A policy records intent. It does not prove what happened.

You have the ticket. You have the account. But when an auditor asks who granted the authority, whether it was still valid, and whether execution stayed inside it, the answer is scattered across systems that were never designed to agree.

Cerydora connects the decision to the evidence—and preserves the basis for human review.

The operating arc

Record. Observe. Preserve.

Record

Capture the accountable official, purpose, limits, term, protected boundary, and required evidence in a versioned authority record.

Explore the platform

Observe

Normalize what directory, cloud, delegation, and execution sources report without letting a collector decide what the facts mean.

Inspect the evidence

Preserve

Seal the conclusion with its sources, timing, and coverage limits so a third party can inspect the record without the engine.

See offline verification

Platform

One proof engine. Four named surfaces.

Declared authority remains the standard. Evidence sources report what they saw; Cerydora reconciles those facts and routes consequential judgment to accountable people.

01 / RECORD

NHA Ledger

Shows what each governed service account, workload identity, bot, or AI agent was authorized to do versus what it was observed doing—across on-prem Active Directory, Entra ID, and supported activity sources.

Surfaces dormant, ownerless, over-privileged, and revalidation-required states where the evidence supports them.
02 / PRESERVE

Proof bundle

An open, signed evidence package with declared authority, evaluated conditions, source references, integrity material, and explicit coverage limits—the artifact an examiner receives.

03 / VERIFY

Offline verifier

Checks format conformance, payload integrity, signature validity, and issuer trust as four separate results, without contacting the engine or a network service.

These checks cover the package. Source truth and legal sufficiency require separate review.
04 / TRACE

Authorizer lineage

Ties each authorization to an immutable directory identity instead of a reusable username, then records when that approving principal is disabled or deleted.

What the record shows

Plain enough to inspect. Precise enough to defend.

Every evaluated condition lands in a closed disposition, with the evidence and timing behind it. The outward package can be curated without exposing internal working state.

Honesty rule: no evidence is not evidence of conformance. If an instrument stops reporting or evidence becomes stale, the record says so.

Cascadia / AUTH-CAS-2026-0011Demonstration

Agent operations / departed approver

AuthorizerDirectory account deletedauthorizer_deleted
Attestation currencyStale—no successor attestedstale_attestation
Actor fingerprintNot declaredunattested_execution
DelegationPlain AD, inferredunattested_delegation
OutcomeNo comparison builtnot evaluated

Internal operator view, as rendered for the synthetic corpus. The examiner projection withholds these determinations and says so. Names, identifiers, and evidence are fictional.

Cascadia / offline verificationSynthetic result
Format conformance
PASS
Payload integrity
PASS
Signature validity
VALID
Issuer trust
NOT ESTABLISHED

Four separate results; no aggregate “verified” verdict. Issuer trust is not established for the self-presented demonstration identity.

cerydora-verify <bundle> · no network.

Exit 0: format PASS, integrity PASS, signature VALID, issuer trust not MISMATCH. Issuer trust may still be NOT ESTABLISHED. Exit 1: verification failed. Exit 2: unreadable or structurally nonconforming input.

Crosswalk by reference

Evidences, never satisfies.

Framework identifiers travel with the authority record. Cerydora reproduces no control text, claims no certification, and does not decide whether a control is met.

NIST SP 800-53
Rev. 5 control identifiers.
IRS Pub 1075
Safeguard references by section.
Florida 60GG-2
Identity, authorization, and monitoring identifiers.
NIST AI RMF 1.0
Voluntary, tailorable context.

Offerings

A bounded way to put the evidence to work.

Each engagement starts with a named operation and a limited set of actors. The aim is usable authority evidence, not another abstract governance program.

Fixed-price engagement

AI Authorization Package

A fixed-price engagement to record, observe, and preserve accountable authority for a named set of AI systems and non-human actors.

Request the scope
Advisory engagement

AI policy stand-up

Put an agency or business AI policy in place, connect it to named decisions and evidence, and define how exceptions reach an accountable human.

Discuss a policy stand-up
Retained service

Managed authorization review

Work the non-human-actor authorization queue on retainer, with reviewer-role templates and request handling for cases such as app-registration admin consent.

Review the operating model
Florida agencies · evidence deliverable

60GG-2 Evidence Pack

Control-by-control evidence for Rule 60GG-2's identity, authorization, and monitoring subset, shaped for the July 31 gap assessment and the triennial risk assessment.

Review the named subset

Florida public sector · 60GG-2 Evidence Pack

Stronger governance, brighter tomorrow

Trusted AI for a more resilient public sector

Every Florida agency head files a strategic and operational plan with the Florida Digital Service by July 31, including a gap assessment against Rule 60GG-2, and re-authorizes systems through a triennial risk assessment. The named identity, authorization, and monitoring subset is PR.AC-1, PR.AC-4, PR.PT-1, PR.IP-7, DE.CM-3, DE.CM-6 and neighboring identifiers.

The Cerydora 60GG-2 Evidence Pack generates control-by-control evidence from recorded authority and observed activity: what each human and non-human actor was authorized to do, who granted it, whether it was still valid, and whether execution stayed inside it. Output is shaped for the July 31 gap assessment, the risk assessment's authorize-and-monitor steps, System Security Plan authorization-boundary sections, and after-action reports — each artifact signed and verifiable offline.

Coverage is the identity, authorization, and monitoring subset. It does not replace the agency's plan, training, network controls, or the information security manager's judgment.

Illustrative Florida-shaped network of anonymous evidence points
Illustrative evidence paths.

Latest

Latest from Cerydora

The authorization column

The NHA Ledger leads with one question for every service account, workload, and agent: is a current human authorization on record? Attested, unattested, no active authorizer, or not evaluated—each with its reason, and never a blank.

Product note

An offline verifier with four answers

Format, integrity, signature validity, and issuer trust stay separate. The verifier needs no engine connection and never turns missing trust into a clean result.

Product note

Authority is not an enforcement event

Other systems enforce or infer authority. Cerydora proves who granted it, whether it was still valid, and whether execution stayed inside it.

Field note

Company

Founder-led. Built in Florida.

Cerydora is founder-led and based in Florida, built by practitioners who have run identity, endpoint, and compliance programs inside regulated public-sector environments.

hello@cerydora.com

Operational boundaries

What the product does—and what it refuses to claim.

01

Decision authority remains human.

Cerydora never approves an activity. It makes the responsible person's decision precise, durable, and checkable.

02

Evidence sources report; the engine determines.

Evidence sources do not grade themselves. The declared authorization remains the standard.

03

Missing evidence remains visible.

Silence, gaps, and stale observations are recorded as such. They are not treated as evidence that the boundary held.

04

Working state and examiner evidence are distinct.

Internal detail stays separate from curated evidence views, while omissions and coverage limits remain explicit.

Cascadia corpus

A fully synthetic Cascadia corpus with 2025 source dates runs end to end: authorizer lifecycle and execution receipts reconcile as governed ledger records; internal views distinguish binding outcomes, authorizer currency, execution-continuity findings, and cases not evaluated; the served read-face exports in internal and examiner modes; and the offline verifier checks proof-bundle format v1.

Cascadia demonstration

Review the departed-approver case in five minutes.

Trace one authorization from the approving official through the day the directory deleted their account, the receipts the actors kept producing, and the four separate offline verification results.

Email instead

Submitting opens your email application. This site stores no form data and uses no tracking pixels.

Accessibility