?
Logs live inside the system you are questioning. Files move. Platforms shut down. Dashboards go behind logins. Metadata gets stripped. When you need to prove something happened, the log is usually owned by the same party whose word you cannot take. A ZK-SNAP receipt is portable. It survives outside the system that created it.
- 04
S4 Proven: Mathematics Alone
When a receipt passes cryptographic verification, it reaches Sigil S4 — Proven. No network required. No server call. No company still existing. The structure, signature, and declared profiles all check out from bytes alone. S4 is the baseline: independent proof that this receipt is real.
- 05
S5 Recorded: On the Chain
S4 says mathematics prove this. S5 says mathematics prove this, and governed Chain evidence records it at a specific time — so anyone can verify not just that the receipt is valid, but when it was witnessed on-log.
- 06
3DVC: The Certification Mark
A certification mark means independent testing happened — not self-declaration. Operators must pass the 3DVC Conformance Suite through an independent testing authority before the mark can be displayed. Validity, Transparency, Finality, and Context all need to pass. Any system can issue ZK-SNAP receipts and show Sigils. Only qualified operators earn 3DVC when the governed program is active.
The Trust Flow
The Trust Pipeline
Every receipt flows through the same stages. Mathematical proof first. Governed on-log witness evidence second. Independent certification for operators who earn it. The trust builds progressively — and each stage is independently verifiable.
- Action creates receipt
- Every machine action generates a signed ZK-SNAP receipt at the moment it happens.
- Cryptographic proof (S4)
- The receipt proves itself using only math — no network required. This is the 'Proven' state.
- Chain anchor (S5)
- Receipts batch into a compact on-log commitment on ZK-AI Chain for governed timestamp evidence.
- Discovery layer
- Evidence Graph indexes receipts so they remain findable even after files move or are copied.
- Certification (3DVC)
- Operators who pass the 3DVC Conformance Suite earn the right to display the program mark when the governed program is active.
1
What Is a ZK-SNAP Receipt?
A signed record created at the moment a machine acts. It can describe a file, image, dataset, tool action, robot command, settlement event, or public record. What makes it different from a log: it proves itself. You do not need to ask the original platform. You do not need to check a dashboard. You do not need to trust a vendor's database. The mathematics do the verification.
- Claim
- What the receipt says about the file, action, dataset, or record — the who, what, and context of the machine action.
- Fingerprint
- A cryptographic hash that changes if a single byte of the underlying material changes. The content proves itself.
- Signature
- Proof that a specific issuer key signed this exact receipt object. Edits break it. That's the point.
- Sigil
- The trust mark showing what level of proof has been satisfied — from S4 (mathematics alone) to S5 (recorded with governed on-log witness evidence).
2
Why Not Just Use Logs?
Logs live inside the system that produced them. The same system you are trying to verify. Files move. Dashboards go offline. Metadata gets stripped. Accounts close. When something goes wrong — an AI makes a bad decision, a robot deviates from its safety policy, a dataset gets reused without authorisation — the log is usually owned by the same party whose word is in question. A ZK-SNAP receipt is portable. It is not owned by the platform. It survives the platform disappearing entirely.
3
S4 Proven: The Moment Mathematics Alone Are Enough
When a receipt passes cryptographic verification, it achieves Sigil S4 — Proven. No network. No server. No company still existing. The structure, signature, and declared profiles all check out from the bytes alone. S4 is the baseline guarantee: this receipt is real, independent of anyone's word. One Sigil. One glance. The proof is self-contained.
4
S5 Recorded: Recognized on ZK-AI Chain
S4 says: the mathematics prove this is real. S5 says: the mathematics prove this is real, and governed Chain evidence records it at a specific point in time. The receipt bytes do not change. Witness material attaches — linking the receipt to on-log recognition. S4 is independent proof. S5 is recognized on-log proof. Both are valid. The question is which one the situation requires.
5
The Evidence Graph
Nobody keeps the receipt file. They keep the content. Because ZK-AI receipts are anchored by content hash, the Evidence Graph can work backwards from the copy to the proof. Upload the image. Upload the export. Upload the screenshot. ZK-AI finds the receipt — no original file, no account, no platform. The Evidence Graph finds. ZK-SNAP and the chain determine validity. Those are separate roles by design.
receipt_idbatch_rootanchor_id- status
- time
- source artifact
- dataset
- audit package
- claim details
- sealed evidence
6
3DVC: The Certification Mark, Earned Not Automatic
Any system can issue ZK-SNAP receipts and show Sigils. That part is open. 3DVC is different — it is a formal certification program. To earn it, operators must pass formal conformance testing across four dimensions: Validity, Transparency, Finality, and Context. The mark signals that testing happened — by a third party, against published standards, before the mark could appear. It sits adjacent to the Sigil — never inside it, never automatic.
- Sigils (S0-S6)
- Always shown. Automatically computed from verification. Like a battery indicator for trust.
- 3DVC Mark
- Only shown if certified. Requires passing independent conformance testing by a third party.
- The difference
- Any system can use receipts and show Sigils. Only certified operators can display the 3DVC badge.
ZK-SNAP
What ZK-SNAP Is For
- Creators and rights
- Show which version was signed and what claim was attached to it.
- AI training and data audit
- Keep a checkable trail for dataset roots, pipeline stages, and audit claims.
- Agents and machines
- Record tool calls, commands, safety context, and evidence roots for later review.
- Public-interest systems
- Make proof visible without making every underlying document public.