Sealed decisions
Every council judgment becomes a decree identified by a SHA-256 hash of its exact content. A decree carries no credentials and cannot act on its own.
Systems
Every part of Stone, where it sits, and what it does. Drag to orbit. Click any pillar. Press F to fire a request through all of it. Each part is labeled with its real status — nothing here is dressed up as shipped when it isn't.
The request that travels the model is example data — for illustration. If WebGL is unavailable, the same twelve parts render as a card grid with the same descriptions.
How to explore it
Drag to orbit, click any pillar, or fire a request and watch it cross every checkpoint. Every part carries its real status — and where StoneAI already runs a live equivalent, the panel says so.
Keys — F fire a request · T tour · ←/→ step the tour · C cinematic · 1–4 arrangement · L labels · R reset · Esc close. Keys respond while the model is on screen.
Live in production today
Specific, checkable, and running. This is the part of the platform you can use and verify today.
Every council judgment becomes a decree identified by a SHA-256 hash of its exact content. A decree carries no credentials and cannot act on its own.
Every approve or deny is Ed25519-signed over the tenant, decree, scope, content hash, a one-time nonce and an expiry. Change one byte of the decree and the signature no longer verifies.
Each tenant's ledger links every entry to the one before it by hash, with a per-tenant lock so the chain can't fork. Updates and deletes are blocked at the database.
Any decision can be verified without an account at /proof — signature, decree binding, ledger entry and outcome. Merkle roots of the ledger are submitted hourly to OpenTimestamps for independent timestamping (best effort).
Postgres FORCE ROW LEVEL SECURITY scopes decrees, approvals, the ledger and billing to a single tenant — enforced by the database, not by application code alone.
Model seats deliberate independently; the outcome is a majority vote with a deterministic tiebreak, and if every seat fails the answer is hold. Built for many providers — live seat health is published on /status.
Don't take our word for it
The strongest claim a governance system can make is one you can check without asking us.
Straight talk
StoneAI holds no third-party certifications — no SOC 2, no ISO 27001, no ISO 42001 — and software can't make your organization compliant. What StoneAI produces is the evidence auditors ask for: signed, hash-chained, independently verifiable records of who approved what, and when.