The read connectors carry no write method and Nerio has no tool that can act, so a deployment of Nerio alone writes nothing, anywhere. Writing is a separate product you choose to add: Minerva executes only what a person authorized, records the reversal before each write, needs two people above a threshold, and chains every write. Its ERP adapters are declared and answer 501 by name until each ships, so today Minerva writes only to its own ledger. The write-path suite proves the connectors carry no write method, 9 of 9.
Trust Center
What we can prove,
and what we cannot.
Published so it can be read before it is relied on, rather than sent after a security questionnaire arrives. Everything below is either verifiable today or marked as not yet true.
Security architecture
These are consequences of how the product is delivered, which is why the answer is the same in a first call and in a security review.
What you deploy makes no external calls at runtime and carries no third-party package tree to review. It runs air-gapped.
Enforced and executed as a test suite rather than asserted in a document. Cross-tenant access fails closed.
Your reviewer can recompute the identity of what they received and compare it to what was sealed, without trusting us or anyone else.
Verification, by engagement
No account, no form, no contact with us. Tested: the harness carries no sign-in, no access request and no gate.
| Artifact | What it does |
|---|---|
| Source-level diligence | Runs the release integrity gate against the platform's own source. Because it reads the source, it is released under the master services agreement rather than published here. |
| verify.sh | Recomputes the content identity and compares it to the sealed receipt |
| battery-count.sh | Recomputes the assertion count from the run log, rather than reading a stated total |
| receipt.json | The sealed record the other three are checked against |
All four at /verify/ · offline · no network required
Data handling
| Question | Answer |
|---|---|
| Does data leave our environment | Only if you connect something that takes it there. The platform reports, per data class, whether it stayed inside or left |
| Which models see which data | You set the policy. Connect the providers you have already approved, cloud, private or local |
| Is anything written back | No. Read-only toward every system of record |
| Where is data stored | In your environment. This layer holds derivations and decisions, not copies of your systems |
| Retention | Set by you. Evidence packs export and remain verifiable after the platform is gone |
| Sub-processors | None required for the air-gapped deployment. Any optional integration you connect is listed with its data class before it is enabled |
Intellectual property and the moat
The claim ranking, the evidence and decision model, the reconciliation engine, the Proof Object format and the Verify Standard specification. Held by AssetShop.
The Verify Standard and the Proof Object schema are open under CC BY 4.0. A standard only creates a moat if competitors can adopt it.
Not the code. The discipline: model consensus ranked below deterministic calculation, enforced by assertions that fail if a rung is skipped.
Exported evidence still verifies after you stop paying us. That is a deliberate constraint on our own leverage.
The workforce covenant
EOS returns operator hours. What a customer does with those hours is the part most vendors decline to have an opinion about. We take one.
The commitment. A customer commits that operator hours reclaimed through AssetShop EOS will not be attributed to workforce reduction, and acknowledges the alternatives: growing sales, funding innovation, strengthening customer service, training people properly, and opening new segments. Reclaimed capacity is redeployed, not removed.
| Instrument | What it means |
|---|---|
| Good-faith covenant | A mutual undertaking in the agreement itself, not a preamble or a marketing line. It sits at Section 12.14 of the Master Services Agreement. |
| Annual CHRO self-attestation | Once a year the customer's chief people officer attests to the covenant per Exhibit G. Self-attested, and named as self-attested: we do not audit a customer's headcount and would not want the access required to. |
| Subscription term plus a twelve-month tail | The covenant outlives the subscription by a year, so canceling is not a route around it. |
| A remedy that means something | On breach we may cease the Services and terminate, with no refund of fees paid or committed for the current term. A covenant with no consequence is a preference, not a commitment. |
Why we write this in. A procurement tool that quietly funds redundancies is a worse product, not a better one. The value of EOS is that a contested figure reaches a named human faster; that argument collapses if the humans are the saving. Writing the covenant into the agreement is how we keep our own incentive honest, and it is a constraint on us as much as on the customer, because it rules out the easiest sales story in the category.
What it is not. It is a covenant, not a guarantee, and the attestation is the customer's own. We cannot see inside an organization's staffing decisions and have deliberately not built the ability to. What the instrument does is make the commitment explicit, dated, signed and durable past the term, so that a decision to break it has to be a decision rather than a drift.
What breach costs. We may stop providing the Services and terminate, and fees paid or committed for the current term are not refunded. We would rather say that plainly here than have a procurement team find it late. It applies to attribution, meaning whether EOS is cited as the justification for a reduction, not to a staffing decision that would have happened regardless. And it is not a right we would exercise on suspicion: the agreement provides for written notice naming the attribution relied on, a cure period, and escalation to named executives on both sides before anything stops.
Contract terms including the MSA, the DPA and service-level terms are drafted to counsel-review standard, with a counsel pass before signature. Exhibit G is drafted with them.
Legal and corporate
Enterprise procurement asks who they are contracting with. The honest answer is a hierarchy.
| Layer | What it is |
|---|---|
| Web3 Ventures Enterprise | The company. Holds the intellectual property, the platform, the capital structure and the governance. The counterparty on the contract |
| AssetShop | The brand. The name on the contract, the site and the product |
| EOS | The platform. It holds Nerio (read-only), Minerva (write, only what was authorized), Honos, Fides, Forculus and Portunus |
| Nerio | The observation intelligence. Read-only toward every system of record; serves your AI governed context Read how |
| Minerva | The action intelligence. Executes only approved requests, reversibly, on a per-organization chain; ledger today, ERP adapters as they ship |
| Minerva | The write side, a separate product, so EOS can run read-only unless you choose it. It executes only what a person has authorized; every write is reversible, dual-controlled above a threshold, and hash-chained. Read how |
| Fides | The partner layer. Decides what may cross between organizations, at which rung and under whose grant. Read how |
| Forculus | The integration layer. Systems and machines as identities: signed ingress, minimal egress, commands only on approval. Read how |
| Portunus | The traceability layer. Identity, custody on receipt, a footprint that names its factors, and end of life. Read how |
Two delivery models
The platform is delivered one of two ways, and the trust posture is different for each. Hosted leads; Sealed is for organizations that cannot let a control plane outside their boundary.
| Model | Where it runs | Who can see what | Sub-processors | Status |
|---|---|---|---|---|
| Hosted | The control plane on Google Cloud Run in us-central1, with Firestore as the record and Secret Manager for credentials. Read-only connectors reach your systems from there. | Your organization sees its own record in full; the operator sees service health and structured request logs that carry an account id and never a payload; nobody else sees anything. | Google Cloud, Stripe, Anthropic, Netlify, Pinata, SendGrid. Each named here; a data processing addendum is being drafted with counsel. | BUILT. Preconditions for a hosted pilot: the on-call runbook and a rehearsed restore, both open. |
| Sealed | A sealed artifact inside your boundary. No control plane outside it; the record and the evidence stay where you put them. | Only your organization. The operator sees nothing. | None. | The artifact and the verifier ship today; the packaged install for a customer boundary is not yet built. |
Independent assurance planned. Timing stated when an observation window is set. No certification is claimed for either model; the controls map is available on request.
Availability
The enterprise product is served from conventional hosting with an uptime commitment.
Air-gapped deployment removes the question entirely